1. Palo Alto Networks IoT Security Administrator's Guide: "The firewall collects basic device information such as the IP address, MAC address, and operating system... It also collects metadata from the traffic sessions that devices initiate... The IoT Security cloud service then uses its machine learning algorithms to analyze the metadata and identify the device with a high degree of accuracy." (Reference: IoT Security Workflow, Section: How IoT Security Discovers and Identifies Devices).
2. Palo Alto Networks PAN-OS® Administrator's Guide: "Device-ID collects device information... and network traffic information from logs... to provide visibility into the devices on your network." This confirms that collecting traffic metadata is a primary function. (Reference: Device-ID Overview).
3. Palo Alto Networks IoT Security Administrator's Guide: "To enable IoT Security to discover devices, you must enable Device-ID on the zones where IoT devices reside and on the security policy rules that allow traffic from them." This directly contradicts option C, which suggests disabling it. (Reference: Enable Device-ID).