Exam NSEI_OTS_AR-7.6 Topic 1 Question 22 Discussion

Actual exam question for Fortinet's NSEI_OTS_AR-7.6 exam
Question #: 22
Topic #: 1
Refer to the exhibit.

The configuration of firewall policies is shown.
To improve the security of your OT network, you have configured authentication in the firewall policies as shown in the exhibit, with CLI parameters set to their default settings. However, when you test HTTPS access from the LAN subnet to PLC-1, it is successful without any authentication prompt.
What is the reason?

Suggested Answer: A Vote an answer

The correct answer is A . Policy ID 8 contains the Supervisors user group, so authentication is required for traffic matching that policy. However, policy ID 9 permits traffic to PLC-1 without a user or user-group authentication requirement. Fortinet explains that when an authentication policy is followed by a fall-through policy that does not require authentication , traffic can match the fall-through policy and proceed without generating a login prompt. This is particularly relevant because the default CLI setting is auth-on-demand implicitly. Under the default implicitly behavior, FortiGate does not trigger active authentication when a matching unauthenticated fall-through policy exists. Setting auth-on-demand always, or requiring authentication on all potentially matching policies, changes that behavior. Therefore, HTTPS succeeds without prompting because authentication was not configured on firewall policy ID 9 .

by Wayne at Oct 08, 2026, 07:05 AM

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Nick name: Submit Cancel
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

0
0
0
10