Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet NSEI_OTS_AR-7.6 Exam - Topic 4 Question 1 Discussion

You want to protect OT devices that are not updated against known vulnerabilities so you apply virtual patching to the firewall policies. What must you check to confirm that the OT devices are virtually patched? (Choose one answer)
C) The output of the CLI command get rule otvp status
A) The output of the CLI command get virtual-patch profile
B) The OT View page
D) The Asset Identity List page

Fortinet NSEI_OTS_AR-7.6 Exam - Topic 4 Question 1 Discussion

Actual exam question for Fortinet's NSEI_OTS_AR-7.6 exam
Question #: 1
Topic #: 4
[All NSEI_OTS_AR-7.6 Questions]

You want to protect OT devices that are not updated against known vulnerabilities so you apply virtual patching to the firewall policies. What must you check to confirm that the OT devices are virtually patched? (Choose one answer)

Show Suggested Answer Hide Answer
Suggested Answer: C

The correct answer is C. The output of the CLI command get rule otvp status. In the Virtual Patching section, the study guide shows the workflow where FortiGate queries FortiGuard for device-specific vulnerabilities, receives OT virtual patching signatures, maps them to the device MAC address, and then explicitly displays the CLI verification command get rule otvp status together with fields such as Rule-name, Vuln_type, and Cve. This is the direct confirmation mechanism shown in the guide for checking whether OT devices have virtual patching rules associated with them.

The other options are less accurate for confirmation. The OT View page is for Purdue-level visualization, and the Asset Identity List page shows device and asset information, but neither is presented in the guide as the command or control used to verify virtual patching status. The study guide specifically uses get rule otvp status as the status check tied to virtual patching behavior.


Contribute your Thoughts:

0/2000 characters
Nada
3 days ago
C is what I usually check, but A sounds good too!
upvoted 0 times
...
Marya
8 days ago
Wait, can virtual patching really protect outdated devices?
upvoted 0 times
...
Yesenia
13 days ago
Definitely A, that's what I always use!
upvoted 0 times
...
Hermila
18 days ago
I think B might be useful too, but not sure.
upvoted 0 times
...
Gennie
24 days ago
A is the right choice, gotta check that command!
upvoted 0 times
...
Tommy
29 days ago
The Asset Identity List page seems relevant, but I doubt it directly confirms if the devices are virtually patched.
upvoted 0 times
...
Leandro
1 month ago
I feel like the command get rule otvp status sounds familiar from our last practice exam, but I can't recall if it's the correct one.
upvoted 0 times
...
Julieta
1 month ago
I remember practicing with the OT View page, but I don't think that's the right answer for confirming virtual patching.
upvoted 0 times
...
Lavelle
1 month ago
I think we might need to check the CLI command for virtual patching, but I'm not entirely sure which one it is.
upvoted 0 times
...

Save Cancel