Weekend Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: discactive

Fortinet NSEI_OTS_AR-7.6 Fortinet NSE I - OT Security 7.6 Architect Exam Practice Test

Fortinet NSE I - OT Security 7.6 Architect Questions and Answers

Question 1

Refer to the exhibit.

Question # 1

A partial Application Sensor profile is shown. When you apply this profile in a firewall policy, which two statements are correct? (Choose two answers)

Options:

A.

A log is provided for each IEC command.

B.

A log is provided for each Modbus command.

C.

OT signatures are enabled.

D.

All OT protocols are blocked.

Question 2

Refer to the exhibit.

Question # 2

A Virtual Patching profile is shown. You have recently updated your SCADA system and would like to apply the SCADA virtual patching profile. Which two statements about this profile are correct? (Choose two answers)

Options:

A.

Only the vulnerability Schneider.Electric.ClearSCADA.HTTP.Interface.XSS is still present.

B.

Low severity signatures are not blocked for the device with the MAC address 12:12:12:12:12.

C.

This profile blocks critical severity signatures for all the devices.

D.

The device with the MAC address 11:11:11:11:11 is considered to have no vulnerabilities.

Question 3

Refer to the exhibit.

Question # 3

The Core Network Security Connectors page of the FortiGate-2 device is shown. Which statement is correct? (Choose one answer)

Options:

A.

FortiGate-2 serves as Fabric Root.

B.

You must enable Security Fabric Connection on the FortiGate-2 interface.

C.

You must configure the FortiAnalyzer settings on FortiGate-2.

D.

FortiGate-2 is not authorized on the root FortiGate.

Question 4

Refer to the exhibits.

Question # 4

A partial Basic Event Handler page on FortiAnalyzer and the creation of a trigger in a FortiGate device are shown. To improve the protection of your OT network, you want to automate the handling of compromised devices notified through FortiAnalyzer. You have configured an event handler named Alert_trigger as shown in the exhibit. When you create the trigger on the FortiGate device, the Event handler name field does not provide the Alert_trigger option. What two actions must you perform to make the Alert_trigger option available? (Choose two answers)

Options:

A.

You must click + Create in the Event handler name field.

B.

You must authorize the FortiGate device on FortiAnalyzer.

C.

You must configure the FortiAnalyzer setting on the FortiGate device.

D.

You must configure the trigger on the root FortiGate.

Question 5

Refer to the exhibit.

Question # 5

A firewall policy page is shown. To improve the security of your OT network, you have configured a Supervisor profile in the firewall policies, as shown in the exhibit. However, a supervisor is reporting that he cannot ping PLC-1. What are the two reasons? (Choose two answers)

Options:

A.

The supervisor must first authenticate using a protocol such as HTTPS or Telnet.

B.

The Supervisor profile is not configured in the remote server.

C.

The firewall policy ID 8 is not enabled.

D.

The CLI parameter auth-on-demand is set to always.

Question 6

Which industrial protocol does not support VLANs? (Choose one answer)

Options:

A.

[Not clearly visible in the exhibit]

B.

Ethernet over industrial protocol

C.

EtherCAT

D.

Modbus over TCP

Question 7

Refer to the exhibit.

Question # 7

A partial Incident Analysis page is shown. How was the 360-Degree Security Review OT report attached to the incident? (Choose one answer)

Options:

A.

Automatically by a stitch

B.

Automatically by an event handler

C.

Automatically by a playbook

D.

Manually by an administrator

Question 8

Refer to the exhibits.

Question # 8

Question # 8

A partial Incident Analysis page and the log details related to the event are shown. An attack is reported on your OT network. You analyze the corresponding incident. Based on the information provided on the Incident Analysis page and the log details, which two statements are correct? (Choose two answers)

Options:

A.

The attack uses the Modbus protocol.

B.

The attack is mitigated.

C.

The attack uses the IEC 104 protocol.

D.

The event severity is high.

E.

The target device IP address is 10.1.5.20.

Question 9

What are two advantages provided by industrial Ethernet? (Choose two answers)

Options:

A.

Encryption

B.

Real-time control

C.

Remote access

D.

Determinism

Question 10

Refer to the exhibit.

Question # 10

A partial OT network is shown. You must improve the security of this OT network and implement internal segmentation between network 1 and network 2. How can you achieve the segmentation? (Choose one answer)

Options:

A.

You can configure universal ZTNA.

B.

You can configure one traffic VDOM.

C.

You can configure an explicit software switch.

D.

You can configure forward domain IDs for each network.

Question 11

Refer to the exhibit.

Question # 11

A partial OT network is shown. You want to provide the supervisor with secure remote access. Which two features can you implement on Edge-FortiGate ? (Choose two answers)

Options:

A.

IPsec

B.

FortiToken

C.

SD-WAN

D.

FSSO

Question 12

Refer to the exhibit. A partial OT network is shown. You must improve the security of this OT network and implement internal segmentation between network 1 and network 2. How can you achieve the segmentation? (Choose one answer)

Question # 12

Options:

A.

You can configure universal ZTNA.

B.

You can configure one traffic VDOM.

C.

You can configure an explicit software switch.

D.

You can configure forward domain IDs for each network.

Question 13

Refer to the exhibits.

Question # 13

A partial view of the Playbook Monitor page and the corresponding playbook configuration are shown. Based on the monitor page and the configuration of the playbook, what has triggered the Run_Report task? (Choose one answer)

Options:

A.

An IPS_Attack_Handling event

B.

An IPS incident creation

C.

An Event_Trigger log

D.

An IPS_Attack_Incident log