NSE7_OTS-7.2 · Question #35
Refer to the exhibit. PLC-3 and CLIENT can send traffic to PLC-1 and PLC-2. FGT-2 has only one software switch (SSW-2) connecting both PLC-3 and CLIENT. PLC-3 and CLIENT can send traffic to each…
The correct answer is C. Enable explicit intra-switch policy to require firewall policies on FGT-2. Set the software switch to explicit intra-switch policy so traffic between its member ports must pass through FortiGate policies instead of being bridged at Layer 2. This stops PLC‑3 and CLIENT from communicating directly at L2.
Question
Refer to the exhibit. PLC-3 and CLIENT can send traffic to PLC-1 and PLC-2. FGT-2 has only one software switch (SSW-2) connecting both PLC-3 and CLIENT. PLC-3 and CLIENT can send traffic to each other at the layer 2 level. What must the operational technology (OT) admin do to prevent layer 2-level communication between PLC-3 and CLIENT?
Exhibit
Options
- ASet a unique forward domain for each interface of the software switch.
- BCreate a VLAN for each device and replace the current FGT-2 software switch members.
- CEnable explicit intra-switch policy to require firewall policies on FGT-2.
- DImplement policy routes on FGT-2 to control traffic between devices.
How the community answered
(57 responses)- A5% (3)
- B7% (4)
- C72% (41)
- D16% (9)
Explanation
Set the software switch to explicit intra-switch policy so traffic between its member ports must pass through FortiGate policies instead of being bridged at Layer 2. This stops PLC‑3 and CLIENT from communicating directly at L2.
Topics
Community Discussion
No community discussion yet for this question.
