NSE7_OTS-7.2 Exam Questions
89 real NSE7_OTS-7.2 exam questions with expert-verified answers and explanations. Page 2 of 2.
- Question #51FortiGate OT Security
Refer to the exhibit. You are assigned to implement a remote authentication server in the OT network. Which part of the hierarchy should the authentication server be part of?
network hierarchyauthentication server placementOT network designedge zone - Question #52FortiGate OT Security
A FortiGate device is newly deployed as the edge gateway of an OT network security fabric. The downstream FortiGate devices are also newly deployed as Security Fabric leafs to prot...
micro-segmentationsoftware switchintra-VLAN trafficcontrol area zone - Question #53FortiAnalyzer for OT
FortiAnalyzer is implemented in the OT network to receive logs from responsible FortiGate devices. The logs must be processed by FortiAnalyzer. In this scenario, which statement is...
FortiAnalyzer log processingPLC RTU monitoringOT log analysisevent correlation - Question #54FortiGate OT Security
Refer to the exhibit. The IPS profile is added on all of the security policies on FortiGate. For an OT network, which statement of the IPS profile is true?
IPS signaturesSCADA application signaturesindustrial protocol inspectionOT IPS profile - Question #55FortiGate OT Security
With the limit of using one firewall device, the administrator enables multi-VDOM on FortiGate to provide independent multiple security domains to each ICS network. Which statement...
multi-VDOMmanagement VDOMFortiGuard servicesICS network isolation - Question #56FortiGate OT Security
Refer to the exhibit. PLC-3 and CLIENT can send traffic to PLC-1 and PLC-2. FGT-2 has only one software switch (SSW-1) connecting both PLC-3 and CLIENT. PLC-3 and CLIENT cannot sen...
software switchmicro-segmentationintra-VLAN firewall policydevice-to-device control - Question #57FortiNAC for OT
Which three Fortinet products can you use for device identification in an OT industrial control system (ICS)? (Choose three.)
device identificationICS asset discoveryFortiNACFortiSIEM - Question #58FortiGate OT Security
Refer to the exhibit. In order for a FortiGate device to act as router on a stick, what configuration must an OT network architect implement on FortiGate to achieve inter-VLAN rout...
router on stickinter-VLAN routing802.1q trunkVLAN configuration - Question #59FortiAnalyzer for OT
The OT network analyst run different level of reports to quickly explore failures that could put the network at risk. Such reports can be about device performance. Which FortiSIEM...
FortiSIEM reportingCMDB operational reportsdevice performancefailure identification - Question #60OT Threat Landscape
Which statemenl about the IEC 104 protocol is true?
IEC 104 protocolSCADA telecontrolOT communication protocolselectrical engineering SCADA - Question #61FortiGate OT Security
Refer to the exhibit. Which statement is true about application control inspection?
application controlsignature hierarchyparent-child signaturesOT application inspection - Question #62
Refer to the exhibits. Which statement about some of the generated report elements from FortiAnalyzer is true?
- Question #63
Which three device profiling methods of FortiNAC are considered non-direct? (Choose three.)
- Question #64
A supervisor is configuring a software switch on a FortiGate device. What must the supervisor configure on FortiGate to control the traffic between member interfaces on the softwar...
- Question #65
What is the main difference between real-time logs and historical logs on FortiAnalyzer?
- Question #66
An administrator needs to group FortiGate wireless interfaces in NAT mode with multiple physical interfaces. What interface type must the administrator select to group multiple For...
- Question #67
Which deployment option allows an administrator to detect intrusions without any modifications to production traffic?
- Question #68
Which three protocols are used as industrial Ethernet protocols? (Choose three.)
- Question #69
In the context of FortiNAC, what is a key feature of a logical network?
- Question #70
Which two statements about FortiSIEM are true? (Choose two.)
- Question #71
An OT customer is using multiple FortiGate devices in their network to implement two-factor authentication with hardware FortiTokens. A supervisor is carrying multiple FortiTokens...
- Question #72FortiAnalyzer for OT
Refer to the exhibit.A new operational technology rule is being created to monitor Modbus protocol traffic on FortiSIEM. Which action will ensure all Modbus messages on the network...
FortiSIEM rule creationModbus protocolOT traffic monitoringrule conditions - Question #73OT Threat Landscape
Which type of attack posed by skilled and malicious users of security level 3 (SL 3) of IEC 62443 is designed to defend against intentional attacks?
IEC 62443security levelsintentional attacksthreat actor resources - Question #74FortiAnalyzer for OT
As an ОТ network administrator, you are required to generate reports that primarily use the same type of data sent to FortiSIEM. These reports are based on the preloaded analytic s...
FortiSIEManalytic searchesreport generationOT reporting - Question #75FortiAnalyzer for OT
Operational technology (ОТ) network analysts run different levels of reports to identify failures that could put the network at risk. Some of these reports may be related to device...
FortiSIEMCMDB reportsdevice performanceOT monitoring - Question #76FortiAnalyzer for OT
In an operation technology (ОТ) network. FortiAnalyzer is used to receive and process logs from responsible FortiGate devices. Which statement about why FortiAnalyzer is receiving...
FortiAnalyzerPLC loggingRTU loggingOT troubleshooting - Question #77FortiGate OT Security
What is the primary objective of implementing SD-WAN in operational technology (ОТ) networks?
SD-WANOT network performanceOT applicationsnetwork optimization - Question #78FortiGate OT Security
Refer to the exhibit, which shows a nonprotected ОТ environment. An administrator needs to implement appropriate protection on the ОТ network. Which three steps should an administr...
OT segmentationFortiGate deploymentindustrial protocol sensorsICS protection - Question #79FortiGate OT Security
Refer to the exhibit. An operational technology (ОТ) architect has implemented Modbus TCP with a simulation Conpot server to identify and control Modbus traffic in their ОТ network...
Modbus TCPsoftware switchNAT modeFortiGate firewall policy - Question #80FortiNAC for OT
Which statement about how FortiNAC processes matched rogue devices is true?
FortiNACrogue device detectiondevice profiling rulesendpoint management - Question #81FortiAnalyzer for OT
Refer to the exhibit. You are creating a new operational technology (OT) rule to monitor Modbus protocol traffic on FortiSIEM. Which action must you take to ensure that all Modbus...
FortiSIEMModbus ruleaggregate filterOT traffic monitoring - Question #82FortiAnalyzer for OT
An OT network architect must deploy a solution to protect fuel pumps in an industrial remote network. All the fuel pumps must be closely monitored from the corporate network for an...
FortiSIEMtemperature monitoringOT remote networkperformance rule - Question #83FortiGate OT Security
An organization has deployed an entry-level FortiGate device in their operational technology (OT) network. The administrator is looking for a simple solution to detect and block al...
IPSindustrial signature databaseOT intrusion detectionfalse positives - Question #84FortiGate OT Security
Refer to the exhibit. You need to configure VPN user access for supervisors at the branch and HQ sites using the same soft FortiToken. Each site has a FortiGate VPN gateway. What m...
FortiAuthenticatorFortiTokenVPN accessmulti-site authentication - Question #85FortiAnalyzer for OT
Refer to the exhibit. The network topology in the exhibit shows FortiGate devices as well as FortiAnalyzer and FortiSIEM for the OT network. Which two steps must you take to config...
FortiAnalyzer loggingFortiSIEM integrationlog forwardingOT network topology - Question #86FortiGate OT Security
An OT architect has deployed a Layer 2 switch in the OT network at Level 1 in the Purdue model- process control. The purpose of the Layer 2 switch is to segment traffic between PLC...
VLAN segmentationrouter on a stickPurdue modelPLC communication - Question #87FortiGate OT Security
Refer to the exhibit. An OT network architect must implement inter-VLAN routing in the topology. Traffic from each client is tagged with a unique VLAN. Each client is directly conn...
inter-VLAN routingrouter on a stickLayer 2 switchFortiGate - Question #88OT Threat Landscape
Which two of the following features do most industrial protocols lack? (Choose two.)
industrial protocolsTLS encryptionauthenticationprotocol security gaps - Question #89FortiNAC for OT
Which statement about how FortiNAC re-evaluates previously profiled devices is true?
FortiNACdevice profilingrogue device re-evaluationmatching rules