Cloudflare Specials managed firewall rules - many are disabled by default?

I’ve recently had an increase of spam/bot traffic on my site and have been looking into the Cloudflare managed firewall rules, especially “Cloudflare Specials”.

The documentation recommends this ruleset is kept enabled, which it is, however when I click into the ruleset to view it in detail I notice that lots of the rules have “Disabled” as their default action.

Is that correct?

Currently there are 306 rules in the ruleset.

Do users really need to click through all 306 to manually check the behaviour of each one?