Courseiva
Managing ObjectsmediumMultiple SelectObjective-mapped

PCNSA Managing Objects Practice Question

Which three of the following are valid types of address objects in Palo Alto Networks? (Choose three.)

⚠ Common exam trap

A common mix-up: candidates confuse 'Subnet Object' with the valid 'IP Netmask' type, or assume MAC addresses are valid address objects due to their use in other security contexts, but Palo Alto Networks strictly uses Layer 3 IP-based address objects for policy enforcement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

FQDN

FQDN (Fully Qualified Domain Name) is a valid address object type in Palo Alto Networks that allows you to define a security policy rule based on a domain name rather than an IP address. The firewall dynamically resolves the FQDN to IP addresses at runtime, which is useful for destinations like cloud services or websites with changing IPs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • FQDN

    Why this is correct

    FQDN is a valid type for domain names.

  • MAC Address

    Why it's wrong here

    MAC address is not supported as an address object type.

  • Subnet Object

    Why it's wrong here

    Subnet Object is not a valid address object type in PAN-OS.

  • IP Netmask

    Why this is correct

    IP Netmask is a valid address object type (e.g., 192.168.1.0/24).

  • IP Range

    Why this is correct

    IP Range is a valid type (e.g., 192.168.1.1-192.168.1.10).

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This PCNSA question is part of Courseiva's 516-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

3 more ways this is tested on PCNSA

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A security administrator needs to create an address object for a single host with IP address 192.168.1.100. Which address type should the administrator choose?

easy
  • A.FQDN
  • B.IP Netmask
  • C.IP Wildcard Mask
  • D.IP Range

Why B: For a single host with IP address 192.168.1.100, the IP Netmask type is correct because it allows you to define a host by specifying the IP address with a /32 netmask (255.255.255.255). This is the standard method in Palo Alto Networks firewalls to represent a single host, ensuring the device treats it as an exact match for traffic policy and security rules.

Variation 2. Which THREE of the following are valid types of address objects in Palo Alto Networks? (Choose three.)

easy
  • A.IP Range
  • B.IP Netmask
  • C.FQDN
  • D.MAC Address
  • E.URL Category

Why A: IP Range, IP Netmask, and FQDN are all valid address object types in Palo Alto Networks. IP Range defines a contiguous set of IP addresses (e.g., 192.168.1.1-192.168.1.254), IP Netmask uses subnet mask notation (e.g., 192.168.1.0/24), and FQDN represents a fully qualified domain name (e.g., www.example.com). All three are valid address objects in PAN-OS.

Variation 3. Which TWO types of address objects can be used in a security policy? (Choose two.)

easy
  • A.Application
  • B.Tag
  • C.IP Netmask
  • D.IP Range
  • E.Service

Why C: IP Netmask and IP Range are both types of address objects that define specific IP addresses or groups of IP addresses. Security policies in Palo Alto Networks firewalls use these address objects to match source and destination IP addresses in traffic, enabling granular control over which hosts or networks are allowed or denied.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.