nerdexam
Fortinet

NSE7_OTS-7.2 · Question #35

Refer to the exhibit. PLC-3 and CLIENT can send traffic to PLC-1 and PLC-2. FGT-2 has only one software switch (SSW-2) connecting both PLC-3 and CLIENT. PLC-3 and CLIENT can send traffic to each…

The correct answer is C. Enable explicit intra-switch policy to require firewall policies on FGT-2. Set the software switch to explicit intra-switch policy so traffic between its member ports must pass through FortiGate policies instead of being bridged at Layer 2. This stops PLC‑3 and CLIENT from communicating directly at L2.

FortiGate OT Security

Question

Refer to the exhibit. PLC-3 and CLIENT can send traffic to PLC-1 and PLC-2. FGT-2 has only one software switch (SSW-2) connecting both PLC-3 and CLIENT. PLC-3 and CLIENT can send traffic to each other at the layer 2 level. What must the operational technology (OT) admin do to prevent layer 2-level communication between PLC-3 and CLIENT?

Exhibit

NSE7_OTS-7.2 question #35 exhibit

Options

  • ASet a unique forward domain for each interface of the software switch.
  • BCreate a VLAN for each device and replace the current FGT-2 software switch members.
  • CEnable explicit intra-switch policy to require firewall policies on FGT-2.
  • DImplement policy routes on FGT-2 to control traffic between devices.

How the community answered

(57 responses)
  • A
    5% (3)
  • B
    7% (4)
  • C
    72% (41)
  • D
    16% (9)

Explanation

Set the software switch to explicit intra-switch policy so traffic between its member ports must pass through FortiGate policies instead of being bridged at Layer 2. This stops PLC‑3 and CLIENT from communicating directly at L2.

Topics

#intra-switch policy#software switch#Layer 2 isolation#FortiGate segmentation

Community Discussion

No community discussion yet for this question.

Full NSE7_OTS-7.2 Practice