[Jul 31, 2026] Fully Updated Dumps PDF - Latest NSE6_OTS_AR-7.6 Exam Questions and Answers [Q81-Q106]

Share

[Jul 31, 2026] Fully Updated Dumps PDF - Latest NSE6_OTS_AR-7.6 Exam Questions and Answers

100% Free NSE6_OTS_AR-7.6 Exam Dumps to Pass Exam Easily from ActualTorrent


Fortinet NSE6_OTS_AR-7.6 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Network access control: Focuses on OT Ethernet fundamentals and designing secure network segmentation strategies. It also includes configuring authentication methods to control and verify access to the OT network.
Topic 2
  • Monitoring and risk assessment: Covers creating event handlers in FortiAnalyzer to monitor network activity and detect threats. It also includes performing risk assessments and analyzing security reports to support ongoing risk management.
Topic 3
  • Network security: Explains how to apply security inspections specifically for industrial protocols and implement virtual patching to protect vulnerable systems. It also includes configuring automation to enhance threat response and operational efficiency.
Topic 4
  • Asset management: Covers understanding OT standards and how Fortinet aligns with compliance requirements in industrial environments. It also includes using the Fortinet Security Fabric to manage assets and implementing device detection using FortiGate and FortiNAC.

 

NEW QUESTION # 81
Refer to the exhibit. An operational technology (OT) architect has implemented Modbus TCP with a simulation Conpot server to identify and control Modbus traffic in their OT network. The FortiGate-Edge device is configured with a software switch interface, SSW-01.
Based on the topology shown in the exhibit, which two statements must be true for the simulation of traffic between client and server to be successful? (Choose two.)

  • A. The FortiGate device must be in offline intrusion detection system (IDS) mode
  • B. The FortiGate-Edge device must be in network address translation (NAT) operation mode
  • C. An IP address must be assigned to port5
  • D. In the FortiGate firewall policy, NAT must be enabled from port3 to SSW-01

Answer: B,D

Explanation:
In the FortiGate firewall policy, NAT must be enabled from port3 to SSW-01: To ensure successful communication between the client and the Conpot server through FortiGate, Network Address Translation (NAT) must be configured in the firewall policy. This allows the client to access the server via the FortiGate interface by properly routing the traffic.
The FortiGate-Edge device must be in network address translation (NAT) operation mode:
FortiGate in NAT operation mode ensures that traffic between different subnets (e.g., client and server) is routed correctly, enabling communication and simulation in the given topology.


NEW QUESTION # 82
To improve the protection of your OT network, you want to automate on FortiGate the handling of compromised devices notified by FortiAnalyzer. What must you configure?

  • A. The Security Fabric settings on FortiGate
  • B. A FortiOS Event Log trigger on FortiGate
  • C. An event handler with the parameter Automation Stitch enabled on FortiAnalyzer
  • D. An Automation with a LOCAL_HOST connector on FortiAnalyzer

Answer: C

Explanation:
Automation between FortiAnalyzer and FortiGate relies on event handlers configured on FortiAnalyzer with Automation Stitch enabled, which allows FortiAnalyzer to trigger automated actions on FortiGate when specific events, such as compromised devices, are detected.


NEW QUESTION # 83
As the first step in your OT network protection plan, you must identify the OT protocols that the FortiGate device supports. Which two configurations must you implement on this FortiGate device? (Choose two answers)

  • A. You must enable the OT signatures.
  • B. You must implement an Intrusion Prevention security profile that monitors OT.
  • C. You must enable Device detection on all the interfaces.
  • D. You must implement an Application Control security profile that monitors OT.

Answer: A,D

Explanation:
The correct answers are B and C . The study guide states that "You can use application control signatures to detect OT protocols" and that "Application control detects the protocols used in applications like Modbus, IEC 104, and the contents of the telecontrol messages" . It also shows that a Modbus application control profile can be enabled on a firewall policy "for OT protocol visibility in the monitor status." This directly supports B , because application control is the feature used to identify and monitor OT protocols on FortiGate.
The guide also explains under IPS that "By default, OT signatures are excluded from the signatures lists on the GUI until you enable them on the CLI" using config ips global and set exclude-signatures none .
Once enabled, FortiGate can use those OT signatures for OT-aware inspection and protection. That supports C as the second required configuration. A is related to device discovery, not protocol identification, and D is focused on exploit and vulnerability detection rather than the first-step goal of identifying OT protocols.


NEW QUESTION # 84
Drag and Drop Question
Match each industrial protocol to its corresponding characteristics.
Select each OT industrial protocol in the column on the left and drag and drop it into the blank space next to its corresponding characteristics in the column on the right. After matching a device type to its characteristics, you can move it again if you want to change your answer by clicking the industrial protocol name. You must match all four industrial protocols to their characteristics in the work area.

Answer:

Explanation:


NEW QUESTION # 85
Refer to the exhibit. The network topology in the exhibit shows FortiGate devices as well as FortiAnalyzer and FortiSIEM for the OT network.
Which two steps must you take to configure logging on the OT network'? (Choose two.)

  • A. Configure FortiGate and FortiAnalyzer to send industrial signature patterns to FortiSIEM.
  • B. Configure FortiAnalyzer to send security events to FortiSIEM.
  • C. Configure FortiSIEM to send logs and alerts to FortiAnalyzer.
  • D. Configure FortiGate to send logs to FortiAnalyzer and FortiSIEM.

Answer: B,D

Explanation:
FortiGates must forward their logs directly to both FortiAnalyzer and FortiSIEM for storage and correlation. FortiAnalyzer then forwards relevant security events to FortiSIEM, enabling centralized analytics across OT devices.


NEW QUESTION # 86
What are two critical tasks the OT network auditors must perform during OT network risk assessment and management? (Choose two.)

  • A. Evaluating what can go wrong before it happens
  • B. Planning a threat hunting strategy
  • C. Implementing strategies to automatically bring PLCs offline
  • D. Creating disaster recovery plans to switch operations to a backup plant

Answer: A,B

Explanation:
Planning a threat hunting strategy is essential for proactively searching for threats and vulnerabilities in the OT environment before they manifest into attacks.
Evaluating what can go wrong before it happens is a core part of risk assessment, involving the identification and analysis of potential risks and their impacts on OT systems.
Implementing strategies to automatically bring PLCs offline is generally not a responsible or safe approach in OT environments because it could disrupt critical industrial processes.
Creating disaster recovery plans is important for overall business continuity but is not primarily a task of auditors during risk assessment-it is more of a broader business continuity or incident response responsibility.


NEW QUESTION # 87
Which industrial protocol does not support VLANs? (Choose one answer)

  • A. Modbus over TCP
  • B. Ethernet POWERLINK
  • C. EtherCAT
  • D. Ethernet over industrial protocol

Answer: C


NEW QUESTION # 88
Refer to the exhibit.

A basic event handler is shown. You have enabled Automation Stitch to automate the handling of an alert.
Which two steps must you take to use this automation stitch? (Choose two answers)

  • A. You must configure Action on FortiAnalyzer.
  • B. You must configure Rules on FortiAnalyzer.
  • C. You must configure a FortiAnalyzer event handler trigger on FortiGate.
  • D. You must configure a Playbook task on FortiAnalyzer.

Answer: B,C

Explanation:
The correct answers are C and D .
Option D is correct because the study guide states that the configuration of an event handler can include
"Rules" and explains that "Rules are granular conditions" and "Event handlers can have one or more rules." It further states that "FortiAnalyzer uses event handlers to filter all incoming logs" and "If logs match the conditions configured in an event handler, FortiAnalyzer generates an event." Therefore, to use the automation stitch, you must define the rules on FortiAnalyzer so the event handler can actually generate the event that starts the automation flow.
Option C is also correct. The study guide explains that "When a handler generates an event with the automation stitch option enabled, FortiAnalyzer sends a notification" to the FortiGate side, and in the attack-detection example it says "FortiAnalyzer parses the logs and notifies the root FortiGate" and then
"The root FortiGate triggers the action." It also explicitly shows "Stitches configured on root FortiGate." This means the FortiGate must have the corresponding automation trigger configured for the FortiAnalyzer event handler notification.
Option A is incorrect because the study guide does not describe configuring an Action on FortiAnalyzer as the required step for this FortiAnalyzer-to-FortiGate automation-stitch flow. Option B is also incorrect because playbooks are a different FortiAnalyzer automation mechanism; the question specifically refers to using the Automation Stitch option in the event handler.


NEW QUESTION # 89
Refer to the exhibit. PLC-3 and CLIENT can send traffic to PLC-1 and PLC-2. FGT-2 has only one software switch (SSW-2) connecting both PLC-3 and CLIENT. PLC-3 and CLIENT can send traffic to each other at the layer 2 level.
What must the operational technology (OT) admin do to prevent layer 2-level communication between PLC-3 and CLIENT?

  • A. Set a unique forward domain for each interface of the software switch.
  • B. Enable explicit intra-switch policy to require firewall policies on FGT-2.
  • C. Implement policy routes on FGT-2 to control traffic between devices.
  • D. Create a VLAN for each device and replace the current FGT-2 software switch members.

Answer: B

Explanation:
Set the software switch to explicit intra-switch policy so traffic between its member ports must pass through FortiGate policies instead of being bridged at Layer 2. This stops PLC‑3 and CLIENT from communicating directly at L2.


NEW QUESTION # 90
Refer to the exhibit. A Virtual Patching profile is shown.

You have recently updated your SCADAsystem and would like to apply the SCADA virtual patching profile.
Which two statements about this profile are correct? (Choose two answers)

  • A. This profile blocks critical severity signatures for all the devices.
  • B. Only the vulnerability Schneider.Electric.ClearSCADA.HTTP.Interface.XSS is still present.
  • C. The device with the MAC address 11:11:11:11:11 is considered to have no vulnerabilities.
  • D. Low severity signatures are not blocked for the device with the MAC address 12:12:12:12:12.

Answer: A,D


NEW QUESTION # 91
Refer to the exhibits.

A partial Basic Event Handler page on FortiAnalyzer and the creation of a trigger in a FortiGate device are shown. To improve the protection of your OT network, you want to automate the handling of compromised devices notified through FortiAnalyzer. You have configured an event handler named Alert_trigger as shown in the exhibit. When you create the trigger on the FortiGate device, the Event handler name field does not provide the Alert_trigger option. What two actions must you perform to make the Alert_trigger option available? (Choose two answers)

  • A. You must click + Create in the Event handler name field.
  • B. You must configure the FortiAnalyzer setting on the FortiGate device.
  • C. You must authorize the FortiGate device on FortiAnalyzer.
  • D. You must configure the trigger on the root FortiGate.

Answer: B,D

Explanation:
The correct answers are C and D .
Option C is correct because the study guide explains that when "a handler generates an event with the automation stitch option enabled, FortiAnalyzer sends a notification" and, in the Security Fabric workflow, "FortiAnalyzer parses the logs and notifies the root FortiGate." This means FortiGate must first have the FortiAnalyzer connection configured so it can consume FortiAnalyzer event handlers and use them in automation. The wizard message in the exhibit also points to this requirement by indicating that a FortiAnalyzer connection must be configured.
Option D is also correct because the study guide explicitly says that in this automation flow "the root FortiGate triggers the action" and shows "Stitches configured on root FortiGate." Therefore, if you want the FortiAnalyzer event handler to appear and be usable for automation, the trigger must be configured on the root FortiGate , not on an arbitrary downstream FortiGate.
Option A is incorrect because + Create is only a GUI control and does not solve the missing-event-handler visibility problem. Option B is not identified in the study guide as the requirement for making a FortiAnalyzer event handler available in the FortiGate automation trigger list.


NEW QUESTION # 92
Refer to the exhibit. A partial OT network is shown.

In this OT network, you must add additional security measures to detect OT protocols and, therefore, increase the traffic visibility.
Which security sensor must you implement to delect the OT protocols in this network? (Choose one answer)

  • A. Inline IDS on FortiGate_Level3
  • B. Device detection on all the FortiGate interfaces
  • C. IPS sensor on FortiGate Level5
  • D. Application sensor set to monitor on all the FortiGate devices

Answer: D


NEW QUESTION # 93
Refer to the exhibit.

A partial Application Sensor profile is shown. When you apply this profile in a firewall policy, which two statements are correct? (Choose two answers)

  • A. OT signatures are enabled.
  • B. A log is provided for each IEC command.
  • C. All OT protocols are blocked.
  • D. A log is provided for each Modbus command.

Answer: A,B

Explanation:
The correct answers are A and C.
Option C is correct because the profile clearly contains the Operational Technology category and specific OT application signatures such as Modbus and IEC.60870.5.104. The study guide says "You can use application control signatures to detect OT protocols" and "You can filter to a specific OT protocol." That means OT application signatures are active in this sensor profile.
Option A is correct because the guide explains that application control works at different levels: "Detection of protocol (one detection per session)" and "Message level (one detection per protocol message)." It also says you can use application signatures for "granular message type identification." In the exhibit, IEC.60870.5.104.Control.Functions is explicitly configured, which is a granular IEC message/control-level signature rather than only a protocol-level match. That means logging and control can occur at the IEC command level.
Option B is not correct because the profile shows Modbus configured at the parent protocol level as Monitor, while the guide states that the "parent signature takes precedence over the child signature." Since protocol-level detection is one detection per session, that does not mean FortiGate will necessarily log each Modbus command individually.
Option D is incorrect because even though the broader Operational Technology category is set to block, the profile includes specific application and filter overrides for Modbus and IEC 104 behavior. So the resulting effect is not simply that all OT protocols are blocked.


NEW QUESTION # 94
Which three protocols are used as industrial Ethernet protocols? (Choose three.)

  • A. PROFINET
  • B. M12
  • C. RJ45
  • D. EtherNet/IP
  • E. EtherCAT

Answer: A,D,E


NEW QUESTION # 95
What can you assign using network access control policies?

  • A. Layer 3 polling intervals
  • B. Profiling rules
  • C. FortiNAC device polling methods
  • D. Logical networks

Answer: D


NEW QUESTION # 96
Refer to the exhibit.A new operational technology rule is being created to monitor Modbus protocol traffic on FortiSIEM.
Which action will ensure all Modbus messages on the network match the rule?

  • A. This rule is valid and requires no additional changes.
  • B. Set the Aggregate attribute value to equal to or greater than zero.
  • C. Add a new condition to filter Modbus traffic based on the Source TCP/UDP port.
  • D. Remove attributes in the Group By section that are not configured in the Filter section.

Answer: C

Explanation:
https://community.fortinet.com/t5/FortiSIEM/Technical-Note-How-do-I-create-and-or-customize- rules-and-alerts/ta-p/196013


NEW QUESTION # 97
Which three common breach points can you find in a typical OT environment? (Choose three.)

  • A. RTU exploits
  • B. VLAN exploits
  • C. Hard hat
  • D. Global hat
  • E. Black hat

Answer: A,C,E

Explanation:


NEW QUESTION # 98
Refer to the exhibit.

Based on the information provided on the partial Event Monitor page shown in the exhibit, how was the attack detected? (Choose one answer)

  • A. Automatically by an event handler
  • B. Automatically by a stitch
  • C. Manually by an administrator
  • D. Automatically by a playbook

Answer: A

Explanation:
The correct answer is D. Automatically by an event handler . The study guide explicitly states that "Event handlers generate events on FortiAnalyzer" and "FortiAnalyzer uses event handlers to filter all incoming logs. If the logs received match the conditions set in the event handlers, FortiAnalyzer generates an event." It also says "You can view all generated events on the Event Monitor page." This directly matches the exhibit, which is showing entries on the Event Monitor page. Therefore, the attack shown there was detected automatically through an event handler .
The guide also explains the detection flow: "FortiAnalyzer receives logs," "FortiAnalyzer parses logs," and "FortiAnalyzer generates an event if a rule is matched in an event handler." In addition, the Event Monitor view includes the Handler column, which identifies the event handler that generated the event. That is why the attack is not considered manually detected, and it is not primarily detected by a playbook or stitch.
Playbooks and stitches are used for subsequent automation actions, but the event appearing in Event Monitor is created by the event handler mechanism.


NEW QUESTION # 99
Refer to the exhibits.

A partial Basic Event Handler page on FortiAnalyzer and the creation of a trigger in a FortiGate device are shown. To improve the protection of your OT network, you want to automate the handling of compromised devices notified through FortiAnalyzer. You have configured an event handler named Alert_trigger as shown in the exhibit. When you create the trigger on the FortiGate device, the Event handler name field does not provide the Alert_trigger option. What two actions must you perform to make the Alert_trigger option available? (Choose two answers)

  • A. You must click + Create in the Event handler name field.
  • B. You must configure the FortiAnalyzer setting on the FortiGate device.
  • C. You must authorize the FortiGate device on FortiAnalyzer.
  • D. You must configure the trigger on the root FortiGate.

Answer: B,D

Explanation:
The correct answers are C and D.
Option C is correct because the study guide explains that when "a handler generates an event with the automation stitch option enabled, FortiAnalyzer sends a notification" and, in the Security Fabric workflow, "FortiAnalyzer parses the logs and notifies the root FortiGate." This means FortiGate must first have the FortiAnalyzer connection configured so it can consume FortiAnalyzer event handlers and use them in automation. The wizard message in the exhibit also points to this requirement by indicating that a FortiAnalyzer connection must be configured.
Option D is also correct because the study guide explicitly says that in this automation flow "the root FortiGate triggers the action" and shows "Stitches configured on root FortiGate." Therefore, if you want the FortiAnalyzer event handler to appear and be usable for automation, the trigger must be configured on the root FortiGate, not on an arbitrary downstream FortiGate.
Option A is incorrect because + Create is only a GUI control and does not solve the missing-event-handler visibility problem. Option B is not identified in the study guide as the requirement for making a FortiAnalyzer event handler available in the FortiGate automation trigger list.


NEW QUESTION # 100
Refer to the exhibits.


A partial OT network and firewall policies configuration are shown.
You added authentication in the firewall policy from Engineering Workstation to RTU to improve the security. When verifying your configuration, you notice that you can still access RTU from Engineering Workstation without an authentication prompt.
What must you do to enforce authentication?

  • A. You must enable Fortinet Single Sign-On (FSSO).
  • B. You must add a local user instead of FortiAuthenticator.
  • C. You must reboot FortiGate.
  • D. You must add authentication in firewall policy 9.

Answer: D

Explanation:
Firewall policies are evaluated top-down, and a matching policy without authentication is applied before the one requiring authentication. Adding authentication to the higher-priority policy ensures that all matching traffic is subject to authentication.


NEW QUESTION # 101
Refer to the exhibit.

A partial OT network is shown. In this OT network, you must add additional security measures to detect OT protocols and, therefore, increase the traffic visibility. Which security sensor must you implement to detect the OT protocols in this network? (Choose one answer)

  • A. Inline IDS on FortiGate_Level3.
  • B. IPS sensor on FortiGate_Level5.
  • C. Application sensor set to monitor on all the FortiGate devices.
  • D. Device detection on all the FortiGate interfaces.

Answer: C

Explanation:
The correct answer is C. Application sensor set to monitor on all the FortiGate devices.
The study guide clearly explains that application control is the feature used to identify OT protocols. It states that "application control detects the protocols used in applications like Modbus, IEC 104, and the contents of the telecontrol messages" and also says "You can use application control signatures to detect OT protocols." It further shows an example where a Modbus application control profile is enabled on a firewall policy "for OT protocol visibility in the monitor status." This directly matches the requirement in the question, which is to detect OT protocols and increase traffic visibility.
The other options do not fit the requirement as precisely. Device detection is for identifying devices and collecting endpoint information, not for detecting industrial protocols. Inline IDS and IPS are focused more on detecting or blocking attacks, exploits, protocol abnormalities, and known vulnerabilities. While IPS can inspect some OT traffic, the study guide distinguishes it from application control by stating that IPS signatures tend to detect exploits, whereas application control signatures tend to provide protocol detection at various levels. Therefore, the required security sensor for OT protocol detection and traffic visibility is the application sensor in monitor mode.


NEW QUESTION # 102
Refer to the exhibit. Given the configurations on the FortiGate, which statement is true?

  • A. FortiGate is configured with forward-domains to forward only company domain website traffic.
  • B. FortiGate is configured with forward-domains to reduce unnecessary traffic.
  • C. FortiGate is configured with forward-domains to filter and drop non-domain controller traffic.
  • D. FortiGate is configured with forward-domains to forward only domain controller traffic.

Answer: B


NEW QUESTION # 103
Refer to the exhibit.

An industrial Ethernet protocol skipping layers 3 to 6 is shown. Which industrial Ethernet protocol is it?
(Choose one answer)

  • A. POWERLINK
  • B. EtherCAT
  • C. Modbus
  • D. Ethernet over industrial protocol

Answer: B

Explanation:
The correct answer is D. EtherCAT . The study guide explicitly states under the Ethernet/IP and EtherCAT section that "EtherCAT is a protocol that offers real-time communication in a primary-secondary configuration" and "EtherCAT skips layers 3 to 6 to deliver real-time communication." It also adds that
"the most important feature of this protocol is that secondary devices collect only the information they need from the data packets." This matches the exhibit exactly, where the diagram shows Real-Time Data above a Proprietary MAC and Proprietary physical layer , reflecting the protocol structure that bypasses the intermediate OSI layers.
The other options do not match this behavior. The guide says POWERLINK uses layer 2 and layer 7 of the OSI model, not that it skips layers 3 to 6. It also explains that Ethernet/IP is the industrial protocol based entirely on Ethernet standards and adapts to the OSI model. Modbus is described as an open client/server protocol and is not suitable for transmitting data in real time . Therefore, the protocol in the exhibit is clearly EtherCAT .


NEW QUESTION # 104
A FortiGate device is newly deployed as the edge gateway of an OT network security fabric. The downstream FortiGate devices are also newly deployed as Security Fabric leafs to protect the control area zone.
With no additional essential networking devices, and to implement micro-segmentation on this OT network, what configuration must the OT network architect apply to control intra-VLAN traffic?

  • A. Enable transparent mode on the edge FortiGate device.
  • B. Enable security profiles on all interfaces connected in the control area zone.
  • C. Create a software switch on each downstream FortiGate device.
  • D. Set up VPN tunnels between downstream and edge FortiGate devices.

Answer: C

Explanation:
A software switch groups multiple interfaces at Layer 2.
However, for micro-segmentation, you usually separate interfaces per subnet/device group and apply inter-interface policies on the FortiGate.
By doing this, the FortiGate can control intra-VLAN (or intra-subnet) traffic without additional networking hardware.


NEW QUESTION # 105
Refer to the exhibit. A partial OT network is shown. You must improve the security of this OT network and implement internal segmentation between network 1 and network 2. How can you achieve the segmentation?
(Choose one answer)

  • A. You can configure an explicit software switch.
  • B. You can configure universal ZTNA.
  • C. You can configure forward domain IDs for each network.
  • D. You can configure one traffic VDOM.

Answer: C

Explanation:
The correct answer is D. You can configure forward domain IDs for each network . The study guide explains that in FortiGate transparent mode, "all interfaces belong to the same broadcast domain, even interfaces with different VLAN IDs" and then states that you should "use this command to subdivide into multiple broadcast domains" with set forward-domain < domain_ID > . It further explains that
"interfaces with the same domain ID belong to the same broadcast domain" and "traffic arriving on one interface is broadcast only to interfaces in the same forward domain ID." This is exactly the mechanism used to separate one internal network from another and improve segmentation.
The other options do not match this requirement. Universal ZTNA is described as controlling user access to applications , not segmenting two internal OT networks. An explicit software switch is for controlling intra- switch or intra-VLAN traffic inside the same software switch broadcast domain, which is more aligned with microsegmentation than separating two routed internal networks. One traffic VDOM does not create segmentation by itself; segmentation with VDOMs requires multiple VDOMs, not one. Therefore, the best choice for segmenting network 1 and network 2 in this scenario is to assign separate forward domain IDs .


NEW QUESTION # 106
......

Free NSE6_OTS_AR-7.6 Exam Questions NSE6_OTS_AR-7.6 Actual Free Exam Questions: https://www.actualtorrent.com/NSE6_OTS_AR-7.6-questions-answers.html

Verified NSE6_OTS_AR-7.6 dumps and 168 unique questions: https://drive.google.com/open?id=1vzDC8n8XSAjpaoM1L-w9sxhj6gx98kpX