{"id":20983,"date":"2026-09-24T09:58:03","date_gmt":"2026-09-24T09:58:03","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=20983"},"modified":"2026-09-24T09:58:03","modified_gmt":"2026-09-24T09:58:03","slug":"fortinet-nse6_ots_ar-7-6-practice-test-questions-and-exam-dumps-part5-q81-100","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/fortinet-nse6_ots_ar-7-6-practice-test-questions-and-exam-dumps-part5-q81-100\/","title":{"rendered":"Fortinet NSE6_OTS_AR-7.6 Practice Test Questions and Exam Dumps Part5 Q81-100"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/nse6-ots-ar-7-6-exam-dumps\"><b>Fortinet NSE6_OTS_AR-7.6 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 81<\/b><\/h3>\n<p><b>Which FortiGate feature is most useful for controlling communication between different OT network zones?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN tagging<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firewall policies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS forwarding<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP synchronization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Firewall policies provide the primary mechanism for controlling traffic between different network zones on FortiGate. In an OT environment, networks are commonly separated according to their operational roles, such as enterprise, supervisory, control, and field networks. Policies can define which sources are permitted to communicate with specific destinations and services. This helps reduce unnecessary connectivity and supports segmentation principles. VLAN tagging can assist with logical separation, but it does not independently determine which traffic is permitted. DNS and NTP provide supporting network services rather than direct traffic enforcement. Properly designed firewall policies therefore help enforce communication boundaries while allowing required OT processes to continue functioning.<\/span><\/p>\n<h3><b>Question 82<\/b><\/h3>\n<p><b>Which protocol is commonly associated with industrial automation and PLC communication?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Modbus<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">POP3<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IMAP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SMTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Modbus is a widely used industrial communication protocol and is commonly encountered in PLC, SCADA, and other OT environments. It can operate over different physical and transport mechanisms, including serial communications and TCP\/IP. Industrial devices may use Modbus to exchange process data, status information, and control commands. The protocol is relatively simple and widely supported, which contributes to its continued use in industrial environments. However, traditional Modbus implementations generally lack strong built-in security mechanisms such as encryption and authentication. For this reason, organizations should protect Modbus communications through appropriate network segmentation, access controls, monitoring, and security gateways when deploying it within modern OT environments.<\/span><\/p>\n<h3><b>Question 83<\/b><\/h3>\n<p><b>What is the primary purpose of network segmentation in an OT environment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increase Internet bandwidth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Eliminate all remote access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Limit unnecessary communication between systems<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replace industrial protocols<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network segmentation separates systems into logical or physical security zones and limits communication between those zones. In OT environments, segmentation can reduce the potential impact of a compromised workstation, server, or industrial device by restricting how far an attacker can move through the network. For example, an enterprise network may be separated from an industrial control network using firewalls or security gateways. Segmentation does not necessarily eliminate remote access or replace industrial protocols. Instead, it establishes controlled communication paths and allows organizations to apply different security policies to different parts of the infrastructure. Effective segmentation is therefore an important component of defense-in-depth for industrial networks.<\/span><\/p>\n<h3><b>Question 84<\/b><\/h3>\n<p><b>Which FortiGate capability can help identify applications generating traffic in an OT network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP Server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static Routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application Control is designed to identify and control applications based on the traffic they generate. In an OT environment, this capability can provide visibility into applications communicating across security boundaries. Administrators can use application identification as part of policies to allow required applications while restricting unauthorized or unnecessary traffic. This can be particularly useful when traditional port-based controls are insufficient because applications may use shared ports or dynamically changing communication patterns. DHCP provides address assignment, static routing determines packet paths, and NTP provides time synchronization. These services are important for network operations but do not provide the same application-level identification and control functionality.<\/span><\/p>\n<h3><b>Question 85<\/b><\/h3>\n<p><b>Which security principle requires users and devices to receive only the access necessary for their tasks?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network redundancy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">High availability<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The principle of least privilege requires users, applications, and devices to receive only the permissions necessary to perform their intended functions. In OT environments, this principle can reduce the consequences of compromised accounts or devices. For example, an engineering workstation may require access to specific control systems but should not automatically have unrestricted access to every industrial asset. Similarly, service accounts should have only the permissions needed for their applications. Applying least privilege can involve firewall rules, administrative roles, authentication controls, and system permissions. It is an important defense-in-depth measure because limiting unnecessary privileges reduces opportunities for unauthorized changes, lateral movement, and misuse of compromised credentials.<\/span><\/p>\n<h3><b>Question 86<\/b><\/h3>\n<p><b>Why is asset visibility particularly important in an OT security environment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It identifies devices and communication relationships<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It automatically patches every PLC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It eliminates the need for segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It replaces all authentication mechanisms<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Asset visibility helps security teams understand which devices exist, where they are located, how they communicate, and what functions they perform. This information is especially important in OT environments because industrial networks may contain PLCs, HMIs, engineering workstations, historians, sensors, controllers, and legacy systems. Some devices may not be documented accurately or may be difficult to scan using traditional IT security tools because aggressive scanning can affect operations. Passive monitoring and specialized discovery techniques can therefore provide valuable information while reducing operational risk. Accurate asset visibility supports segmentation, incident response, vulnerability management, and policy design by giving administrators a clearer understanding of the environment.<\/span><\/p>\n<h3><b>Question 87<\/b><\/h3>\n<p><b>Which FortiGate feature can be used to inspect traffic for known malicious patterns?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Intrusion Prevention System<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS forwarding<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Intrusion Prevention System, or IPS, examines network traffic for patterns associated with known attacks and suspicious activities. In an OT environment, IPS can help identify attempts to exploit vulnerable services, deliver malicious payloads, or perform other network-based attacks. IPS signatures can recognize specific traffic patterns and generate alerts or block matching traffic depending on the configured policy. Because industrial systems can be sensitive to unexpected traffic, security teams should carefully evaluate IPS profiles and deployment modes before applying them to production OT networks. Proper testing and tuning help reduce false positives and minimize the possibility that legitimate industrial communication will be disrupted.<\/span><\/p>\n<h3><b>Question 88<\/b><\/h3>\n<p><b>What is a major security concern when legacy OT devices cannot receive modern security updates?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Excessive bandwidth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increased exposure to known vulnerabilities<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Faster system recovery<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Improved authentication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Legacy OT devices may remain operational for many years and can be difficult or impossible to patch without affecting production. When vendors no longer provide security updates, known vulnerabilities may remain present for extended periods. Attackers can potentially exploit these weaknesses if they gain network access. Compensating controls therefore become particularly important. Organizations can use network segmentation, restrictive firewall policies, access control, monitoring, and carefully controlled administrative access to reduce exposure. In some cases, virtual patching or IPS controls can provide additional protection against known attack patterns. The goal is to reduce the attack surface while maintaining the availability and reliability required by industrial operations.<\/span><\/p>\n<h3><b>Question 89<\/b><\/h3>\n<p><b>Which component commonly provides operators with a graphical interface for monitoring industrial processes?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HMI<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Router<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Proxy cache<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Human-Machine Interface, or HMI, provides operators with a graphical interface for monitoring and interacting with industrial processes. HMIs can display process values, alarms, equipment status, trends, and other operational information. Depending on the system design, an HMI may also allow authorized operators to issue commands to industrial equipment through control systems. Because HMIs can provide access to operational functions, compromising one can create significant security and safety concerns. Security controls should therefore restrict unnecessary connectivity and administrative access to HMI systems. Monitoring HMI communications can also help identify unusual behavior that may indicate unauthorized activity or attempted compromise.<\/span><\/p>\n<h3><b>Question 90<\/b><\/h3>\n<p><b>Which approach is most appropriate when applying security controls to sensitive OT systems?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Apply every security feature without testing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ignore security monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable all firewall inspection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Validate controls before production deployment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security controls should be carefully validated before being deployed on sensitive OT systems. Industrial environments often have strict availability and timing requirements, and unexpected changes in traffic handling can potentially affect production processes. Testing security policies, inspection profiles, and other controls in a representative environment can help identify compatibility problems before deployment. Organizations should also consider maintenance windows, operational requirements, and change-management procedures. This does not mean security controls should be avoided; instead, they should be implemented in a controlled and measurable manner. Validation helps confirm that the security mechanism provides the intended protection without unnecessarily disrupting legitimate industrial communication.<\/span><\/p>\n<h3><b>Question 91<\/b><\/h3>\n<p><b>Which technology can provide encrypted communication for management access to network devices?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Telnet<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SSH<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TFTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Secure Shell, or SSH, provides encrypted communication for remote administrative access to network devices and systems. It protects management sessions against many forms of eavesdropping by encrypting the transmitted information. Telnet, in contrast, generally sends management information without encryption, making it unsuitable for secure administration across untrusted networks. FTP and TFTP are file-transfer protocols rather than preferred secure management protocols. In an OT environment, secure management access is important because administrative credentials and configuration information can be highly sensitive. Organizations should restrict management interfaces to authorized administrators, use appropriate authentication controls, and limit management access to trusted network segments wherever practical.<\/span><\/p>\n<h3><b>Question 92<\/b><\/h3>\n<p><b>What is the main function of a firewall policy in FortiGate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Define permitted or denied traffic<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Assign CPU resources to PLCs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configure HMI screen layouts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replace industrial controllers<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A FortiGate firewall policy determines how traffic is handled between defined interfaces, zones, or networks. Depending on the policy configuration, traffic can be permitted, denied, logged, or subjected to additional security inspection. In an OT environment, policies can be designed to allow only the communication required between industrial systems and other authorized networks. This supports segmentation and reduces unnecessary exposure. Firewall policies can also incorporate source and destination addresses, services, users, applications, and security profiles. They do not control the internal operation of PLCs or configure HMI screens. Their primary purpose is to enforce network communication rules according to the organization&#8217;s security requirements.<\/span><\/p>\n<h3><b>Question 93<\/b><\/h3>\n<p><b>Which security measure can help prevent unauthorized devices from connecting to an OT network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increasing monitor resolution<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Changing HMI colors<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increasing storage capacity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network access control can help restrict which devices are permitted to connect to a network. Depending on the architecture, controls may evaluate device identity, authentication status, network location, or other attributes before granting access. In OT environments, controlling device connectivity can reduce the possibility that unauthorized laptops, workstations, or other equipment will interact with industrial systems. Such controls should be introduced carefully because some industrial devices may use specialized communication methods or have limited authentication capabilities. Organizations should maintain accurate asset inventories and define approved connection requirements. Network access control works best as part of a broader security strategy that also includes segmentation, monitoring, and strict administrative procedures.<\/span><\/p>\n<h3><b>Question 94<\/b><\/h3>\n<p><b>Why should OT network traffic patterns be monitored over time?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To identify unusual behavior<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To increase PLC processing speed<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To remove all network protocols<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To eliminate backups<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Monitoring traffic patterns over time helps establish an understanding of normal OT communication behavior. Industrial systems often communicate in relatively predictable ways, which means unusual connections, unexpected protocols, or abnormal traffic volumes may provide useful indicators of a security incident or configuration problem. Baseline information can help security teams distinguish expected operational activity from suspicious behavior. Monitoring should be designed carefully so that it does not interfere with sensitive industrial systems. Passive techniques are often useful because they can observe communications without actively probing devices. Combining traffic monitoring with asset information and alerting mechanisms can improve an organization&#8217;s ability to detect and investigate abnormal activity.<\/span><\/p>\n<h3><b>Question 95<\/b><\/h3>\n<p><b>Which FortiGate feature can provide centralized logging and analysis of security events?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiAnalyzer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiSwitch<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiAP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiToken<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiAnalyzer is designed to provide centralized collection, storage, analysis, and reporting of logs from Fortinet devices and supported security components. In an OT security architecture, centralized logging can help security teams investigate firewall events, intrusion attempts, policy violations, and other activities across multiple systems. Consolidating logs can also make it easier to correlate events and identify patterns that might not be obvious when reviewing individual devices. FortiSwitch provides switching capabilities, FortiAP focuses on wireless access, and FortiToken supports authentication functions. Centralized log analysis is especially useful in environments where security teams need historical evidence for investigation and operational monitoring.<\/span><\/p>\n<h3><b>Question 96<\/b><\/h3>\n<p><b>What is the purpose of using an allowlist for OT communications?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permit only approved communication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Allow every discovered application<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable network monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove all firewall policies<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An allowlist approach permits only explicitly approved communication while blocking or restricting traffic that does not meet defined requirements. This approach can be particularly valuable in OT environments because industrial communication patterns are often predictable and stable. Administrators can identify required systems, destinations, protocols, and services and then create policies that allow those communications. Unauthorized or unexpected traffic can subsequently be denied or investigated. An allowlist does require accurate knowledge of operational dependencies because legitimate but undocumented communication could otherwise be blocked. Proper testing and change management are therefore important. When carefully implemented, allowlisting can reduce the attack surface and limit unnecessary network connectivity.<\/span><\/p>\n<h3><b>Question 97<\/b><\/h3>\n<p><b>Which OT system commonly collects and stores historical process data for later analysis?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HMI<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Historian<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Wireless controller<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An industrial historian is designed to collect and store historical process information, such as temperatures, pressures, production measurements, equipment states, and other operational values. This information can be used for reporting, troubleshooting, process optimization, compliance, and performance analysis. Because historians can receive data from important control systems and may communicate with business applications, they should be protected appropriately. Security controls can include network segmentation, restricted access, authentication, monitoring, and controlled communication paths. Unlike an HMI, which primarily presents information to operators in real time, a historian focuses on retaining process information over longer periods for analysis and operational decision-making.<\/span><\/p>\n<h3><b>Question 98<\/b><\/h3>\n<p><b>Which practice helps reduce the risk of unauthorized changes to OT firewall configurations?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared administrator passwords<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted management access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Role-based administrative access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabling configuration logs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Role-based administrative access limits configuration privileges according to an administrator&#8217;s responsibilities. Instead of giving every administrator unrestricted control, organizations can assign permissions based on operational requirements. This supports least privilege and reduces the risk of accidental or unauthorized configuration changes. Administrative access should also be protected with strong authentication, restricted management paths, and appropriate logging. Shared administrator passwords make accountability more difficult because actions cannot easily be associated with an individual. Unrestricted management access increases exposure, while disabling configuration logs removes valuable evidence. Combining role-based access with change management and configuration monitoring provides stronger protection for critical OT security infrastructure.<\/span><\/p>\n<h3><b>Question 99<\/b><\/h3>\n<p><b>Which type of attack attempts to overwhelm a system or service with excessive traffic?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Denial-of-Service<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Credential rotation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configuration backup<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Denial-of-Service attack attempts to make a system, service, or network resource unavailable by overwhelming it with requests or otherwise exhausting its resources. In an OT environment, availability is particularly important because disruption can affect monitoring, control, production, and potentially safety-related operations. Defensive measures can include network segmentation, traffic filtering, rate controls, monitoring, and carefully designed firewall policies. Security teams should consider the operational characteristics of industrial protocols when implementing protections. Not every high-volume event is necessarily malicious, so baseline traffic information can help distinguish legitimate operational activity from abnormal behavior. Rapid detection and controlled response can help minimize the impact of availability-related attacks.<\/span><\/p>\n<h3><b>Question 100<\/b><\/h3>\n<p><b>What is an important objective when designing FortiGate policies for an industrial network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Allow unrestricted communication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove all logging<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Minimize unnecessary exposure while allowing required operations<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable network segmentation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A well-designed FortiGate policy for an industrial network should balance security requirements with operational availability. The objective is to permit the communication necessary for legitimate industrial processes while restricting unnecessary or unauthorized traffic. This can involve specific source and destination definitions, approved services, application controls, logging, and additional security inspection where appropriate. Industrial systems may have strict communication dependencies, so policies should be based on documented requirements and validated before production deployment. Restricting unnecessary exposure reduces opportunities for unauthorized access and lateral movement. At the same time, carefully designed exceptions ensure that required operational communication continues without creating unnecessarily broad access between security zones.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Fortinet NSE6_OTS_AR-7.6 Exam Dumps and Practice Test Dumps. &nbsp; Question 81 Which FortiGate feature is most useful for controlling communication between different OT network zones? VLAN tagging Firewall policies DNS forwarding NTP synchronization Correct Answer: 2 Explanation Firewall policies provide the primary mechanism for controlling traffic between different network zones on FortiGate. In [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20983"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=20983"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20983\/revisions"}],"predecessor-version":[{"id":20984,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20983\/revisions\/20984"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=20983"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=20983"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=20983"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}