nerdexam
Fortinet

NSE7_OTS-7.2 · Question #2

An OT architect has deployed a Layer 2 switch in the OT network at Level 1 in the Purdue model- process control. The purpose of the Layer 2 switch is to segment traffic between PLC1 and PLC2 with…

The correct answer is C. PLC1 and PLC2 traffic must flow through the Layer-2 switch trunk link to the FortiGate device. Since PLC1 and PLC2 are segmented into two VLANs on a Layer 2 switch, traffic between them requires inter-VLAN routing. The Layer 2 switch handles VLAN segmentation but does not route traffic between VLANs. For communication between VLANs, traffic must be sent to a router or…

Troubleshooting FortiGate Infrastructure

Question

An OT architect has deployed a Layer 2 switch in the OT network at Level 1 in the Purdue model- process control. The purpose of the Layer 2 switch is to segment traffic between PLC1 and PLC2 with two VLANs. All the traffic between PLC1 and PLC2 must first flow through the Layer 2 switch and then through the FortiGate device in the Level 2 supervisory control network. Which statement about the traffic between PLC1 and PLC2 is true?

Options

  • AThe Layer 2 switch rewrites VLAN tags before sending traffic to the FortiGate device.
  • BThe Layer 2 switches routes any traffic to the FortiGate device through an Ethernet link.
  • CPLC1 and PLC2 traffic must flow through the Layer-2 switch trunk link to the FortiGate device.
  • DIn order to communicate, PLC1 must be in the same VLAN as PLC2.

How the community answered

(27 responses)
  • A
    19% (5)
  • B
    4% (1)
  • C
    70% (19)
  • D
    7% (2)

Explanation

Since PLC1 and PLC2 are segmented into two VLANs on a Layer 2 switch, traffic between them requires inter-VLAN routing. The Layer 2 switch handles VLAN segmentation but does not route traffic between VLANs. For communication between VLANs, traffic must be sent to a router or Layer 3 device-in this case, the FortiGate device in the Layer 2 supervisory control network. The traffic flows from PLCs to the Layer 2 switch and then over a trunk link (carrying VLAN tags) to the FortiGate, which performs inter-VLAN routing. The trunk link allows multiple VLAN-tagged traffic to be carried between the Layer 2 switch and the FortiGate for routing. Options regarding VLAN tags rewriting or requiring PLCs to be in the same VLAN are incorrect because VLAN tagging remains consistent on trunk links and PLCs are intentionally segmented.

Topics

#VLAN#Layer 2 switch#OT network#Purdue model

Community Discussion

No community discussion yet for this question.

Full NSE7_OTS-7.2 Practice