Pre-Winter Sale - Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70dumps

NSEI_OTS_AR-7.6 Questions and Answers

Question # 6

You want to protect OT devices that are not updated against known vulnerabilities so you apply virtual patching to the firewall policies. What must you check to confirm that the OT devices are virtually patched? (Choose one answer)

A.

The output of the CLI command get virtual-patch profile

B.

The OT View page

C.

The output of the CLI command get rule otvp status

D.

The Asset Identity List page

Full Access
Question # 7

Refer to the exhibits.

Question # 7

A partial Basic Event Handler page on FortiAnalyzer and the creation of a trigger in a FortiGate device are shown. To improve the protection of your OT network, you want to automate the handling of compromised devices notified through FortiAnalyzer. You have configured an event handler named Alert_trigger as shown in the exhibit. When you create the trigger on the FortiGate device, the Event handler name field does not provide the Alert_trigger option. What two actions must you perform to make the Alert_trigger option available? (Choose two answers)

A.

You must click + Create in the Event handler name field.

B.

You must authorize the FortiGate device on FortiAnalyzer.

C.

You must configure the FortiAnalyzer setting on the FortiGate device.

D.

You must configure the trigger on the root FortiGate.

Full Access
Question # 8

Refer to the exhibit.

Question # 8

Which statement about this partial Asset Identity List page is correct? (Choose one answer)

A.

A firewall policy has an Antivirus security profile applied to it.

B.

A firewall policy has a Virtual Patching security profile applied to it.

C.

A firewall policy has an Intrusion Prevention security profile applied to it.

D.

A firewall policy has an Application Control security profile applied to it.

Full Access
Question # 9

You want FortiAnalyzer to trigger an automation stitch on a FortiGate device automatically. What must you configure on FortiAnalyzer to enable direct communication with FortiGate? (Choose one answer)

A.

A Fabric connector

B.

A playbook task

C.

The Fabric settings

D.

An event handler

Full Access
Question # 10

Refer to the exhibit.

Question # 10

A partial OT network is shown. You want to provide the supervisor with secure remote access. Which two features can you implement on Edge-FortiGate ? (Choose two answers)

A.

IPsec

B.

FortiToken

C.

SD-WAN

D.

FSSO

Full Access
Question # 11

Refer to the exhibit.

Question # 11

A partial OT network is shown.

PLC-1 has a known critical vulnerability, but you cannot update it.

What must you configure to protect PLC-1?

A.

OT signatures on FortiGate_Level3

B.

IPS on FortiGate_Level5

C.

Virtual patching on FortiGate_Level2

D.

OT application control on all FortiGate devices

Full Access
Question # 12

Refer to the exhibit.

Question # 12

A partial Incident Analysis page is shown. How was the 360-Degree Security Review OT report attached to the incident? (Choose one answer)

A.

Automatically by a stitch

B.

Automatically by an event handler

C.

Automatically by a playbook

D.

Manually by an administrator

Full Access
Question # 13

Match each industrial protocol to its corresponding characteristics.

Select each OT industrial protocol in the column on the left and drag and drop it into the blank space next to its corresponding characteristic in the column on the right. You must match all four industrial protocols to their characteristics in the work area.

Question # 13

Full Access
Question # 14

Refer to the exhibit.

Question # 14

The OT devices behind the ruggedized FortiGate have vulnerabilities and you want to apply a virtual patching profile in the firewall policy. Why is Virtual Patching not available in the Security Profiles section? (Choose one answer)

A.

You must enable Virtual Patching in the Feature Visibility section.

B.

You must have a ruggedized FortiGate allowing the virtual patching feature.

C.

You must enable OT signatures.

D.

You must have a valid OT security service license.

Full Access
Question # 15

Refer to the exhibit.

Question # 15

A partial OT network is shown.

The OT network is divided into two main networks with a FortiGate device operating in NAT mode.

How can you further segment network 1 from network 2?

A.

You can configure universal ZTNA.

B.

You can configure the FortiGate interface as an implicit software switch.

C.

You can configure two traffic VDOMs.

D.

You can configure different forward domain IDs for network 1 and network 2.

Full Access
Question # 16

What is the main OT component for monitoring and controlling industrial processes? (Choose one answer)

A.

Programmable Logical Controller (PLC)

B.

Supervisory Control and Data Acquisition (SCADA)

C.

Industrial Control System (ICS)

D.

Industrial Internet of Things (IIoT)

Full Access