Courseiva

PCNSA · topic practice

Managing Objects practice questions

The Managing Objects domain covers how PAN-OS stores and reuses address, service, application, and list objects that security policy references. Questions test object creation, naming, and reuse across zones and rules, plus External Dynamic Lists, VLAN interfaces, and deployment modes. Expect drag-and-drop ordering, matching, and multi-select items rather than long configuration scenarios.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Managing Objects

What the exam tests

What to know about Managing Objects

Be able to create and reuse address, service, and application objects, attach EDLs to policy, and order VLAN interface steps correctly. The single most important thing: know which object type belongs in each policy field and that referenced objects cannot be freely changed.

Creating address, address group, service, and application objects in the Objects tab

Using External Dynamic Lists (EDLs) sourced from URLs or IP feeds in policy

Configuring Layer 3 VLAN interfaces with zones, virtual routers, and security zones

Mapping firewall deployment modes such as tap, virtual wire, Layer 2, and Layer 3

Watch out for

Common Managing Objects exam traps

  • ▸Assuming an address object can be edited while referenced by a committed security rule; PAN-OS blocks or warns until references are removed.
  • ▸Confusing EDL source types and refresh intervals, or expecting EDL contents to be editable locally on the firewall.
  • ▸Forgetting that a VLAN interface needs a zone and virtual router assignment before policy can match traffic on it.

Practice set

Managing Objects questions

20 questions · select your answer, then reveal the explanation

Question 1hardmultiple choice
Read the full DNS explanation →

An organization has a data center with servers in the 10.10.0.0/16 subnet and remote users who connect via GlobalProtect. The security team wants to ensure that only approved applications (web-browsing, ssl, dns) are allowed from the remote user subnet (172.16.0.0/24) to the data center. They create a security rule with source zone 'GP' (GlobalProtect), destination zone 'DC', source address '172.16.0.0/24', destination address '10.10.0.0/16', application 'web-browsing', 'ssl', 'dns', action 'allow'. After deployment, users complain that they cannot access a custom web application on port 8080, which uses HTTP but the application is identified as 'web-browsing'. The administrator checks the traffic logs and sees that the traffic is being denied by an implicit deny rule. What is the most likely cause?

Question 2mediummultiple choice
Read the full Managing Objects explanation →

Refer to the exhibit. An administrator configured a dynamic address group named 'WebServers-Group' with filter 'WebServer-*'. However, the group does not include the address objects 'WebServer-1' and 'WebServer-2'. What is the most likely reason?

Exhibit

Refer to the exhibit.

deviceconfig {
    devices {
        localhost.localdomain {
            vsys {
                vsys1 {
                    address {
                        entry {
                            @name = "WebServer-1";
                            ip-netmask = "10.0.1.10/32";
                        }
                        entry {
                            @name = "WebServer-2";
                            ip-range = "10.0.1.20-10.0.1.25";
                        }
                        entry {
                            @name = "WebServers-Group";
                            dynamic {
                                filter = "'WebServer-*'";
                            }
                        }
                    }
                }
            }
        }
    }
}

Which TWO of the following are valid methods to add an IP address to a pre-existing address group in PAN-OS? (Select two.)

Question 4hardmultiple choice
Read the full VPN explanation →

A security administrator manages a Palo Alto Networks firewall in a large enterprise. The company has multiple remote sites connected via IPSec VPNs. Each site has its own subnet (e.g., Site A: 10.10.1.0/24, Site B: 10.10.2.0/24). The administrator needs to create a security policy that allows all inter-site traffic but blocks all traffic to and from the internet except for specific services. The administrator wants to use address groups to simplify management. Currently, there are address groups for each site (e.g., 'Site-A-Networks', 'Site-B-Networks') containing the respective subnets. The administrator also has an address group 'Internet-Allow' for allowed external IPs. The policy should have a rule that permits traffic from any site to any other site, and a rule that permits traffic from internal networks to the 'Internet-Allow' group for destination ports 80 and 443. Which of the following approaches best achieves this with minimal administrative overhead?

Question 5mediumdrag order
Read the full VPN explanation →

Drag and drop the steps to configure a site-to-site IPsec VPN on a Palo Alto Networks firewall into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Match each PAN-OS CLI command to its function.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Displays firewall version and uptime

Lists all interfaces and their status

Displays active security rules

Reboots the firewall

A network administrator needs to block traffic to a specific external website. Which object type should be used in the security policy to define the destination?

An organization uses multiple firewalls and wants to share dynamic address groups across them. Which feature should be used?

Which THREE are valid object types in Palo Alto Networks NGFW? (Choose three.)

A security policy rule has an action of "allow". Which TWO objects are mandatory for the rule to be valid? (Choose two.)

How many address objects are members of the 'web-servers' address group?

Exhibit

Refer to the exhibit.
config shared object address-group 'web-servers'
   type static
   member [ 'server1' 'server2' ]
end
Question 12mediummultiple choice
Read the full Managing Objects explanation →

Based on the log excerpt, which object is used for the destination address?

Exhibit

Refer to the exhibit.
debug log message: 'rule 'Allow-Web', source zone 'trust', destination zone 'untrust', source user 'any', source address '10.0.0.0/8', destination address 'any', application 'web-browsing', service 'service-http', action 'allow'.'

A security policy rule uses 'MyService' and 'ServerGroup'. What is the destination port of the allowed traffic?

Exhibit

Refer to the exhibit.
show running config | match object
set service 'MyService' protocol tcp port 443
set address 'MyServer' ip-netmask 192.168.1.10/32
set address-group 'ServerGroup' static [ MyServer ]

An administrator wants to group multiple servers with different IP addresses that all use the same port 443. What is the most efficient way to create a security policy rule for this traffic?

Question 15hardmultiple choice
Read the full DNS explanation →

An administrator is troubleshooting a security policy that uses a service group containing both TCP and UDP service objects. The policy is intended to allow DNS traffic (UDP 53 and TCP 53). The rule is not allowing TCP DNS. What is the most likely issue?

An organization uses an External Dynamic List (EDL) to block IP addresses. The EDL is updated every 5 minutes on the server, but the firewall still uses the old list even after the refresh interval. What is the most likely cause?

Question 17mediummultiple choice
Read the full Managing Objects explanation →

An admin creates an application group named 'web-apps' that includes 'web-browsing' and 'ssl'. They apply it to a security rule. However, traffic from a client accessing Facebook is being blocked. What is a likely reason?

An administrator needs to create a service group for a custom application that uses TCP ports 1000 and 2000. Which two methods will successfully create a service group that can be used in a single security rule? (Choose two.)

Which three of the following are valid types of address objects in Palo Alto Networks? (Choose three.)

Which three of the following are true about tag-based dynamic address groups? (Choose three.)

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Managing Objects sessions

Start a Managing Objects only practice session

Every question in these sessions is drawn from the Managing Objects domain — nothing else.

Related practice questions

Related PCNSA topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the PCNSA exam test about Managing Objects?
Be able to create and reuse address, service, and application objects, attach EDLs to policy, and order VLAN interface steps correctly. The single most important thing: know which object type belongs in each policy field and that referenced objects cannot be freely changed.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Managing Objects questions in a focused session?
Yes — the session launcher on this page draws every question from the Managing Objects domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other PCNSA topics?
Use the topic links above to move to related areas, or go back to the PCNSA question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the PCNSA exam covers. They are not copied from any real exam or dump site.