New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Palo Alto Networks PSE-Strata-Pro-24 Exam - Topic 2 Question 20 Discussion

Actual exam question for Palo Alto Networks's PSE-Strata-Pro-24 exam
Question #: 20
Topic #: 2
[All PSE-Strata-Pro-24 Questions]

Device-ID can be used in which three policies? (Choose three.)

Show Suggested Answer Hide Answer
Suggested Answer: A, C, E

Device-ID is a feature in Palo Alto Networks firewalls that identifies devices based on their unique attributes (e.g., MAC addresses, device type, operating system). Device-ID can be used in several policy types to provide granular control. Here's how it applies to each option:

Option A: Security

Device-ID can be used in Security policies to enforce rules based on the device type or identity. For example, you can create policies that allow or block traffic for specific device types (e.g., IoT devices).

This is correct.

Option B: Decryption

Device-ID cannot be used in decryption policies. Decryption policies are based on traffic types, certificates, and other SSL/TLS attributes, not device attributes.

This is incorrect.

Option C: Policy-based forwarding (PBF)

Device-ID can be used in PBF policies to control the forwarding of traffic based on the identified device. For example, you can route traffic from certain device types through specific ISPs or VPN tunnels.

This is correct.

Option D: SD-WAN

SD-WAN policies use metrics such as path quality (e.g., latency, jitter) and application information for traffic steering. Device-ID is not a criterion used in SD-WAN policies.

This is incorrect.

Option E: Quality of Service (QoS)

Device-ID can be used in QoS policies to apply traffic shaping or bandwidth control for specific devices. For example, you can prioritize or limit bandwidth for traffic originating from IoT devices or specific endpoints.

This is correct.


Palo Alto Networks documentation on Device-ID

Contribute your Thoughts:

0/2000 characters
Audra
4 days ago
Decryption? Really? That's a bit of a stretch. I'll go with the obvious ones - security, PBF, and QoS.
upvoted 0 times
...
Telma
9 days ago
Device-ID is definitely useful for security and QoS, but I'm not sure about PBF. Hmm, better double-check that one.
upvoted 0 times
...
Sheron
14 days ago
A, C, and E are the correct answers.
upvoted 0 times
...
Carry
19 days ago
I thought Device-ID was also relevant for SD-WAN, but I need to double-check if it fits with QoS too.
upvoted 0 times
...
Lorrine
24 days ago
I feel like Decryption could be one of the answers, but I can't recall if it's specifically related to Device-ID.
upvoted 0 times
...
Lili
29 days ago
I remember practicing a question about Device-ID and Policy-based forwarding, so I might go with that option.
upvoted 0 times
...
Aleta
1 month ago
I think Device-ID is definitely used in Security policies, but I'm not sure about the other two.
upvoted 0 times
...
Francesco
1 month ago
Ah, I think I've got this. Device-ID is used for security, policy-based forwarding, and SD-WAN. I'm pretty confident about those three.
upvoted 0 times
...
Gertude
1 month ago
I'm a bit confused on this one. I know Device-ID is used for some network policies, but I'm not sure which specific ones. I'll have to guess and hope I get at least two right.
upvoted 0 times
...
Titus
2 months ago
I've got a strategy for this. I'll start by identifying the policies I'm familiar with, like security and QoS. Then I'll try to reason through the others based on what I know about Device-ID.
upvoted 0 times
...
Jarod
2 months ago
Okay, let's see. I know Device-ID is used for security, so A is definitely one. I'm not sure about the others, though. I'll have to eliminate the ones I'm unsure of.
upvoted 0 times
...
Stanford
2 months ago
Hmm, this seems like a tricky one. I'll need to think through the different policies and how Device-ID might be used in each.
upvoted 0 times
...

Save Cancel