Pre-Summer Sale Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

Fortinet NSE6_OTS_AR-7.6 Fortinet NSE 6 - OT Security 7.6 Architect Exam Practice Test

Fortinet NSE 6 - OT Security 7.6 Architect Questions and Answers

Question 1

Refer to the exhibit.

Question # 1

The OT devices behind the ruggedized FortiGate have vulnerabilities and you want to apply a virtual patching profile in the firewall policy. Why is Virtual Patching not available in the Security Profiles section? (Choose one answer)

Options:

A.

You must enable Virtual Patching in the Feature Visibility section.

B.

You must have a ruggedized FortiGate allowing the virtual patching feature.

C.

You must enable OT signatures.

D.

You must have a valid OT security service license.

Question 2

In the Purdue model, at which level are physical assets like the Industrial Internet of Things (IIoT) placed? (Choose one answer)

Options:

A.

At Level 5 only

B.

At Level 1 only

C.

Above Level 4

D.

Below Level 3.5

Question 3

Refer to the exhibits.

Question # 3

Question # 3

A partial Incident Analysis page and the log details related to the event are shown. An attack is reported on your OT network. You analyze the corresponding incident. Based on the information provided on the Incident Analysis page and the log details, which two statements are correct? (Choose two answers)

Options:

A.

The attack uses the Modbus protocol.

B.

The attack is mitigated.

C.

The attack uses the IEC 104 protocol.

D.

The event severity is high.

E.

The target device IP address is 10.1.5.20.

Question 4

Refer to the exhibit.

Question # 4

A firewall policy page is shown. To improve the security of your OT network, you have configured a Supervisor profile in the firewall policies, as shown in the exhibit. However, a supervisor is reporting that he cannot ping PLC-1. What are the two reasons? (Choose two answers)

Options:

A.

The supervisor must first authenticate using a protocol such as HTTPS or Telnet.

B.

The Supervisor profile is not configured in the remote server.

C.

The firewall policy ID 8 is not enabled.

D.

The CLI parameter auth-on-demand is set to always.

Question 5

What is the main OT component for monitoring and controlling industrial processes? (Choose one answer)

Options:

A.

Programmable Logical Controller (PLC)

B.

Supervisory Control and Data Acquisition (SCADA)

C.

Industrial Control System (ICS)

D.

Industrial Internet of Things (IIoT)

Question 6

Refer to the exhibit.

Question # 6

A simplified OT network is shown. You want to optimize the protection of this OT network. Which two controls must you implement? (Choose two answers)

Options:

A.

Offline IDS on FortiGate_Level3.

B.

IPS on FortiGate_Level5.

C.

Virtual patching on FortiGate_Level2.

D.

OT signature on FortiGate_Level5.

Question 7

Refer to the exhibit.

Question # 7

A partial Incident Analysis page is shown. How was the 360-Degree Security Review OT report attached to the incident? (Choose one answer)

Options:

A.

Automatically by a stitch

B.

Automatically by an event handler

C.

Automatically by a playbook

D.

Manually by an administrator

Question 8

Refer to the exhibit.

Question # 8

The Core Network Security Connectors page of the FortiGate-2 device is shown. Which statement is correct? (Choose one answer)

Options:

A.

FortiGate-2 serves as Fabric Root.

B.

You must enable Security Fabric Connection on the FortiGate-2 interface.

C.

You must configure the FortiAnalyzer settings on FortiGate-2.

D.

FortiGate-2 is not authorized on the root FortiGate.

Question 9

You want to automate some tasks in your OT network. Which three configurations are directly available in a new basic event handler on FortiAnalyzer? (Choose three answers)

Options:

A.

Send alert email

B.

Create a report

C.

Quarantine an attacker

D.

Automatically create an incident

E.

Automation stitch

Question 10

Refer to the exhibit.

Question # 10

A Run_report task is shown. You want to automate the generation of a newly created report on FortiAnalyzer . When you configure the Run_report task in Playbook, why is the report not shown in the Report field? (Choose two answers)

Options:

A.

You must first configure the connector.

B.

You must first enable Extended Log Filtering in the report.

C.

You must first enable Auto-cache in the report.

D.

You must first configure an event handler.

E.

You must first select Playbook Starter, and then select the newly created report.

Question 11

Refer to the exhibit.

Question # 11

A partial OT network is shown. You want to provide the supervisor with secure remote access. Which two features can you implement on Edge-FortiGate ? (Choose two answers)

Options:

A.

IPsec

B.

FortiToken

C.

SD-WAN

D.

FSSO

Question 12

You want FortiAnalyzer to trigger an automation stitch on a FortiGate device automatically. What must you configure on FortiAnalyzer to enable direct communication with FortiGate? (Choose one answer)

Options:

A.

A Fabric connector

B.

A playbook task

C.

The Fabric settings

D.

An event handler

Question 13

Refer to the exhibit.

Question # 13

Why is the OT View tab not available in the Asset Identity Center section of the FortiGate-1 device? (Choose one answer)

Options:

A.

You must enable the Purdue Levels feature on the FortiGate-1 device. B. Device Detection is not enabled on the FortiGate-1 interface. C. The OT View tab is only available on the root FortiGate. D. You must enable Security Fabric Connection on the interfaces of the FortiGate-1 device.