[Dec 03, 2025] Latest Questions NSE7_OTS-7.2 Guide to Prepare Free Practice Tests [Q18-Q33]

Share

[Dec 03, 2025] Latest Questions NSE7_OTS-7.2 Guide to Prepare Free Practice Tests

Reliable NSE7_OTS-7.2 Dumps Questions Available as Web-Based Practice Test Engine


Fortinet NSE7_OTS-7.2 certification exam consists of 60 multiple-choice questions, and candidates have 120 minutes to complete the exam. To pass the exam, candidates must achieve a minimum score of 70%. NSE7_OTS-7.2 exam is available in English and is administered at Pearson VUE testing centers worldwide.


Fortinet NSE7_OTS-7.2 exam covers a broad range of topics related to OT security. NSE7_OTS-7.2 exam comprises of 60 multiple-choice questions, and the candidate has 120 minutes to complete the test. NSE7_OTS-7.2 exam content includes OT security concepts, OT network design, OT security policies, OT security products, and OT security management.

 

NEW QUESTION # 18
Refer to the exhibit.

You need to configure VPN user access for supervisors at the breach and HQ sites using the same soft FortiToken. Each site has a FortiGate VPN gateway.
What must you do to achieve this objective?

  • A. You must use a third-party RADIUS OTP server.
  • B. You must register the same FortiToken on more than one FortiGate.
  • C. You must use the user self-registration server.
  • D. You must use a FortiAuthenticator.

Answer: D


NEW QUESTION # 19
Refer to the exhibit. An OT architect has implemented a Modbus TCP with a simulation server Conpot to identify and control the Modus traffic in the OT network. The FortiGate-Edge device is configured with a software switch interface ssw-01.
Based on the topology shown in the exhibit, which two statements about the successful simulation of traffic between client and server are true? (Choose two.)

  • A. Port5 is not a member of the software switch.
  • B. The FortiGate-Edge device must be in NAT mode.
  • C. The FortiGate devices is in offline IDS mode.
  • D. NAT is disabled in the FortiGate firewall policy from port3 to ssw-01.

Answer: B,D


NEW QUESTION # 20
As an OT network administrator, you are managing three FortiGate devices that each protect different levels on the Purdue model. To increase traffic visibility, you are required to implement additional security measures to detect exploits that affect PLCs.
Which security sensor must implement to detect these types of industrial exploits?

  • A. Antivirus inspection
  • B. Deep packet inspection (DPI)
  • C. Application control
  • D. Intrusion prevention system (IPS)

Answer: C


NEW QUESTION # 21
Refer to the exhibit.

An operational technology rule is created and successfully activated to monitor the Modbus protocol on FortiSIEM. However, the rule does not trigger incidents despite Modbus traffic and application logs being received correctly by FortiSIEM.
Which statement correctly describes the issue on the rule configuration?

  • A. The attributes in the Group By section must match the ones in Fitters section.
  • B. The Aggregate attribute COUNT expression is incompatible with the filters.
  • C. The SubPattern is missing the filter to match the Modbus protocol.
  • D. The first condition on the SubPattern filter must use the OR logical operator.

Answer: A


NEW QUESTION # 22
When you create a user or host profile, which three criteria can you use? (Choose three.)

  • A. Administrative group membership
  • B. Host or user attributes
  • C. Host or user group memberships
  • D. Location
  • E. An existing access control policy

Answer: B,C,D

Explanation:
Explanation
https://docs.fortinet.com/document/fortinac/9.2.0/administration-guide/15797/user-host-profiles


NEW QUESTION # 23
Refer to the exhibit. Based on the Purdue model, which three measures can be implemented in the control area zone using the Fortinet Security Fabric? (Choose three.)

  • A. FortiNAC for network access control
  • B. FortiGate for application control and IPS
  • C. FortiEDR for endpoint detection
  • D. FortiGate for SD-WAN
  • E. FortiSIEM for security incident and event management

Answer: A,B,C


NEW QUESTION # 24
As an OT network administrator, you are managing three FortiGate devices that each protect different levels on the Purdue model. To increase traffic visibility, you are required to implement additional security measures to detect exploits that affect PLCs.
Which security sensor must implement to detect these types of industrial exploits?

  • A. Deep packet inspection (DPI)
  • B. Antivirus inspection
  • C. Intrusion prevention system (IPS)
  • D. Application control

Answer: A


NEW QUESTION # 25
When you create a user or host profile, which three criteria can you use? (Choose three.)

  • A. Administrative group membership
  • B. Host or user attributes
  • C. Host or user group memberships
  • D. Location
  • E. An existing access control policy

Answer: B,C,D

Explanation:
https://docs.fortinet.com/document/fortinac/9.2.0/administration-guide/15797/user-host-profiles


NEW QUESTION # 26
Refer to the exhibit. The IPS profile is added on all of the security policies on FortiGate. For an OT network, which statement of the IPS profile is true?

  • A. The listed IPS signatures are classified as SCADAapphcat nns
  • B. All IPS signatures are overridden and must block traffic match signature patterns.
  • C. FortiGate has no IPS industrial signature database enabled.
  • D. The IPS profile inspects only traffic originating from SCADA equipment.

Answer: A


NEW QUESTION # 27
Refer to the exhibit.

Based on the topology designed by the OT architect, which two statements about implementing OT security are true? (Choose two.)

  • A. Firewall policies should be configured on FortiGate-3 and FortiGate-4 with industrial protocol sensors.
  • B. Micro-segmentation can be achieved only by replacing FortiGate-3 and FortiGate-4 with a pair of FortiSwitch devices.
  • C. IT and OT networks are separated by segmentation.
  • D. FortiGate-3 and FortiGate-4 devices must be in a transparent mode.

Answer: A,C


NEW QUESTION # 28
Refer to the exhibit and analyze the output.

Which statement about the output is true?

  • A. This is a sample of an SNMP temperature control event log.
  • B. This is a sample of a PAM event type.
  • C. This is a sample of a FortiAnalyzer system interface event log.
  • D. This is a sample of FortiGate interface statistics.

Answer: B


NEW QUESTION # 29
Refer to the exhibit.

An OT network security audit concluded that the application sensor requires changes to ensure the correct security action is committed against the overrides filters.
Which change must the OT network administrator make?

  • A. Set all application categories to apply default actions.
  • B. Remove IEC.60870.5.104 Information.Transfer from the first filter override.
  • C. Change the security action of the industrial category to monitor.
  • D. Set the priority of the C.BO.NA.1 signature override to 1.

Answer: B

Explanation:
According to the Fortinet NSE 7 - OT Security 6.4 exam guide1, the application sensor settings allow you to configure the security action for each application category andnetwork protocol override. The security action determines how the FortiGate unit handles traffic that matches the application category or network protocol override. The security action can be one of the following:
* Allow: The FortiGate unit allows the traffic without any further inspection.
* Monitor: The FortiGate unit allows the traffic and logs it for monitoring purposes.
* Block: The FortiGate unit blocks the traffic and logs it as an attack.
The priority of the network protocol override determines the order in which the FortiGate unit applies the security action to the traffic. The lower the priority number, the higher the priority. For example, a priority of
1 is higher than a priority of 10.
In the exhibit, the application sensor has the following settings:
* The industrial category has a security action of allow, which means that the FortiGate unit will not inspect or log any traffic that belongs to this category.
* The IEC.60870.5.104 Information.Transfer network protocol override has a security action of block, which means that the FortiGate unit will block and log any traffic that matches this protocol.
* The IEC.60870.5.104 Control.Functions network protocol override has a security action of monitor, which means that the FortiGate unit will allow and log any traffic that matches this protocol.
* The IEC.60870.5.104 Start/Stop network protocol override has a security action of allow, which means that the FortiGate unit will not inspect or log any traffic that matches this protocol.
* The IEC.60870.5.104 Transfer.C.BO.NA.1 network protocol override has a security action of block, which means that the FortiGate unit will block and log any traffic that matches this protocol.
The problem with these settings is that the IEC.60870.5.104 Transfer.C.BO.NA.1 network protocol override has a lower priority than the IEC.60870.5.104 Information.Transfer network protocol override. This means that if the traffic matches both protocols, the FortiGate unit will apply the security action of the higher priority override, which is block. However, the IEC.60870.5.104 Transfer.C.BO.NA.1 protocol is used to transfer binary outputs, which are essential for controlling OT devices. Therefore, blocking this protocol could have negative consequences for the OT network.
To fix this issue, the OT network administrator must set the priority of the IEC.60870.5.104 Transfer.C.BO.
NA.1 network protocol override to 1, which is higher than the priority of the IEC.60870.5.104 Information.
Transfer network protocol override. This way, the FortiGate unit will apply the security action of the lower priority override, which is allow, to the traffic that matches both protocols. This will ensure that the FortiGate unit does not block the traffic that is used to transfer binary outputs, while still blocking the traffic that is used to transfer information.
1: NSE 7 Network Security Architect - Fortinet


NEW QUESTION # 30
An OT supervisor has configured LDAP and FSSO for the authentication. The goal is that all the users be authenticated against passive authentication first and, if passive authentication is not successful, then users should be challenged with active authentication.
What should the OT supervisor do to achieve this on FortiGate?

  • A. Configure a firewall policy with LDAP users and place it on the top of list of firewall policies.
  • B. Enable two-factor authentication with FSSO.
  • C. Under config user settings configure set auth-on-demand implicit.
  • D. Configure a firewall policy with FSSO users and place it on the top of list of firewall policies.

Answer: D

Explanation:
The OT supervisor should configure a firewall policy with FSSO users and place it on the top of list of firewall policies in order to achieve the goal of authenticating users against passive authentication first and, if passive authentication is not successful, then challenging them with active authentication.


NEW QUESTION # 31
Which deployment option allows an administrator to detect intrusions without any modifications to production traffic?

  • A. Offline IPS
  • B. Inline IPS and IDS
  • C. Virtual patching
  • D. Offline IDS

Answer: D


NEW QUESTION # 32
Refer to the exhibit, which shows a non-protected OT environment.

An administrator needs to implement proper protection on the OT network.
Which three steps should an administrator take to protect the OT network? (Choose three.)

  • A. Configure firewall policies with web filter to protect the different ICS networks.
  • B. Configure firewall policies with industrial protocol sensors
  • C. Use segmentation
  • D. Deploy an edge FortiGate between the internet and an OT network as a one-arm sniffer.
  • E. Deploy a FortiGate device within each ICS network.

Answer: A,B,D


NEW QUESTION # 33
......

Correct and Up-to-date Fortinet NSE7_OTS-7.2 BrainDumps: https://examsboost.validbraindumps.com/NSE7_OTS-7.2-exam-prep.html