1. Palo Alto Networks TechDocs, "Get Started with ZTNA Connector 2.0," ZTNA Connector 2.0 Concepts section, App Discovery subsection. This document states, "ZTNA Connector 2.0 can discover applications in your data center and suggest security policy rules for them. This helps you to easily migrate your applications from a legacy VPN solution to a ZTNA solution." This directly supports the correct answer.
2. Palo Alto Networks TechDocs, "Prisma Access Administrator’s Guide," Service Connections section. This guide describes a service connection as an IPSec tunnel that "provides Prisma Access with a route to your internal services and resources." It operates at the network layer and does not include application discovery capabilities, which differentiates it from the ZTNA connector.
3. Palo Alto Networks TechDocs, "ZTNA Connector Overview." This document clarifies that the ZTNA connector provides "secure access to specific applications" rather than granting broad network access, which is a key tenet of Zero Trust and is facilitated by features like application discovery.