Skip to content

NSE7-OTS-7-2 Fortinet NSE 7 - OT Security 7.2 Practice Questions

Prepare for NSE7-OTS-7-2 with more than an answer.

210 questions in the full set20 sample questionsUpdated Dec 7, 2025
Exam fee
$400 USD
Level
Solution Specialist
Valid for
2 years
Domains covered on the exam 4
  1. Asset Management25%
  2. Network Access Control25%
  3. OT Network Protection25%
  4. Monitoring and Risk Assessment25%
  1. 1

    A FortiGate is protecting a SCADA network that uses the DNP3 protocol. An administrator needs to configure a firewall policy that allows DNP3 traffic but blocks any attempts to use the 'Write' function code to prevent unauthorized changes to RTUs. Which security profile should be used to enforce this policy?

    Show answer details

    Correct answer: B

    FortiGate's Application Control profile, with the Industrial Security Service, provides granular control over many OT protocols, including DNP3. It contains specific signatures that can differentiate between DNP3 functions like 'Read', 'Write', 'Select', and 'Operate'. By creating a custom Application Control profile, an administrator can explicitly block the DNP3 'Write' signature while allowing other necessary functions.

  2. 2

    An OT administrator is reviewing the asset inventory in FortiNAC and notices several devices are labeled with a 'High Risk' security posture. What are TWO potential reasons for this classification? (Select TWO).

    Show answer details

    Correct answer: B, D

    FortiNAC can perform active vulnerability scans on endpoints. If it discovers CVEs or other known vulnerabilities associated with the device's OS or applications, it will elevate the device's risk score.

    FortiNAC can integrate with FortiGuard and other threat intelligence sources. If the device is detected communicating with a known command-and-control server, botnet, or other malicious host, FortiNAC will flag it as high risk due to this suspicious activity.

  3. 3

    A utility company uses FortiGates to secure its substations. To comply with NERC CIP regulations, they must demonstrate that all traffic between the substation LAN (ICS Zone) and the corporate WAN is logged. However, they are concerned about the performance impact of logging all allowed traffic. What is the recommended approach on the FortiGate to meet compliance without causing excessive performance degradation?

    Show answer details

    Correct answer: C

    To meet the compliance requirement of logging all traffic, the 'Log Allowed Traffic' option must be set to 'All Sessions' on the firewall policies governing that traffic. To mitigate the performance impact on the FortiGate itself, logs should be offloaded to a dedicated logging device like FortiAnalyzer. FortiAnalyzer is optimized for high-speed log ingestion and analysis, freeing the FortiGate to focus on its primary task of packet processing and security enforcement.

  4. 4

    What is the primary purpose of configuring virtual domains (VDOMs) on a FortiGate device deployed in a complex OT environment with multiple, distinct production lines?

    Show answer details

    Correct answer: C

    Virtual Domains (VDOMs) allow a single FortiGate to be split into multiple logical firewalls. Each VDOM has its own separate security policies, routing table, and administrative access. This is ideal for multi-tenant environments or for creating strict administrative and policy separation between different functional areas, such as distinct production lines in an OT network.

  5. 5

    An architect is designing a Security Fabric for a power utility with numerous remote substations, each containing a FortiGate. The goal is to ensure that if a threat is detected at one substation, all other substations are automatically updated to block the threat, even before FortiGuard updates are available. Which TWO Security Fabric components are essential to achieve this? (Select TWO)

    graph TD subgraph Central_SOC["Central SOC"] FAZ[FortiAnalyzer] FMG[FortiManager] end subgraph Substation_A["Substation A"] FG_A[FortiGate] end subgraph Substation_B["Substation B"] FG_B[FortiGate] end subgraph Substation_C["Substation C"] FG_C[FortiGate] end FG_A -- Logs --> FAZ FG_B -- Logs --> FAZ FG_C -- Logs --> FAZ FMG -- Policies --> FG_A FMG -- Policies --> FG_B FMG -- Policies --> FG_C

    Show answer details

    Correct answer: A, C

  6. 6

    A pharmaceutical manufacturing facility uses a FortiGate in transparent mode to segment its Level 1 (Basic Control) and Level 2 (Supervisory Control) networks. The primary goal is to log all DNP3 traffic for auditing without disrupting real-time operations. An OT engineer has enabled promiscuous mode on the SPAN port of the industrial switch connected to the FortiGate's monitoring interface. However, FortiAnalyzer is not receiving any DNP3 traffic logs. All other system and security event logs from the FortiGate are being received correctly. What is the most likely cause of this issue?

    Show answer details

    Correct answer: C

    In a transparent mode or offline deployment where traffic is received from a SPAN/mirror port, the corresponding FortiGate interface must be configured as a one-arm sniffer. This configuration disables the forwarding of packets and allows the FortiGate to inspect the mirrored traffic for logging and threat detection without being inline. If the interface is configured as a regular network interface, it will not process the promiscuous traffic from the SPAN port correctly for logging purposes.

  7. 7

    An OT architect is designing a security solution for a power utility's substation that uses IEC 61850 GOOSE messaging for critical real-time communication between Intelligent Electronic Devices (IEDs). Due to the protocol's non-routable, Layer 2 nature and extreme sensitivity to latency, inline security inspection is not feasible. Which Fortinet deployment strategy and feature set should be used to gain visibility and detect potential threats within this GOOSE traffic? (Select TWO).

    Show answer details

    Correct answer: B, C

    Because GOOSE messaging is highly sensitive to latency and operates at Layer 2, an inline device is unsuitable. A one-arm sniffer deployment allows a FortiGate to receive a copy of the traffic from a SPAN (Switched Port Analyzer) or mirror port without introducing any latency or becoming a point of failure.

    The FortiGuard Industrial Security Service (ISS) provides the necessary IPS and application control signatures to decode and inspect specific OT protocols, including IEC 61850 GOOSE. Without this service, the FortiGate would lack the intelligence to understand and analyze the specialized traffic for threats.

  8. 8

    True or False: When configuring a FortiGate for an OT environment, the Industrial Security Service (ISS) license is only required for Intrusion Prevention (IPS) and is not necessary for Application Control to identify industrial protocols like Modbus or DNP3.

    Show answer details

    Correct answer: B

    The FortiGuard Industrial Security Service (ISS) provides signature updates for both IPS and Application Control specifically for OT environments. Without this license and service, the FortiGate will not have the updated definitions required to accurately identify and control many industrial applications and protocols.

  9. 9

    Case Study

    A regional water treatment authority is modernizing its SCADA system, which spans multiple remote sites. The current architecture consists of a flat network where PLCs and RTUs communicate directly with a central control center over a private WAN. This design has been flagged during a security audit for its lack of segmentation and visibility, posing a significant risk of lateral threat movement.

    The authority's primary requirements are to segment the network according to the Purdue model, control access based on device identity, and gain deep visibility into the EtherNet/IP protocol used by their Rockwell Automation controllers. A key constraint is that any new solution must accommodate legacy devices that do not support 802.1X authentication. The solution must also provide a centralized inventory of all connected OT assets.

    The proposed architecture involves deploying FortiGate firewalls at each remote site and a central FortiGate at the control center. FortiSwitches will replace the unmanaged switches at the remote sites. FortiNAC will be deployed at the central data center for network access control and device profiling.

    Given this scenario, which configuration approach best meets all the stated requirements and constraints?

    Show answer details

    Correct answer: C

    This is the most comprehensive solution. It uses FortiNAC for centralized asset inventory and profiling. It addresses the constraint of legacy devices by using MAB as an alternative to 802.1X. Crucially, it leverages the Security Fabric integration, allowing FortiNAC to dynamically control VLAN assignments on the FortiSwitches and push device information to the FortiGates, which can then apply granular, identity-based policies with deep inspection for the specified EtherNet/IP protocol. This achieves segmentation, access control, and protocol visibility.

  10. 10

    A manufacturing plant has deployed FortiNAC to enhance visibility and control over its ICS network. The OT team observes that while FortiNAC is successfully profiling new devices like HMIs and Engineering Workstations, it is failing to correctly identify a specific model of Siemens S7-1500 PLC. The device is being classified as a generic 'Linux Device' based on its network stack. What is the most effective first step the administrator should take within FortiNAC to resolve this misclassification?

    Show answer details

    Correct answer: B

    FortiNAC uses multiple methods for profiling. While basic methods like DHCP fingerprinting or TCP stack analysis might yield generic results, more advanced methods are needed for specific OT devices. Siemens PLCs use PROFINET, and the Discovery and Configuration Protocol (DCP) within it allows devices to broadcast their identity. Creating a custom profiling rule that leverages PROFINET DCP is the most reliable way for FortiNAC to query the PLC directly and obtain accurate model and vendor details for correct classification.

Create an account to continue.