exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 150 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 150
Topic #: 1
[All PCNSE Questions]

What are the two behavior differences between Highlight Unused Rules and the Rule Usage Hit counter when a firewall is rebooted? (Choose two.)

  • A. Rule Usage Hit counter will not be reset.
  • B. Highlight Unused Rules will highlight all rules.
  • C. Highlight Unused Rules will highlight zero rules.
  • D. Rule Usage Hit counter will reset.
Show Suggested Answer Hide Answer
Suggested Answer: AB 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ChiaPet75
Highly Voted 4 years, 4 months ago
Correct: A,B (Per PANOS Help Function) - Each firewall maintains a traffic flag for the rules that have a match. Because the flag is reset when a dataplane reset occurs on a reboot or a restart, it is best practice to monitor this list periodically to determine whether the rule had a match since the last check before you delete or disable it. This mean when the dataplane is reset or there is a reboot the flag will not be set for any security policies therefore they will all be highlighted until a rule is hit and the flag is set.
upvoted 11 times
...
Anoopmp
Highly Voted 4 years, 5 months ago
Correct Answer A and C.
upvoted 11 times
...
Marshpillowz
Most Recent 9 months, 1 week ago
Selected Answer: AB
A and B correct
upvoted 1 times
...
DatITGuyTho1337
10 months, 1 week ago
D is definitely part of the answer because the rule usage counter always resets following firewall reboot.
upvoted 1 times
DatITGuyTho1337
10 months, 1 week ago
Nevermind, found the following line from one of the articles: "Hit Count—The number of times traffic matched the criteria you defined in the policy rule. Persists through reboot, dataplane restarts, and upgrades unless you manually reset or rename the rule."
upvoted 1 times
...
...
Xuzi
11 months, 3 weeks ago
Selected Answer: AB
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVICA0
upvoted 1 times
...
Micutzu
11 months, 3 weeks ago
Selected Answer: AB
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVICA0
upvoted 1 times
...
gc999
12 months ago
Selected Answer: A
Only "A" is definitely correct. The fact is "Rule Usage Hit Counter will not be reset", it is proven from the lab. Then: 1. "A" - must always be correct 2. "B" - since Hit Count NOT be reset, it would not "all" rules are unused. (Maybe some are unused, i.e. no hit count, but it already happened before reboot) 3. "D" - must always be wrong 4. "C" - It depends. As mentioned on "2" above, maybe some rules are unused before reboot, so "some" rules already have ZERO hit count before reboot.
upvoted 1 times
...
alinio11
1 year, 3 months ago
I've just tested in my LAB: Is A&C. If I had the option to paste here the printscreen , I would do it.
upvoted 1 times
gc999
12 months ago
The question is not good. I agree with A only. If the question is with wording "assume all rules are not zero in hit counter before reboot ...", then I will also go with "C"
upvoted 1 times
...
...
duckduckgooo
1 year, 4 months ago
Selected Answer: AB
FOr people thinking it's C, take a look at the link below. "Notice how the rules looks after selecting "Highlight Unused Rules." You can now see exactly what rules have and have not been used since the last reboot. " https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVICA0
upvoted 1 times
...
lildevil
1 year, 6 months ago
A & B with out question. To all who said answer C...what would happen if a rule is created but never been hit? Of course it would be highlighted so C could never be correct.
upvoted 1 times
...
dogeatdog
1 year, 10 months ago
Selected Answer: AB
A and B. Be careful of the wording. this is a double negative. Cisco uses this trickery also.
upvoted 3 times
...
lol12
2 years ago
Selected Answer: AB
Can't be C. If you have a running firewall with a rule that has not been used then it will be highlighted. If we reboot the appliance then - given there was no traffic - all rules will be highlighted. If zero rules would be highlighted then it means every rule was used...
upvoted 3 times
...
TAKUM1y
2 years ago
Selected Answer: AC
A: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/monitoring/view-policy-rule-usage C: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVICA0
upvoted 2 times
DenskyDen
1 year, 9 months ago
Based on the article posted, it should be A and B.
upvoted 2 times
...
...
Pretorian
2 years, 2 months ago
I agree with A and B but what are the chances that after a reboot, you will check that box before packets hit one or many of the rules?
upvoted 3 times
...
eyelasers1
2 years, 8 months ago
Answer: AB "Hit Count—The number of times traffic matched the criteria you defined in the policy rule. Persists through reboot, dataplane restarts, and upgrades unless you manually reset or rename the rule." Source: https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/monitoring/view-policy-rule-usage.html "Notice how the rules looks after selecting "Highlight Unused Rules." You can now see exactly what rules have and have not been used since the last reboot. The red boxes around the rules have been added to show you how the "highlight" feature works." Source: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVICA0
upvoted 6 times
...
NNgiggs
2 years, 8 months ago
The Right answer is AB, the question is so complicated but what they are looking for is to know if you Understand that highlight unused rules will highlight all unused since the last reboot as opposed to hit count which does not change after a reboot. See link below and read the notice below the second picture. https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVICA0
upvoted 4 times
...
GivemeMoney
2 years, 9 months ago
Selected Answer: AB
Rule usage hit counter will only reset if you manually reset them. Highlight unused rules will highlight all rules if not used since start.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago