Spring Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Free and Premium Fortinet NSE6_OTS_AR-7.6 Dumps Questions Answers

Fortinet NSE 6 - OT Security 7.6 Architect Questions and Answers

Question 1

Refer to the exhibits.

A partial Basic Event Handler page on FortiAnalyzer and the creation of a trigger in a FortiGate device are shown. To improve the protection of your OT network, you want to automate the handling of compromised devices notified through FortiAnalyzer. You have configured an event handler named Alert_trigger as shown in the exhibit. When you create the trigger on the FortiGate device, the Event handler name field does not provide the Alert_trigger option. What two actions must you perform to make the Alert_trigger option available? (Choose two answers)

Options:

A.

You must click + Create in the Event handler name field.

B.

You must authorize the FortiGate device on FortiAnalyzer.

C.

You must configure the FortiAnalyzer setting on the FortiGate device.

D.

You must configure the trigger on the root FortiGate.

Buy Now
Question 2

During layer 2 polling , which two pieces of information are gathered by FortiNAC to identify a device? (Choose two answers)

Options:

A.

Where it was learned

B.

The MAC-to-IP correlation learned

C.

The system name learned

D.

The time it was learned

Question 3

You want FortiAnalyzer to trigger an automation stitch on a FortiGate device automatically. What must you configure on FortiAnalyzer to enable direct communication with FortiGate? (Choose one answer)

Options:

A.

A Fabric connector

B.

A playbook task

C.

The Fabric settings

D.

An event handler

Question 4

In the Purdue model, at which level are physical assets like the Industrial Internet of Things (IIoT) placed? (Choose one answer)

Options:

A.

At Level 5 only

B.

At Level 1 only

C.

Above Level 4

D.

Below Level 3.5

Question 5

Refer to the exhibit.

A partial OT network is shown. You have encountered many disconnections in the links and want to improve the availability of this network. Which action can you perform? (Choose one answer)

Options:

A.

You can implement HA clusters.

B.

You can implement SD-WAN at Floor-1-FortiGate and Floor-2-FortiGate.

C.

You can implement parallel redundancy protocol.

D.

You can implement VDOMs in Edge-FortiGate.

Question 6

Refer to the exhibit.

A partial OT network is shown. In this OT network, you must add additional security measures to detect OT protocols and, therefore, increase the traffic visibility. Which security sensor must you implement to detect the OT protocols in this network? (Choose one answer)

Options:

A.

Device detection on all the FortiGate interfaces.

B.

Inline IDS on FortiGate_Level3.

C.

Application sensor set to monitor on all the FortiGate devices.

D.

IPS sensor on FortiGate_Level5.

Question 7

You want to improve access control for your large OT network using passive authentication. What must you configure on FortiGate? (Choose one answer)

Options:

A.

Fortinet Single-Sign On (FSSO)

B.

Local users

C.

Two-factor authentication

D.

A FortiAuthenticator device as a remote server

Question 8

According to the IEC 62443 standard, your security level is 4 . What is your OT environment defending against? (Choose one answer)

Options:

A.

Intentional cyberthreats posed by skilled malicious users

B.

An intentional attack with low resources

C.

A syndicate of cyber extortion with extensive resources

D.

A casual exposure

Question 9

Refer to the exhibit.

A firewall policy page is shown. To improve the security of your OT network, you have configured a Supervisor profile in the firewall policies, as shown in the exhibit. However, a supervisor is reporting that he cannot ping PLC-1. What are the two reasons? (Choose two answers)

Options:

A.

The supervisor must first authenticate using a protocol such as HTTPS or Telnet.

B.

The Supervisor profile is not configured in the remote server.

C.

The firewall policy ID 8 is not enabled.

D.

The CLI parameter auth-on-demand is set to always.

Question 10

You want to improve the security of your OT network and therefore deploy a FortiGate device with the OT signatures database. Which two statements about this database are true? (Choose two answers)

Options:

A.

You must install a valid OT security service license.

B.

You must import the OT signatures database manually.

C.

The OT signatures database is enabled by default.

D.

You must set exclude-signatures to none in the console line interface.

Question 11

Refer to the exhibit.

A Logical Topology page of a FortiGate device is shown. Your OT company wants to gain visibility into the network. You decide to implement device detection with the Security Fabric. Based on the exhibit, which statement is correct? (Choose one answer)

Options:

A.

Device Detection is enabled on the other identified device.

B.

The other identified device must be authorized on the root FortiGate.

C.

The other identified device must be authorized on FortiAnalyzer.

D.

Device Detection is enabled on port3.

Question 12

What is the next step if FortiGate cannot detect a device locally? (Choose one answer)

Options:

A.

FortiGate queries FortiGuard servers.

B.

FortiGate queries the profiling rules.

C.

FortiGate queries OT servers through service connectors.

D.

FortiGate queries the local device database (CIDB).

Question 13

You want to protect OT devices that are not updated against known vulnerabilities so you apply virtual patching to the firewall policies. What must you check to confirm that the OT devices are virtually patched? (Choose one answer)

Options:

A.

The output of the CLI command get virtual-patch profile

B.

The OT View page

C.

The output of the CLI command get rule otvp status

D.

The Asset Identity List page