NSE7-OTS-7-2 Sample Questions & Answers
Four equally weighted areas run through OT fundamentals plus how the Security Fabric applies to OT networks, authentication and internal segmentation, protecting industrial protocols with IPS and application control, and logging, reporting, and security automation.
Launch the full NSE7-OTS-7-2 simulator →Free NSE7-OTS-7-2 Sample Questions with Answers
Real questions from the Fortinet NSE 7 - OT Security 7.2 practice test — answers and explanations included. Showing 10 of 20 free samples.
- Question 1Intermediate
OT network protection · Implement Application control in OT networks
An OT administrator is configuring a security policy on a FortiGate to allow an Engineering Workstation (EWS) to program a PLC using the Modbus protocol. The goal is to allow only Modbus 'Write' commands (Function Codes 5, 6, 15, 16) and block any 'Read' commands to prevent unauthorized data exfiltration. Which Fortinet feature is required to achieve this level of granular control?
Show answer & explanation
Correct answer: C
FortiGate's Application Control, when used with the Industrial Security Service, provides granular signatures for many OT protocols, including Modbus. It can differentiate between various function codes. An administrator can create a profile that explicitly allows signatures like
Modbus.Write.Coil,Modbus.Write.Single.Register, etc., while blockingModbus.Read.Coil,Modbus.Read.Holding.Register, etc. This provides the required granular control over protocol commands. - Question 2Advanced
Monitoring and risk assessment · Configure security automation with FortiAnalyzer and FortiSIEM
A security analyst in an OT SOC is investigating an alert from FortiSIEM indicating that a PLC has unexpectedly initiated an outbound connection to an external IP address. To create a rapid, automated response, the analyst wants to configure the system to immediately block the PLC's MAC address at the network edge. Which combination of Fortinet products and features is required to implement this automated quarantine action?
Show answer & explanation
Correct answer: C
This scenario requires orchestration between the monitoring tool (FortiSIEM) and the access control tool (FortiNAC). FortiSIEM can be configured with a correlation rule to detect the anomalous behavior. The rule's action can be set to execute a remediation script or API call to FortiNAC. FortiNAC, as the network access control solution, has the capability to quarantine a device by its MAC address, effectively isolating it at the switch level regardless of its IP address. This provides a direct and effective quarantine mechanism.
- Question 3Intermediate
Network access control · Describe OT Availability and Redundancy
An OT network is segmented using a FortiGate with multiple VLANs for different production cells. The administrator wants to ensure that if the primary FortiGate unit fails, a secondary unit takes over with minimal disruption to the SCADA operations. The industrial switches support LACP. Which FortiGate High Availability (HA) configuration is most appropriate to provide both redundancy and optimized link usage?
Show answer & explanation
Correct answer: D
While Active-Passive HA provides the necessary redundancy, combining it with link aggregation (LACP/802.3ad) on the monitored interfaces provides superior physical link redundancy and potentially higher throughput. By creating an LACP bundle of physical ports on the FortiGate and connecting them to an LACP-configured switch, the HA cluster can survive a single link failure without triggering a full device failover. This is a robust design for critical OT environments where both device and link uptime are paramount.
- Question 4Beginner
Network access control · Apply authentication to control access to devices
When implementing a Zero Trust security model in an OT environment using Fortinet solutions, what is the primary function of FortiNAC?
Show answer & explanation
Correct answer: C
In a Zero Trust model, nothing is trusted by default. The foundational step is to verify every access attempt. FortiNAC's core function is to provide network visibility by discovering and profiling every device (the 'who' and 'what'), and then enforcing access control policies (the 'where' and 'when'). This ensures that only authorized and compliant devices are granted the least-privilege access they require, which is a cornerstone of Zero Trust.
- Question 5IntermediateSelect 3
Network access control · Apply authentication to control access to devices
A security audit of a food processing plant revealed that unauthenticated devices can be connected to active network ports in the production area, gaining access to the control network. The plant uses a mix of modern and legacy OT devices. Which of the following Fortinet solutions and configurations should be implemented to address this finding most effectively? (Select THREE).
Show answer & explanation
Correct answers: A, B, C
Managed switches like FortiSwitch are required to implement port-based security features like 802.1X and MAB, and to integrate with a NAC solution for enforcement.
FortiNAC is the central brain for discovering, profiling, and applying access policies to devices. It is essential for managing a mixed-device environment.
This combination addresses the mixed-device environment. Modern devices can authenticate using the more secure 802.1X, while legacy devices that do not support it can be authenticated via their MAC address using MAB, ensuring all devices are subject to an authentication check.
- Question 6Intermediate
Monitoring and risk assessment · Implement logging and monitoring with FortiAnalyzer and FortiSIEM
A FortiGate is deployed at the IT/OT boundary (Purdue Level 3.5). The OT team wants to create a dashboard widget in FortiAnalyzer that specifically tracks all
Modbus.Write.Single.Registercommands sent to a critical group of PLCs. What is the first prerequisite step to ensure FortiAnalyzer can generate this report?Show answer & explanation
Correct answer: C
FortiAnalyzer can only report on data it receives. For it to be aware of specific application commands like
Modbus.Write.Single.Register, the FortiGate must first inspect the traffic using an Application Control profile that has the appropriate signatures enabled. Furthermore, logging must be enabled within that firewall policy and security profile so that the detected application events are sent to FortiAnalyzer for analysis and reporting. - Question 7Advanced
OT network protection · Identify industrial protocols and signatures
An administrator needs to create a custom IPS signature to detect a specific payload within a proprietary OT protocol that operates over TCP port 4000. The proprietary protocol is not recognized by the FortiGuard Industrial Security Service. Which syntax would be used to define the service and the pattern in the custom signature?
Show answer & explanation
Correct answer: A
Fortinet's custom IPS signatures use a specific syntax.
F-SBIDis the header. The--servicekeyword is used to specify the protocol (TCP, UDP, ICMP, IP). The--dportkeyword specifies the destination port. The--patternkeyword is used to define the specific payload to match, with the payload typically enclosed in|characters as a hex string. - Question 8Beginner
Asset Management · Explain OT fundamentals and concept
The Purdue Model provides a conceptual framework for securing ICS networks. At which level of this model would you typically find Engineering Workstations (EWS) used for programming and maintaining control devices?
Show answer & explanation
Correct answer: B
Engineering Workstations (EWS) are specialized computers used to configure, program, and maintain devices at Level 1 (like PLCs) and Level 2 (like HMIs). Therefore, they are typically located at Level 2, the Area Supervisory Control level, where they can interact with the control systems they manage. Sometimes they may also be found at Level 3, but their primary operational context is with the supervisory and control devices.
- Question 9Beginner
Asset Management · Implement device detection
True or False: In a Fortinet OT security architecture, FortiSIEM can be configured to use passive asset discovery methods, such as monitoring traffic from a SPAN port, to build an OT asset inventory without actively scanning the network.
Show answer & explanation
Correct answer: A
FortiSIEM supports multiple discovery methods. For sensitive OT environments where active scanning can disrupt operations, FortiSIEM can be configured to discover assets passively by analyzing network flows (like NetFlow, sFlow) or by directly monitoring traffic from a SPAN/mirror port. This allows it to identify devices, protocols, and communication patterns without sending any packets to the OT devices themselves.
- Question 10Advanced
OT network protection · Implement IPS to secure OT networks
Case Study
A large-scale chemical processing plant operates a Distributed Control System (DCS) that is highly sensitive to network jitter and latency. The plant has recently experienced intermittent communication failures between its controllers and operator stations. A security team has been brought in to improve the security posture without exacerbating the performance issues. The network is currently segmented with a FortiGate at the IT/OT boundary, but there is no internal segmentation within the OT zone.
The plant manager has two primary requirements: first, to implement micro-segmentation to isolate critical DCS components from the rest of the OT network; second, to apply virtual patching for known vulnerabilities on the Windows-based operator stations, as the vendor does not permit direct OS patching.
The security team plans to deploy additional FortiGates internally to create segmentation zones. They need to choose the most appropriate inspection mode for these internal FortiGates to meet the strict performance requirements of the DCS.
Which FortiGate configuration and security feature will best address the plant's requirements for micro-segmentation and virtual patching while minimizing performance impact on the DCS?
Show answer & explanation
Correct answer: B
This approach directly addresses both requirements. Deploying the FortiGates in Transparent Mode allows them to be inserted into the network for segmentation without requiring any IP address changes or introducing routing complexity, which is ideal for a sensitive DCS. The Intrusion Prevention System (IPS) is the Fortinet feature designed for virtual patching; by applying an IPS profile with signatures that block exploits for the known vulnerabilities, the FortiGate can protect the operator stations without altering the underlying OS. This combination provides effective security with the lowest possible performance impact.
Ready for the real thing?
The full NSE7-OTS-7-2 simulator has every exam-style question, timed mode, and instant scoring.