nerdexam
Fortinet

NSE7_OTS-7.2 · Question #38

Refer to the exhibits. Which statement is true about the traffic passing through to PLC-2?

The correct answer is C. IEC 104 signatures are all allowed except the C.BO.NA 1 signature. The application sensor shows several IEC 104 signatures. The action for IEC_60870.5.104_Information.Transfer.C.BO.NA.1 is set to "Block," so this signature's traffic is blocked. Other listed IEC 104 signatures have the action "Monitor," meaning they are allowed but logged IPS…

FortiGate OT Security

Question

Refer to the exhibits. Which statement is true about the traffic passing through to PLC-2?

Exhibit

NSE7_OTS-7.2 question #38 exhibit

Options

  • AIPS must be enabled to inspect application signatures.
  • BThe application filter overrides the default action of some IEC 104 signatures.
  • CIEC 104 signatures are all allowed except the C.BO.NA 1 signature.
  • DSSL Inspection must be set to deep-inspection to correctly apply application control.

How the community answered

(22 responses)
  • A
    5% (1)
  • B
    5% (1)
  • C
    82% (18)
  • D
    9% (2)

Explanation

The application sensor shows several IEC 104 signatures. The action for IEC_60870.5.104_Information.Transfer.C.BO.NA.1 is set to "Block," so this signature's traffic is blocked. Other listed IEC 104 signatures have the action "Monitor," meaning they are allowed but logged IPS enabling is not explicitly indicated as required here. SSL inspection is set to certificate-inspection (not deep-inspection), and the question does not provide enough context to require deep SSL inspection. The application filter overrides actions for only the C.BO.NA.1 signature, blocking it while other signatures pass.

Topics

#IEC 104#application filter override#PLC traffic#signature actions

Community Discussion

No community discussion yet for this question.

Full NSE7_OTS-7.2 Practice