NSE7_OTS-7.2 · Question #56
Refer to the exhibit. PLC-3 and CLIENT can send traffic to PLC-1 and PLC-2. FGT-2 has only one software switch (SSW-1) connecting both PLC-3 and CLIENT. PLC-3 and CLIENT cannot send traffic to each…
The correct answer is B. Micro-segmentation on FGT-2 prevents direct device-to-device communication. D. FGT-2 controls intra-VLAN traffic through firewall policies. Micro-segmentation prevents direct traffic flow between devices at the same VLAN or switch level, such as PLC-3 and CLIENT connected on FGT-2's software switch. FGT-2 enforces this control by applying firewall policies on its interfaces to control intra-VLAN (east-west) traffic…
Question
Refer to the exhibit. PLC-3 and CLIENT can send traffic to PLC-1 and PLC-2. FGT-2 has only one software switch (SSW-1) connecting both PLC-3 and CLIENT. PLC-3 and CLIENT cannot send traffic to each other. Which two statements about the traffic between PCL-1 and PLC-2 are true? (Choose two.)
Exhibit
Options
- AThe switch on FGT-2 must be hardware to implement micro-segmentation.
- BMicro-segmentation on FGT-2 prevents direct device-to-device communication.
- CTraffic must be inspected by FGT-EDGE in OT networks.
- DFGT-2 controls intra-VLAN traffic through firewall policies.
How the community answered
(27 responses)- A15% (4)
- B78% (21)
- C7% (2)
Explanation
Micro-segmentation prevents direct traffic flow between devices at the same VLAN or switch level, such as PLC-3 and CLIENT connected on FGT-2's software switch. FGT-2 enforces this control by applying firewall policies on its interfaces to control intra-VLAN (east-west) traffic within the OT network. The switch on FGT-2 does not need to be hardware; software switches can also enforce micro- Traffic inspection by FGT-EDGE is possible but local intra-VLAN traffic segmentation and control are the responsibility of FGT-2.
Topics
Community Discussion
No community discussion yet for this question.
