Palo_Alto_Networks
NETSEC-ANALYST · Question #10
A company moved its old port-based firewall to a new Palo Alto Networks NGFW 60 days ago. Which utility should the company use to identify out-of-date or unused rules on the firewall?
The correct answer is D. Rule Usage Filter > Hit Count > Unused in 90 days. The filter is applied to the within the last 90 days, that includes the 60 days. https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/monitoring/view-policy-rule-usage
Security Policy Management
Question
A company moved its old port-based firewall to a new Palo Alto Networks NGFW 60 days ago. Which utility should the company use to identify out-of-date or unused rules on the firewall?
Options
- ARule Usage Filter > No App Specified
- BRule Usage Filter >Hit Count > Unused in 30 days
- CRule Usage Filter > Unused Apps
- DRule Usage Filter > Hit Count > Unused in 90 days
How the community answered
(40 responses)- A3% (1)
- B8% (3)
- C5% (2)
- D85% (34)
Explanation
The filter is applied to the within the last 90 days, that includes the 60 days. https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/monitoring/view-policy-rule-usage
Topics
#rule usage filter#hit count#unused rules#policy optimization
Community Discussion
No community discussion yet for this question.