Free NSE7_OTS-7.2 Sample Questions and 100% Cover Real Exam Questions (Updated 90 Questions)
Download Real Fortinet NSE7_OTS-7.2 Exam Dumps Test Engine Exam Questions
Fortinet NSE7_OTS-7.2 (Fortinet NSE 7 - OT Security 7.2) Certification Exam is a professional-level certification for individuals who want to validate their expertise in securing operational technology (OT) networks. NSE7_OTS-7.2 exam is designed to test the candidate's knowledge and skills in securing OT environments against cyber threats such as malware, ransomware, and other advanced persistent threats.
NEW QUESTION # 32
Refer to the exhibit. You need to configure VPN user access for supervisors at the branch and HQ sites using the same soft FortiToken. Each site has a FortiGate VPN gateway.
What must you do to achieve this objective?
- A. Import the FortiToken on each FortiGate.
- B. Direct users to the self-registration server portal.
- C. Use a RADIUS OTP server.
- D. Deploy FortiAuthenticator.
Answer: D
Explanation:
A single soft FortiToken can be validated by multiple FortiGate VPN gateways only when token authentication is centralized. FortiAuthenticator provides that central OTP/RADIUS service, so both FortiGates query the same token record for the supervisors.
NEW QUESTION # 33
Refer to the exhibits. Which statement is true about the traffic passing through to PLC-2?
- A. The application filter overrides the default action of some IEC 104 signatures.
- B. IEC 104 signatures are all allowed except the C.BO.NA 1 signature.
- C. SSL Inspection must be set to deep-inspection to correctly apply application control.
- D. IPS must be enabled to inspect application signatures.
Answer: B
Explanation:
The application sensor shows several IEC 104 signatures.
The action for IEC_60870.5.104_Information.Transfer.C.BO.NA.1 is set to "Block," so this signature's traffic is blocked.
Other listed IEC 104 signatures have the action "Monitor," meaning they are allowed but logged or monitored.
IPS enabling is not explicitly indicated as required here.
SSL inspection is set to certificate-inspection (not deep-inspection), and the question does not provide enough context to require deep SSL inspection.
The application filter overrides actions for only the C.BO.NA.1 signature, blocking it while other signatures pass.
NEW QUESTION # 34
Refer to the exhibit.
An operational technology rule is created and successfully activated to monitor the Modbus protocol on FortiSIEM. However, the rule does not trigger incidents despite Modbus traffic and application logs being received correctly by FortiSIEM.
Which statement correctly describes the issue on the rule configuration?
- A. The Aggregate attribute COUNT expression is incompatible with the filters.
- B. The first condition on the SubPattern filter must use the OR logical operator.
- C. The attributes in the Group By section must match the ones in Fitters section.
- D. The SubPattern is missing the filter to match the Modbus protocol.
Answer: C
NEW QUESTION # 35
Refer to the exhibit, which shows a non-protected OT environment.
An administrator needs to implement proper protection on the OT network.
Which three steps should an administrator take to protect the OT network? (Choose three.)
- A. Deploy a FortiGate device within each ICS network.
- B. Use segmentation
- C. Configure firewall policies with web filter to protect the different ICS networks.
- D. Configure firewall policies with industrial protocol sensors
- E. Deploy an edge FortiGate between the internet and an OT network as a one-arm sniffer.
Answer: A,B,D
NEW QUESTION # 36
Refer to the exhibit, which shows a nonprotected OT environment. An administrator needs to implement appropriate protection on the OT network.
Which three steps should an administrator take to protect the OT network? (Choose three.)
- A. Deploy an edge FortiGate between the internet and the OT network as a one-arm sniffer.
- B. Configure firewall policies with industrial protocol sensors.
- C. Use segmentation.
- D. Configure firewall policies with web filtering to protect the different ICS networks.
- E. Deploy a FortiGate device within each ICS network.
Answer: B,C,E
Explanation:
Use segmentation: Network segmentation is critical in an OT environment to isolate different ICS (Industrial Control System) networks and protect sensitive systems. This limits the spread of threats and provides controlled access between segments.
Deploy a FortiGate device within each ICS network: Deploying FortiGate devices in each ICS network ensures that localized security measures are in place to detect and prevent unauthorized access or threats.
Configure firewall policies with industrial protocol sensors: Configuring policies with industrial protocol sensors helps monitor and protect OT-specific traffic (e.g., Modbus, DNP3).
This enables the FortiGate to detect and respond to malicious activities targeting OT protocols.
NEW QUESTION # 37
Refer to the exhibit.
Which statement is true about application control inspection?
- A. The industrial application control inspection process is unique among application categories.
- B. Security actions cannot be applied on the lowest level of the hierarchy.
- C. You can control security actions only on the parent-level application signature
- D. The parent signature takes precedence over the child application signature.
Answer: C
NEW QUESTION # 38
Refer to the exhibit. From your analysis of the output, which statement about the output is true?
- A. This is a sample of a FortiAnalyzer system interface event log.
- B. This is a sample of FortiGate interface statistics.
- C. This is a sample of a PAM event type.
- D. This is a sample of an SNMP temperature control event log.
Answer: C
Explanation:
ph_dev_mon is a PAM event. Hostname is WIN2K8DC (a win server) not Fortigate.
NEW QUESTION # 39
Refer to the exhibit.
You are navigating through FortiSIEM in an OT network.
How do you view information presented in the exhibit and what does the FortiGate device security status tell you?
- A. In the PCI logging dashboard and there are one or more high-severity security incidents for the FortiGate device.
- B. In the business service dashboard and there are one or more high-severity security incidents for the FortiGate device.
- C. In the widget dashboard and there are one or more high-severity incidents for the FortiGate device.
- D. In the summary dashboard and there are one or more high-severity security incidents for the FortiGate device.
Answer: D
NEW QUESTION # 40
Refer to the exhibit.
In order for a FortiGate device to act as router on a stick, what configuration must an OT network architect implement on FortiGate to achieve inter-VLAN routing?
- A. Set a FortiGate interface with the switch to operate as an 802.1 q trunk.
- B. Set a software switch on FortiGate to handle inter-VLAN traffic.
- C. Set a unique forward domain on each interface on the network.
- D. Set FortiGate to operate in transparent mode.
Answer: A
NEW QUESTION # 41
An OT administrator configured and ran a default application risk and control report in FortiAnalyzer to learn more about the key application crossing the network. However, the report output is empty despite the fact that some related real-time and historical logs are visible in the FortiAnalyzer.
What are two possible reasons why the report output was empty? (Choose two.)
- A. The administrator selected the wrong logs to be indexed in FortiAnalyzer.
- B. The administrator selected the wrong devices in the Devices section.
- C. The administrator selected the wrong time period for the report.
- D. The administrator selected the wrong hcache table for the report.
Answer: B,C
Explanation:
https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/32cb817d-a307-11eb-b70b-0050569258
NEW QUESTION # 42
Which two statements are true when you deploy FortiGate as an offline IDS? (Choose two.)
- A. Network attacks can be detected and blocked.
- B. FortiGate receives traffic from configured port mirroring.
- C. FortiGate acts as network sensor.
- D. Network traffic goes through FortiGate.
Answer: C,D
NEW QUESTION # 43
When you create a user or host profile, which three criteria can you use? (Choose three.)
- A. Host or user group memberships
- B. Host or user attributes
- C. Administrative group membership
- D. Location
- E. An existing access control policy
Answer: A,B,D
Explanation:
https://docs.fortinet.com/document/fortinac/9.2.0/administration-guide/15797/user-host-profiles
NEW QUESTION # 44
Refer to the exhibit.
Given the configurations on the FortiGate, which statement is true?
- A. FortiGate is configured with forward-domains to filter and drop non-domain controller traffic.
- B. FortiGate is configured with forward-domains to reduce unnecessary traffic.
- C. FortiGate is configured with forward-domains to forward only domain controller traffic.
- D. FortiGate is configured with forward-domains to forward only company domain website traffic.
Answer: B
NEW QUESTION # 45
In a wireless network integration, how does FortiNAC obtain connecting MAC address information?
- A. MAC notification traps
- B. RADIUS
- C. Link traps
- D. End station traffic monitoring
Answer: B
Explanation:
FortiNAC can integrate with RADIUS servers to obtain MAC address information for wireless clients that authenticate through the RADIUS server.
Reference:
Fortinet NSE 7 - OT Security 6.4 Study Guide, Chapter 4: OT Security Devices, page 4-28.
NEW QUESTION # 46
Which three protocols are used as industrial Ethernet protocols? (Choose three.)
- A. PROFINET
- B. M12
- C. RJ45
- D. EtherCAT
- E. EtherNet/IP
Answer: A,D,E
NEW QUESTION # 47
As an OT administrator, it is important to understand how industrial protocols work in an OT network.
Which communication method is used by the Modbus protocol?
- A. It uses OSI Layer 2 and both the primary/secondary devices always send data during the communication.
- B. It uses OSI Layer 2 and the secondary device sends data based on request from primary device.
- C. It uses OSI Layer 2 and both the primary/secondary devices send data based on a matching token ring.
- D. It uses OSI Layer 2 and the primary device sends data based on request from secondary device.
Answer: B
NEW QUESTION # 48
Refer to the exhibit. PLC-3 and CLIENT can send traffic to PLC-1 and PLC-2. FGT-2 has only one software switch (SSW-1) connecting both PLC-3 and CLIENT. PLC-3 and CLIENT can send traffic to each other at the Layer 2 level.
What must the OT admin do to prevent Layer 2-level communication between PLC-3 and CLIENT?
- A. Implement policy routes on FGT-2 to control traffic between devices.
- B. Enable explicit intra-switch policy to require firewall policies on FGT-2.
- C. Set a unique forward domain for each interface of the software switch.
- D. Create a VLAN for each device and replace the current FGT-2 software switch members.
Answer: C,D
NEW QUESTION # 49
Refer to the exhibit.
Given the configurations on the FortiGate, which statement is true?
- A. FortiGate is configured with forward-domains to filter and drop non-domain controller traffic.
- B. FortiGate is configured with forward-domains to reduce unnecessary traffic.
- C. FortiGate is configured with forward-domains to forward only domain controller traffic.
- D. FortiGate is configured with forward-domains to forward only company domain website traffic.
Answer: B
NEW QUESTION # 50
What are two critical tasks the OT network auditors must perform during OT network risk assessment and management? (Choose two.)
- A. Evaluating what can go wrong before it happens
- B. Planning a threat hunting strategy
- C. Creating disaster recovery plans to switch operations to a backup plant
- D. Implementing strategies to automatically bring PLCs offline
Answer: A,B
Explanation:
Planning a threat hunting strategy is essential for proactively searching for threats and vulnerabilities in the OT environment before they manifest into attacks.
Evaluating what can go wrong before it happens is a core part of risk assessment, involving the identification and analysis of potential risks and their impacts on OT systems.
Implementing strategies to automatically bring PLCs offline is generally not a responsible or safe approach in OT environments because it could disrupt critical industrial processes.
Creating disaster recovery plans is important for overall business continuity but is not primarily a task of auditors during risk assessment-it is more of a broader business continuity or incident response responsibility.
NEW QUESTION # 51
Refer to the exhibit. Which statement is true about application control inspection?
- A. The industrial application control inspection process is unique among application categories.
- B. Security actions cannot be applied on the lowest level of the hierarchy.
- C. You can control security actions only on the parent-level application signature
- D. The parent signature takes precedence over the child application signature.
Answer: C
NEW QUESTION # 52
Refer to the exhibit.
Based on the Purdue model, which three measures can be implemented in the control area zone using the Fortinet Security Fabric? (Choose three.)
- A. FortiEDR for endpoint detection
- B. FortiGate for application control and IPS
- C. FortiNAC for network access control
- D. FortiSIEM for security incident and event management
- E. FortiGate for SD-WAN
Answer: A,B,C
NEW QUESTION # 53
How can you achieve remote access and internel availability in an OT network?
- A. Add additional internal firewalls to access OT devices.
- B. Implement SD-WAN to manage traffic on each ISP link.
- C. Create a back-end backup network as a redundancy measure.
- D. Create more access policies to prevent unauthorized access.
Answer: B
Explanation:
SD-WAN provides reliable and efficient management of multiple ISP links, ensuring high availability and optimized traffic routing.
It offers redundancy and performance improvements critical for OT networks where continuous availability is essential.
SD-WAN can dynamically route traffic, maintain session persistence, and provide secure connectivity between remote and internal OT environments.
NEW QUESTION # 54
in an operation technology (OT) network FortiAnalyzer is used to receive and process logs from responsible FortiGate devices Which statement about why FortiAnalyzer is receiving and processing multiple tog messages from a given programmable logic controller (PLC) or remote terminal unit (RTU) is true'?
- A. To track external threats and prevent them attacking the OT network
- B. To help OT administrators troubleshoot and diagnose the OT network
- C. To isolate PLCs or RTUs in the event of external attacks
- D. To determine which type of messages from the PLC or RTU causes issues in the plant
Answer: A
NEW QUESTION # 55
......
New NSE7_OTS-7.2 exam dumps Use Updated Fortinet Exam: https://dumpstorrent.dumpsking.com/NSE7_OTS-7.2-testking-dumps.html
