Refer to the exhibit.

A partial OT network is shown. You have configured the FortiGate device with VLANs to segment the OT network. The supervisor now wants to connect to the PLC from the Engineering Workstation. How can you allow access from the Engineering Workstation to the PLC? (Choose one answer)
The correct answer is D. You must configure a layer 3 switch.
The study guide explains that ''Layer 2 devices can add or remove tags'' but ''cannot modify them.'' It then states that ''A layer 3 device, such as a router or FortiGate, can modify the VLAN tag before routing the packet. This allows them to route traffic between VLANs.'' It also explicitly describes ''Router on a Stick'' as ''a way to allow routing between VLANs.'' Since the exhibit shows a layer-2 switch and the Engineering Workstation and PLC are placed in different VLANs, inter-VLAN communication requires layer-3 routing.
The other options do not solve this requirement. intra-switch-policy explicit/implicit applies to a software switch, where member interfaces are in the same broadcast domain and same subnet, not to routing between separate VLANs. forward domain IDs are used in transparent mode to confine broadcasts to specific broadcast domains; they do not provide inter-VLAN access. Therefore, to let the Engineering Workstation in one VLAN reach the PLC in another VLAN, you need a layer 3 routing function, which matches option D.
Currently there are no comments in this discussion, be the first to comment!