Device-ID can be used in which three policies? (Choose three.)
Device-ID is a feature in Palo Alto Networks firewalls that identifies devices based on their unique attributes (e.g., MAC addresses, device type, operating system). Device-ID can be used in several policy types to provide granular control. Here's how it applies to each option:
Option A: Security
Device-ID can be used in Security policies to enforce rules based on the device type or identity. For example, you can create policies that allow or block traffic for specific device types (e.g., IoT devices).
This is correct.
Option B: Decryption
Device-ID cannot be used in decryption policies. Decryption policies are based on traffic types, certificates, and other SSL/TLS attributes, not device attributes.
This is incorrect.
Option C: Policy-based forwarding (PBF)
Device-ID can be used in PBF policies to control the forwarding of traffic based on the identified device. For example, you can route traffic from certain device types through specific ISPs or VPN tunnels.
This is correct.
Option D: SD-WAN
SD-WAN policies use metrics such as path quality (e.g., latency, jitter) and application information for traffic steering. Device-ID is not a criterion used in SD-WAN policies.
This is incorrect.
Option E: Quality of Service (QoS)
Device-ID can be used in QoS policies to apply traffic shaping or bandwidth control for specific devices. For example, you can prioritize or limit bandwidth for traffic originating from IoT devices or specific endpoints.
This is correct.
Palo Alto Networks documentation on Device-ID
Audra
4 days agoTelma
9 days agoSheron
14 days agoCarry
19 days agoLorrine
24 days agoLili
29 days agoAleta
1 month agoFrancesco
1 month agoGertude
1 month agoTitus
2 months agoJarod
2 months agoStanford
2 months ago