Fortinet NSE 7 - OT Security 7.2 Free Sample Questions

Create a free account to browse all 20 sample questions. The full practice test includes 210 questions. Use the simulator for timed and flashcard mode.

Try Simulator

NSE7-OTS-7-2 Sample Questions

  1. Question 1

    Q1

    A pharmaceutical manufacturing facility uses a FortiGate in transparent mode to segment its Level 1 (Basic Control) and Level 2 (Supervisory Control) networks. The primary goal is to log all DNP3 traffic for auditing without disrupting real-time operations. An OT engineer has enabled promiscuous mode on the SPAN port of the industrial switch connected to the FortiGate's monitoring interface. However, FortiAnalyzer is not receiving any DNP3 traffic logs. All other system and security event logs from the FortiGate are being received correctly. What is the most likely cause of this issue?

    Show answer & explanation

    Correct answer: C

    In a transparent mode or offline deployment where traffic is received from a SPAN/mirror port, the corresponding FortiGate interface must be configured as a one-arm sniffer. This configuration disables the forwarding of packets and allows the FortiGate to inspect the mirrored traffic for logging and threat detection without being inline. If the interface is configured as a regular network interface, it will not process the promiscuous traffic from the SPAN port correctly for logging purposes.

  2. Question 2

    Q2Multiple answers

    An OT architect is designing a security solution for a power utility's substation that uses IEC 61850 GOOSE messaging for critical real-time communication between Intelligent Electronic Devices (IEDs). Due to the protocol's non-routable, Layer 2 nature and extreme sensitivity to latency, inline security inspection is not feasible. Which Fortinet deployment strategy and feature set should be used to gain visibility and detect potential threats within this GOOSE traffic? (Select TWO).

    Show answer & explanation

    Correct answers: B, C

    Because GOOSE messaging is highly sensitive to latency and operates at Layer 2, an inline device is unsuitable. A one-arm sniffer deployment allows a FortiGate to receive a copy of the traffic from a SPAN (Switched Port Analyzer) or mirror port without introducing any latency or becoming a point of failure.

    The FortiGuard Industrial Security Service (ISS) provides the necessary IPS and application control signatures to decode and inspect specific OT protocols, including IEC 61850 GOOSE. Without this service, the FortiGate would lack the intelligence to understand and analyze the specialized traffic for threats.

  3. Question 3

    Q3

    True or False: When configuring a FortiGate for an OT environment, the Industrial Security Service (ISS) license is only required for Intrusion Prevention (IPS) and is not necessary for Application Control to identify industrial protocols like Modbus or DNP3.

    Show answer & explanation

    Correct answer: B

    The FortiGuard Industrial Security Service (ISS) provides signature updates for both IPS and Application Control specifically for OT environments. Without this license and service, the FortiGate will not have the updated definitions required to accurately identify and control many industrial applications and protocols.

  4. Question 4

    Q4

    Case Study

    A regional water treatment authority is modernizing its SCADA system, which spans multiple remote sites. The current architecture consists of a flat network where PLCs and RTUs communicate directly with a central control center over a private WAN. This design has been flagged during a security audit for its lack of segmentation and visibility, posing a significant risk of lateral threat movement.

    The authority's primary requirements are to segment the network according to the Purdue model, control access based on device identity, and gain deep visibility into the EtherNet/IP protocol used by their Rockwell Automation controllers. A key constraint is that any new solution must accommodate legacy devices that do not support 802.1X authentication. The solution must also provide a centralized inventory of all connected OT assets.

    The proposed architecture involves deploying FortiGate firewalls at each remote site and a central FortiGate at the control center. FortiSwitches will replace the unmanaged switches at the remote sites. FortiNAC will be deployed at the central data center for network access control and device profiling.

    Given this scenario, which configuration approach best meets all the stated requirements and constraints?

    Show answer & explanation

    Correct answer: C

    This is the most comprehensive solution. It uses FortiNAC for centralized asset inventory and profiling. It addresses the constraint of legacy devices by using MAB as an alternative to 802.1X. Crucially, it leverages the Security Fabric integration, allowing FortiNAC to dynamically control VLAN assignments on the FortiSwitches and push device information to the FortiGates, which can then apply granular, identity-based policies with deep inspection for the specified EtherNet/IP protocol. This achieves segmentation, access control, and protocol visibility.

  5. Question 5

    Q5

    A manufacturing plant has deployed FortiNAC to enhance visibility and control over its ICS network. The OT team observes that while FortiNAC is successfully profiling new devices like HMIs and Engineering Workstations, it is failing to correctly identify a specific model of Siemens S7-1500 PLC. The device is being classified as a generic 'Linux Device' based on its network stack. What is the most effective first step the administrator should take within FortiNAC to resolve this misclassification?

    Show answer & explanation

    Correct answer: B

    FortiNAC uses multiple methods for profiling. While basic methods like DHCP fingerprinting or TCP stack analysis might yield generic results, more advanced methods are needed for specific OT devices. Siemens PLCs use PROFINET, and the Discovery and Configuration Protocol (DCP) within it allows devices to broadcast their identity. Creating a custom profiling rule that leverages PROFINET DCP is the most reliable way for FortiNAC to query the PLC directly and obtain accurate model and vendor details for correct classification.

  6. Question 6

    Q6

    An OT administrator is configuring a security policy on a FortiGate to allow an Engineering Workstation (EWS) to program a PLC using the Modbus protocol. The goal is to allow only Modbus 'Write' commands (Function Codes 5, 6, 15, 16) and block any 'Read' commands to prevent unauthorized data exfiltration. Which Fortinet feature is required to achieve this level of granular control?

    Show answer & explanation

    Correct answer: C

    FortiGate's Application Control, when used with the Industrial Security Service, provides granular signatures for many OT protocols, including Modbus. It can differentiate between various function codes. An administrator can create a profile that explicitly allows signatures like Modbus.Write.Coil, Modbus.Write.Single.Register, etc., while blocking Modbus.Read.Coil, Modbus.Read.Holding.Register, etc. This provides the required granular control over protocol commands.

  7. Question 7

    Q7

    A security analyst in an OT SOC is investigating an alert from FortiSIEM indicating that a PLC has unexpectedly initiated an outbound connection to an external IP address. To create a rapid, automated response, the analyst wants to configure the system to immediately block the PLC's MAC address at the network edge. Which combination of Fortinet products and features is required to implement this automated quarantine action?

    Show answer & explanation

    Correct answer: C

    This scenario requires orchestration between the monitoring tool (FortiSIEM) and the access control tool (FortiNAC). FortiSIEM can be configured with a correlation rule to detect the anomalous behavior. The rule's action can be set to execute a remediation script or API call to FortiNAC. FortiNAC, as the network access control solution, has the capability to quarantine a device by its MAC address, effectively isolating it at the switch level regardless of its IP address. This provides a direct and effective quarantine mechanism.

  8. Question 8

    Q8

    An OT network is segmented using a FortiGate with multiple VLANs for different production cells. The administrator wants to ensure that if the primary FortiGate unit fails, a secondary unit takes over with minimal disruption to the SCADA operations. The industrial switches support LACP. Which FortiGate High Availability (HA) configuration is most appropriate to provide both redundancy and optimized link usage?

    Show answer & explanation

    Correct answer: D

    While Active-Passive HA provides the necessary redundancy, combining it with link aggregation (LACP/802.3ad) on the monitored interfaces provides superior physical link redundancy and potentially higher throughput. By creating an LACP bundle of physical ports on the FortiGate and connecting them to an LACP-configured switch, the HA cluster can survive a single link failure without triggering a full device failover. This is a robust design for critical OT environments where both device and link uptime are paramount.

  9. Question 9

    Q9

    When implementing a Zero Trust security model in an OT environment using Fortinet solutions, what is the primary function of FortiNAC?

    Show answer & explanation

    Correct answer: C

    In a Zero Trust model, nothing is trusted by default. The foundational step is to verify every access attempt. FortiNAC's core function is to provide network visibility by discovering and profiling every device (the 'who' and 'what'), and then enforcing access control policies (the 'where' and 'when'). This ensures that only authorized and compliant devices are granted the least-privilege access they require, which is a cornerstone of Zero Trust.

  10. Question 10

    Q10Multiple answers

    A security audit of a food processing plant revealed that unauthenticated devices can be connected to active network ports in the production area, gaining access to the control network. The plant uses a mix of modern and legacy OT devices. Which of the following Fortinet solutions and configurations should be implemented to address this finding most effectively? (Select THREE).

    Show answer & explanation

    Correct answers: A, B, C

    Managed switches like FortiSwitch are required to implement port-based security features like 802.1X and MAB, and to integrate with a NAC solution for enforcement.

    FortiNAC is the central brain for discovering, profiling, and applying access policies to devices. It is essential for managing a mixed-device environment.

    This combination addresses the mixed-device environment. Modern devices can authenticate using the more secure 802.1X, while legacy devices that do not support it can be authenticated via their MAC address using MAB, ensuring all devices are subject to an authentication check.

Register free to unlock 10 more sample questions

Create a free account to continue with the rest of the NSE7-OTS-7-2 sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 210 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon