Real Fortinet NSE7_OTS-7.2 Exam Dumps with Correct 70 Questions and Answers [Q33-Q49]

Share

Real Fortinet NSE7_OTS-7.2 Exam Dumps with Correct 70 Questions and Answers

Valid NSE7_OTS-7.2 Test Answers & Fortinet NSE7_OTS-7.2 Exam PDF


Fortinet NSE7_OTS-7.2 certification exam is a vendor-neutral certification that is recognized globally. NSE7_OTS-7.2 exam is based on the latest industry standards and best practices for securing OT environments. Fortinet NSE 7 - OT Security 7.2 certification exam is designed to validate the skills and knowledge required to design, implement, and manage secure OT networks. Fortinet NSE 7 - OT Security 7.2 certification exam is intended for security professionals who want to demonstrate their expertise in securing OT environments against cyber threats.

 

NEW QUESTION # 33
Refer to the exhibit.

You need to configure VPN user access for supervisors at the breach and HQ sites using the same soft FortiToken. Each site has a FortiGate VPN gateway.
What must you do to achieve this objective?

  • A. You must use the user self-registration server.
  • B. You must use a third-party RADIUS OTP server.
  • C. You must register the same FortiToken on more than one FortiGate.
  • D. You must use a FortiAuthenticator.

Answer: D


NEW QUESTION # 34
Refer to the exhibit.

Which statement about the interfaces shown in the exhibit is true?

  • A. port2, port2-vlan10, and port2-vlan1 are part of the software switch interface.
  • B. port1-vlan10 and port2-vlan10 are part of the same broadcast domain
  • C. port1, port1-vlan10, and port1-vlan1 are in different broadcast domains
  • D. The VLAN ID of port1-vlan1 can be changed to the VLAN ID 10.

Answer: C


NEW QUESTION # 35
An OT network architect needs to secure control area zones with a single network access policy to provision devices to any number of different networks.
On which device can this be accomplished?

  • A. FortiNAC
  • B. FortiEDR
  • C. FortiGate
  • D. FortiSwitch

Answer: C

Explanation:
An OT network architect can accomplish the goal of securing control area zones with a single network access policy to provision devices to any number of different networks on a FortiGate device.


NEW QUESTION # 36
An OT customer is using multiple FortiGate devices in their network to implement two-factor authentication with hardware FortiTokens. A supervisor is carrying multiple FortiTokens to be used when logging in to a critical server behind different FortiGate devices.
As an OT network architect, which approach must you take in order to assign one token per user and still use two-factor authentication on multiple FortiGate devices?

  • A. Provision the Edge-FortiGate device with all the FortiTokens and configure it as a remote authentication server on other FortiGate devices.
  • B. Configure FSSO-based two-factor authentication.
  • C. Implement FortiAuthenticator with FortiTokens provisioned for each user, and configure FortiAuthenticator as remote authentication server on all FortiGate devices in the OT network.
  • D. Implement a FortiManager and manage all FortiGate devices in the OT network to share the FortiTokens database.

Answer: C


NEW QUESTION # 37
A FortiGate device is newly deployed as the edge gateway of an OT network security fabric. The downstream FortiGate devices are also newly deployed as Security Fabric leafs to protect the control area zone.
With no additional essential networking devices, and to implement micro-segmentation on this OT network, what configuration must the OT network architect apply to control intra-VLAN traffic?

  • A. Enable security profiles on all interfaces connected in the control area zone.
  • B. Set up VPN tunnels between downstream and edge FortiGate devices.
  • C. Create a software switch on each downstream FortiGate device.
  • D. Enable transparent mode on the edge FortiGate device.

Answer: C


NEW QUESTION # 38
in an operation technology (OT) network FortiAnalyzer is used to receive and process logs from responsible FortiGate devices Which statement about why FortiAnalyzer is receiving and processing multiple tog messages from a given programmable logic controller (PLC) or remote terminal unit (RTU) is true'?

  • A. To help OT administrators troubleshoot and diagnose the OT network
  • B. To isolate PLCs or RTUs in the event of external attacks
  • C. To determine which type of messages from the PLC or RTU causes issues in the plant
  • D. To track external threats and prevent them attacking the OT network

Answer: D


NEW QUESTION # 39
Refer to the exhibits.

Which statement is true about the traffic passing through to PLC-2?

  • A. SSL Inspection must be set to deep-inspection to correctly apply application control.
  • B. IPS must be enabled to inspect application signatures.
  • C. The application filter overrides the default action of some IEC 104 signatures.
  • D. IEC 104 signatures are all allowed except the C.BO.NA 1 signature.

Answer: C


NEW QUESTION # 40
An OT administrator configured and ran a default application risk and control report in FortiAnalyzer to learn more about the key application crossing the network. However, the report output is empty despite the fact that some related real-time and historical logs are visible in the FortiAnalyzer.
What are two possible reasons why the report output was empty? (Choose two.)

  • A. The administrator selected the wrong hcache table for the report.
  • B. The administrator selected the wrong devices in the Devices section.
  • C. The administrator selected the wrong time period for the report.
  • D. The administrator selected the wrong logs to be indexed in FortiAnalyzer.

Answer: B,C

Explanation:
Explanation
https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/32cb817d-a307-11eb-b70b-0050569258


NEW QUESTION # 41
You are investigating a series of incidents that occurred in the OT network over past 24 hours in FortiSIEM. Which three FortiSIEM options can you use to investigate these incidents? (Choose three.)

  • A. Security
  • B. IPS
  • C. Risk
  • D. Overview
  • E. List

Answer: C,D,E


NEW QUESTION # 42
Refer to the exhibit.

Given the configurations on the FortiGate, which statement is true?

  • A. FortiGate is configured with forward-domains to forward only company domain website traffic.
  • B. FortiGate is configured with forward-domains to filter and drop non-domain controller traffic.
  • C. FortiGate is configured with forward-domains to reduce unnecessary traffic.
  • D. FortiGate is configured with forward-domains to forward only domain controller traffic.

Answer: C


NEW QUESTION # 43
A supervisor is configuring a software switch on a FortiGate device. What must the supervisor configure on FortiGate to control the traffic between member interfaces on the software switch, using firewall policies?

  • A. The supervisor must configure intra-switch-policy to explicit.
  • B. The supervisor must add different VLAN interfaces to the software switch.
  • C. The supervisor must configure the software switch with at least one wireless interface and one VLAN interface.
  • D. The supervisor must configure a separate forward domain for the software switch.

Answer: A


NEW QUESTION # 44
Which two statements about the Modbus protocol are true? (Choose two.)

  • A. You can implement Modbus networking settings on internetworking devices.
  • B. Most of the PLC brands come with a built-in Modbus module.
  • C. Modbus uses UDP frames to transport MBAP and function codes.
  • D. Modbus is used to establish communication between intelligent devices.

Answer: A,B


NEW QUESTION # 45
An OT network architect needs to secure control area zones with a single network access policy to provision devices to any number of different networks. On which device can this be accomplished?

  • A. FortiNAC
  • B. FortiEDR
  • C. FortiGate
  • D. FortiSwitch

Answer: C

Explanation:
An OT network architect can accomplish the goal of securing control area zones with a single network access policy to provision devices to any number of different networks on a FortiGate device.


NEW QUESTION # 46
In a wireless network integration, how does FortiNAC obtain connecting MAC address information?

  • A. RADIUS
  • B. MAC notification traps
  • C. End station traffic monitoring
  • D. Link traps

Answer: A

Explanation:
FortiNAC can integrate with RADIUS servers to obtain MAC address information for wireless clients that authenticate through the RADIUS server.
Reference:
Fortinet NSE 7 - OT Security 6.4 Study Guide, Chapter 4: OT Security Devices, page 4-28.


NEW QUESTION # 47
Refer to the exhibit. An operational technology rule is created and successfully activated to monitor the Modbus protocol on FortiSIEM. However, the rule does not trigger incidents despite Modbus traffic and application logs being received correctly by FortiSIEM.
Which statement correctly describes the issue on the rule configuration?

  • A. The Aggregate attribute COUNT expression is incompatible with the filters.
  • B. The first condition on the SubPattern filter must use the OR logical operator.
  • C. The attributes in the Group By section must match the ones in Fitters section.
  • D. The SubPattern is missing the filter to match the Modbus protocol.

Answer: C


NEW QUESTION # 48
Which type of attack posed by skilled and malicious users of security level 4 (SL 4) of IEC 62443 is designed to defend against intentional attacks?

  • A. Users with unintentional operator error
  • B. Users with substantial resources
  • C. Users with low access to resources
  • D. Users with access to moderate resources

Answer: B


NEW QUESTION # 49
......

NSE7_OTS-7.2 Exam Questions and Valid PMP Dumps PDF: https://www.itpass4sure.com/NSE7_OTS-7.2-practice-exam.html

Fortinet NSE7_OTS-7.2 Certification Real 2025 Mock Exam: https://drive.google.com/open?id=1LMVrkTaQaJ3BTBPbRXrD-Ask5Ry0K_5r