[Q18-Q42] 検証済みのNSE7_OTS-7.2問題集と解答で合格保証で試験問題集テストエンジン [2024]

Share

検証済みのNSE7_OTS-7.2問題集と解答で合格保証で試験問題集テストエンジン [2024]

NSE7_OTS-7.2問題集と64独特な問題


Fortinet NSE7_OTS-7.2 認定試験の出題範囲:

トピック出題範囲
トピック 1
  • Monitoring and risk assessment: It covers sub-topics of risk assessment, security automation, reports generation, and implementation of logging and monitoring with FortiAnalyzer and FortiSIEM.
トピック 2
  • Asset management: Sub-topics of this topic are related to explaining OT fundamentals, explaining the OT architecture with Fortinet products, configuration of the security fabric for OT network, implementation of device detection, and finally categorizing different devices for the management of OT asset.
トピック 3
  • Network access control: It explains Industrial Ethernet protocols and Industrial Ethernet networks. The topic also describes OT Availability as well as configuring internal segmentation. Lastly, it delves into application of authentication to control access to devices.
トピック 4
  • OT network protection: The topic discusses how to implement IPS to secure OT networks and Application control in OT networks. Configuration of OT firewall and identification of industrial protocols are also discussed in this topic.


Fortinet NSE 7 -OTセキュリティ7.2認定試験は、OTセキュリティの概念と技術を深く理解する必要がある挑戦的な試験です。この試験は、現実世界のシナリオでOTセキュリティ概念を適用する能力をテストする複数選択の質問とシミュレーションで構成されています。この試験は、OT環境でのサイバー脅威を特定して軽減する能力を検証し、安全なOTネットワークを設計および実装し、OT環境でセキュリティインシデントを管理する能力を検証するように設計されています。


Fortinet NSE7_OTS-7.2認定試験は、グローバルに認識されているベンダー中立認証です。この試験は、OT環境を確保するための最新の業界標準とベストプラクティスに基づいています。認定試験は、安全なOTネットワークを設計、実装、および管理するために必要なスキルと知識を検証するように設計されています。認定試験は、サイバーの脅威に対するOT環境を確保するための専門知識を実証したいセキュリティ専門家を対象としています。

 

質問 # 18
As an OT network administrator, you are managing three FortiGate devices that each protect different levels on the Purdue model. To increase traffic visibility, you are required to implement additional security measures to detect exploits that affect PLCs.
Which security sensor must implement to detect these types of industrial exploits?

  • A. Antivirus inspection
  • B. Intrusion prevention system (IPS)
  • C. Deep packet inspection (DPI)
  • D. Application control

正解:D


質問 # 19
Refer to the exhibit.

In order for a FortiGate device to act as router on a stick, what configuration must an OT network architect implement on FortiGate to achieve inter-VLAN routing?

  • A. Set a FortiGate interface with the switch to operate as an 802.1 q trunk.
  • B. Set a software switch on FortiGate to handle inter-VLAN traffic.
  • C. Set a unique forward domain on each interface on the network.
  • D. Set FortiGate to operate in transparent mode.

正解:A


質問 # 20
What can be assigned using network access control policies?

  • A. Logical networks
  • B. FortiNAC device polling methods
  • C. Layer 3 polling intervals
  • D. Profiling rules

正解:A


質問 # 21
What triggers Layer 2 polling of infrastructure devices connected in the network?

  • A. A linkup or linkdown trap
  • B. A matched profiling rule
  • C. A failed Layer 3 poll
  • D. A matched security policy

正解:A


質問 # 22
What two advantages does FortiNAC provide in the OT network? (Choose two.)

  • A. It can be used for network micro-segmentation.
  • B. It can be used for industrial intrusion detection and prevention.
  • C. It can be used for device profiling.
  • D. It can be used for IoT device detection.

正解:C、D

解説:
Typically, in a microsegmented network, NGFWs are used in conjunction with VLANs to implement security policies and to inspect and filter network communications. Fortinet FortiSwitch and FortiGate NGFW offer an integrated approach to microsegmentation.


質問 # 23
Refer to the exhibit.

An operational technology rule is created and successfully activated to monitor the Modbus protocol on FortiSIEM. However, the rule does not trigger incidents despite Modbus traffic and application logs being received correctly by FortiSIEM.
Which statement correctly describes the issue on the rule configuration?

  • A. The SubPattern is missing the filter to match the Modbus protocol.
  • B. The Aggregate attribute COUNT expression is incompatible with the filters.
  • C. The first condition on the SubPattern filter must use the OR logical operator.
  • D. The attributes in the Group By section must match the ones in Fitters section.

正解:D


質問 # 24
An administrator wants to use FortiSoC and SOAR features on a FortiAnalyzer device to detect and block any unauthorized access to FortiGate devices in an OT network.
Which two statements about FortiSoC and SOAR features on FortiAnalyzer are true? (Choose two.)

  • A. Each playbook can include multiple triggers.
  • B. You cannot use Windows and Linux hosts security events with FortiSoC.
  • C. You can automate SOC tasks through playbooks.
  • D. You must set correct operator in event handler to trigger an event.

正解:C、D

解説:
Ref: https://docs.fortinet.com/document/fortianalyzer/7.0.0/administration-guide/268882/fortisoc


質問 # 25
Which statement is correct about processing matched rogue devices by FortiNAC?

  • A. FortiNAC matches the rogue device with only one device profiling rule.
  • B. FortiNAC disables matching rule of previously-profiled rogue devices.
  • C. FortiNAC cannot revalidate matched devices.
  • D. FortiNAC remembers the match ng rule of the rogue device

正解:A


質問 # 26
A FortiGate device is newly deployed as the edge gateway of an OT network security fabric. The downstream FortiGate devices are also newly deployed as Security Fabric leafs to protect the control area zone.
With no additional essential networking devices, and to implement micro-segmentation on this OT network, what configuration must the OT network architect apply to control intra-VLAN traffic?

  • A. Create a software switch on each downstream FortiGate device.
  • B. Enable security profiles on all interfaces connected in the control area zone.
  • C. Enable transparent mode on the edge FortiGate device.
  • D. Set up VPN tunnels between downstream and edge FortiGate devices.

正解:D


質問 # 27
Refer to the exhibit

In the topology shown in the exhibit, both PLCs can communicate directly with each other, without going through the firewall.
Which statement about the topology is true?

  • A. An administrator can create firewall policies in the switch to secure between PLCs.
  • B. PLCs use IEEE802.1Q protocol to communicate each other.
  • C. There is no micro-segmentation in this topology.
  • D. This integration solution expands VLAN capabilities from Layer 2 to Layer 3.

正解:C


質問 # 28
When you create a user or host profile, which three criteria can you use? (Choose three.)

  • A. Host or user group memberships
  • B. Host or user attributes
  • C. Administrative group membership
  • D. Location
  • E. An existing access control policy

正解:A、B、D

解説:
Explanation
https://docs.fortinet.com/document/fortinac/9.2.0/administration-guide/15797/user-host-profiles


質問 # 29
Which two statements are true when you deploy FortiGate as an offline IDS? (Choose two.)

  • A. Network attacks can be detected and blocked.
  • B. FortiGate acts as network sensor.
  • C. Network traffic goes through FortiGate.
  • D. FortiGate receives traffic from configured port mirroring.

正解:B、C


質問 # 30
Which three Fortinet products can be used for device identification in an OT industrial control system (ICS)?
(Choose three.)

  • A. FortiSIEM
  • B. FortiAnalyzer
  • C. FortiManager
  • D. FortiNAC
  • E. FortiGate

正解:A、D、E

解説:
A: FortiNAC - FortiNAC is a network access control solution that provides visibility and control over network devices. It can identify devices, enforce access policies, and automate threat response.
D: FortiSIEM - FortiSIEM is a security information and event management solution that can collect and analyze data from multiple sources, including network devices and servers. It can help identify potential security threats, as well as monitor compliance with security policies and regulations.
E: FortiAnalyzer - FortiAnalyzer is a central logging and reporting solution that collects and analyzes data from multiple sources, including FortiNAC and FortiSIEM. It can provide insights into network activity and help identify anomalies or security threats.


質問 # 31
An OT administrator is defining an incident notification policy using FortiSIEM and would like to configure the system with a notification policy. If an incident occurs, the administrator would like to be able to intervene and block an IP address or disable a user in Active Directory from FortiSIEM.
Which step must the administrator take to achieve this task?

  • A. Configure a fabric connector with a notification policy on FortiSIEM to connect with FortiGate.
  • B. Deploy a mitigation script on Active Directory and create a notification policy on FortiSIEM.
  • C. Define a script/remediation on FortiManager and enable a notification rule on FortiSIEM.
  • D. Create a notification policy and define a script/remediation on FortiSIEM.

正解:D

解説:
Explanation
https://fusecommunity.fortinet.com/blogs/silviu/2022/04/12/fortisiempublishingscript


質問 # 32
Refer to the exhibit.

PLC-3 and CLIENT can send traffic to PLC-1 and PLC-2. FGT-2 has only one software switch (SSW-1) connecting both PLC-3 and CLIENT. PLC-3 and CLIENT can send traffic to each other at the Layer 2 level.
What must the OT admin do to prevent Layer 2-level communication between PLC-3 and CLIENT?

  • A. Set a unique forward domain for each interface of the software switch.
  • B. Create a VLAN for each device and replace the current FGT-2 software switch members.
  • C. Implement policy routes on FGT-2 to control traffic between devices.
  • D. Enable explicit intra-switch policy to require firewall policies on FGT-2.

正解:A、B


質問 # 33
Refer to the exhibit.

Based on the Purdue model, which three measures can be implemented in the control area zone using the Fortinet Security Fabric? (Choose three.)

  • A. FortiGate for SD-WAN
  • B. FortiEDR for endpoint detection
  • C. FortiSIEM for security incident and event management
  • D. FortiNAC for network access control
  • E. FortiGate for application control and IPS

正解:B、D、E


質問 # 34
Which three methods of communication are used by FortiNAC to gather visibility information? (Choose three.)

  • A. ICMP
  • B. TACACS
  • C. SNMP
  • D. API
  • E. RADIUS

正解:C、D、E


質問 # 35
An OT network administrator is trying to implement active authentication.
Which two methods should the administrator use to achieve this? (Choose two.)

  • A. Two-factor authentication on FortiAuthenticator
  • B. Local authentication on FortiGate
  • C. FSSO authentication on FortiGate
  • D. Role-based authentication on FortiNAC

正解:A、B


質問 # 36
Refer to the exhibit.

PLC-3 and CLIENT can send traffic to PLC-1 and PLC-2. FGT-2 has only one software switch (SSW-1) connecting both PLC-3 and CLIENT. PLC-3 and CLIENT can send traffic to each other at the Layer 2 level.
What must the OT admin do to prevent Layer 2-level communication between PLC-3 and CLIENT?

  • A. Set a unique forward domain for each interface of the software switch.
  • B. Create a VLAN for each device and replace the current FGT-2 software switch members.
  • C. Implement policy routes on FGT-2 to control traffic between devices.
  • D. Enable explicit intra-switch policy to require firewall policies on FGT-2.

正解:A、B


質問 # 37
What two advantages does FortiNAC provide in the OT network? (Choose two.)

  • A. It can be used for network micro-segmentation.
  • B. It can be used for industrial intrusion detection and prevention.
  • C. It can be used for device profiling.
  • D. It can be used for IoT device detection.

正解:C、D

解説:
Explanation
Typically, in a microsegmented network, NGFWs are used in conjunction with VLANs to implement security policies and to inspect and filter network communications. Fortinet FortiSwitch and FortiGate NGFW offer an integrated approach to microsegmentation.


質問 # 38
Refer to the exhibit, which shows a non-protected OT environment.

An administrator needs to implement proper protection on the OT network.
Which three steps should an administrator take to protect the OT network? (Choose three.)

  • A. Deploy a FortiGate device within each ICS network.
  • B. Use segmentation
  • C. Deploy an edge FortiGate between the internet and an OT network as a one-arm sniffer.
  • D. Configure firewall policies with industrial protocol sensors
  • E. Configure firewall policies with web filter to protect the different ICS networks.

正解:C、D、E


質問 # 39
Which three criteria can a FortiGate device use to look for a matching firewall policy to process traffic?
(Choose three.)

  • A. Lowest to highest policy ID number
  • B. Source defined as internet services in the firewall policy
  • C. Destination defined as internet services in the firewall policy
  • D. Highest to lowest priority defined in the firewall policy
  • E. Services defined in the firewall policy.

正解:C、D、E

解説:
Explanation
The three criteria that a FortiGate device can use to look for a matching firewall policy to process traffic are:
A: Services defined in the firewall policy - FortiGate devices can match firewall policies based on the services defined in the policy, such as HTTP, FTP, or DNS.
D: Destination defined as internet services in the firewall policy - FortiGate devices can also match firewall policies based on the destination of the traffic, including destination IP address, interface, or internet services.
E: Highest to lowest priority defined in the firewall policy - FortiGate devices can prioritize firewall policies based on the priority defined in the policy. The device will process traffic against the policy with the highest priority first and move down the list until it finds a matching policy.


質問 # 40
An OT administrator configured and ran a default application risk and control report in FortiAnalyzer to learn more about the key application crossing the network. However, the report output is empty despite the fact that some related real-time and historical logs are visible in the FortiAnalyzer.
What are two possible reasons why the report output was empty? (Choose two.)

  • A. The administrator selected the wrong devices in the Devices section.
  • B. The administrator selected the wrong time period for the report.
  • C. The administrator selected the wrong hcache table for the report.
  • D. The administrator selected the wrong logs to be indexed in FortiAnalyzer.

正解:A、B

解説:
Explanation
https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/32cb817d-a307-11eb-b70b-0050569258


質問 # 41
Refer to the exhibit.

Given the configurations on the FortiGate, which statement is true?

  • A. FortiGate is configured with forward-domains to filter and drop non-domain controller traffic.
  • B. FortiGate is configured with forward-domains to reduce unnecessary traffic.
  • C. FortiGate is configured with forward-domains to forward only domain controller traffic.
  • D. FortiGate is configured with forward-domains to forward only company domain website traffic.

正解:B


質問 # 42
......

NSE7_OTS-7.2問題集は合格保証付き!合格させるNSE7_OTS-7.2試験:https://jp.fast2test.com/NSE7_OTS-7.2-premium-file.html

NSE7_OTS-7.2試験問題集でベスト問題集を無料で試そうNSE7_OTS-7.2試験問題:https://drive.google.com/open?id=1lwwZIIoKGE9YaYNqKGQwKNT5Btyb6oUN


弊社を連絡する

我々は12時間以内ですべてのお問い合わせを答えます。

我々の働いている時間: ( GMT 0:00-15:00 )
月曜日から土曜日まで

サポート: 現在連絡 

English Deutsch 繁体中文 한국어