Hi DPWP,
I’d like to confirm your issue step by step.
First of all, please select “White list” as “Matching rule” at “Validation rule settings“. I guess you already do this.
1. Test of logs
Please select “All of validation” as “Record validation logs” at “Record settings“. After you save settings, you’ll find some “passed” at “Logs” page. Those are footprints of yourself.
2. Test of “Admin area“
Please select “Only when blocked” as “Record validation logs” at “Record settings“. And also select “Prevent Zero-day Exploit” as “Admin area” at “Validation target settings” and save settings. Then access “https://yoursite.com/wp-admin/about.php?action=test” with your browser. You’ll encounter “403 Forbidden” and also find “wp-zep” in “Logs” page. It means that an access to admin area without a secret nonce will be blocked even from your country.
Please tell me about the result of 1 and 2.
I hope the document “The best practice of target settings” helps you to find the best settings to fit your site. I’m afraid this doc is a bit mess. So please ask me about your setting for each target if you’re confused.
Thanks for asking!