{"id":20989,"date":"2026-09-24T09:58:50","date_gmt":"2026-09-24T09:58:50","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=20989"},"modified":"2026-09-24T09:58:50","modified_gmt":"2026-09-24T09:58:50","slug":"fortinet-nse6_ots_ar-7-6-practice-test-questions-and-exam-dumps-part8-q141-160","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/fortinet-nse6_ots_ar-7-6-practice-test-questions-and-exam-dumps-part8-q141-160\/","title":{"rendered":"Fortinet NSE6_OTS_AR-7.6 Practice Test Questions and Exam Dumps Part8 Q141-160"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/nse6-ots-ar-7-6-exam-dumps\"><b>Fortinet NSE6_OTS_AR-7.6 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 141<\/b><\/h3>\n<p><b>Which FortiGate feature can be used to restrict access to specific network services?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firewall policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiAnalyzer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiGate firewall policies can restrict access to specific network services by defining permitted services such as HTTP, HTTPS, SSH, or other protocols. In an OT environment, this allows administrators to limit communication to only the services required by industrial applications. Restricting unnecessary services reduces the available attack surface and helps enforce segmentation between different security zones. Policies can combine source and destination addresses with service definitions and additional security controls. Administrators should identify legitimate communication requirements before implementing restrictions because blocking a required industrial service could affect operations. Regular policy reviews are also important as systems and communication requirements change over time.<\/span><\/p>\n<h3><b>Question 142<\/b><\/h3>\n<p><b>What is the primary purpose of an OT asset discovery process?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identify devices and their characteristics<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increase network bandwidth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable industrial protocols<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replace firewall policies<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">OT asset discovery helps organizations identify the devices operating within their industrial environment and understand their characteristics. This may include PLCs, HMIs, engineering workstations, servers, network devices, sensors, and other specialized equipment. Information such as device type, IP address, communication behavior, and location can support security planning. Asset discovery is especially important in OT because some legacy devices may not be included in traditional IT inventories. Passive discovery methods can be useful because they observe network activity without aggressively probing sensitive equipment. Accurate asset information supports segmentation, monitoring, vulnerability management, incident response, and appropriate security policy development.<\/span><\/p>\n<h3><b>Question 143<\/b><\/h3>\n<p><b>Which authentication method provides an additional verification factor beyond a password?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Multifactor authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN tagging<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic shaping<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Multifactor authentication requires more than one type of authentication factor before access is granted. For example, a user may provide a password and then verify their identity using a security token or authentication application. This reduces reliance on passwords alone and can help protect privileged and remote access accounts. In OT environments, MFA should be implemented carefully because some legacy applications and industrial devices may not support it directly. It can often be applied at remote-access gateways or administrative entry points instead. MFA is most effective when combined with least privilege, secure network segmentation, strong account management, and monitoring of authentication events.<\/span><\/p>\n<h3><b>Question 144<\/b><\/h3>\n<p><b>Which security control can help prevent unauthorized communication from an OT zone to the Internet?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firewall policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Screen lock<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP synchronization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asset naming<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Firewall policies can restrict outbound communication from OT zones to the Internet by defining approved destinations, services, and applications. Industrial systems generally should not have unrestricted Internet access unless there is a documented operational requirement. Restricting unnecessary outbound connectivity reduces opportunities for unauthorized data transfer, malicious command-and-control communication, and exploitation of external services. Administrators can create specific policies that permit required communication while denying other traffic. Logging denied connections can provide additional visibility into attempted communication. Firewall restrictions should be tested carefully because some industrial systems may depend on specific external services for updates, licensing, monitoring, or vendor support.<\/span><\/p>\n<h3><b>Question 145<\/b><\/h3>\n<p><b>Which OT device commonly executes programmed instructions to control physical equipment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Historian<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HMI<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">PLC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firewall<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Programmable Logic Controller, or PLC, commonly executes programmed control logic used to operate industrial equipment. PLCs can process information received from sensors and produce outputs that control motors, valves, actuators, and other machinery. Because PLCs can directly affect physical processes, unauthorized access to their configurations or control logic presents an important security concern. Organizations should restrict PLC communication to authorized systems and monitor relevant network activity. Engineering access should also be carefully controlled because changes to PLC logic can affect production and potentially safety-related processes. Segmentation, authentication, secure configuration, backups, and monitoring can provide multiple layers of protection around PLCs.<\/span><\/p>\n<h3><b>Question 146<\/b><\/h3>\n<p><b>What is the main benefit of maintaining a known-good configuration baseline?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It increases Internet speed<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It provides a reference for detecting unauthorized changes<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It eliminates all vulnerabilities<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It replaces authentication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A known-good configuration baseline provides a reference against which current system configurations can be compared. In an OT environment, this can help identify unauthorized or unexpected changes to firewalls, network devices, servers, engineering workstations, and other systems. If a configuration differs from the approved baseline, administrators can investigate whether the change was intentional, accidental, or potentially malicious. Baselines should be updated when approved changes are made so that legitimate modifications do not continually generate false alerts. Maintaining backups of known-good configurations also supports recovery. Configuration baselines therefore contribute to change management, monitoring, incident response, and overall security governance.<\/span><\/p>\n<h3><b>Question 147<\/b><\/h3>\n<p><b>Which Fortinet solution is designed to provide centralized security event logging and analysis?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiAnalyzer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiAP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiSwitch<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiToken<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiAnalyzer is designed to collect, store, analyze, and report on logs from supported Fortinet security devices. In an OT environment, centralized logging can provide valuable visibility into firewall decisions, security events, administrative activity, and other network behavior. Instead of examining individual devices separately, security teams can use centralized information to investigate events and identify patterns across the environment. Historical logs can also support incident investigations and compliance requirements. FortiAP focuses on wireless access, FortiSwitch provides switching capabilities, and FortiToken supports authentication functions. Centralized log management should be combined with appropriate retention, access controls, and monitoring procedures.<\/span><\/p>\n<h3><b>Question 148<\/b><\/h3>\n<p><b>Why should unnecessary administrative services be disabled on OT devices?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To increase screen resolution<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To improve wireless coverage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To reduce the available attack surface<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To eliminate backups<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Disabling unnecessary administrative services reduces the number of network-accessible functions that attackers could potentially exploit. OT devices may contain legacy management services that are not required for normal operation. Leaving such services enabled can create additional entry points and increase the complexity of security management. Administrators should first confirm that a service is genuinely unnecessary before disabling it because some industrial systems depend on specific management functions. Secure alternatives should be used where available, and required administrative services should be restricted to trusted networks. Reducing unnecessary services is one element of hardening and should be combined with segmentation, authentication, monitoring, and regular configuration reviews.<\/span><\/p>\n<h3><b>Question 149<\/b><\/h3>\n<p><b>What does network segmentation primarily limit?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The number of employees<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The physical size of a facility<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The storage capacity of servers<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unnecessary communication between systems<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network segmentation primarily limits unnecessary communication between systems or groups of systems. In an OT environment, segmentation can separate enterprise IT, industrial DMZs, supervisory networks, control networks, and other zones. Security policies can then determine exactly which communication paths are permitted between those areas. If one system is compromised, segmentation can make it more difficult for an attacker to reach other critical systems. Segmentation does not guarantee that an attack cannot spread, but it can reduce available paths and limit the potential impact. Effective segmentation requires an understanding of legitimate communication dependencies and should be reviewed as the industrial environment changes.<\/span><\/p>\n<h3><b>Question 150<\/b><\/h3>\n<p><b>Which security practice helps maintain accountability for administrative actions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Using individual administrator accounts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Sharing one administrator password<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Allowing anonymous access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabling audit logs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Individual administrator accounts help maintain accountability because administrative actions can be associated with specific users. This allows security teams to determine who performed a configuration change, accessed a management interface, or modified a security policy. Shared administrator credentials make attribution difficult and can prevent effective investigation when something goes wrong. Individual accounts should be combined with appropriate privileges, strong authentication, and administrative logging. In OT environments, accountability is especially important because configuration changes can influence critical communication paths and industrial operations. Regularly reviewing privileged accounts can also help identify unnecessary access and ensure that former or inactive accounts are removed or disabled.<\/span><\/p>\n<h3><b>Question 151<\/b><\/h3>\n<p><b>Which technology can help detect malicious activity by inspecting network traffic against security signatures?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An Intrusion Prevention System, or IPS, inspects applicable network traffic and compares it with known attack signatures and other detection mechanisms. When suspicious traffic matches a relevant signature, the system can generate an alert or block the communication depending on the configured policy. In OT environments, IPS requires careful tuning because industrial protocols and applications may have specialized communication patterns. Security teams should understand the traffic requirements of critical systems and validate IPS configurations before applying them broadly. IPS is not a replacement for segmentation or access control. Instead, it provides an additional inspection layer that can help identify and prevent certain network-based attacks.<\/span><\/p>\n<h3><b>Question 152<\/b><\/h3>\n<p><b>What is the main purpose of an industrial firewall between two OT security zones?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increase PLC memory<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Provide email services<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Enforce controlled communication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Store historical process data<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An industrial firewall between OT security zones enforces controlled communication between systems with different security requirements. Administrators can create policies that allow only the required sources, destinations, services, and applications. This helps prevent unnecessary connectivity and reduces the potential for unauthorized movement between zones. For example, communication between a supervisory network and a control network can be restricted to documented operational requirements. Firewalls should be carefully configured because overly restrictive policies can interrupt legitimate processes, while overly permissive rules can create security gaps. Regular policy review, logging, and change management help maintain effective controls as the industrial environment evolves.<\/span><\/p>\n<h3><b>Question 153<\/b><\/h3>\n<p><b>Which protocol is commonly associated with secure remote command-line administration?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HTTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SSH<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TFTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Secure Shell, or SSH, provides encrypted remote command-line access to supported systems and network devices. Encryption helps protect administrative credentials and commands from interception during a management session. SSH is generally preferred over older protocols such as Telnet when secure remote administration is required. In an OT environment, administrative access should still be restricted to authorized users and trusted management networks. Strong authentication and logging should also be enabled where supported. SSH does not by itself secure the entire OT environment; it is one component of secure administration. Network segmentation and access-control policies should limit where and by whom SSH management connections can be initiated.<\/span><\/p>\n<h3><b>Question 154<\/b><\/h3>\n<p><b>Which activity is most useful for identifying unusual communication from an OT asset?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network traffic monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Changing the device wallpaper<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increasing storage capacity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabling firewall logs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network traffic monitoring provides visibility into how OT assets communicate with other systems. By establishing normal communication patterns, security teams can identify unusual destinations, unexpected protocols, abnormal traffic volumes, or newly observed connections. This can provide an early indication of malware activity, unauthorized access, configuration errors, or other security concerns. Passive monitoring can be particularly valuable in OT environments because it observes traffic without necessarily interacting directly with sensitive industrial devices. Monitoring should be combined with asset inventories and appropriate alerting so that security teams can understand whether unusual activity is legitimate. Regular baseline updates are also important as industrial processes and network architectures change.<\/span><\/p>\n<h3><b>Question 155<\/b><\/h3>\n<p><b>What should be used to control communication between an OT network and an industrial DMZ?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firewall policies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared passwords<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Screen locks<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Firewall policies can control communication between an OT network and an industrial DMZ by defining the specific traffic that is permitted or denied. The DMZ can host services that need carefully controlled communication with both enterprise and industrial environments. Firewall rules should specify appropriate source and destination systems, services, and applications rather than allowing broad connectivity. Logging can provide visibility into permitted and denied communication. Because OT systems may have strict operational requirements, changes should be tested and documented before deployment. Properly configured firewall policies help maintain the security boundary while still allowing legitimate data exchange and approved services to operate between the DMZ and OT network.<\/span><\/p>\n<h3><b>Question 156<\/b><\/h3>\n<p><b>Which security principle recommends removing unnecessary permissions from users and devices?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">High availability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Redundancy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Least privilege recommends giving users, applications, and devices only the permissions necessary to perform their approved functions. Removing unnecessary permissions reduces the potential impact if an account or device is compromised. In OT environments, excessive privileges could allow unauthorized users to modify configurations, access sensitive systems, or move between network zones. Administrators should review permissions periodically and adjust them when responsibilities change. Individual accounts and role-based access controls can help enforce this principle. Least privilege does not mean denying legitimate operational access; rather, it ensures that access is narrowly aligned with actual requirements. This approach strengthens security while maintaining necessary industrial functionality.<\/span><\/p>\n<h3><b>Question 157<\/b><\/h3>\n<p><b>Which control can help protect configuration backups from unauthorized modification?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted administrator permissions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure storage with access controls<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous file sharing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Configuration backups should be stored securely and protected by appropriate access controls. If attackers can modify or delete backup files, recovery may become more difficult after a security incident or device failure. Restricting access to authorized personnel helps preserve the integrity of backup data. Organizations should also consider maintaining multiple copies and periodically testing restoration procedures. In OT environments, known-good configurations can be valuable for quickly restoring firewalls and network devices after accidental or malicious changes. Backup protection should therefore include secure storage, authentication, authorization, monitoring, and appropriate retention. These measures help ensure that recovery resources remain trustworthy when they are needed.<\/span><\/p>\n<h3><b>Question 158<\/b><\/h3>\n<p><b>What is one reason to monitor failed authentication attempts on OT systems?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To identify possible unauthorized access attempts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To increase network bandwidth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To replace asset inventories<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To disable security controls<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Monitoring failed authentication attempts can help identify possible unauthorized access attempts, password attacks, misconfigured applications, or other authentication-related problems. A high number of failures from a particular source may indicate repeated attempts to obtain access to an account or service. In OT environments, authentication monitoring should be correlated with other security information because failed attempts can also result from legitimate operational issues. Administrators can establish appropriate alert thresholds and investigate unusual patterns. Strong authentication, account lockout policies where appropriate, restricted management access, and least privilege provide additional protection. Authentication logs therefore provide useful evidence for both security monitoring and troubleshooting.<\/span><\/p>\n<h3><b>Question 159<\/b><\/h3>\n<p><b>Which action best supports secure decommissioning of an obsolete OT device?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Leave all accounts active<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove or disable its network access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Publish its management interface<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Keep unnecessary firewall rules<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When an OT device is decommissioned, its network access should be removed or disabled so that it cannot become an unnecessary entry point into the environment. Related accounts, firewall rules, credentials, and monitoring configurations should also be reviewed and removed when they are no longer required. Asset inventories should be updated so security teams know that the device is no longer operational. Simply disconnecting a device without documenting the change may leave obsolete access paths elsewhere in the network. Proper decommissioning reduces the attack surface and prevents old systems, credentials, and policies from remaining active after the equipment has been removed from service.<\/span><\/p>\n<h3><b>Question 160<\/b><\/h3>\n<p><b>Which approach provides the strongest basis for securing communications between critical OT systems?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Allow all protocols by default<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use documented requirements and explicitly permit necessary traffic<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable all monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Provide unrestricted administrator access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Using documented communication requirements and explicitly permitting necessary traffic provides a strong foundation for securing communications between critical OT systems. Administrators can identify which systems need to communicate, which protocols are required, and which services should be restricted. Firewall policies can then be designed around these documented requirements using a least-privilege approach. This reduces unnecessary connectivity while maintaining essential industrial operations. Monitoring and logging can provide additional visibility into deviations from the expected communication model. The approach should be validated before deployment because incorrect restrictions can affect production. Regular reviews are also necessary to keep policies aligned with changes in equipment, applications, and operational requirements.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Fortinet NSE6_OTS_AR-7.6 Exam Dumps and Practice Test Dumps. &nbsp; Question 141 Which FortiGate feature can be used to restrict access to specific network services? NTP DHCP Firewall policy FortiAnalyzer Correct Answer: 3 Explanation FortiGate firewall policies can restrict access to specific network services by defining permitted services such as HTTP, HTTPS, SSH, or [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20989"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=20989"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20989\/revisions"}],"predecessor-version":[{"id":20990,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20989\/revisions\/20990"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=20989"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=20989"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=20989"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}