Fortinet NSE6_OTS_AR-7.6 Practice Test Questions and Exam Dumps Part4 Q61-80

View Full Fortinet NSE6_OTS_AR-7.6 Exam Dumps and Practice Test Dumps.

 

Question 61

Which security control can help identify unauthorized communication between OT devices?

  1. Passive traffic monitoring
  2. Screen locking
  3. Printer management
  4. Email archiving

Correct Answer: 1

Explanation

Passive traffic monitoring can help administrators observe communication between OT devices without actively probing the devices. This can provide visibility into protocols, source and destination systems, and communication patterns that may be unexpected. Such visibility is useful for identifying unauthorized or unusual communication within an industrial environment. Screen locking, printer management, and email archiving do not provide network-level visibility into OT communications. Passive monitoring is particularly valuable for sensitive systems that may not tolerate aggressive scanning. Administrators can use observed traffic patterns to improve asset inventories, develop segmentation policies, investigate anomalies, and identify communications that require further security review.

Question 62

Which OT security concept requires administrators to permit only necessary network communications?

  1. Open access
  2. Least privilege
  3. Full trust
  4. Universal connectivity

Correct Answer: 2

Explanation

Least privilege is the principle of providing only the access or communication required to perform legitimate functions. In an OT network, this can be applied to users, applications, devices, and network connections. Firewall policies can restrict communication to approved addresses, services, and protocols. This reduces unnecessary exposure and limits potential attack paths if a device or account becomes compromised. Open access and universal connectivity work against this principle because they allow more communication than may be operationally necessary. Applying least privilege requires administrators to understand legitimate OT communication requirements and regularly review policies to ensure that unnecessary permissions and connections are removed.

Question 63

Which component commonly communicates directly with sensors and actuators in an industrial control environment?

  1. PLC
  2. FortiAnalyzer
  3. Email server
  4. Web proxy

Correct Answer: 1

Explanation

A Programmable Logic Controller, or PLC, commonly communicates with sensors and actuators as part of an industrial control process. It receives input information from sensors, processes that information according to its programmed logic, and sends outputs to actuators or other equipment. This allows the PLC to control physical industrial processes. FortiAnalyzer provides logging and analysis, while email servers and web proxies perform communication and security functions unrelated to direct industrial control. Because PLCs can influence physical processes, they are important OT assets that require appropriate protection. Segmentation, authentication, monitoring, and controlled access can help reduce unauthorized interaction with PLCs.

Question 64

Which FortiGate capability is useful for detecting malicious files transferred through supported network traffic?

  1. Antivirus
  2. NTP
  3. DHCP
  4. Static routing

Correct Answer: 1

Explanation

The Antivirus security profile can inspect supported traffic for malicious files and known malware patterns. This provides an additional layer of protection when file-based threats may enter or move through network environments. NTP is used for time synchronization, DHCP provides network configuration, and static routing controls packet forwarding. In an OT environment, antivirus inspection should be implemented carefully because industrial systems may have specialized requirements and may not support all types of security inspection. Administrators should determine which systems require file inspection and ensure that security profiles are applied in ways that protect the environment without interfering with legitimate operational communications or critical system availability.

Question 65

Which network architecture can provide an additional security boundary between an enterprise network and an OT network?

  1. Industrial DMZ
  2. Open LAN
  3. Shared wireless network
  4. Unrestricted bridge

Correct Answer: 1

Explanation

An industrial DMZ can provide an additional security boundary between enterprise systems and operational technology networks. Services that require controlled communication between the two environments can be placed within or accessed through the DMZ according to defined security policies. This architecture can reduce direct connectivity between enterprise and critical OT systems. An open LAN, shared wireless network, or unrestricted bridge does not provide the same level of controlled separation. Firewalls and other security controls can regulate traffic across the DMZ boundaries. Proper design should consider the required communication flows, security zones, monitoring requirements, and operational dependencies of the industrial environment.

Question 66

Which technology can provide centralized visibility into logs generated by multiple Fortinet devices?

  1. FortiAnalyzer
  2. FortiSwitch
  3. FortiAP
  4. FortiToken

Correct Answer: 1

Explanation

FortiAnalyzer provides centralized collection, storage, analysis, and reporting of logs from supported Fortinet devices. This centralized approach allows administrators to review security events and network activity across multiple devices from a common platform. It can simplify investigation by providing historical information and tools for analyzing collected data. FortiSwitch provides switching capabilities, FortiAP provides wireless access functionality, and FortiToken is associated with authentication mechanisms. Centralized logging is especially useful in OT environments because security events can occur across several network zones. Reviewing information from multiple security devices can help administrators establish timelines and identify activity that requires investigation.

Question 67

Which security practice can help prevent unauthorized users from accessing OT engineering systems?

  1. Strong authentication
  2. Anonymous login
  3. Shared passwords
  4. Unrestricted remote access

Correct Answer: 1

Explanation

Strong authentication helps verify the identity of users before they receive access to sensitive OT systems. Engineering workstations can provide access to PLC configurations and other important industrial resources, so unauthorized access can create significant security risks. Strong authentication can include appropriate password controls, multifactor authentication where supported, and integration with centralized identity systems. Anonymous access and shared passwords reduce accountability and increase the possibility of unauthorized use. Unrestricted remote access also increases exposure. Authentication should be combined with authorization, segmentation, logging, and least-privilege policies so that authenticated users receive only the access necessary for their legitimate engineering responsibilities.

Question 68

Which industrial protocol is commonly associated with supervisory control and data acquisition environments?

  1. Modbus
  2. SMTP
  3. IMAP
  4. HTTP proxy

Correct Answer: 1

Explanation

Modbus is a widely deployed industrial communication protocol and is commonly encountered in SCADA and other OT environments. It can be used to exchange information between controllers, supervisory systems, and industrial devices. Because Modbus and similar industrial protocols were often designed primarily for operational communication rather than modern cybersecurity requirements, security controls may need to provide additional protection around them. Administrators should identify where industrial protocols are used and determine which communication paths are necessary. Segmentation, protocol-aware inspection, access controls, and monitoring can help protect systems that rely on Modbus while maintaining the communications required for legitimate industrial operations.

Question 69

What is one purpose of using role-based access control in an OT environment?

  1. Assign permissions according to job responsibilities
  2. Allow every user administrative access
  3. Remove authentication
  4. Permit anonymous management

Correct Answer: 1

Explanation

Role-based access control assigns permissions according to the responsibilities associated with a user’s role. In an OT environment, this can help ensure that operators, engineers, administrators, and other personnel receive only the access required for their duties. For example, an operator may need process monitoring capabilities without requiring full administrative privileges. Giving every user administrative access would increase the potential impact of compromised accounts or mistakes. Removing authentication or allowing anonymous management would further weaken access controls. Role-based permissions work well with least privilege, strong authentication, network segmentation, and logging to provide controlled access to critical industrial systems.

Question 70

Which FortiGate capability can help block traffic associated with known network attacks?

  1. IPS
  2. DHCP
  3. DNS
  4. NTP

Correct Answer: 1

Explanation

Intrusion Prevention System functionality can inspect network traffic and use signatures or detection rules to identify known attacks. When configured in prevention mode, IPS can take action against traffic that matches applicable security signatures. DHCP, DNS, and NTP provide network configuration, name resolution, and time synchronization functions rather than intrusion prevention. In OT environments, IPS policies should be carefully selected because industrial systems may have sensitive communication requirements. Administrators should understand the supported protocols and operational behavior before enabling protective signatures. Properly configured IPS can provide an additional layer of defense alongside segmentation, authentication, application control, monitoring, and other OT security measures.

Question 71

Which method can help administrators identify normal communication patterns in an OT network?

  1. Network traffic monitoring
  2. Disabling logging
  3. Removing firewall policies
  4. Blocking all traffic

Correct Answer: 1

Explanation

Network traffic monitoring allows administrators to observe communication patterns between OT systems and establish an understanding of normal network behavior. This baseline can help identify unexpected connections, unusual protocols, new devices, or other changes that may require investigation. Disabling logging removes useful information, while removing firewall policies reduces security control. Blocking all traffic would prevent normal industrial operations and would not provide a practical baseline. Monitoring should be implemented with consideration for the operational requirements of the environment. Over time, observed traffic can help administrators refine security policies, improve segmentation, investigate anomalies, and identify communication that falls outside expected operational behavior.

Question 72

Which security measure can help limit the impact of a compromised OT workstation?

  1. Network segmentation
  2. Shared administrator credentials
  3. Open network access
  4. Unrestricted routing

Correct Answer: 1

Explanation

Network segmentation can limit the systems and services that a compromised workstation can reach. By placing workstations and critical industrial assets into appropriate security zones, administrators can control communication between them using firewall policies and other security mechanisms. This can reduce opportunities for lateral movement after a compromise. Shared administrator credentials, open network access, and unrestricted routing can increase exposure and make unauthorized movement easier. Segmentation should be combined with authentication, endpoint security, monitoring, and appropriate access controls. The goal is to establish meaningful boundaries that restrict unnecessary communication while continuing to support legitimate operational and engineering workflows.

Question 73

Which FortiGate feature can provide visibility into supported industrial protocols?

  1. OT protocol inspection
  2. DHCP reservation
  3. DNS forwarding
  4. Static NAT only

Correct Answer: 1

Explanation

OT protocol inspection provides visibility into supported industrial protocols and can help security administrators understand the characteristics of communications occurring within an industrial network. This type of inspection is valuable because traditional network controls may not fully understand specialized OT protocol behavior. DHCP reservations associate addresses with devices, DNS forwarding handles name resolution, and static NAT translates addresses. Protocol-aware inspection can support threat detection, policy enforcement, and investigation of unexpected industrial communications. Administrators should validate supported protocols and inspection behavior before deploying controls broadly because industrial systems can be sensitive to network changes and security mechanisms should be aligned with operational requirements.

Question 74

Which security control can help protect administrative credentials while they are transmitted over a network?

  1. Encrypted management protocols
  2. Plaintext Telnet
  3. Anonymous access
  4. Shared passwords

Correct Answer: 1

Explanation

Encrypted management protocols help protect administrative credentials and management information from interception while they travel across a network. Protocols such as HTTPS and SSH can provide encrypted communication when properly configured and supported by the device. Plaintext protocols can expose credentials to interception, while anonymous access and shared passwords weaken accountability and access control. In an OT environment, secure management should also be restricted to authorized networks and users. Encryption is one part of a broader security strategy that should include strong authentication, least privilege, segmentation, logging, and monitoring. Administrators should disable insecure management services where operationally and technically appropriate.

Question 75

Which activity can help determine whether an OT security policy is functioning as intended?

  1. Reviewing logs and security events
  2. Disabling monitoring
  3. Removing all restrictions
  4. Ignoring blocked traffic

Correct Answer: 1

Explanation

Reviewing logs and security events helps administrators determine whether security policies are allowing legitimate traffic and blocking activity that should be restricted. Logs can show accepted connections, denied traffic, security detections, and other events that provide insight into policy behavior. Disabling monitoring removes this visibility, while removing all restrictions would prevent meaningful security enforcement. Ignoring blocked traffic can also make it difficult to identify incorrectly configured policies or potentially malicious activity. Regular review helps administrators identify false positives, unnecessary rules, unexpected communication, and security events. Policy changes should be tested carefully in OT environments to avoid disrupting required industrial communications.

Question 76

Which approach is appropriate for managing remote access to sensitive OT systems?

  1. Restrict access to authorized users and required resources
  2. Allow direct Internet access to PLCs
  3. Share one remote administrator account
  4. Disable authentication

Correct Answer: 1

Explanation

Remote access to sensitive OT systems should be restricted to authorized users and only the resources required for legitimate operational tasks. Security controls can include VPNs, strong authentication, role-based access, firewall policies, segmentation, session monitoring, and logging. Directly exposing PLCs or other critical devices to the Internet increases their attack surface and should generally be avoided. Shared administrator accounts reduce accountability, while disabling authentication removes an essential security control. Remote access architectures should be carefully designed and monitored because remote connections can provide powerful access to industrial systems. Organizations should also review remote access permissions regularly and remove unnecessary access.

Question 77

Which FortiAnalyzer capability can help administrators generate security reports from collected logs?

  1. Reporting
  2. PLC control
  3. Industrial routing
  4. Cable testing

Correct Answer: 1

Explanation

FortiAnalyzer provides reporting capabilities that can organize information collected from supported Fortinet devices into useful security and operational reports. Reports can help administrators review events, identify trends, communicate security information, and support investigations. PLC control and industrial routing are operational functions outside FortiAnalyzer’s primary purpose, while cable testing is a physical network activity. Reporting can be particularly useful in OT environments where security teams need to maintain visibility across multiple devices and zones. Administrators can use available reports and configured data views to support monitoring and analysis while retaining centralized records of relevant security activity.

Question 78

Which practice can reduce the likelihood that an attacker can move from an enterprise network into critical OT systems?

  1. Controlled communication through security boundaries
  2. Unrestricted network bridging
  3. Shared internal credentials
  4. Open firewall policies

Correct Answer: 1

Explanation

Controlled communication through security boundaries can reduce the likelihood that an attacker will move directly from an enterprise network into critical OT systems. Firewalls, DMZs, segmentation, authentication, and restrictive access policies can limit the paths available between different environments. Unrestricted bridging and open firewall policies provide fewer barriers to lateral movement. Shared credentials can further increase risk by giving attackers broader access if those credentials are compromised. Enterprise and OT networks should therefore be separated according to their security requirements, with clearly documented communication paths. Monitoring traffic between the environments can also help identify unusual activity and support incident investigation.

Question 79

Which security control can provide temporary protection when a vulnerable industrial application cannot immediately be patched?

  1. Virtual patching
  2. Open routing
  3. Anonymous access
  4. Disabled inspection

Correct Answer: 1

Explanation

Virtual patching can provide temporary or compensating protection when a vulnerable industrial application or device cannot immediately receive a software update. Network security controls can inspect relevant traffic and block exploitation attempts associated with known vulnerabilities. This is useful in OT environments where maintenance windows, vendor requirements, legacy systems, or availability concerns may delay direct patching. Virtual patching should not replace proper vulnerability remediation when an approved update becomes available. Administrators should continue tracking the vulnerability and plan appropriate maintenance. Other controls such as segmentation, access restrictions, monitoring, and IPS can provide additional layers of protection while remediation is being planned.

Question 80

Which combination provides stronger protection for critical OT assets?

  1. Segmentation, authentication, monitoring, and threat prevention
  2. Unrestricted internal access
  3. One shared administrator account
  4. No logging or inspection

Correct Answer: 1

Explanation

A combination of segmentation, authentication, monitoring, and threat prevention provides multiple layers of protection for critical OT assets. Segmentation controls communication paths, authentication verifies user identity, monitoring provides visibility, and threat-prevention technologies can help detect or block malicious activity. Using only one control can leave other attack paths insufficiently protected. Unrestricted internal access increases exposure, shared administrator accounts reduce accountability, and disabling logging or inspection removes important security visibility. OT security should therefore use a layered architecture that is designed around operational requirements. Each security control should have a defined purpose while preserving the availability and reliability required by industrial processes.