PSE-STRATA · Question #166
Which filtering criterion is used to determine users to be included as members of a dynamic user group (DUG)?
The correct answer is B. Tag. Tags are the filtering criterion for Dynamic User Groups because DUGs use tag-based membership - when a tag is assigned to a user (often automatically via User-ID, SIEM integrations, or API), the firewall dynamically adds that user to the group without requiring a static policy…
Question
Which filtering criterion is used to determine users to be included as members of a dynamic user group (DUG)?
Options
- ASecurity policy rule
- BTag
- CLogin ID
- DIP address
How the community answered
(40 responses)- A18% (7)
- B70% (28)
- C5% (2)
- D8% (3)
Explanation
Tags are the filtering criterion for Dynamic User Groups because DUGs use tag-based membership - when a tag is assigned to a user (often automatically via User-ID, SIEM integrations, or API), the firewall dynamically adds that user to the group without requiring a static policy change.
Why the distractors are wrong:
- A. Security policy rule - policy rules consume group membership; they don't define which users belong to a DUG.
- C. Login ID - static groups can be built around specific login IDs, but DUGs are dynamic by nature and rely on tags, not hardcoded identifiers.
- D. IP address - IP addresses are used in traditional IP-based policies or address objects, not as the membership criterion for user-based DUGs.
Memory tip: Think "DUG = Dynamic User Group uses Tags" - both "dynamic" and "tag" imply something that can be applied and removed automatically, which is exactly how DUG membership works in real time.
Topics
Community Discussion
No community discussion yet for this question.