nerdexam
Fortinet

NSE7_OTS-7.2 · Question #40

Refer to the exhibit. The FGT-Edge device is a VPN gateway that allows remote administrators access to the local ICS network. Management hires a third-party company to conduct health and safety on…

The correct answer is C. Split the edge FortiGate device into multiple logical devices to allocate an independent VDOM for. By splitting the edge FortiGate into VDOMs, you isolate the third‑party company in its own virtual firewall. That VDOM can have outbound internet policies without exposing or risking the ICS networks protected by the other VDOMs.

FortiGate OT Security

Question

Refer to the exhibit. The FGT-Edge device is a VPN gateway that allows remote administrators access to the local ICS network. Management hires a third-party company to conduct health and safety on site. The third-party company must have outbound access to external resources. What is the best scenario to provide external access to the third-party company while continuing to secure the ICS networks?

Exhibit

NSE7_OTS-7.2 question #40 exhibit

Options

  • AConfigure outbound security policies with limited active authentication users of the third-party
  • BCreate VPN tunnels between downstream FortiGate devices and the edge FortiGate to protect
  • CSplit the edge FortiGate device into multiple logical devices to allocate an independent VDOM for
  • DImplement an additional firewall using an additional upstream link to the internet.

How the community answered

(58 responses)
  • A
    9% (5)
  • B
    2% (1)
  • C
    83% (48)
  • D
    7% (4)

Explanation

By splitting the edge FortiGate into VDOMs, you isolate the third‑party company in its own virtual firewall. That VDOM can have outbound internet policies without exposing or risking the ICS networks protected by the other VDOMs.

Topics

#VDOM segmentation#VPN gateway#ICS access control#third-party access

Community Discussion

No community discussion yet for this question.

Full NSE7_OTS-7.2 Practice