nerdexam
Fortinet

NSE7_OTS-7.2 · Question #79

Refer to the exhibit. An operational technology (ОТ) architect has implemented Modbus TCP with a simulation Conpot server to identify and control Modbus traffic in their ОТ network. The…

The correct answer is B. In the FortiGate firewall policy, NAT must be enabled from port3 to SSW-01 D. The FortiGate-Edge device must be in network address translation (NAT) operation mode. In the FortiGate firewall policy, NAT must be enabled from port3 to SSW-01: To ensure successful communication between the client and the Conpot server through FortiGate, Network Address Translation (NAT) must be configured in the firewall policy. This allows the client to…

FortiGate OT Security

Question

Refer to the exhibit. An operational technology (ОТ) architect has implemented Modbus TCP with a simulation Conpot server to identify and control Modbus traffic in their ОТ network. The FortiGate-Edge device is configured with a software switch interface, SSW-01. Based on the topology shown in the exhibit, which two statements must be true for the simulation of traffic between client and server to be successful? (Choose two.)

Exhibit

NSE7_OTS-7.2 question #79 exhibit

Options

  • AAn IP address must be assigned to port5
  • BIn the FortiGate firewall policy, NAT must be enabled from port3 to SSW-01
  • CThe FortiGate device must be in offline intrusion detection system (IDS) mode
  • DThe FortiGate-Edge device must be in network address translation (NAT) operation mode

How the community answered

(40 responses)
  • A
    20% (8)
  • B
    70% (28)
  • C
    10% (4)

Explanation

In the FortiGate firewall policy, NAT must be enabled from port3 to SSW-01: To ensure successful communication between the client and the Conpot server through FortiGate, Network Address Translation (NAT) must be configured in the firewall policy. This allows the client to access the server via the FortiGate interface by properly routing the traffic. The FortiGate-Edge device must be in network address translation (NAT) operation mode: FortiGate in NAT operation mode ensures that traffic between different subnets (e.g., client and server) is routed correctly, enabling communication and simulation in the given topology.

Topics

#Modbus TCP#software switch#NAT mode#FortiGate firewall policy

Community Discussion

No community discussion yet for this question.

Full NSE7_OTS-7.2 Practice