Nov-2022 New Version NSE7_OTS-6.4 Certificate & Helpful Exam Dumps is Online
NSE7_OTS-6.4 Free Certification Exam Material with 36 Q&As
NEW QUESTION 21
An OT supervisor has configured LDAP and FSSO for the authentication. The goal is that all the users be authenticated against passive authentication first and, if passive authentication is not successful, then users should be challenged with active authentication.
What should the OT supervisor do to achieve this on FortiGate?
- A. Configure a firewall policy with FSSO users and place it on the top of list of firewall policies.
- B. Enable two-factor authentication with FSSO.
- C. Under config user settings configure set auth-on-demand implicit.
- D. Configure a firewall policy with LDAP users and place it on the top of list of firewall policies.
Answer: C
NEW QUESTION 22
When device profiling rules are enabled, which devices connected on the network are evaluated by the device profiling rules?
- A. Rogue devices, each time they connect
- B. All connected devices, each time they connect
- C. Known trusted devices, each time they change location
- D. Rogue devices, only when they connect for the first time
Answer: D
NEW QUESTION 23
What two advantages does FortiNAC provide in the OT network? (Choose two.)
- A. It can be used for industrial intrusion detection and prevention.
- B. It can be used for device profiling.
- C. It can be used for IoT device detection.
- D. It can be used for network micro-segmentation.
Answer: B,D
NEW QUESTION 24
As an OT administrator, it is important to understand how industrial protocols work in an OT network.
Which communication method is used by the Modbus protocol?
- A. It uses OSI Layer 2 and both the primary/secondary devices always send data during the communication.
- B. It uses OSI Layer 2 and the primary device sends data based on request from secondary device.
- C. It uses OSI Layer 2 and the secondary device sends data based on request from primary device.
- D. It uses OSI Layer 2 and both the primary/secondary devices send data based on a matching token ring.
Answer: C
NEW QUESTION 25
Refer to the exhibit.
You need to configure VPN user access for supervisors at the breach and HQ sites using the same soft FortiToken. Each site has a FortiGate VPN gateway.
What must you do to achieve this objective?
- A. You must register the same FortiToken on more than one FortiGate.
- B. You must use a FortiAuthenticator.
- C. You must use a third-party RADIUS OTP server.
- D. You must use the user self-registration server.
Answer: B
NEW QUESTION 26
Refer to the exhibit.
Based on the Purdue model, which three measures can be implemented in the control area zone using the Fortinet Security Fabric? (Choose three.)
- A. FortiGate for SD-WAN
- B. FortiGate for application control and IPS
- C. FortiSIEM for security incident and event management
- D. FortiEDR for endpoint detection
- E. FortiNAC for network access control
Answer: B,C,E
NEW QUESTION 27
What can be assigned using network access control policies?
- A. Layer 3 polling intervals
- B. Profiling rules
- C. Logical networks
- D. FortiNAC device polling methods
Answer: B
NEW QUESTION 28
Which three criteria can a FortiGate device use to look for a matching firewall policy to process traffic? (Choose three.)
- A. Highest to lowest priority defined in the firewall policy
- B. Source defined as internet services in the firewall policy
- C. Destination defined as internet services in the firewall policy
- D. Lowest to highest policy ID number
- E. Services defined in the firewall policy.
Answer: B,C,E
NEW QUESTION 29
Refer to the exhibit, which shows a non-protected OT environment.
An administrator needs to implement proper protection on the OT network.
Which three steps should an administrator take to protect the OT network? (Choose three.)
- A. Configure firewall policies with web filter to protect the different ICS networks.
- B. Deploy a FortiGate device within each ICS network.
- C. Use segmentation
- D. Deploy an edge FortiGate between the internet and an OT network as a one-arm sniffer.
- E. Configure firewall policies with industrial protocol sensors
Answer: A,D,E
NEW QUESTION 30
Refer to the exhibit and analyze the output.
Which statement about the output is true?
- A. This is a sample of a FortiAnalyzer system interface event log.
- B. This is a sample of FortiGate interface statistics.
- C. This is a sample of a PAM event type.
- D. This is a sample of an SNMP temperature control event log.
Answer: A
NEW QUESTION 31
Which three methods of communication are used by FortiNAC to gather visibility information? (Choose three.)
- A. TACACS
- B. SNMP
- C. RADIUS
- D. ICMP
- E. API
Answer: B,C,E
NEW QUESTION 32
An OT supervisor needs to protect their network by implementing security with an industrial signature database on the FortiGate device.
Which statement about the industrial signature database on FortiGate is true?
- A. An administrator must create their own database using custom signatures.
- B. A supervisor must purchase an industrial signature database and import it to the FortiGate.
- C. By default, the industrial database is enabled.
- D. A supervisor can enable it through the FortiGate CLI.
Answer: D
NEW QUESTION 33
An OT network architect must deploy a solution to protect fuel pumps in an industrial remote network. All the fuel pumps must be closely monitored from the corporate network for any temperature fluctuations.
How can the OT network architect achieve this goal?
- A. Configure both fuel server and FortiSIEM with a single-pattern temperature performance rule on the corporate network.
- B. Configure a fuel server on the remote network, and deploy a FortiSIEM with a single pattern temperature performance rule on the corporate network.
- C. Configure a fuel server on the remote network, and deploy a FortiSIEM with a single pattern temperature security rule on the corporate network.
- D. Configure a fuel server on the corporate network, and deploy a FortiSIEM with a single pattern temperature performance rule on the remote network.
Answer: D
NEW QUESTION 34
An OT network administrator is trying to implement active authentication.
Which two methods should the administrator use to achieve this? (Choose two.)
- A. Role-based authentication on FortiNAC
- B. Two-factor authentication on FortiAuthenticator
- C. Local authentication on FortiGate
- D. FSSO authentication on FortiGate
Answer: A,B
NEW QUESTION 35
......
Get The Important Preparation Guide With NSE7_OTS-6.4 Dumps: https://www.vceengine.com/NSE7_OTS-6.4-vce-test-engine.html
UPDATED NSE7_OTS-6.4 Exam Questions Certification Test Engine to PDF: https://drive.google.com/open?id=1SUZDowuDRkbtQ4xJhMnG1h2yKGUpAG2N
