Courseiva

PCNSA Policy Evaluation and Management Practice Question

How can an administrator quickly identify which security rules are not being used in order to clean up the rulebase?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use the Policy Optimizer tool to view rule hit counts.

The Policy Optimizer tool in Palo Alto Networks firewalls provides rule hit counts, allowing administrators to quickly identify which security rules are not being used. Option A, 'show rulebase', displays the rulebase but does not show hit counts. Option B, checking commit logs, reveals recent changes but not usage frequency. Option C, sorting rules by rule number, does not indicate whether rules are used.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use the 'show rulebase' command.

    Why it's wrong here

    The show rulebase command merely displays configured rules; it reports no hit counts or usage data, so unused rules cannot be distinguished. It is tempting as a rulebase overview, but the rule usage feature, which tracks match counters, is required to identify zero-hit rules.

  • ✗

    Check the commit logs for recent changes.

    Why it's wrong here

    Commit logs record configuration changes, not traffic matches, so a rule can be unused yet appear in recent commits. It is tempting when auditing change history, but the rule usage feature, which counts hits per rule, is required to find rules with no matches.

  • ✗

    Sort rules by rule number in descending order.

    Why it's wrong here

    Sorting by rule number orders rules by position, not by traffic usage, so zero-hit rules remain unidentified. It is tempting when tidying rule order, but the rule usage feature, which records per-rule match counts, is what reveals rules that never matched.

  • ✓

    Use the Policy Optimizer tool to view rule hit counts.

    Why this is correct

    Policy Optimizer directly satisfies the unused-rule identification requirement by surfacing per-rule hit counts, letting the administrator filter rules with zero matches across the specified timeframe. Unlike App-ID dependency or traffic log inspection, it aggregates match statistics natively within the firewall rulebase view, enabling rapid cleanup decisions without manual correlation.

About these practice questions

Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.