更新されたのは2024年10月10日認定試験NSE7_OTS-7.2問題集で練習テスト問題
更新された検証済みのNSE7_OTS-7.2問題集と解答で合格保証もしくは全額返金
質問 # 40
In a wireless network integration, how does FortiNAC obtain connecting MAC address information?
- A. Link traps
- B. End station traffic monitoring
- C. RADIUS
- D. MAC notification traps
正解:C
解説:
Explanation
FortiNAC can integrate with RADIUS servers to obtain MAC address information for wireless clients that authenticate through the RADIUS server.
質問 # 41
An OT network architect must deploy a solution to protect fuel pumps in an industrial remote network. All the fuel pumps must be closely monitored from the corporate network for any temperature fluctuations.
How can the OT network architect achieve this goal?
- A. Configure a fuel server on the remote network, and deploy a FortiSIEM with a single pattern temperature security rule on the corporate network.
- B. Configure both fuel server and FortiSIEM with a single-pattern temperature performance rule on the corporate network.
- C. Configure a fuel server on the corporate network, and deploy a FortiSIEM with a single pattern temperature performance rule on the remote network.
- D. Configure a fuel server on the remote network, and deploy a FortiSIEM with a single pattern temperature performance rule on the corporate network.
正解:D
解説:
This way, FortiSIEM can discover and monitor everything attached to the remote network and provide security visibility to the corporate network
質問 # 42
What two advantages does FortiNAC provide in the OT network? (Choose two.)
- A. It can be used for network micro-segmentation.
- B. It can be used for industrial intrusion detection and prevention.
- C. It can be used for device profiling.
- D. It can be used for IoT device detection.
正解:C、D
解説:
Explanation
Typically, in a microsegmented network, NGFWs are used in conjunction with VLANs to implement security policies and to inspect and filter network communications. Fortinet FortiSwitch and FortiGate NGFW offer an integrated approach to microsegmentation.
質問 # 43
Refer to the exhibit and analyze the output.
Which statement about the output is true?
- A. This is a sample of an SNMP temperature control event log.
- B. This is a sample of a FortiAnalyzer system interface event log.
- C. This is a sample of FortiGate interface statistics.
- D. This is a sample of a PAM event type.
正解:D
質問 # 44
You are investigating a series of incidents that occurred in the OT network over past 24 hours in FortiSIEM.
Which three FortiSIEM options can you use to investigate these incidents? (Choose three.)
- A. List
- B. Security
- C. IPS
- D. Overview
- E. Risk
正解:A、D、E
質問 # 45
Refer to the exhibit. You are navigating through FortiSIEM in an OT network. How do you view information presented in the exhibit and what does the FortiGate device security status tell you?
- A. In the PCI logging dashboard and there are one or more high-severity security incidents for the FortiGate device.
- B. In the business service dashboard and there are one or more high-severity security incidents for the FortiGate device.
- C. In the widget dashboard and there are one or more high-severity incidents for the FortiGate device.
- D. In the summary dashboard and there are one or more high-severity security incidents for the FortiGate device.
正解:D
質問 # 46
Which type of attack posed by skilled and malicious users of security level 4 (SL 4) of IEC 62443 is designed to defend against intentional attacks?
- A. Users with low access to resources
- B. Users with access to moderate resources
- C. Users with unintentional operator error
- D. Users with substantial resources
正解:C
質問 # 47
Refer to the exhibit. In the topology shown in the exhibit, both PLCs can communicate directly with each other, without going through the firewall. Which statement about the topology is true?
- A. This integration solution expands VLAN capabilities from Layer 2 to Layer 3.
- B. An administrator can create firewall policies in the switch to secure between PLCs.
- C. PLCs use IEEE802.1Q protocol to communicate each other.
- D. There is no micro-segmentation in this topology.
正解:D
質問 # 48
An OT administrator configured and ran a default application risk and control report in FortiAnalyzer to learn more about the key application crossing the network. However, the report output is empty despite the fact that some related real-time and historical logs are visible in the FortiAnalyzer.
What are two possible reasons why the report output was empty? (Choose two.)
- A. The administrator selected the wrong devices in the Devices section.
- B. The administrator selected the wrong time period for the report.
- C. The administrator selected the wrong logs to be indexed in FortiAnalyzer.
- D. The administrator selected the wrong hcache table for the report.
正解:A、B
解説:
Explanation
https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/32cb817d-a307-11eb-b70b-0050569258
質問 # 49
As an OT network administrator, you are managing three FortiGate devices that each protect different levels on the Purdue model. To increase traffic visibility, you are required to implement additional security measures to detect exploits that affect PLCs.
Which security sensor must implement to detect these types of industrial exploits?
- A. Application control
- B. Antivirus inspection
- C. Deep packet inspection (DPI)
- D. Intrusion prevention system (IPS)
正解:C
質問 # 50
Refer to the exhibit, which shows a non-protected OT environment.
An administrator needs to implement proper protection on the OT network.
Which three steps should an administrator take to protect the OT network? (Choose three.)
- A. Configure firewall policies with industrial protocol sensors
- B. Configure firewall policies with web filter to protect the different ICS networks.
- C. Deploy a FortiGate device within each ICS network.
- D. Deploy an edge FortiGate between the internet and an OT network as a one-arm sniffer.
- E. Use segmentation
正解:A、B、D
質問 # 51
An OT administrator is defining an incident notification policy using FortiSIEM and would like to configure the system with a notification policy. If an incident occurs, the administrator would like to be able to intervene and block an IP address or disable a user in Active Directory from FortiSIEM. Which step must the administrator take to achieve this task?
- A. Deploy a mitigation script on Active Directory and create a notification policy on FortiSIEM.
- B. Define a script/remediation on FortiManager and enable a notification rule on FortiSIEM.
- C. Configure a fabric connector with a notification policy on FortiSIEM to connect with FortiGate.
- D. Create a notification policy and define a script/remediation on FortiSIEM.
正解:D
解説:
https://fusecommunity.fortinet.com/blogs/silviu/2022/04/12/fortisiempublishingscript
質問 # 52
Which three common breach points can be found in a typical OT environment? (Choose three.)
- A. RTU exploits
- B. VLAN exploits
- C. Black hat
- D. Global hat
- E. Hard hat
正解:A、C、E
質問 # 53
Refer to the exhibit.
An OT administrator ran a report to identify device inventory in an OT network.
Based on the report results, which report was run?
- A. A FortiSIEM incident report
- B. A FortiAnalyzer device report
- C. A FortiSIEM analytics report
- D. A FortiSIEM CMDB report
正解:D
質問 # 54
Refer to the exhibit and analyze the output.
Which statement about the output is true?
- A. This is a sample of an SNMP temperature control event log.
- B. This is a sample of a FortiAnalyzer system interface event log.
- C. This is a sample of FortiGate interface statistics.
- D. This is a sample of a PAM event type.
正解:D
質問 # 55
An OT network consists of multiple FortiGate devices. The edge FortiGate device is deployed as the secure gateway and is only allowing remote operators to access the ICS networks on site.
Management hires a third-party company to conduct health and safety on site. The third-party company must have outbound access to external resources.
As the OT network administrator, what is the best scenario to provide external access to the third-party company while continuing to secure the ICS networks?
- A. Create VPN tunnels between downstream FortiGate devices and the edge FortiGate to protect ICS network traffic.
- B. Configure outbound security policies with limited active authentication users of the third-party company.
- C. Implement an additional firewall using an additional upstream link to the internet.
- D. Split the edge FortiGate device into multiple logical devices to allocate an independent VDOM for the third-party company.
正解:D
質問 # 56
As an OT network administrator, you are managing three FortiGate devices that each protect different levels on the Purdue model. To increase traffic visibility, you are required to implement additional security measures to detect exploits that affect PLCs.
Which security sensor must implement to detect these types of industrial exploits?
- A. Antivirus inspection
- B. Application control
- C. Intrusion prevention system (IPS)
- D. Deep packet inspection (DPI)
正解:B
質問 # 57
......
試験エンジンはNSE7_OTS-7.2試験無料お試しサンプル365日更新されます:https://jp.fast2test.com/NSE7_OTS-7.2-premium-file.html
NSE7_OTS-7.2のPDF問題とテストエンジンには74問があります:https://drive.google.com/open?id=1lwwZIIoKGE9YaYNqKGQwKNT5Btyb6oUN