The correct answer is B . A historically flat OT network permits excessive east-west communication, allowing a compromised host to move laterally toward other controllers, HMIs, and critical systems. Fortinet recommends microsegmentation to control these communication paths. The study guide explains that microsegmentation controls intra-VLAN traffic through firewall policies , prevents hosts in the same segment from directly seeing or communicating with each other, and forces permitted communication through an enforcement point such as FortiGate. This provides granular host isolation and increased traffic visibility for monitoring and threat hunting. A normal hardware switch does not inherently impose the required security policies and therefore does not adequately restrict lateral movement. SD-WAN addresses WAN path selection and resilience, while two-factor authentication strengthens user authentication but does not control device-to-device traffic inside a flat process or control network. Therefore, firewall-based microsegmentation is the required architectural control.
================
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit