[Jan 13, 2022] Pass Fortinet NSE7_OTS-6.4 Exam Info and Free Practice Test
NSE7_OTS-6.4 Exam Dumps PDF Updated Dump from Exams-boost Guaranteed Success
Fortinet NSE7_OTS-6.4 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
NEW QUESTION 18
An administrator wants to use FortiSoC and SOAR features on a FortiAnalyzer device to detect and block any unauthorized access to FortiGate devices in an OT network.
Which two statements about FortiSoC and SOAR features on FortiAnalyzer are true? (Choose two.)
- A. Each playbook can include multiple triggers.
- B. You cannot use Windows and Linux hosts security events with FortiSoC.
- C. You can automate SOC tasks through playbooks.
- D. You must set correct operator in event handler to trigger an event.
Answer: A,C
Explanation:
Ref: https://docs.fortinet.com/document/fortianalyzer/7.0.0/administration-guide/268882/fortisoc
NEW QUESTION 19
Refer to the exhibit.
An OT administrator ran a report to identify device inventory in an OT network.
Based on the report results, which report was run?
- A. A FortiSIEM analytics report
- B. A FortiAnalyzer device report
- C. A FortiSIEM CMDB report
- D. A FortiSIEM incident report
Answer: C
NEW QUESTION 20
An OT network administrator is trying to implement active authentication.
Which two methods should the administrator use to achieve this? (Choose two.)
- A. Role-based authentication on FortiNAC
- B. Local authentication on FortiGate
- C. FSSO authentication on FortiGate
- D. Two-factor authentication on FortiAuthenticator
Answer: A,D
NEW QUESTION 21
Refer to the exhibit.
An OT architect has implemented a Modbus TCP with a simulation server Conpot to identify and control the Modus traffic in the OT network. The FortiGate-Edge device is configured with a software switch interface ssw-01.
Based on the topology shown in the exhibit, which two statements about the successful simulation of traffic between client and server are true? (Choose two.)
- A. Port5 is not a member of the software switch.
- B. NAT is disabled in the FortiGate firewall policy from port3 to ssw-01.
- C. The FortiGate-Edge device must be in NAT mode.
- D. The FortiGate devices is in offline IDS mode.
Answer: C,D
NEW QUESTION 22
Refer to the exhibit.
Which statement about the interfaces shown in the exhibit is true?
- A. The VLAN ID of port1-vlan1 can be changed to the VLAN ID 10.
- B. port1, port1-vlan10, and port1-vlan1 are in different broadcast domains
- C. port1-vlan10 and port2-vlan10 are part of the same broadcast domain
- D. port2, port2-vlan10, and port2-vlan1 are part of the software switch interface.
Answer: B
NEW QUESTION 23
When you create a user or host profile, which three criteria can you use? (Choose three.)
- A. Host or user attributes
- B. Host or user group memberships
- C. Administrative group membership
- D. Location
- E. An existing access control policy
Answer: A,B,D
NEW QUESTION 24
What are two benefits of a Nozomi integration with FortiNAC? (Choose two.)
- A. Enhanced point of connection details
- B. Adapter consolidation for multi-adapter hosts
- C. Direct VLAN assignment
- D. Importation and classification of hosts
Answer: A,C
NEW QUESTION 25
Which three criteria can a FortiGate device use to look for a matching firewall policy to process traffic? (Choose three.)
- A. Source defined as internet services in the firewall policy
- B. Highest to lowest priority defined in the firewall policy
- C. Destination defined as internet services in the firewall policy
- D. Services defined in the firewall policy.
- E. Lowest to highest policy ID number
Answer: A,C,D
NEW QUESTION 26
What two advantages does FortiNAC provide in the OT network? (Choose two.)
- A. It can be used for network micro-segmentation.
- B. It can be used for device profiling.
- C. It can be used for industrial intrusion detection and prevention.
- D. It can be used for IoT device detection.
Answer: A,B
NEW QUESTION 27
Which three common breach points can be found in a typical OT environment? (Choose three.)
- A. Global hat
- B. RTU exploits
- C. Black hat
- D. VLAN exploits
- E. Hard hat
Answer: B,C,D
NEW QUESTION 28
Refer to the exhibit.
Based on the topology designed by the OT architect, which two statements about implementing OT security are true? (Choose two.)
- A. IT and OT networks are separated by segmentation.
- B. Micro-segmentation can be achieved only by replacing FortiGate-3 and FortiGate-4 with a pair of FortiSwitch devices.
- C. FortiGate-3 and FortiGate-4 devices must be in a transparent mode.
- D. Firewall policies should be configured on FortiGate-3 and FortiGate-4 with industrial protocol sensors.
Answer: A,C
NEW QUESTION 29
When device profiling rules are enabled, which devices connected on the network are evaluated by the device profiling rules?
- A. Rogue devices, each time they connect
- B. Known trusted devices, each time they change location
- C. All connected devices, each time they connect
- D. Rogue devices, only when they connect for the first time
Answer: D
NEW QUESTION 30
You are investigating a series of incidents that occurred in the OT network over past 24 hours in FortiSIEM.
Which three FortiSIEM options can you use to investigate these incidents? (Choose three.)
- A. Overview
- B. Security
- C. List
- D. Risk
- E. IPS
Answer: A,C,D
NEW QUESTION 31
Which three methods of communication are used by FortiNAC to gather visibility information? (Choose three.)
- A. SNMP
- B. RADIUS
- C. TACACS
- D. API
- E. ICMP
Answer: A,B,D
NEW QUESTION 32
......
Pass Your Fortinet Exam with NSE7_OTS-6.4 Exam Dumps: https://www.exams-boost.com/NSE7_OTS-6.4-valid-materials.html
NSE7_OTS-6.4 Exam Dumps - Fortinet Practice Test Questions: https://drive.google.com/open?id=12ojCSMNrJwV8YtMrPqWtRi8HpYAWO6Hb