Free 365 Days Exam Updates NSE7_OTS-7.2 dumps with test Engine Practice
Updated Verified NSE7_OTS-7.2 dumps Q&As - 100% Pass Guaranteed
Fortinet NSE7_OTS-7.2 certification exam is a valuable credential for IT professionals who want to enhance their career prospects in the field of OT security. Fortinet NSE 7 - OT Security 7.2 certification demonstrates that the holder has a deep understanding of OT security best practices, and is capable of designing and implementing secure OT networks. Fortinet NSE 7 - OT Security 7.2 certification is also a testament to the holder's commitment to ongoing professional development, and can help them stand out in a competitive job market.
NEW QUESTION # 26
An OT architect has deployed a Layer 2 switch in the OT network at Level 1 the Purdue model-process control. The purpose of the Layer 2 switch is to segment traffic between PLC1 and PLC2 with two VLANs.
All the traffic between PLC1 and PLC2 must first flow through the Layer 2 switch and then through the FortiGate device in the Level 2 supervisory control network.
What statement about the traffic between PLC1 and PLC2 is true?
- A. PLC1 and PLC2 traffic must flow through the Layer-2 switch trunk link to the FortiGate device.
- B. The Layer 2 switch rewrites VLAN tags before sending traffic to the FortiGate device.
- C. In order to communicate, PLC1 must be in the same VLAN as PLC2.
- D. The Layer 2 switches routes any traffic to the FortiGate device through an Ethernet link.
Answer: A
Explanation:
Explanation
The statement that is true about the traffic between PLC1 and PLC2 is that PLC1 and PLC2 traffic must flow through the Layer-2 switch trunk link to the FortiGate device.
NEW QUESTION # 27
An OT network administrator is trying to implement active authentication.
Which two methods should the administrator use to achieve this? (Choose two.)
- A. Local authentication on FortiGate
- B. Two-factor authentication on FortiAuthenticator
- C. Role-based authentication on FortiNAC
- D. FSSO authentication on FortiGate
Answer: A,B
NEW QUESTION # 28
Refer to the exhibit
In the topology shown in the exhibit, both PLCs can communicate directly with each other, without going through the firewall.
Which statement about the topology is true?
- A. There is no micro-segmentation in this topology.
- B. This integration solution expands VLAN capabilities from Layer 2 to Layer 3.
- C. PLCs use IEEE802.1Q protocol to communicate each other.
- D. An administrator can create firewall policies in the switch to secure between PLCs.
Answer: A
NEW QUESTION # 29
An OT administrator is defining an incident notification policy using FortiSIEM and would like to configure the system with a notification policy. If an incident occurs, the administrator would like to be able to intervene and block an IP address or disable a user in Active Directory from FortiSIEM.
Which step must the administrator take to achieve this task?
- A. Configure a fabric connector with a notification policy on FortiSIEM to connect with FortiGate.
- B. Deploy a mitigation script on Active Directory and create a notification policy on FortiSIEM.
- C. Define a script/remediation on FortiManager and enable a notification rule on FortiSIEM.
- D. Create a notification policy and define a script/remediation on FortiSIEM.
Answer: D
Explanation:
Explanation
https://fusecommunity.fortinet.com/blogs/silviu/2022/04/12/fortisiempublishingscript
NEW QUESTION # 30
An OT supervisor has configured LDAP and FSSO for the authentication. The goal is that all the users be authenticated against passive authentication first and, if passive authentication is not successful, then users should be challenged with active authentication.
What should the OT supervisor do to achieve this on FortiGate?
- A. Enable two-factor authentication with FSSO.
- B. Configure a firewall policy with LDAP users and place it on the top of list of firewall policies.
- C. Under config user settings configure set auth-on-demand implicit.
- D. Configure a firewall policy with FSSO users and place it on the top of list of firewall policies.
Answer: D
Explanation:
Explanation
The OT supervisor should configure a firewall policy with FSSO users and place it on the top of list of firewall policies in order to achieve the goal of authenticating users against passive authentication first and, if passive authentication is not successful, then challenging them with active authentication.
NEW QUESTION # 31
You are investigating a series of incidents that occurred in the OT network over past 24 hours in FortiSIEM.
Which three FortiSIEM options can you use to investigate these incidents? (Choose three.)
- A. Overview
- B. IPS
- C. List
- D. Risk
- E. Security
Answer: A,C,D
NEW QUESTION # 32
Refer to the exhibit.
An OT architect has implemented a Modbus TCP with a simulation server Conpot to identify and control the Modus traffic in the OT network. The FortiGate-Edge device is configured with a software switch interface ssw-01.
Based on the topology shown in the exhibit, which two statements about the successful simulation of traffic between client and server are true? (Choose two.)
- A. The FortiGate-Edge device must be in NAT mode.
- B. NAT is disabled in the FortiGate firewall policy from port3 to ssw-01.
- C. Port5 is not a member of the software switch.
- D. The FortiGate devices is in offline IDS mode.
Answer: A,B
NEW QUESTION # 33
How can you achieve remote access and internel availability in an OT network?
- A. Implement SD-WAN to manage traffic on each ISP link.
- B. Create more access policies to prevent unauthorized access.
- C. Create a back-end backup network as a redundancy measure.
- D. Add additional internal firewalls to access OT devices.
Answer: A
NEW QUESTION # 34
An OT network architect needs to secure control area zones with a single network access policy to provision devices to any number of different networks.
On which device can this be accomplished?
- A. FortiSwitch
- B. FortiEDR
- C. FortiNAC
- D. FortiGate
Answer: D
Explanation:
An OT network architect can accomplish the goal of securing control area zones with a single network access policy to provision devices to any number of different networks on a FortiGate device.
NEW QUESTION # 35
Refer to the exhibit.
Given the configurations on the FortiGate, which statement is true?
- A. FortiGate is configured with forward-domains to forward only domain controller traffic.
- B. FortiGate is configured with forward-domains to reduce unnecessary traffic.
- C. FortiGate is configured with forward-domains to filter and drop non-domain controller traffic.
- D. FortiGate is configured with forward-domains to forward only company domain website traffic.
Answer: B
NEW QUESTION # 36
What two advantages does FortiNAC provide in the OT network? (Choose two.)
- A. It can be used for IoT device detection.
- B. It can be used for device profiling.
- C. It can be used for industrial intrusion detection and prevention.
- D. It can be used for network micro-segmentation.
Answer: A,B
Explanation:
Explanation
Typically, in a microsegmented network, NGFWs are used in conjunction with VLANs to implement security policies and to inspect and filter network communications. Fortinet FortiSwitch and FortiGate NGFW offer an integrated approach to microsegmentation.
NEW QUESTION # 37
Refer to the exhibit.
PLC-3 and CLIENT can send traffic to PLC-1 and PLC-2. FGT-2 has only one software switch (SSW-1) connecting both PLC-3 and CLIENT. PLC-3 and CLIENT cannot send traffic to each other.
Which two statements about the traffic between PCL-1 and PLC-2 are true? (Choose two.)
- A. The switch on FGT-2 must be hardware to implement micro-segmentation.
- B. Traffic must be inspected by FGT-EDGE in OT networks.
- C. FGT-2 controls intra-VLAN traffic through firewall policies.
- D. Micro-segmentation on FGT-2 prevents direct device-to-device communication.
Answer: C,D
NEW QUESTION # 38
Refer to the exhibit, which shows a non-protected OT environment.
An administrator needs to implement proper protection on the OT network.
Which three steps should an administrator take to protect the OT network? (Choose three.)
- A. Configure firewall policies with web filter to protect the different ICS networks.
- B. Configure firewall policies with industrial protocol sensors
- C. Use segmentation
- D. Deploy a FortiGate device within each ICS network.
- E. Deploy an edge FortiGate between the internet and an OT network as a one-arm sniffer.
Answer: A,B,E
NEW QUESTION # 39
When device profiling rules are enabled, which devices connected on the network are evaluated by the device profiling rules?
- A. Rogue devices, only when they connect for the first time
- B. Rogue devices, each time they connect
- C. All connected devices, each time they connect
- D. Known trusted devices, each time they change location
Answer: A
NEW QUESTION # 40
Which two statements about the Modbus protocol are true? (Choose two.)
- A. Modbus is used to establish communication between intelligent devices.
- B. Most of the PLC brands come with a built-in Modbus module.
- C. Modbus uses UDP frames to transport MBAP and function codes.
- D. You can implement Modbus networking settings on internetworking devices.
Answer: B,D
NEW QUESTION # 41
What triggers Layer 2 polling of infrastructure devices connected in the network?
- A. A linkup or linkdown trap
- B. A failed Layer 3 poll
- C. A matched security policy
- D. A matched profiling rule
Answer: A
NEW QUESTION # 42
The OT network analyst runs different level of reports to quickly explore threats that exploit the network. Such reports can be run on all routers, switches, and firewalls. Which FortiSIEM reporting method helps to identify these type of exploits of image firmware files?
- A. Threat hunting reports
- B. OT/loT reports
- C. Compliance reports
- D. CMDB reports
Answer: A
NEW QUESTION # 43
......
Provide Valid Dumps To Help You Prepare For Fortinet NSE 7 - OT Security 7.2 Exam: https://certlibrary.itpassleader.com/Fortinet/NSE7_OTS-7.2-dumps-pass-exam.html