nerdexam
Palo_Alto_Networks

PSE-STRATA · Question #166

Which filtering criterion is used to determine users to be included as members of a dynamic user group (DUG)?

The correct answer is B. Tag. Tags are the filtering criterion for Dynamic User Groups because DUGs use tag-based membership - when a tag is assigned to a user (often automatically via User-ID, SIEM integrations, or API), the firewall dynamically adds that user to the group without requiring a static policy…

Identity and Access Management

Question

Which filtering criterion is used to determine users to be included as members of a dynamic user group (DUG)?

Options

  • ASecurity policy rule
  • BTag
  • CLogin ID
  • DIP address

How the community answered

(40 responses)
  • A
    18% (7)
  • B
    70% (28)
  • C
    5% (2)
  • D
    8% (3)

Explanation

Tags are the filtering criterion for Dynamic User Groups because DUGs use tag-based membership - when a tag is assigned to a user (often automatically via User-ID, SIEM integrations, or API), the firewall dynamically adds that user to the group without requiring a static policy change.

Why the distractors are wrong:

  • A. Security policy rule - policy rules consume group membership; they don't define which users belong to a DUG.
  • C. Login ID - static groups can be built around specific login IDs, but DUGs are dynamic by nature and rely on tags, not hardcoded identifiers.
  • D. IP address - IP addresses are used in traditional IP-based policies or address objects, not as the membership criterion for user-based DUGs.

Memory tip: Think "DUG = Dynamic User Group uses Tags" - both "dynamic" and "tag" imply something that can be applied and removed automatically, which is exactly how DUG membership works in real time.

Topics

#Dynamic User Groups#Tag-based User Segmentation#User Identity Management#Access Control

Community Discussion

No community discussion yet for this question.

Full PSE-STRATA Practice