Palo_Alto_Networks
PCNSA · Question #10
A company moved its old port-based firewall to a new Palo Alto Networks NGFW 60 days ago. Which utility should the company use to identify out-of-date or unused rules on the firewall?
The correct answer is D. Rule Usage Filter > Hit Count > Unused in 90 days. The filter is applied to the within the last 90 days, that includes the 60 days. https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/monitoring/view-policy-rule-usage
Submitted by marco_it· Apr 18, 2026Policy Evaluation and Management
Question
A company moved its old port-based firewall to a new Palo Alto Networks NGFW 60 days ago. Which utility should the company use to identify out-of-date or unused rules on the firewall?
Options
- ARule Usage Filter > No App Specified
- BRule Usage Filter >Hit Count > Unused in 30 days
- CRule Usage Filter > Unused Apps
- DRule Usage Filter > Hit Count > Unused in 90 days
How the community answered
(37 responses)- A8% (3)
- B5% (2)
- C16% (6)
- D70% (26)
Explanation
The filter is applied to the within the last 90 days, that includes the 60 days. https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/monitoring/view-policy-rule-usage
Topics
#Policy management#Rule optimization#Hit count#Firewall rules
Community Discussion
No community discussion yet for this question.