Summer Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

Fortinet NSE6_OTS_AR-7.6 - Fortinet NSE 6 - OT Security 7.6 Architect

Page: 1 / 2
Total 45 questions

Refer to the exhibit.

An automation trigger creation wizard is shown. You want to automate some tasks in your OT network. In a FortiGate device, you create a new automation trigger based on a FortiAnalyzer event handler. When you want to configure the Event handler name field, the event handler created in FortiAnalyzer is not shown. What are two reasons for this? (Choose two answers)

A.

You must configure the Fabric settings on the FortiGate device.

B.

You must enable Automation Stitch in the event handler on FortiAnalyzer.

C.

You must click + Create in the Event handler name field.

D.

You must add the FortiGate device to FortiAnalyzer and authorize it.

Refer to the exhibit.

The OT devices behind the ruggedized FortiGate have vulnerabilities and you want to apply a virtual patching profile in the firewall policy. Why is Virtual Patching not available in the Security Profiles section? (Choose one answer)

A.

You must enable Virtual Patching in the Feature Visibility section.

B.

You must have a ruggedized FortiGate allowing the virtual patching feature.

C.

You must enable OT signatures.

D.

You must have a valid OT security service license.

Refer to the exhibits.

A partial Incident Analysis page and the log details related to the event are shown. An attack is reported on your OT network. You analyze the corresponding incident. Based on the information provided on the Incident Analysis page and the log details, which two statements are correct? (Choose two answers)

A.

The attack uses the Modbus protocol.

B.

The attack is mitigated.

C.

The attack uses the IEC 104 protocol.

D.

The event severity is high.

E.

The target device IP address is 10.1.5.20.

Refer to the exhibit.

A partial Application Sensor profile is shown. When you apply this profile in firewall policy, which two statements are correct? (Choose two answers)

A.

OT signatures are enabled.

B.

All OT protocols are monitored.

C.

Modbus write commands are blocked.

D.

A log is provided for each Modbus read holding registers command.

Refer to the exhibit.

A partial OT network is shown. In this OT network, you must add additional security measures to detect OT protocols and, therefore, increase the traffic visibility. Which security sensor must you implement to detect the OT protocols in this network? (Choose one answer)

A.

Device detection on all the FortiGate interfaces.

B.

Inline IDS on FortiGate_Level3.

C.

Application sensor set to monitor on all the FortiGate devices.

D.

IPS sensor on FortiGate_Level5.

You would like to customize your current FortiAnalyzer report to provide a better risk assessment of your OT network. Which two options can you use to enhance your report? (Choose two answers)

A.

The FortiView library

B.

The Datasets library

C.

The Log View library

D.

The Chart library

E.

The Dashboard library

What is the next step if FortiGate cannot detect a device locally? (Choose one answer)

A.

FortiGate queries FortiGuard servers.

B.

FortiGate queries the profiling rules.

C.

FortiGate queries OT servers through service connectors.

D.

FortiGate queries the local device database (CIDB).

You want to improve the security of your OT network and therefore deploy a FortiGate device with the OT signatures database. Which two statements about this database are true? (Choose two answers)

A.

You must install a valid OT security service license.

B.

You must import the OT signatures database manually.

C.

The OT signatures database is enabled by default.

D.

You must set exclude-signatures to none in the console line interface.

Refer to the exhibit.

An industrial Ethernet protocol skipping layers 3 to 6 is shown. Which industrial Ethernet protocol is it? (Choose one answer)

A.

POWERLINK

B.

Ethernet over industrial protocol

C.

Modbus

D.

EtherCAT

Refer to the exhibit.

A partial OT network is shown. You want to configure an automated alert sent by FortiAnalyzer when an attack occurs on a FortiGate device. Which two configurations must you implement? (Choose two answers)

A.

You must configure a stitch on the root FortiGate.

B.

You must configure a LOCALHOST task in the FortiAnalyzer playbook.

C.

You must configure an intrusion prevention security profile on all FortiGate devices.

D.

You must configure an event handler on FortiAnalyzer.