Fortinet NSEI_OTS_AR-7.6 Fortinet NSE I - OT Security 7.6 Architect Exam Practice Test
Fortinet NSE I - OT Security 7.6 Architect Questions and Answers
You want to improve the security of your OT network and therefore deploy a FortiGate device with the OT signatures database. Which two statements about this database are true? (Choose two answers)
Refer to the exhibit.

A Run_report task is shown. You want to automate the generation of a newly created report on FortiAnalyzer . When you configure the Run_report task in Playbook, why is the report not shown in the Report field? (Choose two answers)
Refer to the exhibits.

A partial view of the Playbook Monitor page and the corresponding playbook configuration are shown. Based on the monitor page and the configuration of the playbook, what has triggered the Run_Report task? (Choose one answer)
What is the main OT component for monitoring and controlling industrial processes? (Choose one answer)
Refer to the exhibit. A partial OT network is shown. You must improve the security of this OT network and implement internal segmentation between network 1 and network 2. How can you achieve the segmentation? (Choose one answer)

You would like to customize your current FortiAnalyzer report to provide a better risk assessment of your OT network. Which two options can you use to enhance your report? (Choose two answers)
Refer to the exhibit.

A partial Incident Analysis page is shown. How was the 360-Degree Security Review OT report attached to the incident? (Choose one answer)
Refer to the exhibit.

A simplified OT network is shown. You want to optimize the protection of this OT network. Which two controls must you implement? (Choose two answers)
You want to automate some tasks in your OT network. Which three configurations are directly available in a new basic event handler on FortiAnalyzer? (Choose three answers)
Refer to the exhibit.

A Logical Topology page of a FortiGate device is shown. Your OT company wants to gain visibility into the network. You decide to implement device detection with the Security Fabric. Based on the exhibit, which statement is correct? (Choose one answer)
For the installation of your first FortiGate device, you want to minimize the impact in your OT network. Therefore, you deploy it initially as an offline IDS. Which two statements about this deployment are correct? (Choose two answers)
Refer to the exhibit.

A Virtual Patching profile is shown. You have recently updated your SCADA system and would like to apply the SCADA virtual patching profile. Which two statements about this profile are correct? (Choose two answers)
Refer to the exhibit.

The Core Network Security Connectors page of a FortiGate device is shown. You are configuring the Security Fabric in your OT network. One of the devices is not sending logs to FortiAnalyzer. When you check the status of the FortiGate device, it is Disabled as shown in the exhibit. Which two actions must you perform to enable this FortiGate device to send logs to FortiAnalyzer? (Choose two answers)
Refer to the exhibit.

Based on the information provided on the partial Event Monitor page shown in the exhibit, how was the attack detected? (Choose one answer)
You want to gain complete visibility of the entire attack surface using FortiAnalyzer.
Which two views must you use to achieve this result? (Choose two.)
Refer to the exhibit.

The configuration of firewall policies is shown.
To improve the security of your OT network, you have configured authentication in the firewall policies as shown in the exhibit, with CLI parameters set to their default settings. However, when you test HTTPS access from the LAN subnet to PLC-1, it is successful without any authentication prompt.
What is the reason?