Fortinet - Big Savings Alert – Don’t Miss This Deal - Ends In 1d 00h 00m 00s Coupon code: 26Y30OFF
  1. Home
  2. Fortinet
  3. NSEI_OTS_AR-7.6 Exam
  4. Free NSEI_OTS_AR-7.6 Questions

Free Practice Questions for Fortinet NSEI_OTS_AR-7.6 Exam

Pass4Future also provide interactive practice exam software for preparing Fortinet NSE I - OT Security 7.6 Architect (NSEI_OTS_AR-7.6) Exam effectively. You are welcome to explore sample free Fortinet NSEI_OTS_AR-7.6 Exam questions below and also try Fortinet NSEI_OTS_AR-7.6 Exam practice test software.

Page:    1 / 14   
Total 45 questions

Question 1

According to the IEC 62443 standard, your security level is 4. What is your OT environment defending against? (Choose one answer)



Answer : C

According to the OT Security 7.6 Architect study guide regarding IEC 62443 Security Levels:

Security Level 4 (SL 4) Definition: This level provides 'Protection against intentional violation using sophisticated means with extended resources, specific skills, and high motivation'.

Real-World Application: The study guide specifically notes: 'If you are facing a syndicate of cyber extortionists with extensive resources and capabilities, then you should strive for security level 4'.

Comparison to other levels:

SL 1: Protection against 'casual or unintentional system violation'.

SL 2: Protection against 'intentional violation using simple means with low resources'.

SL 3: Protection against 'intentional violation using sophisticated means with moderate resources'.


Question 2

You want to automate some tasks in your OT network. Which three configurations are directly available in a new basic event handler on FortiAnalyzer? (Choose three answers)



Answer : A, D, E

According to the OT Security 7.6 Architect study guide regarding FortiAnalyzer Event Management:

Notification Options: When configuring a new event handler, FortiAnalyzer provides several built-in notification methods to alert administrators when specific log criteria are met. The most common and direct method is Send alert email (Option A).

Incident Management: To streamline the SOC workflow, an event handler can be configured to Automatically create an incident (Option D) based on the triggered event. This moves the event into the Incident Manager for further analysis.

Security Fabric Integration: In the 7.6 architecture, event handlers can directly trigger an Automation stitch (Option E). This allows the FortiAnalyzer to notify the root FortiGate to take action (like running a CLI script or changing a policy) across the Security Fabric.

Exclusions: Create a report (Option B) is typically a task performed by a Playbook or a scheduled report job, not a direct setting inside the basic event handler configuration. Quarantine an attacker (Option C) is an action that results from an automation stitch or playbook, but it is not a direct configuration toggle within the event handler itself.


Question 3

Refer to the exhibit.

Which statement about this partial Asset Identity List page is correct? (Choose one answer)



Answer : B

Based on the OT Security 7.6 Architect study guide regarding the Asset Identity Center and Asset Management:

Vulnerability Visibility: The Asset Identity List tab displays key metadata for IT and OT devices, including detected addresses, users, and a specific column for Vulnerabilities.

Virtual Patching Feature: In the OT Security 7.6 architecture, the 'Vulnerabilities' column is populated through the OT Security Service license, which includes 'OT vulnerability correlation definitions & virtual patching signatures'.

Correlation Mechanism: FortiGate extracts metadata from OT traffic and uses these signatures to identify known vulnerabilities on the assets. For these vulnerabilities to be identified and correlated in the Asset Identity Center as shown in the exhibit (displaying a count of 8 vulnerabilities), the Virtual Patching feature must be active.

Architectural Implementation: Virtual patching is a critical component of the 'Protection' layer in OT networks, allowing administrators to secure legacy or unpatchable PLCs and RTUs by blocking exploit attempts at the network level using IPS-based virtual patching signatures.

Exhibit Analysis: The presence of identified vulnerabilities (the number '8' in the red shield) in the Asset Identity List confirms that the FortiGate is actively performing vulnerability correlation, which is the operational result of having a Virtual Patching security profile applied to the relevant firewall policy.


Question 4

Refer to the exhibit.

A partial OT network is shown. You have encountered many disconnections in the links and want to improve the availability of this network. Which action can you perform? (Choose one answer)



Answer : C

The correct answer is C. You can implement parallel redundancy protocol. The study guide explains that media redundancy involves creating a backup path that can be used when part of the network fails and specifically states that ''Parallel Redundancy Protocol (PRP) can be used for a star topology.'' Since the problem described is many disconnections in the links, the issue is link availability, which is a media redundancy problem rather than a firewall virtualization or policy separation problem. PRP is designed to provide a backup communication path with low recovery time when links fail.

The other options do not fit this scenario as well. HA clusters are described in the guide as a solution for network node redundancy, where a backup firewall or switch takes over when the primary device fails. SD-WAN is recommended for remote site access across multiple WAN links, not for the local floor links shown in this topology. VDOMs provide logical segmentation, not link redundancy or higher link availability. Because the question is specifically about repeated link disconnections, the best action is to implement PRP.


Question 5

Refer to the exhibit.

A partial OT network is shown. In this OT network, you must add additional security measures to detect OT protocols and, therefore, increase the traffic visibility. Which security sensor must you implement to detect the OT protocols in this network? (Choose one answer)



Answer : C

The correct answer is C. Application sensor set to monitor on all the FortiGate devices.

The study guide clearly explains that application control is the feature used to identify OT protocols. It states that ''application control detects the protocols used in applications like Modbus, IEC 104, and the contents of the telecontrol messages'' and also says ''You can use application control signatures to detect OT protocols.'' It further shows an example where a Modbus application control profile is enabled on a firewall policy ''for OT protocol visibility in the monitor status.'' This directly matches the requirement in the question, which is to detect OT protocols and increase traffic visibility.

The other options do not fit the requirement as precisely. Device detection is for identifying devices and collecting endpoint information, not for detecting industrial protocols. Inline IDS and IPS are focused more on detecting or blocking attacks, exploits, protocol abnormalities, and known vulnerabilities. While IPS can inspect some OT traffic, the study guide distinguishes it from application control by stating that IPS signatures tend to detect exploits, whereas application control signatures tend to provide protocol detection at various levels. Therefore, the required security sensor for OT protocol detection and traffic visibility is the application sensor in monitor mode.


Page:    1 / 14   
Total 45 questions