Weekend Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: my75ex

Home > Fortinet > Fortinet Network Security Expert > NSEI_OTS_AR-7.6

NSEI_OTS_AR-7.6 Fortinet NSE I - OT Security 7.6 Architect Question and Answers

Question # 4

Refer to the exhibit.

A partial OT network is shown. In this OT network, you must add additional security measures to detect OT protocols and, therefore, increase the traffic visibility. Which security sensor must you implement to detect the OT protocols in this network? (Choose one answer)

A.

Device detection on all the FortiGate interfaces.

B.

Inline IDS on FortiGate_Level3.

C.

Application sensor set to monitor on all the FortiGate devices.

D.

IPS sensor on FortiGate_Level5.

Full Access
Question # 5

Refer to the exhibit.

A firewall policy page is shown. To improve the security of your OT network, you have configured a Supervisor profile in the firewall policies, as shown in the exhibit. However, a supervisor is reporting that he cannot ping PLC-1. What are the two reasons? (Choose two answers)

A.

The supervisor must first authenticate using a protocol such as HTTPS or Telnet.

B.

The Supervisor profile is not configured in the remote server.

C.

The firewall policy ID 8 is not enabled.

D.

The CLI parameter auth-on-demand is set to always.

Full Access
Question # 6

You want FortiAnalyzer to trigger an automation stitch on a FortiGate device automatically. What must you configure on FortiAnalyzer to enable direct communication with FortiGate? (Choose one answer)

A.

A Fabric connector

B.

A playbook task

C.

The Fabric settings

D.

An event handler

Full Access
Question # 7

For the installation of your first FortiGate device, you want to minimize the impact in your OT network. Therefore, you deploy it initially as an offline IDS. Which two statements about this deployment are correct? (Choose two answers)

A.

The FortiGate device acts as a network sensor.

B.

The cybersecurity visibility increases with the security profiles.

C.

Attacks, including zero-day attacks, are blocked.

D.

OT traffic flows through the FortiGate device.

Full Access
Question # 8

What are two advantages provided by industrial Ethernet? (Choose two answers)

A.

Encryption

B.

Real-time control

C.

Remote access

D.

Determinism

Full Access
Question # 9

Refer to the exhibit.

Which statement about this partial Asset Identity List page is correct? (Choose one answer)

A.

A firewall policy has an Antivirus security profile applied to it.

B.

A firewall policy has a Virtual Patching security profile applied to it.

C.

A firewall policy has an Intrusion Prevention security profile applied to it.

D.

A firewall policy has an Application Control security profile applied to it.

Full Access
Question # 10

Refer to the exhibit.

A simplified OT network is shown. You want to optimize the protection of this OT network. Which two controls must you implement? (Choose two answers)

A.

Offline IDS on FortiGate_Level3.

B.

IPS on FortiGate_Level5.

C.

Virtual patching on FortiGate_Level2.

D.

OT signature on FortiGate_Level5.

Full Access
Question # 11

Which industrial protocol does not support VLANs? (Choose one answer)

A.

[Not clearly visible in the exhibit]

B.

Ethernet over industrial protocol

C.

EtherCAT

D.

Modbus over TCP

Full Access
Question # 12

Refer to the exhibit.

A partial OT network is shown. You want to provide the supervisor with secure remote access. Which two features can you implement on Edge-FortiGate ? (Choose two answers)

A.

IPsec

B.

FortiToken

C.

SD-WAN

D.

FSSO

Full Access
Question # 13

How are rogue devices evaluated in FortiNAC? (Choose one answer)

A.

Through device profiling rules

B.

Through queries to FortiGuard servers

C.

Through the import of the devices list

D.

Through the local device database (CIDB)

Full Access