Courseiva

PCNSA Policy Evaluation and Management Practice Question

An administrator is reviewing the rulebase and finds a rule with a hit count of 0 over the past 30 days. What action should the administrator consider?

⚠ Common exam trap

The trap is thinking that a zero hit count means the rule is broken or needs to be moved — the exam tests whether you recognize that zero hits over a long period indicates the rule is unused and should be removed, not repositioned.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Consider removing the rule as it is not being used.

A rule with a hit count of 0 over 30 days indicates no traffic has matched it, meaning it is likely obsolete, redundant, or misconfigured. Removing unused rules reduces the attack surface and simplifies the rulebase, which is a recommended hygiene practice in Palo Alto Networks best-practice assessments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Move the rule higher in the rulebase.

    Why it's wrong here

    A zero hit count suggests the rule matches no traffic, so the administrator should review it for removal or disabling; moving it higher increases its evaluation precedence without addressing that it is unused. It is tempting because rule order matters when a shadowed rule never matches, but here the rule itself is idle.

  • ✓

    Consider removing the rule as it is not being used.

    Why this is correct

    A hit count of zero across 30 days indicates the rule matches no traffic, so it contributes nothing while enlarging the rulebase and its audit surface. Removing it satisfies the stem's implied goal of rulebase hygiene, though the administrator should first confirm no dependent rules or expected seasonal traffic exist.

  • ✗

    Increase the log setting to capture more data.

    Why it's wrong here

    Logging captures session detail for rules already matching traffic; a rule with zero hits over 30 days has nothing to log, so raising the log setting changes no data. It tempts administrators wanting forensic evidence, but logging suits rules already matching traffic that need deeper session visibility.

  • ✗

    Disable the rule to see if any traffic matches.

    Why it's wrong here

    Disabling removes the rule from enforcement without first confirming whether legitimate traffic depends on it, risking an outage if hits were simply not logged. It tempts administrators seeking a quick test, but disabling suits rules already proven redundant after traffic analysis confirms no dependency.

About these practice questions

Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.