Palo_Alto_NetworksPalo_Alto_Networks
PCNSA · Question #134
PCNSA Question #134: Real Exam Question with Answer & Explanation
The correct answer is B: dynamic user group. PAN-OS version 9.1 introduced Dynamic User Groups (DUGs), which allow user groups in security policies to be populated automatically based on attributes fetched from external identity sources.
Submitted by sofia.br· Apr 18, 2026Managing Objects
Question
Starting with PAN-OS version 9.1, which new type of object is supported for use within the User field of a Security policy rule?
Options
- Aremote username
- Bdynamic user group
- Cstatic user group
- Dlocal username
Explanation
PAN-OS version 9.1 introduced Dynamic User Groups (DUGs), which allow user groups in security policies to be populated automatically based on attributes fetched from external identity sources.
Common mistakes.
- A. Remote usernames, referring to individual users identified via User-ID, were already supported in security policies prior to PAN-OS 9.1.
- C. Static user groups, where users are manually added to predefined groups, were a feature available before the release of PAN-OS 9.1.
- D. Local usernames, representing users defined directly on the firewall, were already available for use in security policies before PAN-OS 9.1.
Concept tested. PAN-OS 9.1 Dynamic User Groups
Topics
#PAN-OS 9.1#Dynamic User Groups#Security Policy#User-ID
Community Discussion
No community discussion yet for this question.