[Feb 15, 2024] New NSE7_OTS-7.2 Exam Dumps with High Passing Rate [Q28-Q49]

Share

[Feb 15, 2024] New NSE7_OTS-7.2 Exam Dumps with High Passing Rate

Get NSE7_OTS-7.2 Braindumps & NSE7_OTS-7.2 Real Exam Questions


Fortinet NSE7_OTS-7.2 Certification Exam is a comprehensive exam that tests the knowledge and skills of security professionals in the field of OT security. By earning this certification, candidates can demonstrate their expertise in Fortinet NSE 7 OT Security 7.2 and their ability to design and implement secure solutions for industrial control systems and other OT environments. Fortinet NSE 7 - OT Security 7.2 certification is recognized globally and can help professionals advance their careers in the field of cybersecurity.


The primary objective of the Fortinet NSE7_OTS-7.2 exam is to test the candidate's ability to design, implement, and manage OT security solutions. NSE7_OTS-7.2 exam aims to evaluate the candidate's knowledge of OT security principles, including device hardening, access control, and threat detection and response.

 

NEW QUESTION # 28
An administrator wants to use FortiSoC and SOAR features on a FortiAnalyzer device to detect and block any unauthorized access to FortiGate devices in an OT network.
Which two statements about FortiSoC and SOAR features on FortiAnalyzer are true? (Choose two.)

  • A. You cannot use Windows and Linux hosts security events with FortiSoC.
  • B. You can automate SOC tasks through playbooks.
  • C. Each playbook can include multiple triggers.
  • D. You must set correct operator in event handler to trigger an event.

Answer: B,D

Explanation:
Explanation
Ref: https://docs.fortinet.com/document/fortianalyzer/7.0.0/administration-guide/268882/fortisoc


NEW QUESTION # 29
Which three common breach points can be found in a typical OT environment? (Choose three.)

  • A. Hard hat
  • B. Global hat
  • C. VLAN exploits
  • D. RTU exploits
  • E. Black hat

Answer: A,D,E


NEW QUESTION # 30
An OT supervisor has configured LDAP and FSSO for the authentication. The goal is that all the users be authenticated against passive authentication first and, if passive authentication is not successful, then users should be challenged with active authentication.
What should the OT supervisor do to achieve this on FortiGate?

  • A. Enable two-factor authentication with FSSO.
  • B. Under config user settings configure set auth-on-demand implicit.
  • C. Configure a firewall policy with LDAP users and place it on the top of list of firewall policies.
  • D. Configure a firewall policy with FSSO users and place it on the top of list of firewall policies.

Answer: D

Explanation:
Explanation
The OT supervisor should configure a firewall policy with FSSO users and place it on the top of list of firewall policies in order to achieve the goal of authenticating users against passive authentication first and, if passive authentication is not successful, then challenging them with active authentication.


NEW QUESTION # 31
What are two critical tasks the OT network auditors must perform during OT network risk assessment and management? (Choose two.)

  • A. Planning a threat hunting strategy
  • B. Implementing strategies to automatically bring PLCs offline
  • C. Creating disaster recovery plans to switch operations to a backup plant
  • D. Evaluating what can go wrong before it happens

Answer: B,C


NEW QUESTION # 32
Refer to the exhibit.

An OT network security audit concluded that the application sensor requires changes to ensure the correct security action is committed against the overrides filters.
Which change must the OT network administrator make?

  • A. Set all application categories to apply default actions.
  • B. Change the security action of the industrial category to monitor.
  • C. Remove IEC.60870.5.104 Information.Transfer from the first filter override.
  • D. Set the priority of the C.BO.NA.1 signature override to 1.

Answer: D

Explanation:
Explanation
According to the Fortinet NSE 7 - OT Security 6.4 exam guide1, the application sensor settings allow you to configure the security action for each application category andnetwork protocol override. The security action determines how the FortiGate unit handles traffic that matches the application category or network protocol override. The security action can be one of the following:
Allow: The FortiGate unit allows the traffic without any further inspection.
Monitor: The FortiGate unit allows the traffic and logs it for monitoring purposes.
Block: The FortiGate unit blocks the traffic and logs it as an attack.
The priority of the network protocol override determines the order in which the FortiGate unit applies the security action to the traffic. The lower the priority number, the higher the priority. For example, a priority of 1 is higher than a priority of 10.
In the exhibit, the application sensor has the following settings:
The industrial category has a security action of allow, which means that the FortiGate unit will not inspect or log any traffic that belongs to this category.
The IEC.60870.5.104 Information.Transfer network protocol override has a security action of block, which means that the FortiGate unit will block and log any traffic that matches this protocol.
The IEC.60870.5.104 Control.Functions network protocol override has a security action of monitor, which means that the FortiGate unit will allow and log any traffic that matches this protocol.
The IEC.60870.5.104 Start/Stop network protocol override has a security action of allow, which means that the FortiGate unit will not inspect or log any traffic that matches this protocol.
The IEC.60870.5.104 Transfer.C.BO.NA.1 network protocol override has a security action of block, which means that the FortiGate unit will block and log any traffic that matches this protocol.
The problem with these settings is that the IEC.60870.5.104 Transfer.C.BO.NA.1 network protocol override has a lower priority than the IEC.60870.5.104 Information.Transfer network protocol override. This means that if the traffic matches both protocols, the FortiGate unit will apply the security action of the higher priority override, which is block. However, the IEC.60870.5.104 Transfer.C.BO.NA.1 protocol is used to transfer binary outputs, which are essential for controlling OT devices. Therefore, blocking this protocol could have negative consequences for the OT network.
To fix this issue, the OT network administrator must set the priority of the IEC.60870.5.104 Transfer.C.BO.NA.1 network protocol override to 1, which is higher than the priority of the IEC.60870.5.104 Information.Transfer network protocol override. This way, the FortiGate unit will apply the security action of the lower priority override, which is allow, to the traffic that matches both protocols. This will ensure that the FortiGate unit does not block the traffic that is used to transfer binary outputs, while still blocking the traffic that is used to transfer information.
1: NSE 7 Network Security Architect - Fortinet


NEW QUESTION # 33
Refer to the exhibit, which shows a non-protected OT environment.

An administrator needs to implement proper protection on the OT network.
Which three steps should an administrator take to protect the OT network? (Choose three.)

  • A. Use segmentation
  • B. Configure firewall policies with web filter to protect the different ICS networks.
  • C. Configure firewall policies with industrial protocol sensors
  • D. Deploy an edge FortiGate between the internet and an OT network as a one-arm sniffer.
  • E. Deploy a FortiGate device within each ICS network.

Answer: B,C,D


NEW QUESTION # 34
Refer to the exhibit.

PLC-3 and CLIENT can send traffic to PLC-1 and PLC-2. FGT-2 has only one software switch (SSW-1) connecting both PLC-3 and CLIENT. PLC-3 and CLIENT can send traffic to each other at the Layer 2 level.
What must the OT admin do to prevent Layer 2-level communication between PLC-3 and CLIENT?

  • A. Create a VLAN for each device and replace the current FGT-2 software switch members.
  • B. Enable explicit intra-switch policy to require firewall policies on FGT-2.
  • C. Set a unique forward domain for each interface of the software switch.
  • D. Implement policy routes on FGT-2 to control traffic between devices.

Answer: A,C


NEW QUESTION # 35
Refer to the exhibit.

Based on the topology designed by the OT architect, which two statements about implementing OT security are true? (Choose two.)

  • A. Micro-segmentation can be achieved only by replacing FortiGate-3 and FortiGate-4 with a pair of FortiSwitch devices.
  • B. FortiGate-3 and FortiGate-4 devices must be in a transparent mode.
  • C. Firewall policies should be configured on FortiGate-3 and FortiGate-4 with industrial protocol sensors.
  • D. IT and OT networks are separated by segmentation.

Answer: C,D


NEW QUESTION # 36
Which three Fortinet products can be used for device identification in an OT industrial control system (ICS)?
(Choose three.)

  • A. FortiSIEM
  • B. FortiManager
  • C. FortiNAC
  • D. FortiAnalyzer
  • E. FortiGate

Answer: A,C,E

Explanation:
Explanation
A: FortiNAC - FortiNAC is a network access control solution that provides visibility and control over network devices. It can identify devices, enforce access policies, and automate threat response.
D: FortiSIEM - FortiSIEM is a security information and event management solution that can collect and analyze data from multiple sources, including network devices and servers. It can help identify potential security threats, as well as monitor compliance with security policies and regulations.
E: FortiAnalyzer - FortiAnalyzer is a central logging and reporting solution that collects and analyzes data from multiple sources, including FortiNAC and FortiSIEM. It can provide insights into network activity and help identify anomalies or security threats.


NEW QUESTION # 37
Refer to the exhibit.

Which statement about the interfaces shown in the exhibit is true?

  • A. port1-vlan10 and port2-vlan10 are part of the same broadcast domain
  • B. port1, port1-vlan10, and port1-vlan1 are in different broadcast domains
  • C. The VLAN ID of port1-vlan1 can be changed to the VLAN ID 10.
  • D. port2, port2-vlan10, and port2-vlan1 are part of the software switch interface.

Answer: B


NEW QUESTION # 38
How can you achieve remote access and internel availability in an OT network?

  • A. Create a back-end backup network as a redundancy measure.
  • B. Add additional internal firewalls to access OT devices.
  • C. Implement SD-WAN to manage traffic on each ISP link.
  • D. Create more access policies to prevent unauthorized access.

Answer: C


NEW QUESTION # 39
You are investigating a series of incidents that occurred in the OT network over past 24 hours in FortiSIEM.
Which three FortiSIEM options can you use to investigate these incidents? (Choose three.)

  • A. Security
  • B. Overview
  • C. Risk
  • D. List
  • E. IPS

Answer: B,C,D


NEW QUESTION # 40
An OT network architect needs to secure control area zones with a single network access policy to provision devices to any number of different networks.
On which device can this be accomplished?

  • A. FortiEDR
  • B. FortiNAC
  • C. FortiSwitch
  • D. FortiGate

Answer: D

Explanation:
Explanation
An OT network architect can accomplish the goal of securing control area zones with a single network access policy to provision devices to any number of different networks on a FortiGate device.


NEW QUESTION # 41
An OT network consists of multiple FortiGate devices. The edge FortiGate device is deployed as the secure gateway and is only allowing remote operators to access the ICS networks on site.
Management hires a third-party company to conduct health and safety on site. The third-party company must have outbound access to external resources.
As the OT network administrator, what is the best scenario to provide external access to the third-party company while continuing to secure the ICS networks?

  • A. Configure outbound security policies with limited active authentication users of the third-party company.
  • B. Implement an additional firewall using an additional upstream link to the internet.
  • C. Create VPN tunnels between downstream FortiGate devices and the edge FortiGate to protect ICS network traffic.
  • D. Split the edge FortiGate device into multiple logical devices to allocate an independent VDOM for the third-party company.

Answer: D


NEW QUESTION # 42
Which three criteria can a FortiGate device use to look for a matching firewall policy to process traffic?
(Choose three.)

  • A. Destination defined as internet services in the firewall policy
  • B. Source defined as internet services in the firewall policy
  • C. Lowest to highest policy ID number
  • D. Services defined in the firewall policy.
  • E. Highest to lowest priority defined in the firewall policy

Answer: A,D,E

Explanation:
Explanation
The three criteria that a FortiGate device can use to look for a matching firewall policy to process traffic are:
A: Services defined in the firewall policy - FortiGate devices can match firewall policies based on the services defined in the policy, such as HTTP, FTP, or DNS.
D: Destination defined as internet services in the firewall policy - FortiGate devices can also match firewall policies based on the destination of the traffic, including destination IP address, interface, or internet services.
E: Highest to lowest priority defined in the firewall policy - FortiGate devices can prioritize firewall policies based on the priority defined in the policy. The device will process traffic against the policy with the highest priority first and move down the list until it finds a matching policy.


NEW QUESTION # 43
Refer to the exhibit.

You are navigating through FortiSIEM in an OT network.
How do you view information presented in the exhibit and what does the FortiGate device security status tell you?

  • A. In the PCI logging dashboard and there are one or more high-severity security incidents for the FortiGate device.
  • B. In the summary dashboard and there are one or more high-severity security incidents for the FortiGate device.
  • C. In the widget dashboard and there are one or more high-severity incidents for the FortiGate device.
  • D. In the business service dashboard and there are one or more high-severity security incidents for the FortiGate device.

Answer: B


NEW QUESTION # 44
When you create a user or host profile, which three criteria can you use? (Choose three.)

  • A. Host or user group memberships
  • B. An existing access control policy
  • C. Location
  • D. Administrative group membership
  • E. Host or user attributes

Answer: A,C,E

Explanation:
Explanation
https://docs.fortinet.com/document/fortinac/9.2.0/administration-guide/15797/user-host-profiles


NEW QUESTION # 45
Refer to the exhibit.

Given the configurations on the FortiGate, which statement is true?

  • A. FortiGate is configured with forward-domains to forward only domain controller traffic.
  • B. FortiGate is configured with forward-domains to forward only company domain website traffic.
  • C. FortiGate is configured with forward-domains to filter and drop non-domain controller traffic.
  • D. FortiGate is configured with forward-domains to reduce unnecessary traffic.

Answer: D


NEW QUESTION # 46
What two advantages does FortiNAC provide in the OT network? (Choose two.)

  • A. It can be used for industrial intrusion detection and prevention.
  • B. It can be used for IoT device detection.
  • C. It can be used for device profiling.
  • D. It can be used for network micro-segmentation.

Answer: B,C

Explanation:
Explanation
Typically, in a microsegmented network, NGFWs are used in conjunction with VLANs to implement security policies and to inspect and filter network communications. Fortinet FortiSwitch and FortiGate NGFW offer an integrated approach to microsegmentation.


NEW QUESTION # 47
What can be assigned using network access control policies?

  • A. FortiNAC device polling methods
  • B. Layer 3 polling intervals
  • C. Profiling rules
  • D. Logical networks

Answer: D


NEW QUESTION # 48
......

NSE7_OTS-7.2 Dumps To Pass Fortinet Exam in 24 Hours - ActualTestsIT: https://2cram.actualtestsit.com/Fortinet/NSE7_OTS-7.2-exam-prep-dumps.html