View Full Fortinet NSE6_OTS_AR-7.6 Exam Dumps and Practice Test Dumps.
Question 361
What is the primary purpose of an industrial control system security assessment?
- To identify and evaluate security risks affecting operational systems
- To remove all industrial devices
- To allow unrestricted remote access
- To disable production monitoring
Correct Answer: 3
Explanation
An industrial control system security assessment evaluates the security posture of systems that support operational processes. It can identify weaknesses in network architecture, device configurations, access controls, software, communication paths, and security procedures. Assessments help organizations understand where risks exist and determine which controls may require improvement. In OT environments, assessment methods must account for availability, safety, and the possibility that active testing could affect sensitive devices. Passive techniques and controlled validation can reduce operational risks. Assessment findings should be reviewed with both cybersecurity and operational teams so that remediation decisions consider technical vulnerabilities as well as the potential effect on industrial processes.
Question 362
Which security control can restrict communication between an enterprise network and an OT control network?
- File compression
- Firewall policy
- Screen resolution
- Disk formatting
Correct Answer: 1
Explanation
Firewall policies can control communication between different security zones, including enterprise IT and OT control networks. A properly configured policy can specify which sources, destinations, services, and protocols are permitted while blocking unnecessary communication. This helps reduce the risk that a compromised enterprise system could directly access sensitive industrial assets. In many architectures, an industrial DMZ provides an additional boundary between IT and OT networks. Firewall policies should be based on documented operational requirements and reviewed periodically. Logging can provide visibility into allowed and denied connections. Because industrial systems depend on specific communication paths, policies should be tested carefully before deployment.
Question 363
Why should OT security teams maintain documentation of authorized communication flows?
- To increase unnecessary traffic
- To eliminate network segmentation
- To support accurate security-policy configuration
- To make all devices publicly accessible
Correct Answer: 4
Explanation
Documenting authorized communication flows helps security teams understand which systems must communicate and why. This information is important when designing firewall policies, segmentation rules, monitoring requirements, and access controls. For example, a documented flow may specify that a particular HMI communicates with a specific control server using an approved industrial protocol. Traffic outside the documented requirements can then be investigated or restricted. Accurate documentation also supports troubleshooting and change management. Because industrial environments evolve, communication documentation should be reviewed when systems are added, removed, upgraded, or reconfigured. Clear documentation reduces the risk of accidentally blocking legitimate operational traffic or allowing unnecessary connections.
Question 364
Which approach can help protect a critical OT workstation from unauthorized software execution?
- Disabling all authentication
- Application allowlisting
- Opening all network ports
- Sharing administrator credentials
Correct Answer: 2
Explanation
Application allowlisting can restrict an OT workstation so that only approved applications are allowed to execute. This can reduce the likelihood that unauthorized software, malware, or unapproved utilities will run on a critical system. The approach can be particularly effective for industrial workstations with stable and predictable software requirements. However, administrators must identify legitimate applications, scripts, drivers, and maintenance tools before creating the allowlist. Updates and approved changes also need a controlled process so required software is not accidentally blocked. Testing is important before deployment because incorrectly configured allowlisting can interfere with operator or engineering functions and potentially affect industrial operations.
Question 365
What is a key purpose of privileged access management in an OT environment?
- To provide unrestricted administrator access
- To remove all user authentication
- To control and monitor access to privileged accounts
- To eliminate network segmentation
Correct Answer: 1
Explanation
Privileged access management helps organizations control, monitor, and secure accounts that have elevated permissions. In OT environments, privileged accounts may be capable of changing configurations, modifying security policies, or accessing critical industrial systems. Compromise of such accounts can therefore have significant consequences. Privileged access controls can include individual administrator identities, strong authentication, approval workflows, session monitoring, password management, and limited access duration. The exact implementation depends on the capabilities of the OT systems involved. Where legacy devices cannot support modern privileged-access mechanisms, organizations can use compensating controls such as jump servers, network restrictions, and controlled administrative procedures.
Question 366
Which activity can help determine whether an OT device has changed from its approved configuration?
- Removing the device from the inventory
- Comparing the current state with a configuration baseline
- Disabling all monitoring
- Allowing anonymous administration
Correct Answer: 3
Explanation
Comparing the current configuration of an OT device against an approved baseline can reveal configuration drift or unauthorized changes. A baseline represents a known and documented state that has been reviewed and approved for operational use. Monitoring changes to settings, software, services, or communication parameters can help security teams investigate unexpected modifications. Not every change is malicious because authorized maintenance and engineering activities can also modify configurations. Change-management records should therefore be considered when reviewing alerts. Maintaining accurate baselines, backups, and logs improves the ability to identify unauthorized changes and restore systems when necessary after a security incident or operational problem.
Question 367
What is a major benefit of using separate administrative accounts for privileged activities?
- It improves accountability and limits unnecessary privilege use
- It makes all users administrators
- It eliminates the need for logging
- It allows anonymous access
Correct Answer: 2
Explanation
Separate administrative accounts can improve accountability by distinguishing normal user activity from privileged administrative actions. They also encourage administrators to use elevated privileges only when required instead of performing everyday tasks with highly privileged accounts. In OT environments, this separation can reduce the potential impact of compromised credentials or accidental changes. Administrative activities should be logged and monitored where technically feasible. Strong authentication and appropriate access restrictions should also be applied. Organizations should avoid unnecessary shared privileged credentials because they make individual accountability difficult. For legacy systems that require shared accounts, additional controls can help reduce the associated risks.
Question 368
Which technology can help identify malicious behavior by analyzing files in an isolated environment?
- FortiManager
- FortiSwitch
- FortiAP
- FortiSandbox
Correct Answer: 4
Explanation
FortiSandbox provides an isolated environment for analyzing suspicious files and content to identify potentially malicious behavior. This type of analysis can provide additional protection when traditional detection mechanisms do not have enough information to classify a file confidently. In an OT environment, sandboxing can complement network security controls, endpoint protection, and monitoring. Deployment should be planned carefully because OT networks may have strict availability and connectivity requirements. Suspicious content should be handled according to the organization’s security architecture and policies. FortiSandbox does not replace segmentation or access control; instead, it provides another security layer that can contribute to defense in depth.
Question 369
Why should OT networks use a documented change-management process?
- To ensure changes are reviewed, tested, approved, and traceable
- To permit unauthorized modifications
- To eliminate system documentation
- To disable operational monitoring
Correct Answer: 1
Explanation
A documented change-management process helps ensure that modifications to OT systems are reviewed, approved, tested, and recorded before implementation. This is particularly important because changes to firewalls, controllers, software, or network configurations can affect availability and industrial processes. Documentation provides a record of what changed, who approved it, when it occurred, and how it was implemented. Testing can identify compatibility or operational problems before deployment. A rollback plan can also help restore the previous state if a change causes unexpected behavior. Change management should involve both cybersecurity and operational personnel when changes could affect critical industrial functions or safety requirements.
Question 370
Which security measure can help detect unauthorized modifications to critical OT files?
- Removing file permissions
- File integrity monitoring
- Sharing administrator accounts
- Disabling system logs
Correct Answer: 4
Explanation
File integrity monitoring can detect changes to important files by comparing their current state with an established known-good state. Unexpected modifications may indicate malware activity, unauthorized administrative actions, configuration changes, or other security events. In OT environments, critical files may include application components, configuration files, scripts, or system files supporting engineering and supervisory applications. Monitoring should be configured carefully to avoid excessive alerts caused by legitimate maintenance activities. Approved changes should be documented so security teams can distinguish authorized modifications from suspicious ones. File integrity monitoring is most effective when combined with access controls, logging, endpoint protection, and a documented change-management process.
Question 371
What should be considered before isolating an OT device during a suspected cyberattack?
- Only the device’s manufacturer
- The potential impact on safety and industrial operations
- The color of the device
- The number of employees in the company
Correct Answer: 2
Explanation
Isolating a compromised OT device can help contain a cyberattack, but the action must be evaluated against operational and safety requirements. Disconnecting a controller, server, or communication path may interrupt a critical industrial process or create unexpected equipment behavior. Security teams should therefore coordinate with operational and engineering personnel when possible. Incident-response procedures should identify preapproved containment options and escalation paths for different asset types. The decision should consider the device’s criticality, dependencies, available redundancy, and potential consequences of disconnection. Careful containment helps balance the need to limit attacker activity with the requirement to maintain safe and stable industrial operations.
Question 372
Which type of traffic should normally be allowed through an OT firewall between security zones?
- All internet traffic
- Only documented and required communication
- Unknown traffic from any source
- Unrestricted administrative traffic
Correct Answer: 3
Explanation
OT firewalls should generally permit only communication that is documented as necessary for legitimate operational functions. Restricting traffic to approved sources, destinations, services, and protocols supports a least-privilege network architecture. For example, a control system may require communication with a specific supervisory server but have no operational reason to communicate with unrelated enterprise systems. Allowing unnecessary traffic increases the attack surface and can provide attackers with additional paths for lateral movement. Firewall rules should be reviewed regularly because operational requirements can change. Logging permitted and denied connections can help security teams identify unexpected communication and verify that policies continue to match the actual OT architecture.
Question 373
What is the purpose of security awareness training for personnel who access OT systems?
- To eliminate all technical vulnerabilities
- To teach users how to bypass security controls
- To help personnel recognize and avoid risky security behavior
- To provide unrestricted administrator privileges
Correct Answer: 4
Explanation
Security awareness training helps personnel understand common threats and the actions expected of them when using OT systems. Training may cover phishing, credential protection, removable media, remote access, suspicious activity reporting, and safe handling of industrial systems. Human actions can influence OT security because operators, engineers, administrators, and vendors may interact directly with sensitive equipment or networks. Training should be relevant to each person’s responsibilities and should reinforce established procedures rather than encourage users to bypass controls for convenience. Regular training and exercises can improve awareness and help personnel recognize suspicious behavior before it develops into a larger security incident.
Question 374
Which practice can reduce the risk of malware entering an isolated OT environment through removable media?
- Allowing any USB device
- Controlled removable-media procedures
- Disabling all access controls
- Sharing USB devices without inspection
Correct Answer: 1
Explanation
Removable media can introduce malware into OT environments when files or devices are transferred between systems. Controlled removable-media procedures can reduce this risk by defining which devices are approved, how they are inspected, where they can be used, and how their contents are transferred. Depending on operational requirements, organizations may use malware scanning, dedicated transfer stations, device controls, and approval processes. Personnel should avoid using unknown or personal removable media on critical systems. Procedures should account for legitimate maintenance activities because industrial technicians may need to transfer software or configuration files. The goal is to maintain necessary operational functionality while reducing the risk of uncontrolled media introducing malicious content.
Question 375
Which security control can help identify unusual login attempts against OT management systems?
- Network segmentation only
- Security event logging and monitoring
- Data compression
- Screen locking only
Correct Answer: 3
Explanation
Security event logging and monitoring can record authentication attempts and help identify unusual patterns such as repeated failures, logins at unexpected times, or access from unauthorized systems. Monitoring these events can provide early indications of credential attacks or unauthorized access attempts. In OT environments, logs should be collected carefully so important authentication events are available for investigation without overwhelming security teams with unnecessary information. Alerts should be correlated with asset and operational context where possible. Strong authentication, access restrictions, least privilege, and account-management procedures should complement monitoring because detecting suspicious login activity is only one part of protecting administrative interfaces.
Question 376
What is a key reason to maintain offline or isolated backups of critical OT configurations?
- To ensure attackers cannot easily modify every backup through the production network
- To increase dependence on production systems
- To eliminate recovery testing
- To expose backups to the internet
Correct Answer: 2
Explanation
Offline or isolated backups can provide an additional layer of resilience if production systems or connected backups are compromised. An attacker who gains control of an OT network may attempt to modify or delete accessible backups to prevent recovery. Keeping important configurations and data separated from production networks can reduce this risk. Backups should be protected, documented, and periodically tested to verify that restoration is possible. Organizations should identify which configurations, software, and data are essential for recovering critical systems. Recovery procedures should also account for dependencies and operational sequencing. Reliable isolated backups can significantly improve an organization’s ability to recover after a disruptive incident.
Question 377
Which activity can help validate that OT incident-response personnel are prepared for a cybersecurity event?
- Ignoring previous incidents
- Conducting tabletop or response exercises
- Removing the incident-response plan
- Disabling communication channels
Correct Answer: 4
Explanation
Tabletop and practical response exercises allow OT personnel to rehearse how they would respond to realistic security incidents. Exercises can reveal weaknesses in communication, escalation, decision-making, technical procedures, and coordination between cybersecurity and operational teams. They can also help personnel understand the potential operational consequences of containment actions. Exercises should use scenarios relevant to the organization’s architecture, such as compromised engineering workstations, unauthorized remote access, or suspicious controller activity. Lessons learned should be documented and used to improve the incident-response plan. Regular testing helps ensure that procedures remain practical as systems, personnel, vendors, and operational requirements change.
Question 378
Which principle helps limit the damage caused by a compromised OT account?
- Least privilege
- Unrestricted administration
- Shared credentials
- Anonymous access
Correct Answer: 3
Explanation
Least privilege limits what a compromised account can access or modify. If an attacker obtains valid credentials, excessive permissions could allow them to move laterally, alter configurations, or interfere with critical systems. Restricting accounts to the permissions required for their roles can reduce this potential impact. OT organizations should review privileges regularly, remove unnecessary permissions, and use separate administrative accounts where practical. Network segmentation can provide an additional boundary by restricting which systems an account can reach. Together, identity controls and network restrictions can make it more difficult for attackers to turn one compromised account into broad access across the operational environment.
Question 379
What is an important function of an industrial DMZ in a defense-in-depth architecture?
- It provides a controlled intermediary between enterprise and OT networks
- It connects controllers directly to the public internet
- It removes the need for firewalls
- It provides unrestricted access between all zones
Correct Answer: 1
Explanation
An industrial DMZ can act as a controlled intermediary between enterprise IT networks and OT environments. Services that require communication across the boundary can be placed in or mediated through this zone, reducing the need for direct connections between enterprise systems and sensitive control networks. Firewall policies can restrict communication between the enterprise network, DMZ, and OT network. Examples of services that may be located in an industrial DMZ depend on the organization’s architecture and requirements. The DMZ should not be treated as a trusted extension of either network. Strong authentication, monitoring, secure configuration, and controlled communication remain important within the DMZ itself.
Question 380
Why should OT security policies be reviewed periodically?
- Industrial environments and communication requirements can change over time
- Security policies never become outdated
- Review automatically disables all threats
- Policies should remain unchanged regardless of system changes
Correct Answer: 2
Explanation
OT environments can change as equipment is replaced, software is upgraded, networks are redesigned, new production processes are introduced, or vendors require different access methods. Security policies that were appropriate when originally created may therefore become outdated or fail to reflect current communication requirements. Periodic reviews help identify obsolete rules, unnecessary access, new risks, and gaps in monitoring. Reviews should consider asset inventories, firewall policies, remote-access permissions, authentication requirements, and documented communication flows. Changes should follow established change-management procedures and be validated before implementation. Regular policy review helps maintain alignment between cybersecurity controls and the operational requirements of the industrial environment.