[Jan 13, 2022] Pass Fortinet NSE7_OTS-6.4 Exam Info and Free Practice Test [Q18-Q34]

Share

[Jan 13, 2022] Pass Fortinet NSE7_OTS-6.4 Exam Info and Free Practice Test

NSE7_OTS-6.4 Exam Dumps PDF Updated Dump from Exams-boost Guaranteed Success


Fortinet NSE7_OTS-6.4 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Configure the security fabric for OT network
  • Implement application control for industrial applications
Topic 2
  • Explain network visibility with FortiNAC
  • Build OT security dashboard with FortiSIEM
Topic 3
  • Explain internal segmentation implementation for OT networks
  • Explain role-based authentication
Topic 4
  • Explain industrial Ethernet protocols
  • Explain FortiSIEM rules and incidents

 

NEW QUESTION 18
An administrator wants to use FortiSoC and SOAR features on a FortiAnalyzer device to detect and block any unauthorized access to FortiGate devices in an OT network.
Which two statements about FortiSoC and SOAR features on FortiAnalyzer are true? (Choose two.)

  • A. Each playbook can include multiple triggers.
  • B. You cannot use Windows and Linux hosts security events with FortiSoC.
  • C. You can automate SOC tasks through playbooks.
  • D. You must set correct operator in event handler to trigger an event.

Answer: A,C

Explanation:
Ref: https://docs.fortinet.com/document/fortianalyzer/7.0.0/administration-guide/268882/fortisoc

 

NEW QUESTION 19
Refer to the exhibit.

An OT administrator ran a report to identify device inventory in an OT network.
Based on the report results, which report was run?

  • A. A FortiSIEM analytics report
  • B. A FortiAnalyzer device report
  • C. A FortiSIEM CMDB report
  • D. A FortiSIEM incident report

Answer: C

 

NEW QUESTION 20
An OT network administrator is trying to implement active authentication.
Which two methods should the administrator use to achieve this? (Choose two.)

  • A. Role-based authentication on FortiNAC
  • B. Local authentication on FortiGate
  • C. FSSO authentication on FortiGate
  • D. Two-factor authentication on FortiAuthenticator

Answer: A,D

 

NEW QUESTION 21
Refer to the exhibit.

An OT architect has implemented a Modbus TCP with a simulation server Conpot to identify and control the Modus traffic in the OT network. The FortiGate-Edge device is configured with a software switch interface ssw-01.
Based on the topology shown in the exhibit, which two statements about the successful simulation of traffic between client and server are true? (Choose two.)

  • A. Port5 is not a member of the software switch.
  • B. NAT is disabled in the FortiGate firewall policy from port3 to ssw-01.
  • C. The FortiGate-Edge device must be in NAT mode.
  • D. The FortiGate devices is in offline IDS mode.

Answer: C,D

 

NEW QUESTION 22
Refer to the exhibit.

Which statement about the interfaces shown in the exhibit is true?

  • A. The VLAN ID of port1-vlan1 can be changed to the VLAN ID 10.
  • B. port1, port1-vlan10, and port1-vlan1 are in different broadcast domains
  • C. port1-vlan10 and port2-vlan10 are part of the same broadcast domain
  • D. port2, port2-vlan10, and port2-vlan1 are part of the software switch interface.

Answer: B

 

NEW QUESTION 23
When you create a user or host profile, which three criteria can you use? (Choose three.)

  • A. Host or user attributes
  • B. Host or user group memberships
  • C. Administrative group membership
  • D. Location
  • E. An existing access control policy

Answer: A,B,D

 

NEW QUESTION 24
What are two benefits of a Nozomi integration with FortiNAC? (Choose two.)

  • A. Enhanced point of connection details
  • B. Adapter consolidation for multi-adapter hosts
  • C. Direct VLAN assignment
  • D. Importation and classification of hosts

Answer: A,C

 

NEW QUESTION 25
Which three criteria can a FortiGate device use to look for a matching firewall policy to process traffic? (Choose three.)

  • A. Source defined as internet services in the firewall policy
  • B. Highest to lowest priority defined in the firewall policy
  • C. Destination defined as internet services in the firewall policy
  • D. Services defined in the firewall policy.
  • E. Lowest to highest policy ID number

Answer: A,C,D

 

NEW QUESTION 26
What two advantages does FortiNAC provide in the OT network? (Choose two.)

  • A. It can be used for network micro-segmentation.
  • B. It can be used for device profiling.
  • C. It can be used for industrial intrusion detection and prevention.
  • D. It can be used for IoT device detection.

Answer: A,B

 

NEW QUESTION 27
Which three common breach points can be found in a typical OT environment? (Choose three.)

  • A. Global hat
  • B. RTU exploits
  • C. Black hat
  • D. VLAN exploits
  • E. Hard hat

Answer: B,C,D

 

NEW QUESTION 28
Refer to the exhibit.

Based on the topology designed by the OT architect, which two statements about implementing OT security are true? (Choose two.)

  • A. IT and OT networks are separated by segmentation.
  • B. Micro-segmentation can be achieved only by replacing FortiGate-3 and FortiGate-4 with a pair of FortiSwitch devices.
  • C. FortiGate-3 and FortiGate-4 devices must be in a transparent mode.
  • D. Firewall policies should be configured on FortiGate-3 and FortiGate-4 with industrial protocol sensors.

Answer: A,C

 

NEW QUESTION 29
When device profiling rules are enabled, which devices connected on the network are evaluated by the device profiling rules?

  • A. Rogue devices, each time they connect
  • B. Known trusted devices, each time they change location
  • C. All connected devices, each time they connect
  • D. Rogue devices, only when they connect for the first time

Answer: D

 

NEW QUESTION 30
You are investigating a series of incidents that occurred in the OT network over past 24 hours in FortiSIEM.
Which three FortiSIEM options can you use to investigate these incidents? (Choose three.)

  • A. Overview
  • B. Security
  • C. List
  • D. Risk
  • E. IPS

Answer: A,C,D

 

NEW QUESTION 31
Which three methods of communication are used by FortiNAC to gather visibility information? (Choose three.)

  • A. SNMP
  • B. RADIUS
  • C. TACACS
  • D. API
  • E. ICMP

Answer: A,B,D

 

NEW QUESTION 32
......

Pass Your Fortinet Exam with NSE7_OTS-6.4 Exam Dumps: https://www.exams-boost.com/NSE7_OTS-6.4-valid-materials.html

NSE7_OTS-6.4 Exam Dumps - Fortinet Practice Test Questions: https://drive.google.com/open?id=12ojCSMNrJwV8YtMrPqWtRi8HpYAWO6Hb