nerdexam
Palo_Alto_Networks

PCNSA · Question #10

A company moved its old port-based firewall to a new Palo Alto Networks NGFW 60 days ago. Which utility should the company use to identify out-of-date or unused rules on the firewall?

The correct answer is D. Rule Usage Filter > Hit Count > Unused in 90 days. The filter is applied to the within the last 90 days, that includes the 60 days. https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/monitoring/view-policy-rule-usage

Submitted by marco_it· Apr 18, 2026Policy Evaluation and Management

Question

A company moved its old port-based firewall to a new Palo Alto Networks NGFW 60 days ago. Which utility should the company use to identify out-of-date or unused rules on the firewall?

Options

  • ARule Usage Filter > No App Specified
  • BRule Usage Filter >Hit Count > Unused in 30 days
  • CRule Usage Filter > Unused Apps
  • DRule Usage Filter > Hit Count > Unused in 90 days

How the community answered

(37 responses)
  • A
    8% (3)
  • B
    5% (2)
  • C
    16% (6)
  • D
    70% (26)

Explanation

The filter is applied to the within the last 90 days, that includes the 60 days. https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/monitoring/view-policy-rule-usage

Topics

#Policy management#Rule optimization#Hit count#Firewall rules

Community Discussion

No community discussion yet for this question.

Full PCNSA Practice