nerdexam
Palo_Alto_Networks

NETSEC-ANALYST · Question #10

A company moved its old port-based firewall to a new Palo Alto Networks NGFW 60 days ago. Which utility should the company use to identify out-of-date or unused rules on the firewall?

The correct answer is D. Rule Usage Filter > Hit Count > Unused in 90 days. The filter is applied to the within the last 90 days, that includes the 60 days. https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/monitoring/view-policy-rule-usage

Security Policy Management

Question

A company moved its old port-based firewall to a new Palo Alto Networks NGFW 60 days ago. Which utility should the company use to identify out-of-date or unused rules on the firewall?

Options

  • ARule Usage Filter > No App Specified
  • BRule Usage Filter >Hit Count > Unused in 30 days
  • CRule Usage Filter > Unused Apps
  • DRule Usage Filter > Hit Count > Unused in 90 days

How the community answered

(40 responses)
  • A
    3% (1)
  • B
    8% (3)
  • C
    5% (2)
  • D
    85% (34)

Explanation

The filter is applied to the within the last 90 days, that includes the 60 days. https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/monitoring/view-policy-rule-usage

Topics

#rule usage filter#hit count#unused rules#policy optimization

Community Discussion

No community discussion yet for this question.

Full NETSEC-ANALYST Practice