NSE5-FSW-AD-7-6: Fortinet NSE 5 - FortiSwitch 7.6… Practice Exam
QuestionQ1
Enterprise Networking
Save question
Refer to the exhibit.
Routing Monitor -
The routing monitor shows multiple route entries, but only some are installed in the forwarding information base (FIB).
After examining the two route entries with destination 0.0.0.0/0, which statement correctly describes why one of these routes is not installed in the FIB?
AThe OSPF route has a higher metric, making it less preferred than the static route.
BThe interface V100 for the OSPF route is down, preventing its installation.
CThe OSPF route with a lower administrative distance is preferred over the static route.
DThe two routes have identical destination prefixes, causing a conflict where only one is selected.
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ2
Enterprise Networking
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ3
Network Security
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ4
Network Security
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ5
Enterprise Networking
0
Community Discussion
No comments yet. Be the first to start the discussion!
It's free
100% of the questions are free for all users. No strings attached.
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Which two statements about the FortiLink authorization process are correct?
Choose two
AA FortiLink frame is sent by FortiGate to FortiSwitch to complete the authorization.
BFortiLink authorization sets the FortiSwitch management mode to FortiLink.
CFortiSwitch requires a reboot to complete the authorization process.
DFortiLink authorization permanently erases the existing configuration of the FortiSwitch.
When Dynamic Host Configuration Protocol (DHCP) snooping is enabled on a FortiSwitch VLAN, which two statements are correct?
Choose two
ADHCP replies are accepted only on trusted ports.
BDHCP snooping blocks all unicast traffic.
COption 82 can be inserted into DHCP requests.
DDHCP requests are dropped if sent from trusted ports.
You are designing a multi-tenant network with FortiSwitch devices operating in standalone mode. Security is a priority: every tenant’s servers must be fully isolated from each other and from every other server on the network to prevent lateral communication. However, all servers must be able to access the shared FortiGate firewall for internet connectivity.
Which private VLAN (PVLAN) configuration type should you use to meet these security requirements?
APrimary VLAN
BCommunity VLAN
CIsolated VLAN
DStandalone VLAN
Refer to the exhibit.
Port24 is the sole uplink port connected to the network from which access to FortiSwitch management services is required. However, FortiSwitch cannot be reached through its management interface at IP address 10.0.13.3.
Based on the configuration displayed in the exhibit, which two actions should you take to resolve the issue and access FortiSwitch?
Choose two
AAdd VLAN 4094 to the allowed VLANs on port24.
BChange the native VLAN on port24 to VLAN 4094.
CRemove VLAN 200 from the allowed VLANs on port24.
DChange the management IP address to use the VLAN 100 subnet.
Refer to the exhibits.
Topology view —
Core-1 CLI output —
Core-2 CLI output —
An administrator deployed two FortiSwitch devices, Core-1 and Core-2, as multichassis link aggregation group (MCLAG) peers. The switches connect to FortiGate for FortiLink and to an access switch (Access-1) through an inter-switch link (ISL). After configuration, the administrator observes that both Core-1 and Core-2 claim to be the root bridge in the Multiple Spanning Tree Protocol (MSTP) topology.
What accounts for this behavior?
AFortiGate participates in MSTP and causes both switches to assume the root bridge role.
BThe ISL was not configured correctly, leading to MSTP inconsistency.
CBoth switches share the same bridge ID because MCLAG treats them as one logical switch.
DMCLAG automatically disables STP on all peer switches.
On supported FortiSwitch models, which access control list (ACL) stage is recommended to apply actions before the switch carries out any Layer 2 or Layer 3 processing?
APrelookup
BIngress
CEgress
DForwarding
Refer to the exhibit.
How does Spanning Tree Protocol (STP) view MC-LAG and LAG when they are configured according to the physical topology shown?
Choose two
ASTP treats Switch 3 and Switch 4 uplinks as single interfaces.
BSTP see Switch 3 and switch 4 as one MCLAG switch client.
CSTP sees Switch 1, Switch 2, and Switch 3 as one MCLAG peer group.
DSTP see Switch 1 and Switch 2 as a single switch.
Which statement most accurately describes a benefit of using MAC-, IP address-, or protocol-based VLAN assignments on FortiSwitch?
AIt disables 802.1X authentication while preserving user access control.
BIt requires devices to authenticate through a RADIUS server before VLAN tagging.
CIt assigns ports to VLANs regardless of device type or traffic.
DIt offers dynamic segmentation benefits similar to 802.1X authentication.
Refer to the exhibit.
Debug output:
Which two statements best describe the FortiLink debug output displayed in the exhibit?
Choose two
AFortiSwitch is in a waiting state to join the stack group on FortiGate.
BFortiSwitch is sending FortiLink heartbeats to FortiGate.
CFortiSwitch is discovered and authorized by FortiGate.
DFortiSwitch is sending LLDP-MED inventory management updates to FortiGate.
Which LLDP-MED type-length-values (TLV) does FortiSwitch obtain from endpoints to track network devices and identify their characteristics?
AAsset management
BInventory management
CCapabilities
DNetwork policy
Refer to the exhibit.
What information does FortiGate use to create the port details in the FortiSwitch Faceplates view?
AThe FortiSwitch model
BThe Cisco Discovery Protocol (CDP) advertisements from FortiSwitch
CThe LLDP advertisements received from the FortiSwitch
DThe FortiLink discovery frames sent by FortiSwitch
You are configuring VLANs on a FortiSwitch device that is managed by FortiGate.
Which two statements correctly describe VLAN-assignment requirements and behavior on FortiSwitch ports?
Choose two
AUntagged defines the list of VLANs that are allowed on the port for both ingress and egress traffic.
BUntagged VLAN applies to egress traffic only.
CYou can assign only one native VLAN on a port.
DVLAN assignments must be configured directly on the FortiSwitch.
Refer to the exhibit.
A debug capture of the fortilinkd process on FortiGate is displayed.
A managed FortiSwitch sends a periodic heartbeat message, and the corresponding FortiGate acknowledgments are shown. What does this behavior indicate?
AThe FortiLink connection between FortiGate and FortiSwitch is healthy and active.
BFortiGate is unable to establish a FortiLink session with FortiSwitch.
CForitSwitch is expecting an authorization from FortiGate.
DFortiSwitch has not been authorized yet.
Refer to the exhibits.
You enable Dynamic Host Configuration Protocol (DHCP) snooping on the Student VLAN. The Linux-Client VM sends DHCP requests, and tcpdump verifies the broadcasts. However, the Linux-Server VM, acting as the DHCP server, receives no DHCP traffic.
What is the most likely reason this intra-VLAN traffic is being blocked?
APort4 is not configured as a trusted port.
BPort1 is configured as an untrusted port.
CThe DHCP requests are being sent on the wrong VLAN.
DThe Student VLAN must be configured as an allowed VLAN on port1.
Refer to the exhibits.
Network topology —
DHCP snooping database —
All three FortiSwitch-connected ports are configured in VLAN 10. FortiGate operates as the Dynamic Host Configuration Protocol (DHCP) server and is connected to a DHCP-snooping trusted trunk port. PC1 and PC2 connect to ports configured as untrusted for DAI, and no static bindings are configured in the IP source guard (IPSG) database.
PC2 is compromised and tries to spoof the FortiGate IP address by transmitting forged Address Resolution Protocol (ARP) replies using its own MAC address. What will FortiSwitch do with the ARP packets from PC2?
AForward the ARP replies because there are no IPSG bindings blocking them.
BAccept the ARP replies because the VLAN has DAI enabled and FortiGate is a trusted DHCP server.
CForward the ARP replies to all VLAN 10 ports because DAI is only active on trusted ports.
DDrop the ARP replies because they fail DAI validation against the DHCP snooping database.
How does FortiSwitch choose the route for traffic passing through its interfaces?
AHardware-based routing on FortiSwitch is handled by the CPU.
BASIC hardware routing can handle only dynamic routing, if supported.
CFortiSwitch looks up the hardware routing table and then the forwarding information base (FIB).
DFortiSwitch forwards all traffic to FortiGate for routing decisions.
Which two statements about 802.1X authentication on FortiSwitch ports are correct?
Choose two
AIn port-based 802.1x, all hosts behind an authenticated port are allowed access after a successful authentication.
BA port policy is used to apply 802.1x authentication on a FortiSwitch interface.
C802.1X authentication can be applied only to trunk ports and not access ports.
DAll devices connecting to FortiSwitch must support 802.1X authentication.
What happens to the existing standalone configuration when you change a FortiSwitch management mode from standalone to managed?
AFortiSwitch registers to FortiSwitch Cloud to save a copy before managing with FortiGate.
BFortiSwitch merges the existing standalone configuration with the default FortiLink configuration.
CFortiSwitch saves the standalone configuration and changes to the default FortiLink configuration.
DFortiGate automatically saves the existing FortiSwitch configuration during the FortiLink management process.
You must mirror traffic from a source port on Switch A to a monitoring device on Switch C. To do this, you are configuring Remote Switched PortAnalyzer (RSPAN).
Because of the nature of RSPAN, what is the recommended practice when configuring it?
AUse a dedicated VLAN assigned only to motoring devices.
BUse the RSPAN VLAN as a native VLAN on all trunk ports.
CUse the same VLAN already configured for regular data traffic.
DUse a dynamic VLAN that includes all switch ports.
Which three actions can a FortiSwitch access control list (ACL) validly apply to traffic that matches it?
Community Discussion