Weekend Sale Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 75epass

Exact2Pass Menu

Fortinet NSE I - OT Security 7.6 Architect

Last Update 14 hours ago Total Questions : 56

The Fortinet NSE I - OT Security 7.6 Architect content is now fully updated, with all current exam questions added 14 hours ago. Deciding to include NSEI_OTS_AR-7.6 practice exam questions in your study plan goes far beyond basic test preparation.

You'll find that our NSEI_OTS_AR-7.6 exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these NSEI_OTS_AR-7.6 sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any Fortinet NSE I - OT Security 7.6 Architect practice test comfortably within the allotted time.

Question # 1

Refer to the exhibit.

A partial OT network is shown.

PLC-1 has a known critical vulnerability, but you cannot update it.

What must you configure to protect PLC-1?

A.

OT signatures on FortiGate_Level3

B.

IPS on FortiGate_Level5

C.

Virtual patching on FortiGate_Level2

D.

OT application control on all FortiGate devices

Question # 2

Refer to the exhibit.

The configuration of firewall policies is shown.

To improve the security of your OT network, you have configured authentication in the firewall policies as shown in the exhibit, with CLI parameters set to their default settings. However, when you test HTTPS access from the LAN subnet to PLC-1, it is successful without any authentication prompt.

What is the reason?

A.

You did not configure authentication in firewall policy ID 9.

B.

You must first authenticate using a protocol such as HTTP or Telnet.

C.

You are authenticated with the default implicit firewall policy.

D.

You are passively authenticated.

Question # 3

Refer to the exhibit.

A partial OT network is shown.

You have recently removed the air gap in the network to provide full connectivity.

What must you configure to protect your OT network from external attacks?

A.

OT signatures on FortiGate_Level3

B.

Virtual patching on FortiGate_Level2

C.

OT application control on all FortiGate devices

D.

IPS on FortiGate_Level5

Question # 4

You want to automate some tasks in your OT network. Which three configurations are directly available in a new basic event handler on FortiAnalyzer? (Choose three answers)

A.

Send alert email

B.

Create a report

C.

Quarantine an attacker

D.

Automatically create an incident

E.

Automation stitch

Question # 5

What is the next step if FortiGate cannot detect a device locally? (Choose one answer)

A.

FortiGate queries FortiGuard servers.

B.

FortiGate queries the profiling rules.

C.

FortiGate queries OT servers through service connectors.

D.

FortiGate queries the local device database (CIDB).

Question # 6

Refer to the exhibit.

A partial OT network is shown. You must improve the security of this OT network and implement internal segmentation between network 1 and network 2. How can you achieve the segmentation? (Choose one answer)

A.

You can configure universal ZTNA.

B.

You can configure one traffic VDOM.

C.

You can configure an explicit software switch.

D.

You can configure forward domain IDs for each network.

Question # 7

Refer to the exhibit.

The Core Network Security Connectors page of the FortiGate-2 device is shown. Which statement is correct? (Choose one answer)

A.

FortiGate-2 serves as Fabric Root.

B.

You must enable Security Fabric Connection on the FortiGate-2 interface.

C.

You must configure the FortiAnalyzer settings on FortiGate-2.

D.

FortiGate-2 is not authorized on the root FortiGate.

Question # 8

As the first step in your OT network protection plan, you must identify the OT protocols that the FortiGate device supports. Which two configurations must you implement on this FortiGate device? (Choose two answers)

A.

You must enable Device detection on all the interfaces.

B.

You must implement an Application Control security profile that monitors OT.

C.

You must enable the OT signatures.

D.

You must implement an Intrusion Prevention security profile that monitors OT.

Question # 9

Which industrial protocol does not support VLANs? (Choose one answer)

A.

[Not clearly visible in the exhibit]

B.

Ethernet over industrial protocol

C.

EtherCAT

D.

Modbus over TCP

Question # 10

Refer to the exhibit.

A Virtual Patching profile is shown. You have recently updated your SCADA system and would like to apply the SCADA virtual patching profile. Which two statements about this profile are correct? (Choose two answers)

A.

Only the vulnerability Schneider.Electric.ClearSCADA.HTTP.Interface.XSS is still present.

B.

Low severity signatures are not blocked for the device with the MAC address 12:12:12:12:12.

C.

This profile blocks critical severity signatures for all the devices.

D.

The device with the MAC address 11:11:11:11:11 is considered to have no vulnerabilities.

Go to page: