NSE7_OTS-7.2 · Question #52
A FortiGate device is newly deployed as the edge gateway of an OT network security fabric. The downstream FortiGate devices are also newly deployed as Security Fabric leafs to protect the control…
The correct answer is D. Create a software switch on each downstream FortiGate device. A software switch groups multiple interfaces at Layer 2. However, for micro-segmentation, you usually separate interfaces per subnet/device group and apply inter-interface policies on the FortiGate. By doing this, the FortiGate can control intra-VLAN (or intra-subnet) traffic…
Question
A FortiGate device is newly deployed as the edge gateway of an OT network security fabric. The downstream FortiGate devices are also newly deployed as Security Fabric leafs to protect the control area zone. With no additional essential networking devices, and to implement micro-segmentation on this OT network, what configuration must the OT network architect apply to control intra-VLAN traffic?
Options
- AEnable transparent mode on the edge FortiGate device.
- BEnable security profiles on all interfaces connected in the control area zone.
- CSet up VPN tunnels between downstream and edge FortiGate devices.
- DCreate a software switch on each downstream FortiGate device.
How the community answered
(31 responses)- A6% (2)
- B6% (2)
- C13% (4)
- D74% (23)
Explanation
A software switch groups multiple interfaces at Layer 2. However, for micro-segmentation, you usually separate interfaces per subnet/device group and apply inter-interface policies on the FortiGate. By doing this, the FortiGate can control intra-VLAN (or intra-subnet) traffic without additional networking hardware.
Topics
Community Discussion
No community discussion yet for this question.