NSE7_OTS-7.2 Sample Practice Exam Questions 2026 Updated Verified
Exam Study Guide Free Practice Test LAST UPDATED NSE7_OTS-7.2
NEW QUESTION # 45
As an OT administrator, it is important to understand how industrial protocols work in an OT network. Which communication method is used by the Modbus protocol?
- A. It uses OSI Layer 2 and the secondary device sends data based on request from primary device.
- B. It uses OSI Layer 2 and both the primary/secondary devices send data based on a matching token ring.
- C. It uses OSI Layer 2 and both the primary/secondary devices always send data during the communication.
- D. It uses OSI Layer 2 and the primary device sends data based on request from secondary device.
Answer: A
Explanation:
Modbus is master/slave: the master (primary) polls; a slave (secondary) replies only when requested. That fits "secondary sends data based on request from primary device."
NEW QUESTION # 46
An OT administrator has configured FSSO and local firewall authentication. A user who is part of a user group is not prompted for credentials during authentication.
What is a possible reason?
- A. Two-factor authentication is not configured with RADIUS authentication method
- B. FortiNAC determined the user by DHCP fingerprint method
- C. FortiGate determined the user by passive authentication
- D. The user was determined by Security Fabric
Answer: C
Explanation:
Fortinet Single Sign-On (FSSO) includes a method called passive authentication. This allows FortiGate to identify and authenticate a user based on their existing Windows login session without prompting the user again for credentials.
Because of this passive authentication, the user will not see a prompt for credentials when accessing resources protected by FortiGate.
This behavior is expected in FSSO deployments where FortiGate can retrieve user login information from the domain controller or through the FSSO agent.
The other options (Security Fabric, two-factor with RADIUS, FortiNAC DHCP fingerprint) are less relevant to this scenario or would not explain the lack of prompt during authentication.
NEW QUESTION # 47
Refer to the exhibit.
You are creating a new operational technology (OT) rule to monitor Modbus protocol traffic on FortiSIEM Which action must you take to ensure that all Modbus messages on the network match the rule?
- A. the Aggregate section, set the attribute value to equal to or greater than 0
- B. The condition on the SubPattern filter must use the AND logical operator
- C. In the Group By section remove all attributes that are not configured in the Filter section
- D. Add a new condition to filter Modbus traffic based on the source TCP/UDP port
Answer: D
NEW QUESTION # 48
Which type of attack posed by skilled and malicious users of security level 4 (SL 4) of IEC 62443 is designed to defend against intentional attacks?
- A. Users with low access to resources
- B. Users with access to moderate resources
- C. Users with unintentional operator error
- D. Users with substantial resources
Answer: D
NEW QUESTION # 49
You are investigating a series of incidents that occurred in the OT network over past 24 hours in FortiSIEM. Which three FortiSIEM options can you use to investigate these incidents? (Choose three.)
- A. List
- B. Overview
- C. Security
- D. Risk
- E. IPS
Answer: A,B,D
NEW QUESTION # 50
Which two statements are true when you deploy FortiGate as an offline IDS? (Choose two.)
- A. Network attacks can be detected and blocked.
- B. FortiGate acts as network sensor.
- C. FortiGate receives traffic from configured port mirroring.
- D. Network traffic goes through FortiGate.
Answer: B,D
NEW QUESTION # 51
An organization has deployed an entry-level FortiGate device in their operational technology (OT) network. The administrator is looking for a simple solution to detect and block all network intrusions in that specific part of the network without any false positive activities.
Which solution should the administrator use to achieve this goal?
- A. Enable intrusion prevention system (IPS) and use the regular signature database.
- B. Block all foreign inbound traffic.
- C. Enable the industrial signature database in the IPS global setting.
- D. Configure a local-in firewall policy.
Answer: C
Explanation:
Enabling the IPS industrial signature database focuses detection on OT/ICS protocols and known attack patterns, giving accurate blocking with minimal false positives on an entry-level FortiGate.
NEW QUESTION # 52
An OT administrator is defining an incident notification policy using FortiSIEM and would like to configure the system with a notification policy. If an incident occurs, the administrator would like to be able to intervene and block an IP address or disable a user in Active Directory from FortiSIEM.
Which step must the administrator take to achieve this task?
- A. Define a script/remediation on FortiManager and enable a notification rule on FortiSIEM.
- B. Deploy a mitigation script on Active Directory and create a notification policy on FortiSIEM.
- C. Create a notification policy and define a script/remediation on FortiSIEM.
- D. Configure a fabric connector with a notification policy on FortiSIEM to connect with FortiGate.
Answer: C
Explanation:
https://fusecommunity.fortinet.com/blogs/silviu/2022/04/12/fortisiempublishingscript
NEW QUESTION # 53
Refer to the exhibit. PLC-3 and CLIENT can send traffic to PLC-1 and PLC-2. FGT-2 has only one software switch (SSW-1) connecting both PLC-3 and CLIENT. PLC-3 and CLIENT cannot send traffic to each other.
Which two statements about the traffic between PCL-1 and PLC-2 are true? (Choose two.)
- A. Micro-segmentation on FGT-2 prevents direct device-to-device communication.
- B. Traffic must be inspected by FGT-EDGE in OT networks.
- C. FGT-2 controls intra-VLAN traffic through firewall policies.
- D. The switch on FGT-2 must be hardware to implement micro-segmentation.
Answer: A,C
Explanation:
Micro-segmentation prevents direct traffic flow between devices at the same VLAN or switch level, such as PLC-3 and CLIENT connected on FGT-2's software switch.
FGT-2 enforces this control by applying firewall policies on its interfaces to control intra-VLAN (east-west) traffic within the OT network.
The switch on FGT-2 does not need to be hardware; software switches can also enforce micro- segmentation.
Traffic inspection by FGT-EDGE is possible but local intra-VLAN traffic segmentation and control are the responsibility of FGT-2.
NEW QUESTION # 54
Refer to the exhibit. The IPS profile is added on all of the security policies on FortiGate. For an OT network, which statement of the IPS profile is true?
- A. FortiGate has no IPS industrial signature database enabled.
- B. The IPS profile inspects only traffic originating from SCADA equipment.
- C. All IPS signatures are overridden and must block traffic match signature patterns.
- D. The listed IPS signatures are classified as SCADAapphcat nns
Answer: D
NEW QUESTION # 55
What are two critical tasks the OT network auditors must perform during OT network risk assessment and management? (Choose two.)
- A. Implementing strategies to automatically bring PLCs offline
- B. Evaluating what can go wrong before it happens
- C. Planning a threat hunting strategy
- D. Creating disaster recovery plans to switch operations to a backup plant
Answer: C,D
NEW QUESTION # 56
Refer to the exhibit.
You are creating a new operational technology (OT) rule to monitor Modbus protocol traffic on FortiSIEM Which action must you take to ensure that all Modbus messages on the network match the rule?
- A. the Aggregate section, set the attribute value to equal to or greater than 0
- B. In the Group By section remove all attributes that are not configured in the Filter section
- C. Add a new condition to filter Modbus traffic based on the source TCP/UDP port
- D. The condition on the SubPattern filter must use the AND logical operator
Answer: B
NEW QUESTION # 57
Refer to the exhibit and analyze the output. Which statement about the output is true?
- A. This is a sample of a PAM event type.
- B. This is a sample of FortiGate interface statistics.
- C. This is a sample of a FortiAnalyzer system interface event log.
- D. This is a sample of an SNMP temperature control event log.
Answer: A
NEW QUESTION # 58
Refer to the exhibit.
You are assigned to implement a remote authentication server in the OT network.
Which part of the hierarchy should the authentication server be part of?
- A. Edge
- B. Access
- C. Cloud
- D. Core
Answer: A
NEW QUESTION # 59
Refer to the exhibit.
Which statement about the interfaces shown in the exhibit is true?
- A. port1-vlan10 and port2-vlan10 are part of the same broadcast domain
- B. port1, port1-vlan10, and port1-vlan1 are in different broadcast domains
- C. The VLAN ID of port1-vlan1 can be changed to the VLAN ID 10.
- D. port2, port2-vlan10, and port2-vlan1 are part of the software switch interface.
Answer: B
NEW QUESTION # 60
Which statement about the IEC 104 protocol is true?
- A. IEC 104 is IEC 101 compliant in old SCADA systems.
- B. IEC 104 protects data transmission between OT devices and services.
- C. IEC 104 uses non-TCP/IP standards.
- D. IEC 104 is used for telecontrol SCADA in electrical engineering applications.
Answer: D
NEW QUESTION # 61
Which three criteria can a FortiGate device use to look for a matching firewall policy to process traffic? (Choose three.)
- A. Highest to lowest priority defined in the firewall policy
- B. Lowest to highest policy ID number
- C. Source defined as internet services in the firewall policy
- D. Destination defined as internet services in the firewall policy
- E. Services defined in the firewall policy.
Answer: C,D,E
Explanation:
When a packet arrives, how does FortiGate find a matching policy?
Each policy has match criteria, which you can define using the following objects:
* Incoming Interface
* Outgoing Interface
* Source: IP address, user, internet services
* Destination: IP address or internet services
* Service: IP protocol and port number
* Schedule: Applies during configured times
NEW QUESTION # 62
Refer to the exhibit, which shows a non-protected OT environment.
An administrator needs to implement proper protection on the OT network.
Which three steps should an administrator take to protect the OT network? (Choose three.)
- A. Deploy an edge FortiGate between the internet and an OT network as a one-arm sniffer.
- B. Use segmentation
- C. Deploy a FortiGate device within each ICS network.
- D. Configure firewall policies with industrial protocol sensors
- E. Configure firewall policies with web filter to protect the different ICS networks.
Answer: A,D,E
NEW QUESTION # 63
Refer to the exhibits. Which statement is true about the traffic passing through to PLC-2?
- A. IEC 104 signatures are all allowed except the C.BO.NA 1 signature.
- B. The application filter overrides the default action of some IEC 104 signatures.
- C. SSL Inspection must be set to deep-inspection to correctly apply application control.
- D. IPS must be enabled to inspect application signatures.
Answer: B
NEW QUESTION # 64
A FortiGate device is newly deployed as the edge gateway of an OT network security fabric. The downstream FortiGate devices are also newly deployed as Security Fabric leafs to protect the control area zone.
With no additional essential networking devices, and to implement micro-segmentation on this OT network, what configuration must the OT network architect apply to control intra-VLAN traffic?
- A. Enable security profiles on all interfaces connected in the control area zone.
- B. Set up VPN tunnels between downstream and edge FortiGate devices.
- C. Create a software switch on each downstream FortiGate device.
- D. Enable transparent mode on the edge FortiGate device.
Answer: A
NEW QUESTION # 65
Refer to the exhibits.
Which statement about some of the generated report elements from FortiAnalyzer is true?
- A. The file types confirm the infected applications on the PLCs.
- B. This report is predefined and is not available for customization.
- C. FortiGate collects the logs and generates the report to FortiAnalyzer.
- D. The report confirms Modbus and IEC 104 are the key applications crossing the network.
Answer: D
NEW QUESTION # 66
Refer to the exhibits.
Which statement about some of the generated report elements from FortiAnalyzer is true?
- A. The file types confirm the infected applications on the PLCs.
- B. This report is predefined and is not available for customization.
- C. FortiGate collects the logs and generates the report to FortiAnalyzer.
- D. The report confirms Modbus and IEC 104 are the key applications crossing the network.
Answer: D
NEW QUESTION # 67
You are investigating a series of incidents that occurred in the OT network over past 24 hours in FortiSIEM.
Which three FortiSIEM options can you use to investigate these incidents? (Choose three.)
- A. List
- B. Overview
- C. Security
- D. Risk
- E. IPS
Answer: A,B,D
Explanation:
List:
This section allows you to view a detailed list of all logged events, including those related to the OT network incidents, providing a comprehensive overview of activity within the system.
Risk:
By analyzing the risk associated with detected incidents in the OT network, you can identify potential vulnerabilities and prioritize further investigation.
Overview:
The overview section provides a high-level summary of network activity, including alerts, trends, and potential issues, which can help you quickly pinpoint areas of concern within the OT network.
NEW QUESTION # 68
In an operation technology (OT) network. FortiAnalyzer is used to receive and process logs from responsible FortiGate devices.
Which statement about why FortiAnalyzer is receiving and processing multiple log messages from a given programmable logic controller (PLC) or remote terminal unit (RTU) is true?
- A. To track external threats and prevent them attacking the OT network.
- B. To help OT administrators troubleshoot and diagnose the OT network
- C. To determine which type of messages from the PLC or RTU causes issues in the plant.
- D. To isolate PLCs or RTUs in the event of external attacks
Answer: B
Explanation:
FortiAnalyzer is designed to collect and process logs from devices in the OT network, such as PLCs and RTUs, to provide actionable insights. By receiving and analyzing these log messages, FortiAnalyzer helps OT administrators troubleshoot and diagnose issues in the network. This includes identifying abnormal behavior, performance issues, or security threats, which are critical for maintaining the operational integrity and reliability of the OT environment.
NEW QUESTION # 69
......
The New NSE7_OTS-7.2 2026 Updated Verified Study Guides & Best Courses: https://www.prep4sureexam.com/NSE7_OTS-7.2-dumps-torrent.html
Authentic NSE7_OTS-7.2 Exam Dumps PDF - 2026 Updated: https://drive.google.com/open?id=1zgj4edncVMTJS8Sr0FTbAgnCiWP3IUlz