nerdexam
Fortinet

NSE7_OTS-7.2 · Question #56

Refer to the exhibit. PLC-3 and CLIENT can send traffic to PLC-1 and PLC-2. FGT-2 has only one software switch (SSW-1) connecting both PLC-3 and CLIENT. PLC-3 and CLIENT cannot send traffic to each…

The correct answer is B. Micro-segmentation on FGT-2 prevents direct device-to-device communication. D. FGT-2 controls intra-VLAN traffic through firewall policies. Micro-segmentation prevents direct traffic flow between devices at the same VLAN or switch level, such as PLC-3 and CLIENT connected on FGT-2's software switch. FGT-2 enforces this control by applying firewall policies on its interfaces to control intra-VLAN (east-west) traffic…

FortiGate OT Security

Question

Refer to the exhibit. PLC-3 and CLIENT can send traffic to PLC-1 and PLC-2. FGT-2 has only one software switch (SSW-1) connecting both PLC-3 and CLIENT. PLC-3 and CLIENT cannot send traffic to each other. Which two statements about the traffic between PCL-1 and PLC-2 are true? (Choose two.)

Exhibit

NSE7_OTS-7.2 question #56 exhibit

Options

  • AThe switch on FGT-2 must be hardware to implement micro-segmentation.
  • BMicro-segmentation on FGT-2 prevents direct device-to-device communication.
  • CTraffic must be inspected by FGT-EDGE in OT networks.
  • DFGT-2 controls intra-VLAN traffic through firewall policies.

How the community answered

(27 responses)
  • A
    15% (4)
  • B
    78% (21)
  • C
    7% (2)

Explanation

Micro-segmentation prevents direct traffic flow between devices at the same VLAN or switch level, such as PLC-3 and CLIENT connected on FGT-2's software switch. FGT-2 enforces this control by applying firewall policies on its interfaces to control intra-VLAN (east-west) traffic within the OT network. The switch on FGT-2 does not need to be hardware; software switches can also enforce micro- Traffic inspection by FGT-EDGE is possible but local intra-VLAN traffic segmentation and control are the responsibility of FGT-2.

Topics

#software switch#micro-segmentation#intra-VLAN firewall policy#device-to-device control

Community Discussion

No community discussion yet for this question.

Full NSE7_OTS-7.2 Practice