{"id":20987,"date":"2026-09-24T09:58:35","date_gmt":"2026-09-24T09:58:35","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=20987"},"modified":"2026-09-24T09:58:35","modified_gmt":"2026-09-24T09:58:35","slug":"fortinet-nse6_ots_ar-7-6-practice-test-questions-and-exam-dumps-part7-q121-140","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/fortinet-nse6_ots_ar-7-6-practice-test-questions-and-exam-dumps-part7-q121-140\/","title":{"rendered":"Fortinet NSE6_OTS_AR-7.6 Practice Test Questions and Exam Dumps Part7 Q121-140"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/nse6-ots-ar-7-6-exam-dumps\"><b>Fortinet NSE6_OTS_AR-7.6 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 121<\/b><\/h3>\n<p><b>Which OT security practice helps prevent unauthorized lateral movement between network zones?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increasing storage capacity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabling time synchronization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Using network segmentation and restrictive policies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Changing device screen settings<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network segmentation combined with restrictive security policies helps prevent unauthorized lateral movement between different OT zones. If an attacker compromises one system, segmentation can prevent direct communication with other critical systems unless the required traffic is explicitly permitted. FortiGate policies can enforce these boundaries by controlling sources, destinations, services, and applications. This approach is particularly important when separating enterprise networks, industrial DMZs, supervisory systems, and control networks. Segmentation does not eliminate all threats, but it can significantly limit the paths available to an attacker. Policies should be based on documented communication requirements and reviewed regularly to ensure unnecessary access is removed.<\/span><\/p>\n<h3><b>Question 122<\/b><\/h3>\n<p><b>Which FortiGate security profile is primarily used to identify malicious files transferred through inspected traffic?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Antivirus<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic Shaping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Antivirus security profile is designed to inspect applicable network traffic for malicious files and known malware patterns. In an OT environment, antivirus inspection can provide an additional security layer when files are transferred through supported protocols and security policies. However, industrial systems may use specialized applications and protocols, so inspection should be carefully tested before being enabled broadly. Security teams should consider system performance, protocol compatibility, and operational requirements. Antivirus does not replace segmentation or access control. Instead, it complements those controls by helping detect malicious content that may enter the environment through file transfers, remote access sessions, or other inspected communication paths.<\/span><\/p>\n<h3><b>Question 123<\/b><\/h3>\n<p><b>What is the main purpose of an industrial DMZ?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Store employee personal files<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Provide a controlled boundary between IT and OT networks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replace all PLCs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Provide unrestricted access between networks<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An industrial DMZ provides a controlled intermediary network between enterprise IT systems and critical OT networks. Systems that need to exchange information across the IT and OT boundary can be placed in the DMZ, reducing the need for direct communication between the two environments. Examples can include data brokers, update services, remote access gateways, or other carefully selected services. Firewalls can control traffic entering and leaving the DMZ. This architecture supports defense-in-depth because it adds another security boundary around industrial systems. An industrial DMZ does not provide unrestricted access and should not be treated as a replacement for segmentation, authentication, monitoring, or other security controls.<\/span><\/p>\n<h3><b>Question 124<\/b><\/h3>\n<p><b>Which FortiGate feature can restrict access based on the source and destination IP addresses?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firewall policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Antivirus<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiAnalyzer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiGate firewall policies can use source and destination addresses to determine which network traffic should be permitted or denied. Administrators can define address objects representing specific hosts, subnets, or network zones and then use those objects within policies. This is particularly useful in OT environments where communication paths between systems are often well defined. Restricting communication to known sources and destinations can reduce unnecessary exposure and help enforce segmentation requirements. Additional policy criteria, such as services, applications, and security profiles, can provide more granular control. Address-based policies should be regularly reviewed because network changes may make old rules unnecessary or introduce unintended access.<\/span><\/p>\n<h3><b>Question 125<\/b><\/h3>\n<p><b>Why should security teams maintain an inventory of OT assets?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To increase Internet bandwidth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To identify and understand systems requiring protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To disable all industrial protocols<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To remove network monitoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An accurate OT asset inventory helps security teams understand which devices and systems exist within the environment and what role each one performs. Industrial environments can contain PLCs, HMIs, engineering workstations, servers, sensors, controllers, and specialized equipment. Some assets may be difficult to identify using traditional IT discovery tools, particularly legacy systems. Knowing what assets exist supports vulnerability management, segmentation, monitoring, incident response, and risk assessment. An inventory should ideally include information such as device type, location, owner, communication relationships, and criticality. Keeping this information current is important because undocumented devices can create unexpected security gaps and make incident investigation more difficult.<\/span><\/p>\n<h3><b>Question 126<\/b><\/h3>\n<p><b>Which protocol is commonly used for monitoring and managing network devices?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SMTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SNMP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">POP3<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Simple Network Management Protocol, or SNMP, is commonly used to monitor and manage network devices. It can provide information about device status, interfaces, performance, and other operational metrics. In an OT environment, SNMP may be used with network infrastructure and certain industrial devices to support monitoring and troubleshooting. Security teams should use secure versions and appropriate authentication mechanisms where supported, because older SNMP configurations may expose sensitive information or use weak security. SNMP itself does not replace firewall policies or intrusion prevention. Instead, it can provide useful operational visibility that complements other security controls and helps administrators identify network conditions that may require investigation.<\/span><\/p>\n<h3><b>Question 127<\/b><\/h3>\n<p><b>What is the purpose of using a security policy with a deny action?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To block traffic that does not meet the policy requirements<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To increase PLC memory<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To synchronize system clocks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To configure HMI graphics<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A deny action prevents traffic from passing when it matches the specified policy conditions. In an OT environment, deny policies can be used to block unauthorized communication between security zones or restrict access to services that are not required. Security teams may also log denied traffic so that unexpected communication attempts can be investigated. Policies should be arranged carefully because rule order and matching conditions determine how traffic is processed. A deny policy should be based on a clear security requirement and tested to avoid disrupting legitimate industrial communication. Properly configured deny rules contribute to a least-privilege network architecture by preventing unnecessary connectivity.<\/span><\/p>\n<h3><b>Question 128<\/b><\/h3>\n<p><b>Which method can help securely provide temporary remote vendor access to an OT environment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permanent unrestricted access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared administrator credentials<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Controlled access with authentication and limited permissions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Publicly exposing PLC interfaces<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Temporary vendor access should be tightly controlled using strong authentication, limited permissions, approved access paths, and appropriate monitoring. Instead of providing vendors with permanent unrestricted connectivity, organizations can establish access only when maintenance is required and remove or disable it afterward. Access can also be restricted to specific systems, services, and time periods. Individual accounts improve accountability because activities can be traced to specific users. Publicly exposing PLC interfaces or using shared administrator credentials creates unnecessary risk. Controlled vendor access provides a practical balance between maintenance requirements and security by ensuring that external parties receive only the access necessary for their approved task.<\/span><\/p>\n<h3><b>Question 129<\/b><\/h3>\n<p><b>What does the principle of least privilege mean for OT network access?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Users receive only the access required for their responsibilities<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Everyone receives administrator privileges<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">All network services remain open<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authentication is optional<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Least privilege means providing users, systems, applications, and devices only the access necessary to perform their authorized functions. In OT environments, this principle can reduce the consequences of compromised credentials or systems. For example, an operator may need access to an HMI application but may not require administrative privileges on the underlying operating system. Similarly, a vendor account may need access to a specific engineering workstation without access to the entire control network. Applying least privilege requires careful identification of operational requirements and regular review of permissions. Excessive privileges can increase the potential impact of compromised accounts and make lateral movement easier.<\/span><\/p>\n<h3><b>Question 130<\/b><\/h3>\n<p><b>Which capability can help identify applications rather than relying only on TCP or UDP port numbers?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static routing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application Control allows FortiGate to identify and manage applications based on traffic characteristics rather than relying solely on port numbers. This can provide more granular visibility and control when different applications use shared ports or when port-based identification is insufficient. In OT networks, application awareness can help administrators create policies that permit approved applications while restricting unnecessary or unauthorized traffic. Application Control should be implemented carefully because industrial applications may have specialized communication requirements. Administrators should understand the traffic patterns of critical systems and validate policies before production deployment. Application-based controls work particularly well when combined with network segmentation and explicit access policies.<\/span><\/p>\n<h3><b>Question 131<\/b><\/h3>\n<p><b>Which security measure can help detect unauthorized changes to PLC configurations?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configuration monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increasing bandwidth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabling logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Removing backups<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Configuration monitoring can help detect unauthorized or unexpected changes to PLC configurations. Because PLCs can directly control physical processes, unauthorized modifications may create operational or safety concerns. Monitoring can compare current settings with approved configurations and alert administrators when changes occur. Access to engineering tools should also be restricted so that only authorized personnel can modify control logic or device settings. Maintaining backups of known-good configurations can support recovery if an unauthorized change is confirmed. Monitoring should be integrated with change-management procedures so legitimate maintenance activities are documented. This combination helps distinguish approved modifications from potentially suspicious or unauthorized changes within the industrial environment.<\/span><\/p>\n<h3><b>Question 132<\/b><\/h3>\n<p><b>Which FortiGate component can provide centralized log analysis and reporting?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiAnalyzer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiToken<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiAP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiSwitch<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiAnalyzer provides centralized collection, analysis, storage, and reporting of logs from supported Fortinet devices. In an OT security environment, centralized logging can help administrators investigate firewall events, policy violations, intrusion attempts, and other security-related activity. It can also provide historical information that assists with incident investigations and compliance reporting. Centralized analysis makes it easier to correlate events from multiple security devices instead of reviewing each device separately. FortiToken is associated with authentication, FortiAP provides wireless access functionality, and FortiSwitch provides switching capabilities. Centralized log analysis should complement, rather than replace, network segmentation and other preventive security controls.<\/span><\/p>\n<h3><b>Question 133<\/b><\/h3>\n<p><b>What is a potential risk of allowing unnecessary outbound Internet access from OT systems?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increased exposure to external threats<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Improved asset inventory<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reduced attack surface<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Stronger authentication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Unnecessary outbound Internet access can increase the exposure of OT systems to external threats and may create communication paths that are difficult to monitor. Industrial systems often do not require unrestricted Internet connectivity for their normal operation. Restricting outbound access to approved destinations and services can reduce the potential for malware communication, unauthorized data transfer, or command-and-control activity. Organizations should document legitimate external dependencies before creating restrictions because some systems may require specific update or support services. Firewall policies and application controls can help enforce these requirements. Limiting unnecessary Internet connectivity is therefore one component of reducing the overall attack surface of an industrial network.<\/span><\/p>\n<h3><b>Question 134<\/b><\/h3>\n<p><b>Which technology can provide additional authentication assurance beyond a password?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Multifactor authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port mirroring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic shaping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN tagging<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Multifactor authentication requires users to provide additional verification beyond a password, such as a security token, authentication application, or biometric factor. This can reduce the risk associated with stolen or reused passwords. MFA can be particularly useful for privileged administrators and remote users who access sensitive OT resources. Its implementation should account for operational requirements because some industrial systems may not directly support modern authentication methods. In those situations, MFA can sometimes be applied to remote access gateways or administrative entry points. Multifactor authentication should complement least privilege, network segmentation, secure remote access, and monitoring rather than being treated as a standalone security solution.<\/span><\/p>\n<h3><b>Question 135<\/b><\/h3>\n<p><b>Which action can help reduce the risk of accidental firewall misconfiguration?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Allowing changes without review<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Using documented change-management procedures<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabling configuration backups<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Giving every user administrator privileges<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Documented change-management procedures reduce the risk of accidental or unauthorized firewall configuration changes. A proper process can require administrators to document the reason for a change, identify affected systems, obtain appropriate approval, test the modification, and maintain a rollback plan. This is especially important in OT environments because an incorrect firewall rule can interrupt communication between critical systems. Individual administrator accounts and configuration backups provide additional accountability and recovery options. Changes should be reviewed after implementation to confirm that the intended result was achieved. Structured change management therefore helps organizations improve security without introducing unnecessary operational disruption.<\/span><\/p>\n<h3><b>Question 136<\/b><\/h3>\n<p><b>Which network architecture commonly places Internet-facing or shared services between external and internal security boundaries?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Flat network<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Industrial DMZ<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unmanaged switch<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Direct PLC connection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An industrial DMZ can provide an intermediate security zone for services that need controlled communication between enterprise and OT environments. Instead of allowing direct connections from an external or corporate network into critical control systems, selected services can be placed in the DMZ and protected by security controls on both sides. Firewalls can restrict exactly which communication paths are allowed. This architecture reduces the direct exposure of critical OT systems and provides additional opportunities for inspection and monitoring. The DMZ should not be considered trusted simply because it is separated from the Internet. Systems placed there should still be hardened, monitored, updated appropriately, and protected with access controls.<\/span><\/p>\n<h3><b>Question 137<\/b><\/h3>\n<p><b>Which security function helps identify suspicious network behavior by comparing traffic with known attack patterns?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Intrusion Prevention System<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS caching<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An Intrusion Prevention System compares inspected network traffic against security signatures and other detection mechanisms to identify known malicious or suspicious patterns. When a match occurs, the IPS can generate an alert or take a configured prevention action. In OT environments, IPS deployment should be carefully planned because blocking legitimate industrial traffic could affect operations. Security teams should review signatures, understand critical protocols, and test policies before applying them to production networks. IPS is one layer of protection and should be combined with segmentation, access control, monitoring, and secure configuration. Proper tuning helps improve detection while reducing false positives and operational disruption.<\/span><\/p>\n<h3><b>Question 138<\/b><\/h3>\n<p><b>Why is accurate time synchronization useful during an OT security investigation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It helps correlate events across multiple systems<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It increases CPU speed<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It replaces firewall policies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It eliminates vulnerabilities<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Accurate time synchronization allows security teams to correlate events recorded by different OT systems. During an investigation, administrators may need to compare firewall logs, server events, authentication records, PLC activity, and monitoring alerts. If device clocks are significantly different, the order and timing of events can become difficult to determine. NTP and other approved time synchronization mechanisms can help maintain consistent timestamps across networked systems. Time synchronization does not prevent attacks by itself, but it improves visibility and investigation capabilities. Accurate timestamps also support troubleshooting and operational analysis because teams can more reliably reconstruct what occurred during a particular period.<\/span><\/p>\n<h3><b>Question 139<\/b><\/h3>\n<p><b>Which practice helps reduce the impact of a compromised OT workstation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Granting unrestricted network access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Removing all authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Segmenting the workstation from critical systems<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Publishing its services to the Internet<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Segmenting an OT workstation from critical systems can limit the network paths available if the workstation becomes compromised. For example, firewall policies can restrict the workstation to only the industrial systems and services it legitimately requires. This can reduce the ability of an attacker to move laterally toward PLCs, servers, or other sensitive assets. Additional protections may include endpoint security, application allowlisting, strong authentication, and monitoring. Segmentation should be based on documented communication requirements rather than simply isolating devices without understanding their dependencies. The objective is to limit unnecessary connectivity while preserving the workstation&#8217;s required operational functions.<\/span><\/p>\n<h3><b>Question 140<\/b><\/h3>\n<p><b>What is an important reason to regularly review OT firewall policies?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To identify obsolete or unnecessarily permissive rules<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To disable all security controls<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To increase monitor resolution<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To remove network documentation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Regular firewall policy reviews help identify rules that are obsolete, duplicated, overly broad, or no longer required by current operations. OT environments change over time as equipment is replaced, applications are added, and network architectures evolve. A rule that was appropriate during an earlier deployment may eventually create unnecessary access. Reviewing policies against current asset inventories and communication requirements can help maintain least-privilege connectivity. Administrators should document approved changes and test them carefully because removing a rule without understanding its dependencies could disrupt industrial operations. Regular reviews therefore support both security and operational reliability by keeping firewall configurations aligned with the current environment.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Fortinet NSE6_OTS_AR-7.6 Exam Dumps and Practice Test Dumps. &nbsp; Question 121 Which OT security practice helps prevent unauthorized lateral movement between network zones? Increasing storage capacity Disabling time synchronization Using network segmentation and restrictive policies Changing device screen settings Correct Answer: 3 Explanation Network segmentation combined with restrictive security policies helps prevent unauthorized [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20987"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=20987"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20987\/revisions"}],"predecessor-version":[{"id":20988,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20987\/revisions\/20988"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=20987"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=20987"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=20987"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}