Palo Alto Networks Certified Network Security Engineer (PCNSE) — Question 207
Which Panorama objects restrict administrative access to specific device-groups?
Answer options
- A. admin roles
- B. authentication profiles
- C. templates
- D. access domains
Correct answer: D
Explanation
Access domains are specifically designed to restrict administrative privileges to certain device-groups, ensuring that admins can only manage the devices they are assigned to. While admin roles and authentication profiles are related to access control, they do not directly limit access to specific device-groups like access domains do. Templates are used for configuration management rather than access control.