[Dec-2024] Pass Fortinet NSE7_OTS-7.2 Tests Engine pdf - All Free Dumps
Fortinet NSE 7 - OT Security 7.2 Practice Tests 2024 | Pass NSE7_OTS-7.2 with confidence!
NEW QUESTION # 44
What is the main difference between real-time logs and historical logs on FortiAnalyzer?
- A. Historical logs are compressed and real-time logs are indexed in the SQL database.
- B. Historical logs are indexed in the SQL database, but real-time logs are not.
- C. Real-time logs are indexed in the SQL database, but historical logs are not.
- D. Real-time logs are indexed while historical logs are compressed in the SQL database.
Answer: B
NEW QUESTION # 45
Refer to the exhibit. An OT architect has implemented a Modbus TCP with a simulation server Conpot to identify and control the Modus traffic in the OT network. The FortiGate-Edge device is configured with a software switch interface ssw-01.
Based on the topology shown in the exhibit, which two statements about the successful simulation of traffic between client and server are true? (Choose two.)
- A. NAT is disabled in the FortiGate firewall policy from port3 to ssw-01.
- B. The FortiGate-Edge device must be in NAT mode.
- C. Port5 is not a member of the software switch.
- D. The FortiGate devices is in offline IDS mode.
Answer: A,B
NEW QUESTION # 46
Refer to the exhibit.
An OT architect has implemented a Modbus TCP with a simulation server Conpot to identify and control the Modus traffic in the OT network. The FortiGate-Edge device is configured with a software switch interface ssw-01.
Based on the topology shown in the exhibit, which two statements about the successful simulation of traffic between client and server are true? (Choose two.)
- A. NAT is disabled in the FortiGate firewall policy from port3 to ssw-01.
- B. The FortiGate-Edge device must be in NAT mode.
- C. Port5 is not a member of the software switch.
- D. The FortiGate devices is in offline IDS mode.
Answer: A,B
NEW QUESTION # 47
Refer to the exhibit.
You are navigating through FortiSIEM in an OT network.
How do you view information presented in the exhibit and what does the FortiGate device security status tell you?
- A. In the summary dashboard and there are one or more high-severity security incidents for the FortiGate device.
- B. In the PCI logging dashboard and there are one or more high-severity security incidents for the FortiGate device.
- C. In the widget dashboard and there are one or more high-severity incidents for the FortiGate device.
- D. In the business service dashboard and there are one or more high-severity security incidents for the FortiGate device.
Answer: A
NEW QUESTION # 48
A FortiGate device is newly deployed as the edge gateway of an OT network security fabric. The downstream FortiGate devices are also newly deployed as Security Fabric leafs to protect the control area zone.
With no additional essential networking devices, and to implement micro-segmentation on this OT network, what configuration must the OT network architect apply to control intra-VLAN traffic?
- A. Create a software switch on each downstream FortiGate device.
- B. Enable transparent mode on the edge FortiGate device.
- C. Set up VPN tunnels between downstream and edge FortiGate devices.
- D. Enable security profiles on all interfaces connected in the control area zone.
Answer: C
NEW QUESTION # 49
Which three criteria can a FortiGate device use to look for a matching firewall policy to process traffic?
(Choose three.)
- A. Lowest to highest policy ID number
- B. Destination defined as internet services in the firewall policy
- C. Highest to lowest priority defined in the firewall policy
- D. Source defined as internet services in the firewall policy
- E. Services defined in the firewall policy.
Answer: B,C,E
Explanation:
Explanation
The three criteria that a FortiGate device can use to look for a matching firewall policy to process traffic are:
A: Services defined in the firewall policy - FortiGate devices can match firewall policies based on the services defined in the policy, such as HTTP, FTP, or DNS.
D: Destination defined as internet services in the firewall policy - FortiGate devices can also match firewall policies based on the destination of the traffic, including destination IP address, interface, or internet services.
E: Highest to lowest priority defined in the firewall policy - FortiGate devices can prioritize firewall policies based on the priority defined in the policy. The device will process traffic against the policy with the highest priority first and move down the list until it finds a matching policy.
NEW QUESTION # 50
An OT architect has deployed a Layer 2 switch in the OT network at Level 1 the Purdue model-process control. The purpose of the Layer 2 switch is to segment traffic between PLC1 and PLC2 with two VLANs.
All the traffic between PLC1 and PLC2 must first flow through the Layer 2 switch and then through the FortiGate device in the Level 2 supervisory control network.
What statement about the traffic between PLC1 and PLC2 is true?
- A. The Layer 2 switch rewrites VLAN tags before sending traffic to the FortiGate device.
- B. PLC1 and PLC2 traffic must flow through the Layer-2 switch trunk link to the FortiGate device.
- C. In order to communicate, PLC1 must be in the same VLAN as PLC2.
- D. The Layer 2 switches routes any traffic to the FortiGate device through an Ethernet link.
Answer: B
Explanation:
Explanation
The statement that is true about the traffic between PLC1 and PLC2 is that PLC1 and PLC2 traffic must flow through the Layer-2 switch trunk link to the FortiGate device.
NEW QUESTION # 51
A supervisor is configuring a software switch on a FortiGate device. What must the supervisor configure on FortiGate to control the traffic between member interfaces on the software switch, using firewall policies?
- A. The supervisor must configure a separate forward domain for the software switch.
- B. The supervisor must configure intra-switch-policy to explicit.
- C. The supervisor must configure the software switch with at least one wireless interface and one VLAN interface.
- D. The supervisor must add different VLAN interfaces to the software switch.
Answer: B
NEW QUESTION # 52
In a wireless network integration, how does FortiNAC obtain connecting MAC address information?
- A. End station traffic monitoring
- B. MAC notification traps
- C. RADIUS
- D. Link traps
Answer: C
Explanation:
Explanation
FortiNAC can integrate with RADIUS servers to obtain MAC address information for wireless clients that authenticate through the RADIUS server.
NEW QUESTION # 53
Which two frameworks are common to secure ICS industrial processes, including SCADA and DCS? (Choose two.)
- A. IEC 62443
- B. Modbus
- C. NIST Cybersecurity
- D. IEC104
Answer: A,D
NEW QUESTION # 54
FortiAnalyzer is implemented in the OT network to receive logs from responsible FortiGate devices.
The logs must be processed by FortiAnalyzer.
In this scenario, which statement is correct about the purpose of FortiAnalyzer receiving and processing multiple log messages from a given PLC or RTU?
- A. To configure event handlers and take further action on FortiGate
- B. To help OT administrators configure the network and prevent breaches
- C. To determine which type of messages from the PLC or RTU causes issues in the plant
- D. To isolate PLCs or RTUs in the event of external attacks
Answer: A
NEW QUESTION # 55
To increase security protection in an OT network, how does application control on ForliGate detect industrial traffic?
- A. By inspecting applications with more granularity by inspecting subapplication traffic
- B. By inspecting software and software-based vulnerabilities
- C. By inspecting applications only on nonprotected traffic
- D. By inspecting protocols used in the application traffic
Answer: C
NEW QUESTION # 56
An OT network architect must deploy a solution to protect fuel pumps in an industrial remote network. All the fuel pumps must be closely monitored from the corporate network for any temperature fluctuations.
How can the OT network architect achieve this goal?
- A. Configure a fuel server on the corporate network, and deploy a FortiSIEM with a single pattern temperature performance rule on the remote network.
- B. Configure both fuel server and FortiSIEM with a single-pattern temperature performance rule on the corporate network.
- C. Configure a fuel server on the remote network, and deploy a FortiSIEM with a single pattern temperature performance rule on the corporate network.
- D. Configure a fuel server on the remote network, and deploy a FortiSIEM with a single pattern temperature security rule on the corporate network.
Answer: C
Explanation:
This way, FortiSIEM can discover and monitor everything attached to the remote network and provide security visibility to the corporate network
NEW QUESTION # 57
Which three criteria can a FortiGate device use to look for a matching firewall policy to process traffic?
(Choose three.)
- A. Lowest to highest policy ID number
- B. Destination defined as internet services in the firewall policy
- C. Highest to lowest priority defined in the firewall policy
- D. Source defined as internet services in the firewall policy
- E. Services defined in the firewall policy.
Answer: B,C,E
Explanation:
The three criteria that a FortiGate device can use to look for a matching firewall policy to process traffic are:
A: Services defined in the firewall policy - FortiGate devices can match firewall policies based on the services defined in the policy, such as HTTP, FTP, or DNS.
D: Destination defined as internet services in the firewall policy - FortiGate devices can also match firewall policies based on the destination of the traffic, including destination IP address, interface, or internet services.
E: Highest to lowest priority defined in the firewall policy - FortiGate devices can prioritize firewall policies based on the priority defined in the policy. The device will process traffic against the policy with the highest priority first and move down the list until it finds a matching policy.
NEW QUESTION # 58
Refer to the exhibit. An OT network security audit concluded that the application sensor requires changes to ensure the correct security action is committed against the overrides filters.
Which change must the OT network administrator make?
- A. Change the security action of the industrial category to monitor.
- B. Set the priority of the C.BO.NA.1 signature override to 1.
- C. Set all application categories to apply default actions.
- D. Remove IEC.60870.5.104 Information.Transfer from the first filter override.
Answer: B
Explanation:
The application sensor settings allow you to configure the security action for each application category and network protocol override. The security action determines how the FortiGate unit handles traffic that matches the application category or network protocol override. The security action can be one of the following:
Allow: The FortiGate unit allows the traffic without any further inspection. Monitor: The FortiGate unit allows the traffic and logs it for monitoring purposes.
Block: The FortiGate unit blocks the traffic and logs it as an attack. The priority of the network protocol override determines the order in which the FortiGate unit applies the security action to the traffic. The lower the priority number, the higher the priority. For example, a priority of 1 is higher than a priority of 10. In the exhibit, the application sensor has the following settings:
The industrial category has a security action of allow, which means that the FortiGate unit will not inspect or log any traffic that belongs to this category. The IEC.60870.5.104 Information.Transfer network protocol override has a security action of block, which means that the FortiGate unit will block and log any traffic that matches this protocol. The IEC.60870.5.104 Control.Functions network protocol override has a security action of monitor, which means that the FortiGate unit will allow and log any traffic that matches this protocol. The IEC.60870.5.104 Start/Stop network protocol override has a security action of allow, which means that the FortiGate unit will not inspect or log any traffic that matches this protocol. The IEC.60870.5.104 Transfer.C.BO.NA.1 network protocol override has a security action of block, which means that the FortiGate unit will block and log any traffic that matches this protocol. The problem with these settings is that the IEC.60870.5.104 Transfer.C.BO.NA.1 network protocol override has a lower priority than the IEC.60870.5.104 Information.Transfer network protocol override. This means that if the traffic matches both protocols, the FortiGate unit will apply the security action of the higher priority override, which is block. However, the IEC.60870.5.104 Transfer.C.BO.NA.1 protocol is used to transfer binary outputs, which are essential for controlling OT devices. Therefore, blocking this protocol could have negative consequences for the OT network. To fix this issue, the OT network administrator must set the priority of the IEC.60870.5.104 Transfer.C.BO.NA.1 network protocol override to 1, which is higher than the priority of the IEC.60870.5.104 Information.Transfer network protocol override. This way, the FortiGate unit will apply the security action of the lower priority override, which is allow, to the traffic that matches both protocols. This will ensure that the FortiGate unit does not block the traffic that is used to transfer binary outputs, while still blocking the traffic that is used to transfer information.
NEW QUESTION # 59
You are investigating a series of incidents that occurred in the OT network over past 24 hours in FortiSIEM. Which three FortiSIEM options can you use to investigate these incidents? (Choose three.)
- A. Security
- B. List
- C. IPS
- D. Overview
- E. Risk
Answer: B,D,E
NEW QUESTION # 60
Refer to the exhibit.
Given the configurations on the FortiGate, which statement is true?
- A. FortiGate is configured with forward-domains to forward only company domain website traffic.
- B. FortiGate is configured with forward-domains to filter and drop non-domain controller traffic.
- C. FortiGate is configured with forward-domains to reduce unnecessary traffic.
- D. FortiGate is configured with forward-domains to forward only domain controller traffic.
Answer: C
NEW QUESTION # 61
What are two critical tasks the OT network auditors must perform during OT network risk assessment and management? (Choose two.)
- A. Evaluating what can go wrong before it happens
- B. Implementing strategies to automatically bring PLCs offline
- C. Creating disaster recovery plans to switch operations to a backup plant
- D. Planning a threat hunting strategy
Answer: B,C
NEW QUESTION # 62
Refer to the exhibit. The IPS profile is added on all of the security policies on FortiGate. For an OT network, which statement of the IPS profile is true?
- A. All IPS signatures are overridden and must block traffic match signature patterns.
- B. The IPS profile inspects only traffic originating from SCADA equipment.
- C. FortiGate has no IPS industrial signature database enabled.
- D. The listed IPS signatures are classified as SCADAapphcat nns
Answer: D
NEW QUESTION # 63
Refer to the exhibit.
An operational technology rule is created and successfully activated to monitor the Modbus protocol on FortiSIEM. However, the rule does not trigger incidents despite Modbus traffic and application logs being received correctly by FortiSIEM.
Which statement correctly describes the issue on the rule configuration?
- A. The SubPattern is missing the filter to match the Modbus protocol.
- B. The attributes in the Group By section must match the ones in Fitters section.
- C. The Aggregate attribute COUNT expression is incompatible with the filters.
- D. The first condition on the SubPattern filter must use the OR logical operator.
Answer: B
NEW QUESTION # 64
An OT architect has deployed a Layer 2 switch in the OT network at Level 1 the Purdue model-process control. The purpose of the Layer 2 switch is to segment traffic between PLC1 and PLC2 with two VLANs.
All the traffic between PLC1 and PLC2 must first flow through the Layer 2 switch and then through the FortiGate device in the Level 2 supervisory control network.
What statement about the traffic between PLC1 and PLC2 is true?
- A. The Layer 2 switch rewrites VLAN tags before sending traffic to the FortiGate device.
- B. PLC1 and PLC2 traffic must flow through the Layer-2 switch trunk link to the FortiGate device.
- C. In order to communicate, PLC1 must be in the same VLAN as PLC2.
- D. The Layer 2 switches routes any traffic to the FortiGate device through an Ethernet link.
Answer: B
Explanation:
The statement that is true about the traffic between PLC1 and PLC2 is that PLC1 and PLC2 traffic must flow through the Layer-2 switch trunk link to the FortiGate device.
NEW QUESTION # 65
Which three methods of communication are used by FortiNAC to gather visibility information? (Choose three.)
- A. SNMP
- B. TACACS
- C. ICMP
- D. RADIUS
- E. API
Answer: A,D,E
NEW QUESTION # 66
......
Online Exam Practice Tests with detailed explanations!: https://realexamcollection.examslabs.com/Fortinet/NSE-7-Network-Security-Architect/best-NSE7_OTS-7.2-exam-dumps.html