nerdexam
Fortinet

NSE7_OTS-7.2 · Question #86

An OT architect has deployed a Layer 2 switch in the OT network at Level 1 in the Purdue model- process control. The purpose of the Layer 2 switch is to segment traffic between PLC1 and PLC2 with…

The correct answer is D. The FortiGate must be configured as a "Router on a stick" for intra-PLC communication. With PLC1 and PLC2 in separate VLANs on a Layer 2 switch, inter-VLAN traffic must be routed. The FortiGate provides that routing and policy control by using VLAN subinterfaces on a single physical link ("router on a stick"), so all PLC1<->PLC2 traffic passes through it.

FortiGate OT Security

Question

An OT architect has deployed a Layer 2 switch in the OT network at Level 1 in the Purdue model- process control. The purpose of the Layer 2 switch is to segment traffic between PLC1 and PLC2 with two VLANs. All the traffic between PLC1 and PLC2 must first flow through the Layer 2 switch and then through the FortiGate device in the Level 2 supervisory control network. Which statement about the traffic between PLC1 and PLC2 is true?

Options

  • AIn order to communicate, PLC1 must be in the same VLAN as PLC2.
  • BThe Layer 2 switch rewrites VLAN tags before sending traffic to the FortiGate device.
  • CThe Layer 2 switch routes any traffic to the FortiGate device through an Ethernet link.
  • DThe FortiGate must be configured as a "Router on a stick" for intra-PLC communication.

How the community answered

(50 responses)
  • A
    12% (6)
  • B
    8% (4)
  • C
    2% (1)
  • D
    78% (39)

Explanation

With PLC1 and PLC2 in separate VLANs on a Layer 2 switch, inter-VLAN traffic must be routed. The FortiGate provides that routing and policy control by using VLAN subinterfaces on a single physical link ("router on a stick"), so all PLC1<->PLC2 traffic passes through it.

Topics

#VLAN segmentation#router on a stick#Purdue model#PLC communication

Community Discussion

No community discussion yet for this question.

Full NSE7_OTS-7.2 Practice