nerdexam
Fortinet

NSE7_OTS-7.2 · Question #55

With the limit of using one firewall device, the administrator enables multi-VDOM on FortiGate to provide independent multiple security domains to each ICS network. Which statement ensures security…

The correct answer is B. The management VDOM must have access to all global security services. In a multi-VDOM setup, one VDOM typically acts as the management VDOM (often called "root") which manages global settings and security services like FortiGuard updates. This management VDOM handles access to global security services that benefit all traffic Individual traffic…

FortiGate OT Security

Question

With the limit of using one firewall device, the administrator enables multi-VDOM on FortiGate to provide independent multiple security domains to each ICS network. Which statement ensures security protection is in place for all ICS networks?

Options

  • AEach traffic VDOM must have a direct connection to FortiGuard services to receive the
  • BThe management VDOM must have access to all global security services.
  • CEach VDOM must have an independent security license.
  • DTraffic between VDOMs must pass through the physical interfaces of FortiGate to check for

How the community answered

(38 responses)
  • A
    3% (1)
  • B
    84% (32)
  • C
    8% (3)
  • D
    5% (2)

Explanation

In a multi-VDOM setup, one VDOM typically acts as the management VDOM (often called "root") which manages global settings and security services like FortiGuard updates. This management VDOM handles access to global security services that benefit all traffic Individual traffic VDOMs process their own traffic and enforce security policies but rely on the management VDOM for centralized access to global security services. Each VDOM does not need an independent security license; the license is for the device as a Traffic between VDOMs does not need to pass through physical interfaces to be inspected; inter- VDOM links and policies handle traffic inspection. Each VDOM does not require direct FortiGuard connections; this can be centralized in the management VDOM.

Topics

#multi-VDOM#management VDOM#FortiGuard services#ICS network isolation

Community Discussion

No community discussion yet for this question.

Full NSE7_OTS-7.2 Practice