nerdexam
Palo_Alto_Networks

PCNSA · Question #418

all other sites in the same category. Which object should the administrator create to use as a match condition for the security policy

The correct answer is C. URL category. URL Category lets a security policy match traffic based on the content classification of the destination site - so blocking one gambling site automatically blocks all sites Palo Alto's URL filtering database classifies as "gambling," without needing to enumerate individual…

Submitted by tarun92· Apr 18, 2026Managing Objects

Question

all other sites in the same category. Which object should the administrator create to use as a match condition for the security policy

Options

  • AService
  • BAddress
  • CURL category
  • DApplication group

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    7% (2)
  • C
    86% (24)
  • D
    4% (1)

Explanation

URL Category lets a security policy match traffic based on the content classification of the destination site - so blocking one gambling site automatically blocks all sites Palo Alto's URL filtering database classifies as "gambling," without needing to enumerate individual addresses.

  • A (Service) is wrong because Service objects match on protocol/port (e.g., TCP/443), not site content or category.
  • B (Address) is wrong because Address objects match specific IPs or FQDNs - you'd have to manually list every gambling site, which defeats the purpose.
  • D (Application group) is wrong because Application groups match by application signature (e.g., "web-browsing," "ssl"), not by the content category of the destination.

Memory tip: Think "URL Category = content classification bucket." When the requirement says "this site and all others like it," that's a category-level match - only URL Category covers the whole bucket automatically.

Topics

#URL Filtering#Security Policy#Policy Objects

Community Discussion

No community discussion yet for this question.

Full PCNSA Practice