View Full Fortinet NSE6_OTS_AR-7.6 Exam Dumps and Practice Test Dumps.
Question 161
Which FortiGate feature can identify and control web-based applications according to configured security policies?
- NTP
- Application Control
- DHCP
- Static Routing
Correct Answer: 2
Explanation
Application Control allows FortiGate to identify applications based on their traffic characteristics and apply policies accordingly. This can provide more granular control than relying only on IP addresses or port numbers. In an OT environment, application visibility can help administrators understand which applications are communicating across security boundaries and restrict applications that are not required. Because industrial applications may use specialized communication patterns, policies should be tested carefully before being applied to production systems. Application Control works as one layer of protection alongside segmentation, firewall policies, authentication, and monitoring. Properly configured application policies can help reduce unnecessary communication while preserving required industrial functionality.
Question 162
Which practice helps protect an OT network from unauthorized physical connections?
- Network access control
- Increasing bandwidth
- Disabling logging
- Removing segmentation
Correct Answer: 1
Explanation
Network access control can help prevent unauthorized devices from connecting to an OT environment. Depending on the architecture, access controls may verify device identity, user authentication, or other attributes before allowing network connectivity. This can reduce the risk associated with unauthorized laptops, removable equipment, or unmanaged devices being connected to industrial networks. OT environments often contain specialized equipment, so access controls should be carefully designed to avoid disrupting legitimate devices that may have limited authentication capabilities. Maintaining an approved asset inventory also helps administrators recognize unexpected connections. Network access control should complement segmentation, monitoring, and physical security rather than being treated as the only protection mechanism.
Question 163
What is a key advantage of using individual administrator accounts?
- Shared responsibility
- Anonymous access
- Improved accountability
- Reduced logging
Correct Answer: 3
Explanation
Individual administrator accounts improve accountability by allowing administrative actions to be associated with specific users. In a security-sensitive OT environment, this is important because configuration changes can directly affect communication between critical industrial systems. If administrators share one account, it becomes difficult to determine who performed a particular action during an investigation. Individual accounts also make it easier to apply role-based permissions and remove access when responsibilities change. Strong authentication and appropriate logging should be used alongside individual accounts. Together, these measures provide better control over privileged access and make unauthorized configuration changes easier to investigate and attribute.
Question 164
Which security mechanism can help prevent unauthorized access to a management interface from external networks?
- Firewall policy
- Screen resolution
- NTP
- File compression
Correct Answer: 1
Explanation
A firewall policy can restrict access to management interfaces by allowing connections only from approved source networks or administrative systems. In an OT environment, management services should generally not be exposed unnecessarily to external or untrusted networks. Administrators can use dedicated management networks, VPN gateways, authentication controls, and restrictive firewall rules to establish controlled access paths. Limiting management connectivity reduces opportunities for credential attacks and exploitation of vulnerable services. Policies should specify only the required protocols and destinations rather than allowing broad access. Regular reviews are also important because old administrative rules may remain active after systems or management requirements have changed.
Question 165
Which component typically provides operators with real-time process information and controls?
- HMI
- Historian
- Firewall
- Router
Correct Answer: 1
Explanation
A Human-Machine Interface, or HMI, provides operators with a graphical interface for viewing process information and interacting with industrial systems. HMIs can display values such as temperatures, pressures, equipment status, alarms, and production information. Depending on the system design, authorized operators may also use HMIs to issue control commands. Because an HMI can provide access to operational functions, it should be protected through network segmentation, authentication, access control, and monitoring. An HMI is different from a historian, which primarily stores historical process information. Protecting HMI systems is important because compromise could affect both the visibility of industrial processes and authorized operator interaction with control systems.
Question 166
Which approach helps reduce the risk of exploiting known vulnerabilities in legacy OT systems?
- Exposing the systems directly to the Internet
- Applying compensating controls such as segmentation and IPS
- Disabling all monitoring
- Allowing unrestricted remote access
Correct Answer: 2
Explanation
Legacy OT systems may not support modern security updates or may be difficult to patch without disrupting production. Compensating controls can therefore provide additional protection when direct remediation is not immediately possible. Network segmentation can restrict which systems communicate with the vulnerable device, while firewall policies can limit access to required services. IPS signatures may also help detect or block known exploit attempts when appropriately supported and tested. These controls do not eliminate the underlying vulnerability, but they can reduce exposure. Organizations should maintain an inventory of legacy systems and develop longer-term plans for upgrading or replacing equipment that can no longer receive adequate security support.
Question 167
What is the main purpose of logging security events on an OT firewall?
- To increase CPU performance
- To provide evidence and visibility into network activity
- To replace network segmentation
- To eliminate authentication
Correct Answer: 2
Explanation
Firewall security logs provide visibility into network activity and create records that can be useful during security investigations. Logs can show permitted and denied connections, policy matches, authentication events, and other relevant information depending on the configuration. In OT environments, these records can help identify unauthorized access attempts, troubleshooting issues, or unusual communication patterns. Centralizing logs can make analysis easier across multiple devices. Logging does not prevent attacks by itself, but it provides important evidence that can support detection and response. Administrators should configure appropriate log levels and retention while ensuring that monitoring processes do not negatively affect the performance of critical security infrastructure.
Question 168
Which network design principle limits communication to only what is operationally required?
- Least privilege
- High availability
- Load balancing
- Open access
Correct Answer: 1
Explanation
Applying least privilege to network communication means allowing systems to communicate only with the destinations, services, and applications required for legitimate operations. In an OT environment, this principle can reduce unnecessary exposure between industrial zones and limit potential lateral movement. For example, a control system may need to communicate with a specific supervisory server but may not need access to unrelated enterprise systems. Firewall policies can enforce these restrictions by defining precise communication rules. Least privilege should be based on documented operational dependencies and regularly reviewed. This approach helps maintain necessary functionality while reducing the number of unnecessary communication paths available to attackers.
Question 169
Which security feature can inspect files transferred through supported network traffic for malware?
- Antivirus
- NTP
- DHCP
- Routing
Correct Answer: 1
Explanation
FortiGate Antivirus security profiles can inspect supported traffic for malicious files and known malware patterns. This provides an additional layer of defense when files enter or move through monitored network paths. In OT environments, file transfers may occur through engineering workstations, remote support connections, update mechanisms, or other systems. Security inspection should be carefully evaluated because some industrial applications may use specialized file formats or communication methods. Administrators should test security profiles before enabling them broadly in production environments. Antivirus protection complements other controls such as segmentation, firewall policies, secure remote access, and monitoring rather than replacing those mechanisms.
Question 170
What should be done before enabling aggressive security inspection on critical OT traffic?
- Disable all backups
- Test and validate the configuration
- Allow unrestricted traffic
- Remove monitoring
Correct Answer: 2
Explanation
Security inspection should be tested and validated before being enabled broadly on critical OT traffic. Industrial systems may have strict timing, availability, and protocol requirements, and unexpected inspection behavior could potentially disrupt legitimate communications. Testing allows administrators to identify compatibility issues, false positives, performance concerns, or unexpected blocking behavior before production deployment. Security teams should document the intended configuration and establish a rollback procedure. Where possible, testing should use representative systems or an approved maintenance window. Careful validation does not weaken security; it helps ensure that security controls provide the intended protection without introducing unnecessary operational risk.
Question 171
Which practice can help identify a compromised OT endpoint communicating with an unusual destination?
- Traffic monitoring
- Screen locking
- Printer configuration
- File renaming
Correct Answer: 1
Explanation
Traffic monitoring can help identify unusual communication from OT endpoints. Industrial systems often communicate with a relatively predictable set of systems, so a connection to an unexpected destination may warrant investigation. Monitoring can identify changes in destinations, protocols, traffic volumes, or communication timing. Security teams can compare observed behavior with established baselines and asset information to determine whether activity is expected. Passive monitoring is often useful in OT because it can provide visibility without actively probing sensitive equipment. Monitoring should be combined with alerting and investigation procedures so that unusual traffic can be assessed and appropriate action taken without unnecessarily disrupting legitimate industrial operations.
Question 172
Which technology is commonly used to securely encrypt remote administrative sessions?
- Telnet
- FTP
- SSH
- TFTP
Correct Answer: 3
Explanation
SSH provides encrypted remote administrative sessions for systems and network devices that support it. Encryption protects commands, credentials, and other management information from being transmitted in clear text. This makes SSH preferable to older management protocols such as Telnet when secure remote administration is required. In an OT environment, SSH access should still be restricted to authorized administrators and trusted management networks. Strong authentication, appropriate permissions, and logging should also be used. SSH does not replace network segmentation or firewall controls. Instead, it provides a secure communication method within a broader administrative security architecture designed to minimize exposure of critical industrial systems.
Question 173
What is the primary purpose of an allowlist approach in an OT network?
- Permit explicitly approved communication
- Allow every unknown application
- Disable all firewall policies
- Provide unrestricted Internet access
Correct Answer: 1
Explanation
An allowlist approach permits only communication that has been explicitly approved. This model can be effective in OT environments because industrial communication is often predictable and based on known systems, services, and protocols. Administrators can define required communication and block traffic that does not match approved rules. Allowlisting can reduce the attack surface and limit unauthorized connections. However, accurate documentation is essential because legitimate but undocumented communication could be blocked. Organizations should test allowlist policies carefully and establish procedures for approving new communication requirements. When combined with monitoring and change management, allowlisting can provide strong control over communication between critical industrial systems.
Question 174
Which component is primarily responsible for storing historical industrial process values?
- Firewall
- Historian
- HMI
- Router
Correct Answer: 2
Explanation
An industrial historian collects and stores historical process information generated by control systems and other industrial equipment. Data may include temperatures, pressures, production values, equipment states, alarms, and other operational measurements. Historians support reporting, troubleshooting, trend analysis, optimization, and operational decision-making. Because they often communicate with multiple industrial systems and may also provide information to business applications, they should be protected with appropriate access controls and segmentation. A historian is different from an HMI, which primarily provides an operator interface for viewing and interacting with current process information. Protecting historians helps preserve both operational data and the integrity of historical records.
Question 175
Which measure can help prevent a compromised workstation from accessing every OT subnet?
- Network segmentation
- Unrestricted routing
- Shared credentials
- Public Internet exposure
Correct Answer: 1
Explanation
Network segmentation can restrict a workstation’s access to only the OT subnets and services required for its legitimate function. If the workstation becomes compromised, these restrictions can make it more difficult for an attacker to move laterally toward unrelated systems. Firewalls, VLANs, routing controls, and access policies can be used to enforce segmentation. The design should be based on documented communication requirements so that necessary industrial functions continue to operate. Segmentation is particularly important for engineering workstations and other systems that may interact with multiple devices. It should be supported by monitoring, authentication, endpoint security, and regular policy reviews.
Question 176
Which practice improves the ability to recover a FortiGate configuration after an unexpected failure?
- Deleting configuration backups
- Maintaining and testing backups
- Sharing administrator passwords
- Disabling change management
Correct Answer: 2
Explanation
Maintaining and testing configuration backups improves the ability to recover a FortiGate device after hardware failure, accidental configuration changes, or other incidents. A backup provides a known configuration that can be restored when required. However, simply storing a backup does not guarantee successful recovery, so restoration procedures should be tested periodically. Backup files should also be protected against unauthorized access or modification. In OT environments, recovery planning is important because firewall failures can affect communication between critical network zones. Documented recovery procedures, secure backup storage, and assigned responsibilities help ensure that the organization can restore security controls efficiently when an unexpected event occurs.
Question 177
Which security control can help detect unauthorized administrative changes to FortiGate?
- Configuration logging and monitoring
- Screen brightness
- Increasing storage capacity
- Disabling audit records
Correct Answer: 1
Explanation
Configuration logging and monitoring can help detect unauthorized changes to FortiGate settings. Administrative activities may include creating or modifying firewall policies, changing security profiles, or altering management settings. Recording these activities provides accountability and allows security teams to compare changes against approved change-management records. Unexpected changes can then be investigated to determine whether they were authorized, accidental, or malicious. Individual administrator accounts and appropriate privileges strengthen this process by identifying who performed each action. Configuration monitoring should be combined with secure backups so that known-good settings are available if an unauthorized change needs to be reversed.
Question 178
Why should OT systems be protected from unnecessary Internet connectivity?
- It reduces exposure to external threats
- It guarantees zero vulnerabilities
- It eliminates the need for authentication
- It replaces firewall policies
Correct Answer: 1
Explanation
Limiting unnecessary Internet connectivity reduces the number of external communication paths available to OT systems. Industrial devices generally require only specific communication services, and unrestricted Internet access can expose systems to threats that are not relevant to their operational purpose. Firewall policies can restrict outbound and inbound traffic to approved destinations and services. Organizations should document legitimate external dependencies before implementing restrictions so that required update, monitoring, licensing, or support services are not unintentionally interrupted. Reducing Internet exposure does not guarantee that systems are secure, but it lowers the attack surface and complements other controls such as segmentation, authentication, monitoring, and secure remote access.
Question 179
Which activity should be performed regularly to identify obsolete firewall rules?
- Policy review
- Screen replacement
- Printer maintenance
- Password sharing
Correct Answer: 1
Explanation
Regular firewall policy reviews help identify obsolete, duplicated, overly broad, or unnecessary rules. OT environments evolve as equipment is replaced, applications change, and network architectures are modified. Old firewall rules may continue to permit communication that is no longer required, increasing unnecessary exposure. Reviewing rules against current asset inventories and documented communication requirements can help maintain a least-privilege configuration. Changes should follow established change-management procedures because removing an apparently unused rule without understanding its dependencies could interrupt legitimate operations. Logging and policy usage information can also help administrators determine which rules are actively used and which may require further investigation before removal.
Question 180
Which security approach provides multiple independent protections for critical OT systems?
- Defense-in-depth
- Open access
- Single-factor security
- Flat networking
Correct Answer: 1
Explanation
Defense-in-depth uses multiple complementary security controls to protect critical systems. In an OT environment, these layers can include network segmentation, firewall policies, authentication, least privilege, monitoring, secure remote access, endpoint protection, backups, and incident-response procedures. The purpose is to ensure that if one control fails or is bypassed, other controls remain available to limit the impact. For example, segmentation may restrict an attacker’s movement while monitoring can detect suspicious activity. Defense-in-depth does not mean deploying every security feature without consideration. Controls should be selected according to operational requirements and validated carefully so that security improvements do not unnecessarily disrupt industrial processes.