Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam PCNSA topic 1 question 18 discussion

Actual exam question from Palo Alto Networks's PCNSA
Question #: 18
Topic #: 1
[All PCNSA Questions]

A company moved its old port-based firewall to a new Palo Alto Networks NGFW 60 days ago. Which utility should the company use to identify out-of-date or unused rules on the firewall?

  • A. Rule Usage Filter > No App Specified
  • B. Rule Usage Filter >Hit Count > Unused in 30 days
  • C. Rule Usage Filter > Unused Apps
  • D. Rule Usage Filter > Hit Count > Unused in 90 days
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
LuisLfr
Highly Voted 4 years, 4 months ago
exactly, for that reason it is the correct answer. If you choose the option of 30 days, some rule could be used within 30 to 60, therefore the answer that I assure that it has not been used for more than 60 days is the "D"
upvoted 11 times
...
Darude
Most Recent 1 year, 1 month ago
Selected Answer: D
Guys I check it on our production firewall the 90 days it is timeframe so it includes the 30 days as well. I check the policies inside and the 90 includes the 30 ones as well. So to see 60 days you have to pick 90 for sure. (iven if it make NO sense)
upvoted 1 times
...
KirinKev
1 year, 3 months ago
D is correct, the filter is applied to the within the last 90 days, that includes the 60 days, https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/monitoring/view-policy-rule-usage
upvoted 1 times
...
Ptopics
1 year, 9 months ago
The point of the 30 and 90 day filters in policy optimizer is identifying policies that haven't had hits in a long time so you can assume you can delete them. Thus the 90 day filter looks for policies that have gone 90 OR MORE days without a hit. The firewall in this scenario is only 61 days old so answer D does not apply. I think C is the best answer.
upvoted 2 times
...
error_909
2 years, 1 month ago
Selected Answer: D
Answer is D Policies --> Policy Optimizer --> Unused in 90 days
upvoted 3 times
...
Rowdy_47
2 years, 5 months ago
D is the most accurate answer but all are actually wrong In PAN OS v10, if we select "Policies" at the top of the page and then navigate to the bottom left we can see "Policy Optimizer", where the options are New App Viewer Rules Without App Controls Unused Apps Rule Usage With Rule Usage having the following options Unused in 30 days Unused in 90 days Unused So the actual correct answer is Policies --> Policy Optimizer --> Unused in 90 days
upvoted 2 times
...
Cyril_the_Squirl
2 years, 5 months ago
C is Correct
upvoted 2 times
Cyril_the_Squirl
2 years, 5 months ago
I'm currently loggon into PA-VM with PAN-OS version 10.1.3. You can only do this from the bottom left of the screen under Rule Optimizer. A & C are wrong because there is no such option. There is no "Hit Count" option either so for the sake of this question I think B & D would be correct but B is our best option. The real available options on the firewall are: 1. Unused in 30 days 2. Unused in 90 days 3. Unused
upvoted 2 times
...
...
diego1984
2 years, 6 months ago
C is correct, there is no "Hit Count" option
upvoted 2 times
...
AngelXavier
3 years, 3 months ago
D is correct. With 30 don´t cover all the uptime.
upvoted 1 times
...
Ab121213
3 years, 11 months ago
D is correct. That covers all starting from 61 days ago.
upvoted 2 times
...
PANW
3 years, 11 months ago
The question is, if you put unused in 30 days does that mean 30 days or more, surely it can't mean only used in 30 days.
upvoted 2 times
Theo11M
3 years, 11 months ago
I think the answer to your question is that whatever you pick, it will show you "this number" and downwards, so I would say that choosing Unused in 90 days, would show you rules unused for 1-90 days which includes 60 days (something that Unused in 30 days doesn't).
upvoted 1 times
...
...
John555
4 years, 1 month ago
I'm thinking the answer is B
upvoted 2 times
...
RedByte
4 years, 4 months ago
If they only migrated 60 days ago, there can't be any rules that haven't been hit for more than 90 days.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...