{"id":20981,"date":"2026-09-24T09:57:48","date_gmt":"2026-09-24T09:57:48","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=20981"},"modified":"2026-09-24T09:57:48","modified_gmt":"2026-09-24T09:57:48","slug":"fortinet-nse6_ots_ar-7-6-practice-test-questions-and-exam-dumps-part4-q61-80","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/fortinet-nse6_ots_ar-7-6-practice-test-questions-and-exam-dumps-part4-q61-80\/","title":{"rendered":"Fortinet NSE6_OTS_AR-7.6 Practice Test Questions and Exam Dumps Part4 Q61-80"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/nse6-ots-ar-7-6-exam-dumps\"><b>Fortinet NSE6_OTS_AR-7.6 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 61<\/b><\/h3>\n<p><b>Which security control can help identify unauthorized communication between OT devices?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Passive traffic monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Screen locking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Printer management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Email archiving<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Passive traffic monitoring can help administrators observe communication between OT devices without actively probing the devices. This can provide visibility into protocols, source and destination systems, and communication patterns that may be unexpected. Such visibility is useful for identifying unauthorized or unusual communication within an industrial environment. Screen locking, printer management, and email archiving do not provide network-level visibility into OT communications. Passive monitoring is particularly valuable for sensitive systems that may not tolerate aggressive scanning. Administrators can use observed traffic patterns to improve asset inventories, develop segmentation policies, investigate anomalies, and identify communications that require further security review.<\/span><\/p>\n<h3><b>Question 62<\/b><\/h3>\n<p><b>Which OT security concept requires administrators to permit only necessary network communications?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Full trust<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Universal connectivity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Least privilege is the principle of providing only the access or communication required to perform legitimate functions. In an OT network, this can be applied to users, applications, devices, and network connections. Firewall policies can restrict communication to approved addresses, services, and protocols. This reduces unnecessary exposure and limits potential attack paths if a device or account becomes compromised. Open access and universal connectivity work against this principle because they allow more communication than may be operationally necessary. Applying least privilege requires administrators to understand legitimate OT communication requirements and regularly review policies to ensure that unnecessary permissions and connections are removed.<\/span><\/p>\n<h3><b>Question 63<\/b><\/h3>\n<p><b>Which component commonly communicates directly with sensors and actuators in an industrial control environment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">PLC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiAnalyzer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Email server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web proxy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Programmable Logic Controller, or PLC, commonly communicates with sensors and actuators as part of an industrial control process. It receives input information from sensors, processes that information according to its programmed logic, and sends outputs to actuators or other equipment. This allows the PLC to control physical industrial processes. FortiAnalyzer provides logging and analysis, while email servers and web proxies perform communication and security functions unrelated to direct industrial control. Because PLCs can influence physical processes, they are important OT assets that require appropriate protection. Segmentation, authentication, monitoring, and controlled access can help reduce unauthorized interaction with PLCs.<\/span><\/p>\n<h3><b>Question 64<\/b><\/h3>\n<p><b>Which FortiGate capability is useful for detecting malicious files transferred through supported network traffic?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Antivirus<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static routing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Antivirus security profile can inspect supported traffic for malicious files and known malware patterns. This provides an additional layer of protection when file-based threats may enter or move through network environments. NTP is used for time synchronization, DHCP provides network configuration, and static routing controls packet forwarding. In an OT environment, antivirus inspection should be implemented carefully because industrial systems may have specialized requirements and may not support all types of security inspection. Administrators should determine which systems require file inspection and ensure that security profiles are applied in ways that protect the environment without interfering with legitimate operational communications or critical system availability.<\/span><\/p>\n<h3><b>Question 65<\/b><\/h3>\n<p><b>Which network architecture can provide an additional security boundary between an enterprise network and an OT network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Industrial DMZ<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open LAN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared wireless network<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted bridge<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An industrial DMZ can provide an additional security boundary between enterprise systems and operational technology networks. Services that require controlled communication between the two environments can be placed within or accessed through the DMZ according to defined security policies. This architecture can reduce direct connectivity between enterprise and critical OT systems. An open LAN, shared wireless network, or unrestricted bridge does not provide the same level of controlled separation. Firewalls and other security controls can regulate traffic across the DMZ boundaries. Proper design should consider the required communication flows, security zones, monitoring requirements, and operational dependencies of the industrial environment.<\/span><\/p>\n<h3><b>Question 66<\/b><\/h3>\n<p><b>Which technology can provide centralized visibility into logs generated by multiple Fortinet devices?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiAnalyzer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiSwitch<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiAP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiToken<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiAnalyzer provides centralized collection, storage, analysis, and reporting of logs from supported Fortinet devices. This centralized approach allows administrators to review security events and network activity across multiple devices from a common platform. It can simplify investigation by providing historical information and tools for analyzing collected data. FortiSwitch provides switching capabilities, FortiAP provides wireless access functionality, and FortiToken is associated with authentication mechanisms. Centralized logging is especially useful in OT environments because security events can occur across several network zones. Reviewing information from multiple security devices can help administrators establish timelines and identify activity that requires investigation.<\/span><\/p>\n<h3><b>Question 67<\/b><\/h3>\n<p><b>Which security practice can help prevent unauthorized users from accessing OT engineering systems?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Strong authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous login<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared passwords<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted remote access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Strong authentication helps verify the identity of users before they receive access to sensitive OT systems. Engineering workstations can provide access to PLC configurations and other important industrial resources, so unauthorized access can create significant security risks. Strong authentication can include appropriate password controls, multifactor authentication where supported, and integration with centralized identity systems. Anonymous access and shared passwords reduce accountability and increase the possibility of unauthorized use. Unrestricted remote access also increases exposure. Authentication should be combined with authorization, segmentation, logging, and least-privilege policies so that authenticated users receive only the access necessary for their legitimate engineering responsibilities.<\/span><\/p>\n<h3><b>Question 68<\/b><\/h3>\n<p><b>Which industrial protocol is commonly associated with supervisory control and data acquisition environments?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Modbus<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SMTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IMAP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HTTP proxy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Modbus is a widely deployed industrial communication protocol and is commonly encountered in SCADA and other OT environments. It can be used to exchange information between controllers, supervisory systems, and industrial devices. Because Modbus and similar industrial protocols were often designed primarily for operational communication rather than modern cybersecurity requirements, security controls may need to provide additional protection around them. Administrators should identify where industrial protocols are used and determine which communication paths are necessary. Segmentation, protocol-aware inspection, access controls, and monitoring can help protect systems that rely on Modbus while maintaining the communications required for legitimate industrial operations.<\/span><\/p>\n<h3><b>Question 69<\/b><\/h3>\n<p><b>What is one purpose of using role-based access control in an OT environment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Assign permissions according to job responsibilities<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Allow every user administrative access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permit anonymous management<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Role-based access control assigns permissions according to the responsibilities associated with a user&#8217;s role. In an OT environment, this can help ensure that operators, engineers, administrators, and other personnel receive only the access required for their duties. For example, an operator may need process monitoring capabilities without requiring full administrative privileges. Giving every user administrative access would increase the potential impact of compromised accounts or mistakes. Removing authentication or allowing anonymous management would further weaken access controls. Role-based permissions work well with least privilege, strong authentication, network segmentation, and logging to provide controlled access to critical industrial systems.<\/span><\/p>\n<h3><b>Question 70<\/b><\/h3>\n<p><b>Which FortiGate capability can help block traffic associated with known network attacks?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Intrusion Prevention System functionality can inspect network traffic and use signatures or detection rules to identify known attacks. When configured in prevention mode, IPS can take action against traffic that matches applicable security signatures. DHCP, DNS, and NTP provide network configuration, name resolution, and time synchronization functions rather than intrusion prevention. In OT environments, IPS policies should be carefully selected because industrial systems may have sensitive communication requirements. Administrators should understand the supported protocols and operational behavior before enabling protective signatures. Properly configured IPS can provide an additional layer of defense alongside segmentation, authentication, application control, monitoring, and other OT security measures.<\/span><\/p>\n<h3><b>Question 71<\/b><\/h3>\n<p><b>Which method can help administrators identify normal communication patterns in an OT network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network traffic monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabling logging<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Removing firewall policies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Blocking all traffic<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network traffic monitoring allows administrators to observe communication patterns between OT systems and establish an understanding of normal network behavior. This baseline can help identify unexpected connections, unusual protocols, new devices, or other changes that may require investigation. Disabling logging removes useful information, while removing firewall policies reduces security control. Blocking all traffic would prevent normal industrial operations and would not provide a practical baseline. Monitoring should be implemented with consideration for the operational requirements of the environment. Over time, observed traffic can help administrators refine security policies, improve segmentation, investigate anomalies, and identify communication that falls outside expected operational behavior.<\/span><\/p>\n<h3><b>Question 72<\/b><\/h3>\n<p><b>Which security measure can help limit the impact of a compromised OT workstation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared administrator credentials<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open network access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted routing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network segmentation can limit the systems and services that a compromised workstation can reach. By placing workstations and critical industrial assets into appropriate security zones, administrators can control communication between them using firewall policies and other security mechanisms. This can reduce opportunities for lateral movement after a compromise. Shared administrator credentials, open network access, and unrestricted routing can increase exposure and make unauthorized movement easier. Segmentation should be combined with authentication, endpoint security, monitoring, and appropriate access controls. The goal is to establish meaningful boundaries that restrict unnecessary communication while continuing to support legitimate operational and engineering workflows.<\/span><\/p>\n<h3><b>Question 73<\/b><\/h3>\n<p><b>Which FortiGate feature can provide visibility into supported industrial protocols?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">OT protocol inspection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP reservation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS forwarding<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static NAT only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">OT protocol inspection provides visibility into supported industrial protocols and can help security administrators understand the characteristics of communications occurring within an industrial network. This type of inspection is valuable because traditional network controls may not fully understand specialized OT protocol behavior. DHCP reservations associate addresses with devices, DNS forwarding handles name resolution, and static NAT translates addresses. Protocol-aware inspection can support threat detection, policy enforcement, and investigation of unexpected industrial communications. Administrators should validate supported protocols and inspection behavior before deploying controls broadly because industrial systems can be sensitive to network changes and security mechanisms should be aligned with operational requirements.<\/span><\/p>\n<h3><b>Question 74<\/b><\/h3>\n<p><b>Which security control can help protect administrative credentials while they are transmitted over a network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encrypted management protocols<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Plaintext Telnet<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared passwords<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Encrypted management protocols help protect administrative credentials and management information from interception while they travel across a network. Protocols such as HTTPS and SSH can provide encrypted communication when properly configured and supported by the device. Plaintext protocols can expose credentials to interception, while anonymous access and shared passwords weaken accountability and access control. In an OT environment, secure management should also be restricted to authorized networks and users. Encryption is one part of a broader security strategy that should include strong authentication, least privilege, segmentation, logging, and monitoring. Administrators should disable insecure management services where operationally and technically appropriate.<\/span><\/p>\n<h3><b>Question 75<\/b><\/h3>\n<p><b>Which activity can help determine whether an OT security policy is functioning as intended?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reviewing logs and security events<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabling monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Removing all restrictions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ignoring blocked traffic<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Reviewing logs and security events helps administrators determine whether security policies are allowing legitimate traffic and blocking activity that should be restricted. Logs can show accepted connections, denied traffic, security detections, and other events that provide insight into policy behavior. Disabling monitoring removes this visibility, while removing all restrictions would prevent meaningful security enforcement. Ignoring blocked traffic can also make it difficult to identify incorrectly configured policies or potentially malicious activity. Regular review helps administrators identify false positives, unnecessary rules, unexpected communication, and security events. Policy changes should be tested carefully in OT environments to avoid disrupting required industrial communications.<\/span><\/p>\n<h3><b>Question 76<\/b><\/h3>\n<p><b>Which approach is appropriate for managing remote access to sensitive OT systems?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Restrict access to authorized users and required resources<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Allow direct Internet access to PLCs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Share one remote administrator account<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable authentication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Remote access to sensitive OT systems should be restricted to authorized users and only the resources required for legitimate operational tasks. Security controls can include VPNs, strong authentication, role-based access, firewall policies, segmentation, session monitoring, and logging. Directly exposing PLCs or other critical devices to the Internet increases their attack surface and should generally be avoided. Shared administrator accounts reduce accountability, while disabling authentication removes an essential security control. Remote access architectures should be carefully designed and monitored because remote connections can provide powerful access to industrial systems. Organizations should also review remote access permissions regularly and remove unnecessary access.<\/span><\/p>\n<h3><b>Question 77<\/b><\/h3>\n<p><b>Which FortiAnalyzer capability can help administrators generate security reports from collected logs?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reporting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">PLC control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Industrial routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cable testing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiAnalyzer provides reporting capabilities that can organize information collected from supported Fortinet devices into useful security and operational reports. Reports can help administrators review events, identify trends, communicate security information, and support investigations. PLC control and industrial routing are operational functions outside FortiAnalyzer&#8217;s primary purpose, while cable testing is a physical network activity. Reporting can be particularly useful in OT environments where security teams need to maintain visibility across multiple devices and zones. Administrators can use available reports and configured data views to support monitoring and analysis while retaining centralized records of relevant security activity.<\/span><\/p>\n<h3><b>Question 78<\/b><\/h3>\n<p><b>Which practice can reduce the likelihood that an attacker can move from an enterprise network into critical OT systems?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Controlled communication through security boundaries<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted network bridging<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared internal credentials<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open firewall policies<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Controlled communication through security boundaries can reduce the likelihood that an attacker will move directly from an enterprise network into critical OT systems. Firewalls, DMZs, segmentation, authentication, and restrictive access policies can limit the paths available between different environments. Unrestricted bridging and open firewall policies provide fewer barriers to lateral movement. Shared credentials can further increase risk by giving attackers broader access if those credentials are compromised. Enterprise and OT networks should therefore be separated according to their security requirements, with clearly documented communication paths. Monitoring traffic between the environments can also help identify unusual activity and support incident investigation.<\/span><\/p>\n<h3><b>Question 79<\/b><\/h3>\n<p><b>Which security control can provide temporary protection when a vulnerable industrial application cannot immediately be patched?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Virtual patching<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabled inspection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Virtual patching can provide temporary or compensating protection when a vulnerable industrial application or device cannot immediately receive a software update. Network security controls can inspect relevant traffic and block exploitation attempts associated with known vulnerabilities. This is useful in OT environments where maintenance windows, vendor requirements, legacy systems, or availability concerns may delay direct patching. Virtual patching should not replace proper vulnerability remediation when an approved update becomes available. Administrators should continue tracking the vulnerability and plan appropriate maintenance. Other controls such as segmentation, access restrictions, monitoring, and IPS can provide additional layers of protection while remediation is being planned.<\/span><\/p>\n<h3><b>Question 80<\/b><\/h3>\n<p><b>Which combination provides stronger protection for critical OT assets?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Segmentation, authentication, monitoring, and threat prevention<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted internal access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">One shared administrator account<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">No logging or inspection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A combination of segmentation, authentication, monitoring, and threat prevention provides multiple layers of protection for critical OT assets. Segmentation controls communication paths, authentication verifies user identity, monitoring provides visibility, and threat-prevention technologies can help detect or block malicious activity. Using only one control can leave other attack paths insufficiently protected. Unrestricted internal access increases exposure, shared administrator accounts reduce accountability, and disabling logging or inspection removes important security visibility. OT security should therefore use a layered architecture that is designed around operational requirements. Each security control should have a defined purpose while preserving the availability and reliability required by industrial processes.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Fortinet NSE6_OTS_AR-7.6 Exam Dumps and Practice Test Dumps. &nbsp; Question 61 Which security control can help identify unauthorized communication between OT devices? Passive traffic monitoring Screen locking Printer management Email archiving Correct Answer: 1 Explanation Passive traffic monitoring can help administrators observe communication between OT devices without actively probing the devices. This can [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20981"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=20981"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20981\/revisions"}],"predecessor-version":[{"id":20982,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20981\/revisions\/20982"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=20981"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=20981"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=20981"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}