{"id":20991,"date":"2026-09-24T10:03:41","date_gmt":"2026-09-24T10:03:41","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=20991"},"modified":"2026-09-24T10:03:41","modified_gmt":"2026-09-24T10:03:41","slug":"fortinet-nse6_ots_ar-7-6-practice-test-questions-and-exam-dumps-part9-q161-180","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/fortinet-nse6_ots_ar-7-6-practice-test-questions-and-exam-dumps-part9-q161-180\/","title":{"rendered":"Fortinet NSE6_OTS_AR-7.6 Practice Test Questions and Exam Dumps Part9 Q161-180"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/nse6-ots-ar-7-6-exam-dumps\"><b>Fortinet NSE6_OTS_AR-7.6 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 161<\/b><\/h3>\n<p><b>Which FortiGate feature can identify and control web-based applications according to configured security policies?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static Routing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application Control allows FortiGate to identify applications based on their traffic characteristics and apply policies accordingly. This can provide more granular control than relying only on IP addresses or port numbers. In an OT environment, application visibility can help administrators understand which applications are communicating across security boundaries and restrict applications that are not required. Because industrial applications may use specialized communication patterns, policies should be tested carefully before being applied to production systems. Application Control works as one layer of protection alongside segmentation, firewall policies, authentication, and monitoring. Properly configured application policies can help reduce unnecessary communication while preserving required industrial functionality.<\/span><\/p>\n<h3><b>Question 162<\/b><\/h3>\n<p><b>Which practice helps protect an OT network from unauthorized physical connections?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increasing bandwidth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabling logging<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Removing segmentation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network access control can help prevent unauthorized devices from connecting to an OT environment. Depending on the architecture, access controls may verify device identity, user authentication, or other attributes before allowing network connectivity. This can reduce the risk associated with unauthorized laptops, removable equipment, or unmanaged devices being connected to industrial networks. OT environments often contain specialized equipment, so access controls should be carefully designed to avoid disrupting legitimate devices that may have limited authentication capabilities. Maintaining an approved asset inventory also helps administrators recognize unexpected connections. Network access control should complement segmentation, monitoring, and physical security rather than being treated as the only protection mechanism.<\/span><\/p>\n<h3><b>Question 163<\/b><\/h3>\n<p><b>What is a key advantage of using individual administrator accounts?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared responsibility<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Improved accountability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reduced logging<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Individual administrator accounts improve accountability by allowing administrative actions to be associated with specific users. In a security-sensitive OT environment, this is important because configuration changes can directly affect communication between critical industrial systems. If administrators share one account, it becomes difficult to determine who performed a particular action during an investigation. Individual accounts also make it easier to apply role-based permissions and remove access when responsibilities change. Strong authentication and appropriate logging should be used alongside individual accounts. Together, these measures provide better control over privileged access and make unauthorized configuration changes easier to investigate and attribute.<\/span><\/p>\n<h3><b>Question 164<\/b><\/h3>\n<p><b>Which security mechanism can help prevent unauthorized access to a management interface from external networks?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firewall policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Screen resolution<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File compression<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A firewall policy can restrict access to management interfaces by allowing connections only from approved source networks or administrative systems. In an OT environment, management services should generally not be exposed unnecessarily to external or untrusted networks. Administrators can use dedicated management networks, VPN gateways, authentication controls, and restrictive firewall rules to establish controlled access paths. Limiting management connectivity reduces opportunities for credential attacks and exploitation of vulnerable services. Policies should specify only the required protocols and destinations rather than allowing broad access. Regular reviews are also important because old administrative rules may remain active after systems or management requirements have changed.<\/span><\/p>\n<h3><b>Question 165<\/b><\/h3>\n<p><b>Which component typically provides operators with real-time process information and controls?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HMI<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Historian<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Router<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Human-Machine Interface, or HMI, provides operators with a graphical interface for viewing process information and interacting with industrial systems. HMIs can display values such as temperatures, pressures, equipment status, alarms, and production information. Depending on the system design, authorized operators may also use HMIs to issue control commands. Because an HMI can provide access to operational functions, it should be protected through network segmentation, authentication, access control, and monitoring. An HMI is different from a historian, which primarily stores historical process information. Protecting HMI systems is important because compromise could affect both the visibility of industrial processes and authorized operator interaction with control systems.<\/span><\/p>\n<h3><b>Question 166<\/b><\/h3>\n<p><b>Which approach helps reduce the risk of exploiting known vulnerabilities in legacy OT systems?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exposing the systems directly to the Internet<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Applying compensating controls such as segmentation and IPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabling all monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Allowing unrestricted remote access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Legacy OT systems may not support modern security updates or may be difficult to patch without disrupting production. Compensating controls can therefore provide additional protection when direct remediation is not immediately possible. Network segmentation can restrict which systems communicate with the vulnerable device, while firewall policies can limit access to required services. IPS signatures may also help detect or block known exploit attempts when appropriately supported and tested. These controls do not eliminate the underlying vulnerability, but they can reduce exposure. Organizations should maintain an inventory of legacy systems and develop longer-term plans for upgrading or replacing equipment that can no longer receive adequate security support.<\/span><\/p>\n<h3><b>Question 167<\/b><\/h3>\n<p><b>What is the main purpose of logging security events on an OT firewall?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To increase CPU performance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To provide evidence and visibility into network activity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To replace network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To eliminate authentication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Firewall security logs provide visibility into network activity and create records that can be useful during security investigations. Logs can show permitted and denied connections, policy matches, authentication events, and other relevant information depending on the configuration. In OT environments, these records can help identify unauthorized access attempts, troubleshooting issues, or unusual communication patterns. Centralizing logs can make analysis easier across multiple devices. Logging does not prevent attacks by itself, but it provides important evidence that can support detection and response. Administrators should configure appropriate log levels and retention while ensuring that monitoring processes do not negatively affect the performance of critical security infrastructure.<\/span><\/p>\n<h3><b>Question 168<\/b><\/h3>\n<p><b>Which network design principle limits communication to only what is operationally required?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">High availability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Applying least privilege to network communication means allowing systems to communicate only with the destinations, services, and applications required for legitimate operations. In an OT environment, this principle can reduce unnecessary exposure between industrial zones and limit potential lateral movement. For example, a control system may need to communicate with a specific supervisory server but may not need access to unrelated enterprise systems. Firewall policies can enforce these restrictions by defining precise communication rules. Least privilege should be based on documented operational dependencies and regularly reviewed. This approach helps maintain necessary functionality while reducing the number of unnecessary communication paths available to attackers.<\/span><\/p>\n<h3><b>Question 169<\/b><\/h3>\n<p><b>Which security feature can inspect files transferred through supported network traffic for malware?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Antivirus<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Routing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiGate Antivirus security profiles can inspect supported traffic for malicious files and known malware patterns. This provides an additional layer of defense when files enter or move through monitored network paths. In OT environments, file transfers may occur through engineering workstations, remote support connections, update mechanisms, or other systems. Security inspection should be carefully evaluated because some industrial applications may use specialized file formats or communication methods. Administrators should test security profiles before enabling them broadly in production environments. Antivirus protection complements other controls such as segmentation, firewall policies, secure remote access, and monitoring rather than replacing those mechanisms.<\/span><\/p>\n<h3><b>Question 170<\/b><\/h3>\n<p><b>What should be done before enabling aggressive security inspection on critical OT traffic?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable all backups<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Test and validate the configuration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Allow unrestricted traffic<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove monitoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security inspection should be tested and validated before being enabled broadly on critical OT traffic. Industrial systems may have strict timing, availability, and protocol requirements, and unexpected inspection behavior could potentially disrupt legitimate communications. Testing allows administrators to identify compatibility issues, false positives, performance concerns, or unexpected blocking behavior before production deployment. Security teams should document the intended configuration and establish a rollback procedure. Where possible, testing should use representative systems or an approved maintenance window. Careful validation does not weaken security; it helps ensure that security controls provide the intended protection without introducing unnecessary operational risk.<\/span><\/p>\n<h3><b>Question 171<\/b><\/h3>\n<p><b>Which practice can help identify a compromised OT endpoint communicating with an unusual destination?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Screen locking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Printer configuration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File renaming<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Traffic monitoring can help identify unusual communication from OT endpoints. Industrial systems often communicate with a relatively predictable set of systems, so a connection to an unexpected destination may warrant investigation. Monitoring can identify changes in destinations, protocols, traffic volumes, or communication timing. Security teams can compare observed behavior with established baselines and asset information to determine whether activity is expected. Passive monitoring is often useful in OT because it can provide visibility without actively probing sensitive equipment. Monitoring should be combined with alerting and investigation procedures so that unusual traffic can be assessed and appropriate action taken without unnecessarily disrupting legitimate industrial operations.<\/span><\/p>\n<h3><b>Question 172<\/b><\/h3>\n<p><b>Which technology is commonly used to securely encrypt remote administrative sessions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Telnet<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SSH<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TFTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">SSH provides encrypted remote administrative sessions for systems and network devices that support it. Encryption protects commands, credentials, and other management information from being transmitted in clear text. This makes SSH preferable to older management protocols such as Telnet when secure remote administration is required. In an OT environment, SSH access should still be restricted to authorized administrators and trusted management networks. Strong authentication, appropriate permissions, and logging should also be used. SSH does not replace network segmentation or firewall controls. Instead, it provides a secure communication method within a broader administrative security architecture designed to minimize exposure of critical industrial systems.<\/span><\/p>\n<h3><b>Question 173<\/b><\/h3>\n<p><b>What is the primary purpose of an allowlist approach in an OT network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permit explicitly approved communication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Allow every unknown application<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable all firewall policies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Provide unrestricted Internet access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An allowlist approach permits only communication that has been explicitly approved. This model can be effective in OT environments because industrial communication is often predictable and based on known systems, services, and protocols. Administrators can define required communication and block traffic that does not match approved rules. Allowlisting can reduce the attack surface and limit unauthorized connections. However, accurate documentation is essential because legitimate but undocumented communication could be blocked. Organizations should test allowlist policies carefully and establish procedures for approving new communication requirements. When combined with monitoring and change management, allowlisting can provide strong control over communication between critical industrial systems.<\/span><\/p>\n<h3><b>Question 174<\/b><\/h3>\n<p><b>Which component is primarily responsible for storing historical industrial process values?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Historian<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HMI<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Router<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An industrial historian collects and stores historical process information generated by control systems and other industrial equipment. Data may include temperatures, pressures, production values, equipment states, alarms, and other operational measurements. Historians support reporting, troubleshooting, trend analysis, optimization, and operational decision-making. Because they often communicate with multiple industrial systems and may also provide information to business applications, they should be protected with appropriate access controls and segmentation. A historian is different from an HMI, which primarily provides an operator interface for viewing and interacting with current process information. Protecting historians helps preserve both operational data and the integrity of historical records.<\/span><\/p>\n<h3><b>Question 175<\/b><\/h3>\n<p><b>Which measure can help prevent a compromised workstation from accessing every OT subnet?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared credentials<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public Internet exposure<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network segmentation can restrict a workstation&#8217;s access to only the OT subnets and services required for its legitimate function. If the workstation becomes compromised, these restrictions can make it more difficult for an attacker to move laterally toward unrelated systems. Firewalls, VLANs, routing controls, and access policies can be used to enforce segmentation. The design should be based on documented communication requirements so that necessary industrial functions continue to operate. Segmentation is particularly important for engineering workstations and other systems that may interact with multiple devices. It should be supported by monitoring, authentication, endpoint security, and regular policy reviews.<\/span><\/p>\n<h3><b>Question 176<\/b><\/h3>\n<p><b>Which practice improves the ability to recover a FortiGate configuration after an unexpected failure?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Deleting configuration backups<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Maintaining and testing backups<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Sharing administrator passwords<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabling change management<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Maintaining and testing configuration backups improves the ability to recover a FortiGate device after hardware failure, accidental configuration changes, or other incidents. A backup provides a known configuration that can be restored when required. However, simply storing a backup does not guarantee successful recovery, so restoration procedures should be tested periodically. Backup files should also be protected against unauthorized access or modification. In OT environments, recovery planning is important because firewall failures can affect communication between critical network zones. Documented recovery procedures, secure backup storage, and assigned responsibilities help ensure that the organization can restore security controls efficiently when an unexpected event occurs.<\/span><\/p>\n<h3><b>Question 177<\/b><\/h3>\n<p><b>Which security control can help detect unauthorized administrative changes to FortiGate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configuration logging and monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Screen brightness<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increasing storage capacity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabling audit records<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Configuration logging and monitoring can help detect unauthorized changes to FortiGate settings. Administrative activities may include creating or modifying firewall policies, changing security profiles, or altering management settings. Recording these activities provides accountability and allows security teams to compare changes against approved change-management records. Unexpected changes can then be investigated to determine whether they were authorized, accidental, or malicious. Individual administrator accounts and appropriate privileges strengthen this process by identifying who performed each action. Configuration monitoring should be combined with secure backups so that known-good settings are available if an unauthorized change needs to be reversed.<\/span><\/p>\n<h3><b>Question 178<\/b><\/h3>\n<p><b>Why should OT systems be protected from unnecessary Internet connectivity?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It reduces exposure to external threats<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It guarantees zero vulnerabilities<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It eliminates the need for authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It replaces firewall policies<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Limiting unnecessary Internet connectivity reduces the number of external communication paths available to OT systems. Industrial devices generally require only specific communication services, and unrestricted Internet access can expose systems to threats that are not relevant to their operational purpose. Firewall policies can restrict outbound and inbound traffic to approved destinations and services. Organizations should document legitimate external dependencies before implementing restrictions so that required update, monitoring, licensing, or support services are not unintentionally interrupted. Reducing Internet exposure does not guarantee that systems are secure, but it lowers the attack surface and complements other controls such as segmentation, authentication, monitoring, and secure remote access.<\/span><\/p>\n<h3><b>Question 179<\/b><\/h3>\n<p><b>Which activity should be performed regularly to identify obsolete firewall rules?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Policy review<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Screen replacement<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Printer maintenance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password sharing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Regular firewall policy reviews help identify obsolete, duplicated, overly broad, or unnecessary rules. OT environments evolve as equipment is replaced, applications change, and network architectures are modified. Old firewall rules may continue to permit communication that is no longer required, increasing unnecessary exposure. Reviewing rules against current asset inventories and documented communication requirements can help maintain a least-privilege configuration. Changes should follow established change-management procedures because removing an apparently unused rule without understanding its dependencies could interrupt legitimate operations. Logging and policy usage information can also help administrators determine which rules are actively used and which may require further investigation before removal.<\/span><\/p>\n<h3><b>Question 180<\/b><\/h3>\n<p><b>Which security approach provides multiple independent protections for critical OT systems?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defense-in-depth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single-factor security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Flat networking<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Defense-in-depth uses multiple complementary security controls to protect critical systems. In an OT environment, these layers can include network segmentation, firewall policies, authentication, least privilege, monitoring, secure remote access, endpoint protection, backups, and incident-response procedures. The purpose is to ensure that if one control fails or is bypassed, other controls remain available to limit the impact. For example, segmentation may restrict an attacker&#8217;s movement while monitoring can detect suspicious activity. Defense-in-depth does not mean deploying every security feature without consideration. Controls should be selected according to operational requirements and validated carefully so that security improvements do not unnecessarily disrupt industrial processes.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Fortinet NSE6_OTS_AR-7.6 Exam Dumps and Practice Test Dumps. &nbsp; Question 161 Which FortiGate feature can identify and control web-based applications according to configured security policies? NTP Application Control DHCP Static Routing Correct Answer: 2 Explanation Application Control allows FortiGate to identify applications based on their traffic characteristics and apply policies accordingly. This can [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20991"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=20991"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20991\/revisions"}],"predecessor-version":[{"id":20992,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20991\/revisions\/20992"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=20991"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=20991"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=20991"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}