Check Real Fortinet NSE7_OTS-7.2 Exam Question for Free (2024) [Q18-Q37]

Share

Check Real Fortinet NSE7_OTS-7.2 Exam Question for Free (2024)

Get Ready to Boost your Prepare for your NSE7_OTS-7.2 Exam with 52 Questions


The NSE7_OTS-7.2 exam covers a broad range of topics related to OT security, including threat analysis, risk management, network architecture, protocols, and technologies. NSE7_OTS-7.2 exam also assesses the candidate's proficiency in using Fortinet products and solutions for OT security, such as FortiGate, FortiAnalyzer, and FortiManager. NSE7_OTS-7.2 exam is designed for experienced network security professionals who have a good understanding of OT systems and technologies.


The Fortinet NSE7_OTS-7.2 exam focuses on a range of topics such as OT network and device security, secure network design, policy management, incident response, and risk management. Candidates will need to demonstrate a comprehensive understanding of these topics in order to pass the exam and become certified. NSE7_OTS-7.2 exam is designed to be challenging to ensure that only the most skilled and knowledgeable professionals are awarded certification.

 

NEW QUESTION # 18
Refer to the exhibit.

An operational technology rule is created and successfully activated to monitor the Modbus protocol on FortiSIEM. However, the rule does not trigger incidents despite Modbus traffic and application logs being received correctly by FortiSIEM.
Which statement correctly describes the issue on the rule configuration?

  • A. The first condition on the SubPattern filter must use the OR logical operator.
  • B. The attributes in the Group By section must match the ones in Fitters section.
  • C. The SubPattern is missing the filter to match the Modbus protocol.
  • D. The Aggregate attribute COUNT expression is incompatible with the filters.

Answer: B


NEW QUESTION # 19
Refer to the exhibit.

An OT network security audit concluded that the application sensor requires changes to ensure the correct security action is committed against the overrides filters.
Which change must the OT network administrator make?

  • A. Remove IEC.60870.5.104 Information.Transfer from the first filter override.
  • B. Set all application categories to apply default actions.
  • C. Change the security action of the industrial category to monitor.
  • D. Set the priority of the C.BO.NA.1 signature override to 1.

Answer: D

Explanation:
Explanation
According to the Fortinet NSE 7 - OT Security 6.4 exam guide1, the application sensor settings allow you to configure the security action for each application category andnetwork protocol override. The security action determines how the FortiGate unit handles traffic that matches the application category or network protocol override. The security action can be one of the following:
Allow: The FortiGate unit allows the traffic without any further inspection.
Monitor: The FortiGate unit allows the traffic and logs it for monitoring purposes.
Block: The FortiGate unit blocks the traffic and logs it as an attack.
The priority of the network protocol override determines the order in which the FortiGate unit applies the security action to the traffic. The lower the priority number, the higher the priority. For example, a priority of 1 is higher than a priority of 10.
In the exhibit, the application sensor has the following settings:
The industrial category has a security action of allow, which means that the FortiGate unit will not inspect or log any traffic that belongs to this category.
The IEC.60870.5.104 Information.Transfer network protocol override has a security action of block, which means that the FortiGate unit will block and log any traffic that matches this protocol.
The IEC.60870.5.104 Control.Functions network protocol override has a security action of monitor, which means that the FortiGate unit will allow and log any traffic that matches this protocol.
The IEC.60870.5.104 Start/Stop network protocol override has a security action of allow, which means that the FortiGate unit will not inspect or log any traffic that matches this protocol.
The IEC.60870.5.104 Transfer.C.BO.NA.1 network protocol override has a security action of block, which means that the FortiGate unit will block and log any traffic that matches this protocol.
The problem with these settings is that the IEC.60870.5.104 Transfer.C.BO.NA.1 network protocol override has a lower priority than the IEC.60870.5.104 Information.Transfer network protocol override. This means that if the traffic matches both protocols, the FortiGate unit will apply the security action of the higher priority override, which is block. However, the IEC.60870.5.104 Transfer.C.BO.NA.1 protocol is used to transfer binary outputs, which are essential for controlling OT devices. Therefore, blocking this protocol could have negative consequences for the OT network.
To fix this issue, the OT network administrator must set the priority of the IEC.60870.5.104 Transfer.C.BO.NA.1 network protocol override to 1, which is higher than the priority of the IEC.60870.5.104 Information.Transfer network protocol override. This way, the FortiGate unit will apply the security action of the lower priority override, which is allow, to the traffic that matches both protocols. This will ensure that the FortiGate unit does not block the traffic that is used to transfer binary outputs, while still blocking the traffic that is used to transfer information.
1: NSE 7 Network Security Architect - Fortinet


NEW QUESTION # 20
Refer to the exhibit.

You are navigating through FortiSIEM in an OT network.
How do you view information presented in the exhibit and what does the FortiGate device security status tell you?

  • A. In the PCI logging dashboard and there are one or more high-severity security incidents for the FortiGate device.
  • B. In the summary dashboard and there are one or more high-severity security incidents for the FortiGate device.
  • C. In the widget dashboard and there are one or more high-severity incidents for the FortiGate device.
  • D. In the business service dashboard and there are one or more high-severity security incidents for the FortiGate device.

Answer: B


NEW QUESTION # 21
Which three criteria can a FortiGate device use to look for a matching firewall policy to process traffic?
(Choose three.)

  • A. Lowest to highest policy ID number
  • B. Destination defined as internet services in the firewall policy
  • C. Services defined in the firewall policy.
  • D. Highest to lowest priority defined in the firewall policy
  • E. Source defined as internet services in the firewall policy

Answer: B,C,D

Explanation:
Explanation
The three criteria that a FortiGate device can use to look for a matching firewall policy to process traffic are:
A: Services defined in the firewall policy - FortiGate devices can match firewall policies based on the services defined in the policy, such as HTTP, FTP, or DNS.
D: Destination defined as internet services in the firewall policy - FortiGate devices can also match firewall policies based on the destination of the traffic, including destination IP address, interface, or internet services.
E: Highest to lowest priority defined in the firewall policy - FortiGate devices can prioritize firewall policies based on the priority defined in the policy. The device will process traffic against the policy with the highest priority first and move down the list until it finds a matching policy.


NEW QUESTION # 22
What can be assigned using network access control policies?

  • A. Layer 3 polling intervals
  • B. Logical networks
  • C. Profiling rules
  • D. FortiNAC device polling methods

Answer: B


NEW QUESTION # 23
Which type of attack posed by skilled and malicious users of security level 4 (SL 4) of IEC 62443 is designed to defend against intentional attacks?

  • A. Users with substantial resources
  • B. Users with unintentional operator error
  • C. Users with low access to resources
  • D. Users with access to moderate resources

Answer: B


NEW QUESTION # 24
Refer to the exhibit.

Based on the Purdue model, which three measures can be implemented in the control area zone using the Fortinet Security Fabric? (Choose three.)

  • A. FortiEDR for endpoint detection
  • B. FortiSIEM for security incident and event management
  • C. FortiGate for application control and IPS
  • D. FortiNAC for network access control
  • E. FortiGate for SD-WAN

Answer: A,C,D


NEW QUESTION # 25
Refer to the exhibit.

You need to configure VPN user access for supervisors at the breach and HQ sites using the same soft FortiToken. Each site has a FortiGate VPN gateway.
What must you do to achieve this objective?

  • A. You must use the user self-registration server.
  • B. You must use a third-party RADIUS OTP server.
  • C. You must register the same FortiToken on more than one FortiGate.
  • D. You must use a FortiAuthenticator.

Answer: D


NEW QUESTION # 26
An OT network consists of multiple FortiGate devices. The edge FortiGate device is deployed as the secure gateway and is only allowing remote operators to access the ICS networks on site.
Management hires a third-party company to conduct health and safety on site. The third-party company must have outbound access to external resources.
As the OT network administrator, what is the best scenario to provide external access to the third-party company while continuing to secure the ICS networks?

  • A. Split the edge FortiGate device into multiple logical devices to allocate an independent VDOM for the third-party company.
  • B. Configure outbound security policies with limited active authentication users of the third-party company.
  • C. Implement an additional firewall using an additional upstream link to the internet.
  • D. Create VPN tunnels between downstream FortiGate devices and the edge FortiGate to protect ICS network traffic.

Answer: A


NEW QUESTION # 27
To increase security protection in an OT network, how does application control on ForliGate detect industrial traffic?

  • A. By inspecting applications with more granularity by inspecting subapplication traffic
  • B. By inspecting software and software-based vulnerabilities
  • C. By inspecting applications only on nonprotected traffic
  • D. By inspecting protocols used in the application traffic

Answer: C


NEW QUESTION # 28
Refer to the exhibit.

Which statement about the interfaces shown in the exhibit is true?

  • A. port1-vlan10 and port2-vlan10 are part of the same broadcast domain
  • B. The VLAN ID of port1-vlan1 can be changed to the VLAN ID 10.
  • C. port2, port2-vlan10, and port2-vlan1 are part of the software switch interface.
  • D. port1, port1-vlan10, and port1-vlan1 are in different broadcast domains

Answer: D


NEW QUESTION # 29
What are two benefits of a Nozomi integration with FortiNAC? (Choose two.)

  • A. Direct VLAN assignment
  • B. Enhanced point of connection details
  • C. Adapter consolidation for multi-adapter hosts
  • D. Importation and classification of hosts

Answer: B,D

Explanation:
Explanation
The two benefits of a Nozomi integration with FortiNAC are enhanced point of connection details and importation and classification of hosts. Enhanced point of connection details allows for the identification and separation of traffic from multiple points of connection, such as Wi-Fi, wired, cellular, and VPN. Importation and classification of hosts allows for the automated importing and classification of host and device information into FortiNAC. This allows for better visibility and control of the network.


NEW QUESTION # 30
When device profiling rules are enabled, which devices connected on the network are evaluated by the device profiling rules?

  • A. Rogue devices, each time they connect
  • B. Rogue devices, only when they connect for the first time
  • C. Known trusted devices, each time they change location
  • D. All connected devices, each time they connect

Answer: B


NEW QUESTION # 31
Which three Fortinet products can be used for device identification in an OT industrial control system (ICS)?
(Choose three.)

  • A. FortiManager
  • B. FortiSIEM
  • C. FortiGate
  • D. FortiNAC
  • E. FortiAnalyzer

Answer: B,C,D

Explanation:
Explanation
A: FortiNAC - FortiNAC is a network access control solution that provides visibility and control over network devices. It can identify devices, enforce access policies, and automate threat response.
D: FortiSIEM - FortiSIEM is a security information and event management solution that can collect and analyze data from multiple sources, including network devices and servers. It can help identify potential security threats, as well as monitor compliance with security policies and regulations.
E: FortiAnalyzer - FortiAnalyzer is a central logging and reporting solution that collects and analyzes data from multiple sources, including FortiNAC and FortiSIEM. It can provide insights into network activity and help identify anomalies or security threats.


NEW QUESTION # 32
An OT administrator deployed many devices to secure the OT network. However, the SOC team is reporting that there are too many alerts, and that many of the alerts are false positive. The OT administrator would like to find a solution that eliminates repetitive tasks, improves efficiency, saves time, and saves resources.
Which products should the administrator deploy to address these issues and automate most of the manual tasks done by the SOC team?

  • A. FortiSandbox and FortiSIEM
  • B. A syslog server and FortiSIEM
  • C. FortiSIEM and FortiManager
  • D. FortiSOAR and FortiSIEM

Answer: D


NEW QUESTION # 33
Which three common breach points can be found in a typical OT environment? (Choose three.)

  • A. Black hat
  • B. Hard hat
  • C. Global hat
  • D. VLAN exploits
  • E. RTU exploits

Answer: A,B,E


NEW QUESTION # 34
Refer to the exhibit and analyze the output.

Which statement about the output is true?

  • A. This is a sample of an SNMP temperature control event log.
  • B. This is a sample of a PAM event type.
  • C. This is a sample of FortiGate interface statistics.
  • D. This is a sample of a FortiAnalyzer system interface event log.

Answer: B


NEW QUESTION # 35
An OT network architect needs to secure control area zones with a single network access policy to provision devices to any number of different networks.
On which device can this be accomplished?

  • A. FortiSwitch
  • B. FortiEDR
  • C. FortiGate
  • D. FortiNAC

Answer: C

Explanation:
Explanation
An OT network architect can accomplish the goal of securing control area zones with a single network access policy to provision devices to any number of different networks on a FortiGate device.


NEW QUESTION # 36
Which three methods of communication are used by FortiNAC to gather visibility information? (Choose three.)

  • A. API
  • B. SNMP
  • C. ICMP
  • D. RADIUS
  • E. TACACS

Answer: A,B,D


NEW QUESTION # 37
......

Use Free NSE7_OTS-7.2 Exam Questions that Stimulates Actual EXAM : https://www.passreview.com/NSE7_OTS-7.2_exam-braindumps.html

Get 100% Real NSE7_OTS-7.2 Free Online Practice Test: https://drive.google.com/open?id=1m8Q2mQkmYVzf4LU78TYH4p9WBynh_pIB