Verified NSE7_OTS-7.2 Exam Dumps Q&As - Provide NSE7_OTS-7.2 with Correct Answers
Pass Your NSE7_OTS-7.2 Dumps Free Latest Fortinet Practice Tests
NEW QUESTION # 17
Which deployment option allows an administrator to detect intrusions without any modifications to production traffic?
- A. Offline IDS
- B. Inline IPS and IDS
- C. Offline IPS
- D. Virtual patching
Answer: A
NEW QUESTION # 18
When you create a user or host profile, which three criteria can you use? (Choose three.)
- A. Administrative group membership
- B. An existing access control policy
- C. Host or user attributes
- D. Location
- E. Host or user group memberships
Answer: C,D,E
Explanation:
https://docs.fortinet.com/document/fortinac/9.2.0/administration-guide/15797/user-host-profiles
NEW QUESTION # 19
Refer to the exhibit and analyze the output. Which statement about the output is true?
- A. This is a sample of FortiGate interface statistics.
- B. This is a sample of a PAM event type.
- C. This is a sample of a FortiAnalyzer system interface event log.
- D. This is a sample of an SNMP temperature control event log.
Answer: B
NEW QUESTION # 20
Refer to the exhibit.
Given the configurations on the FortiGate, which statement is true?
- A. FortiGate is configured with forward-domains to forward only company domain website traffic.
- B. FortiGate is configured with forward-domains to reduce unnecessary traffic.
- C. FortiGate is configured with forward-domains to forward only domain controller traffic.
- D. FortiGate is configured with forward-domains to filter and drop non-domain controller traffic.
Answer: B
NEW QUESTION # 21
Refer to the exhibit.A new operational technology rule is being created to monitor Modbus protocol traffic on FortiSIEM.
Which action will ensure all Modbus messages on the network match the rule?
- A. Set the Aggregate attribute value to equal to or greater than zero.
- B. Remove attributes in the Group By section that are not configured in the Filter section.
- C. This rule is valid and requires no additional changes.
- D. Add a new condition to filter Modbus traffic based on the Source TCP/UDP port.
Answer: D
Explanation:
https://community.fortinet.com/t5/FortiSIEM/Technical-Note-How-do-I-create-and-or-customize- rules-and-alerts/ta-p/196013
NEW QUESTION # 22
Refer to the exhibit.
An OT network security audit concluded that the application sensor requires changes to ensure the correct security action is committed against the overrides filters.
Which change must the OT network administrator make?
- A. Change the security action of the industrial category to monitor.
- B. Remove IEC.60870.5.104 Information.Transfer from the first filter override.
- C. Set the priority of the C.BO.NA.1 signature override to 1.
- D. Set all application categories to apply default actions.
Answer: C
Explanation:
Explanation
According to the Fortinet NSE 7 - OT Security 6.4 exam guide1, the application sensor settings allow you to configure the security action for each application category andnetwork protocol override. The security action determines how the FortiGate unit handles traffic that matches the application category or network protocol override. The security action can be one of the following:
Allow: The FortiGate unit allows the traffic without any further inspection.
Monitor: The FortiGate unit allows the traffic and logs it for monitoring purposes.
Block: The FortiGate unit blocks the traffic and logs it as an attack.
The priority of the network protocol override determines the order in which the FortiGate unit applies the security action to the traffic. The lower the priority number, the higher the priority. For example, a priority of 1 is higher than a priority of 10.
In the exhibit, the application sensor has the following settings:
The industrial category has a security action of allow, which means that the FortiGate unit will not inspect or log any traffic that belongs to this category.
The IEC.60870.5.104 Information.Transfer network protocol override has a security action of block, which means that the FortiGate unit will block and log any traffic that matches this protocol.
The IEC.60870.5.104 Control.Functions network protocol override has a security action of monitor, which means that the FortiGate unit will allow and log any traffic that matches this protocol.
The IEC.60870.5.104 Start/Stop network protocol override has a security action of allow, which means that the FortiGate unit will not inspect or log any traffic that matches this protocol.
The IEC.60870.5.104 Transfer.C.BO.NA.1 network protocol override has a security action of block, which means that the FortiGate unit will block and log any traffic that matches this protocol.
The problem with these settings is that the IEC.60870.5.104 Transfer.C.BO.NA.1 network protocol override has a lower priority than the IEC.60870.5.104 Information.Transfer network protocol override. This means that if the traffic matches both protocols, the FortiGate unit will apply the security action of the higher priority override, which is block. However, the IEC.60870.5.104 Transfer.C.BO.NA.1 protocol is used to transfer binary outputs, which are essential for controlling OT devices. Therefore, blocking this protocol could have negative consequences for the OT network.
To fix this issue, the OT network administrator must set the priority of the IEC.60870.5.104 Transfer.C.BO.NA.1 network protocol override to 1, which is higher than the priority of the IEC.60870.5.104 Information.Transfer network protocol override. This way, the FortiGate unit will apply the security action of the lower priority override, which is allow, to the traffic that matches both protocols. This will ensure that the FortiGate unit does not block the traffic that is used to transfer binary outputs, while still blocking the traffic that is used to transfer information.
1: NSE 7 Network Security Architect - Fortinet
NEW QUESTION # 23
Which three protocols are used as industrial Ethernet protocols? (Choose three.)
- A. EtherNet/IP
- B. RJ45
- C. PROFINET
- D. EtherCAT
- E. M12
Answer: A,C,D
NEW QUESTION # 24
Which three criteria can a FortiGate device use to look for a matching firewall policy to process traffic? (Choose three.)
- A. Highest to lowest priority defined in the firewall policy
- B. Source defined as internet services in the firewall policy
- C. Destination defined as internet services in the firewall policy
- D. Services defined in the firewall policy.
- E. Lowest to highest policy ID number
Answer: B,C,D
Explanation:
When a packet arrives, how does FortiGate find a matching policy?
Each policy has match criteria, which you can define using the following objects:
* Incoming Interface
* Outgoing Interface
* Source: IP address, user, internet services
* Destination: IP address or internet services
* Service: IP protocol and port number
* Schedule: Applies during configured times
NEW QUESTION # 25
Refer to the exhibit. Given the configurations on the FortiGate, which statement is true?
- A. FortiGate is configured with forward-domains to forward only company domain website traffic.
- B. FortiGate is configured with forward-domains to reduce unnecessary traffic.
- C. FortiGate is configured with forward-domains to forward only domain controller traffic.
- D. FortiGate is configured with forward-domains to filter and drop non-domain controller traffic.
Answer: B
NEW QUESTION # 26
An OT administrator configured and ran a default application risk and control report in FortiAnalyzer to learn more about the key application crossing the network. However, the report output is empty despite the fact that some related real-time and historical logs are visible in the FortiAnalyzer.
What are two possible reasons why the report output was empty? (Choose two.)
- A. The administrator selected the wrong hcache table for the report.
- B. The administrator selected the wrong time period for the report.
- C. The administrator selected the wrong devices in the Devices section.
- D. The administrator selected the wrong logs to be indexed in FortiAnalyzer.
Answer: B,C
Explanation:
https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/32cb817d-a307-11eb-b70b-
00505692583a/FortiAnalyzer-7.0.0-Administration_Guide.pdf
NEW QUESTION # 27
Which three Fortinet products can be used for device identification in an OT industrial control system (ICS)? (Choose three.)
- A. FortiManager
- B. FortiAnalyzer
- C. FortiSIEM
- D. FortiGate
- E. FortiNAC
Answer: C,D,E
Explanation:
A) FortiNAC - FortiNAC is a network access control solution that provides visibility and control over network devices. It can identify devices, enforce access policies, and automate threat response.
D) FortiSIEM - FortiSIEM is a security information and event management solution that can collect and analyze data from multiple sources, including network devices and servers. It can help identify potential security threats, as well as monitor compliance with security policies and regulations.
E) FortiAnalyzer - FortiAnalyzer is a central logging and reporting solution that collects and analyzes data from multiple sources, including FortiNAC and FortiSIEM. It can provide insights into network activity and help identify anomalies or security threats.
NEW QUESTION # 28
Refer to the exhibit. The network topology in the exhibit shows FortiGate devices as well as FortiAnalyzer and FortiSIEM for the OT network.
Which two steps must you take to configure logging on the OT network'? (Choose two.)
- A. Configure FortiAnalyzer to send security events to FortiSIEM.
- B. Configure FortiGate and FortiAnalyzer to send industrial signature patterns to FortiSIEM.
- C. Configure FortiGate to send logs to FortiAnalyzer and FortiSIEM.
- D. Configure FortiSIEM to send logs and alerts to FortiAnalyzer.
Answer: A,C
Explanation:
FortiGates must forward their logs directly to both FortiAnalyzer and FortiSIEM for storage and correlation. FortiAnalyzer then forwards relevant security events to FortiSIEM, enabling centralized analytics across OT devices.
NEW QUESTION # 29
An OT network architect must deploy a solution to protect fuel pumps in an industrial remote network. All the fuel pumps must be closely monitored from the corporate network for any temperature fluctuations.
How can the OT network architect achieve this goal?
- A. Configure a fuel server on the remote network, and deploy a FortiSIEM with a single pattern temperature security rule on the corporate network.
- B. Configure both fuel server and FortiSIEM with a single-pattern temperature performance rule on the corporate network.
- C. Configure a fuel server on the remote network, and deploy a FortiSIEM with a single pattern temperature performance rule on the corporate network.
- D. Configure a fuel server on the corporate network, and deploy a FortiSIEM with a single pattern temperature performance rule on the remote network.
Answer: C
Explanation:
Explanation
This way, FortiSIEM can discover and monitor everything attached to the remote network and provide security visibility to the corporate network
NEW QUESTION # 30
Refer to the exhibit.
You are creating a new operational technology (OT) rule to monitor Modbus protocol traffic on FortiSIEM Which action must you take to ensure that all Modbus messages on the network match the rule?
- A. the Aggregate section, set the attribute value to equal to or greater than 0
- B. In the Group By section remove all attributes that are not configured in the Filter section
- C. The condition on the SubPattern filter must use the AND logical operator
- D. Add a new condition to filter Modbus traffic based on the source TCP/UDP port
Answer: D
NEW QUESTION # 31
What can you assign using network access control policies?
- A. Layer 3 polling intervals
- B. Logical networks
- C. Profiling rules
- D. FortiNAC device polling methods
Answer: B
Explanation:
Network access control policies in FortiNAC consist of a user/host profile and a network access configuration.
The network access configuration defines how users and devices are treated when they connect to the network.
This includes assigning them to specific logical networks such as VLANs or applying access control lists (ACLs).
Logical networks allow segmenting and controlling device access based on policy conditions.
NEW QUESTION # 32
Refer to the exhibit.
You are assigned to implement a remote authentication server in the OT network.
Which part of the hierarchy should the authentication server be part of?
- A. Core
- B. Access
- C. Cloud
- D. Edge
Answer: D
NEW QUESTION # 33
Refer to the exhibit, which shows a non-protected OT environment.
An administrator needs to implement proper protection on the OT network.
Which three steps should an administrator take to protect the OT network? (Choose three.)
- A. Deploy a FortiGate device within each ICS network.
- B. Use segmentation
- C. Deploy an edge FortiGate between the internet and an OT network as a one-arm sniffer.
- D. Configure firewall policies with industrial protocol sensors
- E. Configure firewall policies with web filter to protect the different ICS networks.
Answer: C,D,E
NEW QUESTION # 34
......
Get Top-Rated Fortinet NSE7_OTS-7.2 Exam Dumps Now: https://www.latestcram.com/NSE7_OTS-7.2-exam-cram-questions.html
NSE7_OTS-7.2 Exam Dumps Pass with Updated Tests Dumps: https://drive.google.com/open?id=1nZHjAjNarjCo_RUARCmD1e6aBMsHIy58
