{"id":20977,"date":"2026-09-24T09:57:10","date_gmt":"2026-09-24T09:57:10","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=20977"},"modified":"2026-09-24T09:57:10","modified_gmt":"2026-09-24T09:57:10","slug":"fortinet-nse6_ots_ar-7-6-practice-test-questions-and-exam-dumps-part2-q21-40","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/fortinet-nse6_ots_ar-7-6-practice-test-questions-and-exam-dumps-part2-q21-40\/","title":{"rendered":"Fortinet NSE6_OTS_AR-7.6 Practice Test Questions and Exam Dumps Part2 Q21-40"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/nse6-ots-ar-7-6-exam-dumps\"><b>Fortinet NSE6_OTS_AR-7.6 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 21<\/b><\/h3>\n<p><b>Which FortiGate capability can help administrators identify devices and operating systems communicating on an OT network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device detection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Email filtering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS forwarding<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static routing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Device detection provides useful visibility into endpoints and devices communicating through a FortiGate. In an OT environment, identifying connected assets can help administrators understand the network and determine which systems require protection. This information may include device characteristics, operating system information, and observed network activity depending on the available detection mechanisms. Email filtering and DNS forwarding perform different functions, while static routing controls how packets are forwarded between networks. Device visibility is an important foundation for OT security because administrators need to understand what is connected before they can effectively implement segmentation, access controls, monitoring, and other security measures.<\/span><\/p>\n<h3><b>Question 22<\/b><\/h3>\n<p><b>Which OT security principle limits users and systems to only the access required for their responsibilities?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Full trust<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared administration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The principle of least privilege limits users, applications, and systems to only the permissions necessary to perform their required tasks. In an OT environment, this principle can reduce the potential impact of compromised credentials or unauthorized access. For example, an operator may need access to specific HMIs but may not require administrative access to firewalls or engineering systems. Least privilege can be implemented through authentication, authorization, firewall policies, role-based access controls, and network segmentation. Open access and shared administration increase the potential exposure of sensitive systems. Applying least privilege carefully helps maintain operational functionality while reducing unnecessary access to critical industrial resources.<\/span><\/p>\n<h3><b>Question 23<\/b><\/h3>\n<p><b>Which FortiGate feature can help enforce restrictions based on the applications or protocols observed in network traffic?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP client<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static route<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application Control can identify applications and supported protocols within network traffic and apply configured controls to that traffic. In an OT environment, this can help administrators distinguish permitted industrial communications from unexpected applications or protocols. Application-based restrictions can complement IP-based firewall policies by providing additional visibility into what traffic is actually being carried. DHCP provides address configuration, NTP provides time synchronization, and static routes determine packet forwarding paths. Application Control should be configured carefully in industrial networks because legitimate OT communications must remain available. Administrators should understand normal traffic patterns before applying restrictive controls to production systems.<\/span><\/p>\n<h3><b>Question 24<\/b><\/h3>\n<p><b>Which OT component commonly provides a centralized system for supervisory monitoring and control?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SCADA system<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network cable<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firewall policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS resolver<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Supervisory Control and Data Acquisition, or SCADA, system is commonly used to provide supervisory monitoring and control capabilities within industrial environments. SCADA systems can collect information from industrial devices, display operational data, generate alarms, and support authorized control activities. Their architecture may include servers, HMIs, communications infrastructure, and connections to field or control devices. Because SCADA components can provide access to important operational information and control functions, they should receive appropriate security protections. Segmentation, authentication, monitoring, controlled communication, and security policies can help reduce unauthorized access while preserving the communication required for legitimate industrial operations.<\/span><\/p>\n<h3><b>Question 25<\/b><\/h3>\n<p><b>Which Fortinet security capability can help identify known vulnerabilities or attacks targeting OT network traffic?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS caching<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Intrusion Prevention System, or IPS, functionality can inspect network traffic and use security signatures to identify known attacks and suspicious patterns. In OT environments, appropriate IPS capabilities can provide an additional security layer for industrial communications. OT-specific signatures may provide more relevant detection for supported industrial protocols and threats. DHCP, DNS caching, and NTP perform network configuration, name resolution, and time synchronization functions respectively and are not intrusion-prevention mechanisms. IPS should be carefully configured in OT environments because security inspection must consider operational requirements and potential sensitivity of industrial devices. Administrators should validate appropriate policies and signatures before applying them to critical production traffic.<\/span><\/p>\n<h3><b>Question 26<\/b><\/h3>\n<p><b>Why is accurate time synchronization important for OT security monitoring?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It increases broadcast traffic<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It helps correlate events using consistent timestamps<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It disables firewall inspection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It replaces authentication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Accurate time synchronization helps security teams correlate events occurring across multiple devices. In an OT environment, logs from firewalls, servers, controllers, monitoring systems, and other components may need to be compared during an investigation. If device clocks differ significantly, establishing the sequence of events can become more difficult. Consistent timestamps therefore improve log analysis and incident investigation. Time synchronization does not replace authentication or firewall inspection, and its purpose is not to increase broadcast traffic. Administrators should configure appropriate time sources and ensure that relevant security devices and systems maintain reliable time information so that collected logs can be analyzed effectively.<\/span><\/p>\n<h3><b>Question 27<\/b><\/h3>\n<p><b>Which network design approach separates critical industrial systems from less trusted enterprise networks?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared unrestricted LAN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open wireless access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single broadcast domain<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network segmentation separates systems into different logical or physical security zones according to their operational requirements and trust levels. In an OT environment, critical industrial systems can be separated from enterprise networks and other less trusted areas. Firewall policies can then control the traffic permitted between these zones. A shared unrestricted LAN or single broadcast domain provides less isolation and can increase unnecessary exposure. Open wireless access can also introduce additional security concerns if not properly controlled. Segmentation is therefore a foundational component of OT security architecture, helping organizations reduce unnecessary communication and establish boundaries around systems that require stronger protection.<\/span><\/p>\n<h3><b>Question 28<\/b><\/h3>\n<p><b>Which protocol is commonly associated with secure web-based management using encryption?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HTTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HTTPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Telnet<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">HTTPS uses HTTP over TLS to provide encrypted communication for web-based services. When supported by a device, secure web management can help protect administrative credentials and management traffic from interception while traversing the network. HTTP does not provide the same encryption, while traditional FTP and Telnet are commonly associated with unencrypted communication unless additional security mechanisms are used. In OT environments, secure management protocols should be used whenever supported and appropriate. Administrators should also restrict management interfaces to authorized networks or users through segmentation and firewall policies. Encryption is one layer of protection and should be combined with authentication and access control.<\/span><\/p>\n<h3><b>Question 29<\/b><\/h3>\n<p><b>What is a key purpose of an OT security zone?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To group systems with similar security or operational requirements<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To remove all firewall policies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To provide unrestricted Internet access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To disable logging<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An OT security zone groups systems that have similar security, operational, or communication requirements. Establishing zones makes it possible to apply security policies appropriate to the systems contained within each area. For example, critical control systems may require stronger restrictions than less sensitive systems. Zones can then be connected through controlled security boundaries where traffic is inspected and permitted according to defined requirements. Removing firewall policies or providing unrestricted Internet access would weaken security boundaries, while disabling logging would reduce visibility. Proper zoning helps organizations organize their OT architecture and establish clearer controls over communication between industrial systems and other network environments.<\/span><\/p>\n<h3><b>Question 30<\/b><\/h3>\n<p><b>Which FortiGate function can restrict traffic based on source and destination addresses and services?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firewall policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiAnalyzer report<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device inventory<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS cache<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A FortiGate firewall policy can control traffic using parameters such as source addresses, destination addresses, services, interfaces, and other configured criteria. This makes firewall policies a fundamental component of OT segmentation and access control. Administrators can define which systems are permitted to communicate and which services or protocols are allowed across a security boundary. FortiAnalyzer reports provide analysis and reporting rather than directly enforcing traffic decisions. Device inventory provides visibility, while DNS caching supports name resolution. In OT environments, policies should be based on documented communication requirements and designed to allow necessary operational traffic while restricting unnecessary or unauthorized connections.<\/span><\/p>\n<h3><b>Question 31<\/b><\/h3>\n<p><b>Which type of system is commonly used by engineers to configure or maintain PLC programs?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Engineering workstation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mail server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Proxy cache<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An engineering workstation is commonly used by authorized personnel to configure, program, troubleshoot, and maintain industrial control systems such as PLCs. Because these workstations can provide privileged access to critical OT devices, they are important security assets. Unauthorized access to an engineering workstation could potentially allow changes to industrial configurations or programs. Security controls such as segmentation, authentication, access restrictions, monitoring, and controlled remote access can help protect these systems. DNS servers, mail servers, and proxy caches serve different network functions and generally do not provide the specialized engineering capabilities required to manage PLC programs.<\/span><\/p>\n<h3><b>Question 32<\/b><\/h3>\n<p><b>Which security measure can help prevent unauthorized remote access to critical OT management interfaces?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Restricting access through firewall policies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Enabling unrestricted Internet access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Sharing administrator credentials<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabling authentication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Firewall policies can restrict remote access to OT management interfaces by controlling which source networks, users, destinations, and services are permitted to communicate. This helps ensure that management interfaces are accessible only through authorized paths. Unrestricted Internet access increases exposure, while sharing administrator credentials reduces accountability and makes unauthorized activity more difficult to trace. Disabling authentication removes an important security control. Remote access to OT systems should generally be tightly controlled and supported by strong authentication, authorization, segmentation, logging, and monitoring. Administrators should allow only the specific access required for legitimate operational responsibilities and avoid exposing sensitive management interfaces unnecessarily.<\/span><\/p>\n<h3><b>Question 33<\/b><\/h3>\n<p><b>Which FortiAnalyzer feature can help administrators visualize security information through dashboards?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dashboard views<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">PLC programming<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN cabling<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Motor configuration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiAnalyzer provides dashboard capabilities that can present collected security information in a more accessible format. Dashboards can help administrators review activity, security events, traffic information, and other available data without manually examining every individual log entry. This can improve situational awareness and help identify information that requires additional investigation. PLC programming, VLAN cabling, and motor configuration are operational or physical tasks and are not FortiAnalyzer functions. In an OT environment, centralized dashboards can support security monitoring by giving administrators a consolidated view of activity across relevant Fortinet devices and helping them identify unusual events or trends.<\/span><\/p>\n<h3><b>Question 34<\/b><\/h3>\n<p><b>What is a major security concern when an OT device uses outdated software that can no longer be easily patched?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increased exposure to known vulnerabilities<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Automatic improvement in security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reduced need for monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Elimination of network attacks<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Outdated software may contain known vulnerabilities that attackers can potentially exploit. In OT environments, patching can be difficult because industrial systems may require specific maintenance windows, vendor approval, compatibility testing, or continuous availability. When direct patching cannot be performed immediately, organizations can use compensating controls such as network segmentation, access restrictions, monitoring, IPS protections, and virtual patching where appropriate. Older software does not automatically become safer, and it does not eliminate the need for security monitoring. Administrators should document vulnerable assets, assess their operational importance, apply available mitigations, and plan appropriate remediation when safe and practical.<\/span><\/p>\n<h3><b>Question 35<\/b><\/h3>\n<p><b>Which approach can help protect an OT network from unnecessary Internet exposure?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Restricting outbound and inbound connections through security policies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Allowing all Internet traffic<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Removing network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabling firewall inspection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Restricting inbound and outbound connections through appropriate security policies can reduce unnecessary Internet exposure for OT environments. Industrial systems generally require only specific communication paths and services, so unrestricted Internet connectivity can create additional security risks. Firewall policies can limit traffic according to documented requirements, while segmentation can separate critical systems from networks with greater external exposure. Allowing all Internet traffic or disabling firewall inspection weakens security controls. Removing segmentation also reduces isolation between systems. Administrators should carefully document legitimate external communication requirements and create restrictive policies that allow necessary services while blocking unnecessary connections to and from sensitive OT networks.<\/span><\/p>\n<h3><b>Question 36<\/b><\/h3>\n<p><b>Which technology is commonly used to collect and transport log messages from network devices to a centralized system?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Syslog<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ARP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Syslog is commonly used to transport log messages from network devices and systems to centralized logging platforms. Centralized logs can help security administrators monitor activity, investigate incidents, identify unusual events, and maintain historical records. In an OT environment, collecting logs from firewalls and other security devices can provide valuable visibility across multiple network zones. DHCP is used for network address configuration, ARP resolves local network addresses, and FTP is primarily used for file transfer. When centralized logging is implemented, administrators should also consider reliable time synchronization so that events collected from different systems can be accurately correlated during security investigations.<\/span><\/p>\n<h3><b>Question 37<\/b><\/h3>\n<p><b>Which OT security practice helps ensure that only authorized personnel can make configuration changes to industrial systems?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Access control and authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted shared accounts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous management access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open network connectivity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Authentication and access control help ensure that only authorized personnel can access management functions and make configuration changes to industrial systems. Strong identity controls can also improve accountability by associating actions with specific users or roles. Shared accounts, anonymous access, and unrestricted connectivity make it more difficult to determine who performed an action and can increase the risk of unauthorized changes. In OT environments, administrative access should be carefully restricted because configuration changes can affect system availability and industrial processes. Role-based permissions, secure authentication, network segmentation, and logging can work together to provide controlled and traceable access to critical systems.<\/span><\/p>\n<h3><b>Question 38<\/b><\/h3>\n<p><b>Which type of traffic should generally be allowed between OT zones?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Only traffic required for documented operational functions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">All available protocols<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">All Internet applications<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unknown traffic by default<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">OT communication between security zones should generally be limited to traffic that has a documented operational purpose. Industrial systems often require specific protocols and services to communicate, and allowing unnecessary traffic can increase the attack surface. Administrators should identify legitimate communication flows and create policies that permit those requirements while restricting unknown or unnecessary connections. Allowing every protocol or Internet application can expose critical systems to additional threats. Unknown traffic should not automatically receive unrestricted access. A carefully documented communication matrix can help administrators build effective firewall policies and maintain operational connectivity while reducing unnecessary exposure between sensitive OT zones.<\/span><\/p>\n<h3><b>Question 39<\/b><\/h3>\n<p><b>Which security capability can help provide additional protection when a vulnerable OT device cannot immediately be upgraded?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Virtual patching<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open management access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabled logging<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Virtual patching can provide an additional protective layer for vulnerable OT devices when immediate software remediation is difficult. Instead of changing the vulnerable device directly, network security controls can inspect traffic and attempt to block known exploitation attempts associated with identified vulnerabilities. This can be valuable when an industrial system cannot be patched immediately because of availability requirements, vendor restrictions, or maintenance constraints. Virtual patching does not eliminate the need for proper vulnerability remediation. Organizations should continue to work toward supported updates while using compensating controls where appropriate. Security teams should also monitor the protected device and review whether the applied controls remain effective.<\/span><\/p>\n<h3><b>Question 40<\/b><\/h3>\n<p><b>Which practice can improve an organization&#8217;s ability to investigate an OT security incident?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Centralized logging and monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabling all logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Sharing one administrator account<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Removing security policies<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Centralized logging and monitoring provide security teams with information needed to understand what occurred during an incident. Logs from firewalls, servers, authentication systems, and other security devices can help establish a timeline, identify affected systems, and determine which communications occurred. Disabling logs removes valuable evidence, while shared administrator accounts reduce accountability and make user activity harder to trace. Removing security policies can also increase exposure rather than improving investigation capabilities. In an OT environment, centralized monitoring should be implemented carefully to preserve operational visibility without interfering with industrial processes. Consistent timestamps and appropriate log retention further support effective incident investigation and analysis.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Fortinet NSE6_OTS_AR-7.6 Exam Dumps and Practice Test Dumps. &nbsp; Question 21 Which FortiGate capability can help administrators identify devices and operating systems communicating on an OT network? Device detection Email filtering DNS forwarding Static routing Correct Answer: 1 Explanation Device detection provides useful visibility into endpoints and devices communicating through a FortiGate. In [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20977"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=20977"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20977\/revisions"}],"predecessor-version":[{"id":20978,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20977\/revisions\/20978"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=20977"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=20977"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=20977"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}