Courseiva
Managing Objects →easyMultiple Select

PCNSA Managing Objects Practice Question

Which TWO types of address objects can be used in a security policy? (Choose two.)

⚠ Common exam trap

Palo Alto Networks often tests the distinction between address objects and other policy elements like services or applications, so the trap here is that candidates mistakenly think Application or Service can serve as address objects because they are also used in security rules, but they occupy different match fields.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

IP Netmask

In a Palo Alto Networks security policy, address objects are used to match the source and destination fields, and the valid address object types include IP Netmask (a subnet defined by an IP address and a subnet mask, e.g., 192.168.1.0/24) and IP Range (a contiguous span of addresses defined by a start and end IP, e.g., 192.168.1.10-192.168.1.20), so options C and D are correct. These two types are explicitly selectable as address objects when building source or destination matching criteria in the policy rule. Option A (Application) is incorrect because applications are matched via the Application field using application objects or application filters, not address objects. Option B (Tag) is incorrect because tags are metadata labels used for grouping and filtering objects or rules, not an address object type usable in the source/destination address fields. Option E (Service) is incorrect because services (TCP/UDP port and protocol definitions) are matched in the Service/Application field, not as address objects.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Application

    Why it's wrong here

    Application objects identify traffic by application signature rather than by IP address, so they cannot populate address fields in a security policy. They are tempting because applications are selectable in policy rules, but application objects would be the correct selection when enforcing App-ID based allow or deny decisions.

  • ✗

    Tag

    Why it's wrong here

    Tags are metadata labels applied to objects for filtering and dynamic grouping, not address object types usable directly in a policy's source or destination. They are tempting because tags appear in policy configuration, but tags would be the correct choice when dynamically grouping existing address objects for rule membership.

  • ✓

    IP Netmask

    Why this is correct

    An IP Netmask address object defines a subnet range, such as 10.0.0.0/24, and is a valid match criterion in Palo Alto Networks security policy source and destination fields, satisfying the question's requirement for usable address object types.

  • ✓

    IP Range

    Why this is correct

    An IP Range object specifies a contiguous span between two addresses, for example 10.0.0.5 to 10.0.0.20, and is accepted in security policy source and destination fields, making it one of the valid address object types the question requires.

  • ✗

    Service

    Why it's wrong here

    Service objects define Layer 4 port and protocol matching, so they cannot be referenced as address objects within a security policy's source or destination fields. They are tempting because services appear alongside addresses in policy rules, but service objects would be the correct selection when defining allowed applications' ports.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This PCNSA question is part of Courseiva's 385-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.