Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Fortinet Fortinet Network Security Expert NSEI_OTS_AR-7.6 Questions and answers with CertsForce

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

Refer to the exhibit. A partial OT network is shown. You must improve the security of this OT network and implement internal segmentation between network 1 and network 2. How can you achieve the segmentation? (Choose one answer)

Question # 1

Options:

A.

You can configure universal ZTNA.


B.

You can configure one traffic VDOM.


C.

You can configure an explicit software switch.


D.

You can configure forward domain IDs for each network.


Expert Solution
Questions # 2:

Refer to the exhibits.

Question # 2

A partial Basic Event Handler page on FortiAnalyzer and the creation of a trigger in a FortiGate device are shown. To improve the protection of your OT network, you want to automate the handling of compromised devices notified through FortiAnalyzer. You have configured an event handler named Alert_trigger as shown in the exhibit. When you create the trigger on the FortiGate device, the Event handler name field does not provide the Alert_trigger option. What two actions must you perform to make the Alert_trigger option available? (Choose two answers)

Options:

A.

You must click + Create in the Event handler name field.


B.

You must authorize the FortiGate device on FortiAnalyzer.


C.

You must configure the FortiAnalyzer setting on the FortiGate device.


D.

You must configure the trigger on the root FortiGate.


Expert Solution
Questions # 3:

Refer to the exhibit.

Question # 3

Which statement about this partial Asset Identity List page is correct? (Choose one answer)

Options:

A.

A firewall policy has an Antivirus security profile applied to it.


B.

A firewall policy has a Virtual Patching security profile applied to it.


C.

A firewall policy has an Intrusion Prevention security profile applied to it.


D.

A firewall policy has an Application Control security profile applied to it.


Expert Solution
Questions # 4:

Refer to the exhibit.

Question # 4

A partial OT network is shown. You have configured the FortiGate device with VLANs to segment the OT network. The supervisor now wants to connect to the PLC from the Engineering Workstation. How can you allow access from the Engineering Workstation to the PLC? (Choose one answer)

Options:

A.

You must configure intra-switch-policy as explicit.


B.

You must configure intra-switch-policy as implicit.


C.

You must configure forward domain IDs.


D.

You must configure a layer 3 switch.


Expert Solution
Questions # 5:

In the Purdue model, at which level are physical assets like the Industrial Internet of Things (IIoT) placed? (Choose one answer)

Options:

A.

At Level 5 only


B.

At Level 1 only


C.

Above Level 4


D.

Below Level 3.5


Expert Solution
Questions # 6:

Refer to the exhibit.

Question # 6

Which statement about this partial Asset Identity List page is correct? (Choose one answer)

Options:

A.

A firewall policy has an Antivirus security profile applied to it.


B.

A firewall policy has a Virtual Patching security profile applied to it.


C.

A firewall policy has an Intrusion Prevention security profile applied to it.


D.

A firewall policy has an Application Control security profile applied to it.


Expert Solution
Questions # 7:

You want FortiAnalyzer to trigger an automation stitch on a FortiGate device automatically. What must you configure on FortiAnalyzer to enable direct communication with FortiGate? (Choose one answer)

Options:

A.

A Fabric connector


B.

A playbook task


C.

The Fabric settings


D.

An event handler


Expert Solution
Questions # 8:

In your OT environment, you want to detect the devices passively. Which two methods must you implement? (Choose two answers)

Options:

A.

SSH


B.

SNMP


C.

Vendor OUI


D.

Network traffic


Expert Solution
Questions # 9:

Refer to the exhibit.

Question # 9

A partial OT network is shown. In this OT network, you must add additional security measures to detect OT protocols and, therefore, increase the traffic visibility. Which security sensor must you implement to detect the OT protocols in this network? (Choose one answer)

Options:

A.

Device detection on all the FortiGate interfaces.


B.

Inline IDS on FortiGate_Level3.


C.

Application sensor set to monitor on all the FortiGate devices.


D.

IPS sensor on FortiGate_Level5.


Expert Solution
Questions # 10:

How are rogue devices evaluated in FortiNAC? (Choose one answer)

Options:

A.

Through device profiling rules


B.

Through queries to FortiGuard servers


C.

Through the import of the devices list


D.

Through the local device database (CIDB)


Expert Solution
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions