正解:B,D
Objects are configuration elements that policy rules reference, for example: IP addresses, URL categories, security profiles, users, services, and applications. Rules of any type (pre-rules, post- rules, default rules, and rules locally defined on a firewall) and any rulebase (Security, NAT, QoS, Policy Based Forwarding, Decryption, Application Override, Captive Portal, and DoS Protection) can reference objects.
https://docs.paloaltonetworks.com/panorama/8-1/panorama-admin/panorama- overview/centralized-firewall-configuration-and-update-management/device-groups/device-group- objects.html#id0fee714c-9e17-43a0-aac5-54e0c34f37e3