NSE7_OTS-7.2 Exam Questions
89 real NSE7_OTS-7.2 exam questions with expert-verified answers and explanations. Page 2 of 2.
- Question #51
Refer to the exhibit. You are assigned to implement a remote authentication server in the OT network. Which part of the hierarchy should the authentication server be part of?
- Question #52
A FortiGate device is newly deployed as the edge gateway of an OT network security fabric. The downstream FortiGate devices are also newly deployed as Security Fabric leafs to prot...
- Question #53
FortiAnalyzer is implemented in the OT network to receive logs from responsible FortiGate devices. The logs must be processed by FortiAnalyzer. In this scenario, which statement is...
- Question #54
Refer to the exhibit. The IPS profile is added on all of the security policies on FortiGate. For an OT network, which statement of the IPS profile is true?
- Question #55
With the limit of using one firewall device, the administrator enables multi-VDOM on FortiGate to provide independent multiple security domains to each ICS network. Which statement...
- Question #56
Refer to the exhibit. PLC-3 and CLIENT can send traffic to PLC-1 and PLC-2. FGT-2 has only one software switch (SSW-1) connecting both PLC-3 and CLIENT. PLC-3 and CLIENT cannot sen...
- Question #57
Which three Fortinet products can you use for device identification in an OT industrial control system (ICS)? (Choose three.)
- Question #58
Refer to the exhibit. In order for a FortiGate device to act as router on a stick, what configuration must an OT network architect implement on FortiGate to achieve inter-VLAN rout...
- Question #59
The OT network analyst run different level of reports to quickly explore failures that could put the network at risk. Such reports can be about device performance. Which FortiSIEM...
- Question #60
Which statemenl about the IEC 104 protocol is true?
- Question #61
Refer to the exhibit. Which statement is true about application control inspection?
- Question #62
Refer to the exhibits. Which statement about some of the generated report elements from FortiAnalyzer is true?
- Question #63
Which three device profiling methods of FortiNAC are considered non-direct? (Choose three.)
- Question #64
A supervisor is configuring a software switch on a FortiGate device. What must the supervisor configure on FortiGate to control the traffic between member interfaces on the softwar...
- Question #65
What is the main difference between real-time logs and historical logs on FortiAnalyzer?
- Question #66
An administrator needs to group FortiGate wireless interfaces in NAT mode with multiple physical interfaces. What interface type must the administrator select to group multiple For...
- Question #67
Which deployment option allows an administrator to detect intrusions without any modifications to production traffic?
- Question #68
Which three protocols are used as industrial Ethernet protocols? (Choose three.)
- Question #69
In the context of FortiNAC, what is a key feature of a logical network?
- Question #70
Which two statements about FortiSIEM are true? (Choose two.)
- Question #71
An OT customer is using multiple FortiGate devices in their network to implement two-factor authentication with hardware FortiTokens. A supervisor is carrying multiple FortiTokens...
- Question #72
Refer to the exhibit.A new operational technology rule is being created to monitor Modbus protocol traffic on FortiSIEM. Which action will ensure all Modbus messages on the network...
- Question #73
Which type of attack posed by skilled and malicious users of security level 3 (SL 3) of IEC 62443 is designed to defend against intentional attacks?
- Question #74
As an ОТ network administrator, you are required to generate reports that primarily use the same type of data sent to FortiSIEM. These reports are based on the preloaded analytic s...
- Question #75
Operational technology (ОТ) network analysts run different levels of reports to identify failures that could put the network at risk. Some of these reports may be related to device...
- Question #76
In an operation technology (ОТ) network. FortiAnalyzer is used to receive and process logs from responsible FortiGate devices. Which statement about why FortiAnalyzer is receiving...
- Question #77
What is the primary objective of implementing SD-WAN in operational technology (ОТ) networks?
- Question #78
Refer to the exhibit, which shows a nonprotected ОТ environment. An administrator needs to implement appropriate protection on the ОТ network. Which three steps should an administr...
- Question #79
Refer to the exhibit. An operational technology (ОТ) architect has implemented Modbus TCP with a simulation Conpot server to identify and control Modbus traffic in their ОТ network...
- Question #80
Which statement about how FortiNAC processes matched rogue devices is true?
- Question #81
Refer to the exhibit. You are creating a new operational technology (OT) rule to monitor Modbus protocol traffic on FortiSIEM. Which action must you take to ensure that all Modbus...
- Question #82
An OT network architect must deploy a solution to protect fuel pumps in an industrial remote network. All the fuel pumps must be closely monitored from the corporate network for an...
- Question #83
An organization has deployed an entry-level FortiGate device in their operational technology (OT) network. The administrator is looking for a simple solution to detect and block al...
- Question #84
Refer to the exhibit. You need to configure VPN user access for supervisors at the branch and HQ sites using the same soft FortiToken. Each site has a FortiGate VPN gateway. What m...
- Question #85
Refer to the exhibit. The network topology in the exhibit shows FortiGate devices as well as FortiAnalyzer and FortiSIEM for the OT network. Which two steps must you take to config...
- Question #86
An OT architect has deployed a Layer 2 switch in the OT network at Level 1 in the Purdue model- process control. The purpose of the Layer 2 switch is to segment traffic between PLC...
- Question #87
Refer to the exhibit. An OT network architect must implement inter-VLAN routing in the topology. Traffic from each client is tagged with a unique VLAN. Each client is directly conn...
- Question #88
Which two of the following features do most industrial protocols lack? (Choose two.)
- Question #89
Which statement about how FortiNAC re-evaluates previously profiled devices is true?