Pass Fortinet NSE5_FSW_AD-7.6 Exam Info and Free Practice Test
New 2026 Latest Questions NSE5_FSW_AD-7.6 Dumps - Use Updated Fortinet Exam
Fortinet NSE5_FSW_AD-7.6 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
NEW QUESTION # 37
(Full question statement start from here)
You are deploying a FortiSwitch virtual stack in a network that contains Cisco devices. You want the Cisco devices toautomatically discover the FortiSwitch devices and exchange device information. Which two protocols must be enabled on the FortiSwitch devices to achieve this? (Choose two answers)
- A. Unidirectional Link Detection
- B. Link Layer Discovery Protocol
- C. Cisco Discovery Protocol
- D. LLDP - Media Endpoint Discovery
Answer: B,C
Explanation:
In mixed-vendor network environments, such as deployments that include bothFortiSwitchandCiscodevices, properLayer 2 discovery protocolsmust be enabled to allow devices to automatically discover neighbors and exchange essential device and interface information. FortiSwitchOS 7.6 supports bothCisco Discovery Protocol (CDP)andLink Layer Discovery Protocol (LLDP)to ensure interoperability.
Cisco Discovery Protocol (CDP)is a Cisco-proprietary Layer 2 discovery protocol widely used by Cisco switches, routers, and IP phones. When CDP is enabled on FortiSwitch interfaces, Cisco devices can discover FortiSwitch neighbors and receive information such as device ID, port ID, platform, and capabilities. This is particularly important in Cisco-centric networks where CDP is the primary discovery mechanism.
Link Layer Discovery Protocol (LLDP), defined by IEEE 802.1AB, is a vendor-neutral discovery protocol supported by both Fortinet and Cisco devices. Enabling LLDP allows FortiSwitch and Cisco devices to exchange standardized information including system name, port description, VLAN information, and management address. LLDP is essential for cross-vendor compatibility and is commonly enabled by default in modern enterprise networks.
The remaining options are incorrect.Unidirectional Link Detection (UDLD)is used to detect unidirectional fiber or copper link failures and does not provide device discovery or information exchange.LLDP-MEDis an extension of LLDP specifically designed for media endpoints such as IP phones and is not required for general switch-to-switch discovery.
Therefore, to ensure automatic discovery and information exchange between FortiSwitch and Cisco devices, both CDP and LLDP must be enabled, makingOptions B and Cthe correct and fully verified answers based on FortiSwitchOS 7.6 documentation.
NEW QUESTION # 38
Refer to the diagnostic output:
What makes the use of the sniffer command on the FortiSwitch CLI unreliable on__port__23?
- A. The switch port might be used as a trunk member
- B. Only untagged VLAN traffic can be captured.
- C. Just the port egress payloads are printed on CLI.
- D. The types of packets captured is limited.
Answer: D
Explanation:
Page 452 of 7.2 study guide, specifically states "Although you can use the sniffer command to capture traffic on switch ports, the types of packets capture by the sniffer are very limited.
The use of the sniffer command on FortiSwitch CLI can be unreliable on port 23 for specific reasons related to the nature of traffic on the port:
D).The switch port might be used as a trunk member.When a switch port is configured as a trunk, it can carry traffic for multiple VLANs. If the sniffer is set up without specifying VLAN tags or a range of VLANs to capture, it may not accurately capture or display all the VLAN traffic due to the volume and variety of VLAN-tagged packets passing through the trunk port. This limitation makes using the sniffer on a trunk port unreliable for capturing specific VLAN traffic unless properly configured to handle tagged traffic.
References:
For guidelines on how to properly use sniffer commands on trunk ports and configure VLAN filtering, consult the FortiSwitch CLI reference available through Fortinet support channels, including theFortinet Knowledge Base.
NEW QUESTION # 39
What are two ways in which automatic MAC address quarantine works on FortiSwitch? (Choose two.)
- A. MAC address quarantine can be enabled through the FortiGate CLI only.
- B. FortiGate applies the quarantine-related configuration only on FortiGate.
- C. FortiSwitch supports only by VLAN quarantine mode.
- D. FortiAnalyzer with a threat detection services license is required.
Answer: A,D
Explanation:
Reference: FortiSwitch 7.2 Study Guide, page 263
NEW QUESTION # 40
(Full question statement start from here)
Refer to the exhibit.


Which information does FortiGate use to generate the port details in the FortiSwitch Faceplates view?
(Choose one answer)
- A. The FortiLink discovery frames sent by FortiSwitch
- B. The LLDP advertisements received from the FortiSwitch
- C. The Cisco Discovery Protocol (CDP) advertisements from FortiSwitch
- D. The FortiSwitch model
Answer: B
Explanation:
In a FortiLink-managed switching architecture, the FortiGate firewall acts as the centralized controller for downstream FortiSwitch devices. TheFortiSwitch Faceplatesview in the FortiGate GUI provides a physical- style representation of switch ports, including port numbers, operational status, link state, speed, duplex, and connected neighbor information. According to FortiOS 7.6 and FortiSwitchOS 7.6 documentation from Fortinet, this port-level intelligence is derived fromLink Layer Discovery Protocol (LLDP)advertisements received from the FortiSwitch.
LLDP is an IEEE 802.1AB standard protocol used for vendor-neutral Layer 2 neighbor discovery.
FortiSwitch periodically sends LLDP frames that include detailed port descriptors such as chassis ID, port ID, port description, system name, system capabilities, and VLAN-related attributes. When FortiGate receives these LLDP advertisements over the FortiLink interface, it correlates the information with the managed FortiSwitch inventory and renders accurate port details in the Faceplates view.
Other options are incorrect for the following reasons. The FortiSwitch model alone is insufficient to populate per-port operational details. Cisco Discovery Protocol (CDP) is a Cisco-proprietary protocol and is not used by FortiGate for Faceplates visualization. FortiLink discovery frames are used to establish and maintain the FortiLink management relationship, but they do not carry the granular per-port metadata required for the Faceplates display.
Therefore, the Faceplates view relies specifically onLLDP advertisements received from the FortiSwitch, making optionCthe correct and fully verified answer based on FortiOS 7.6 and FortiSwitchOS 7.6 behavior.
NEW QUESTION # 41
How is traffic routed on FortiSwitch?
- A. Hardware-based routing on FortiSwitch is handled by the CPU.
- B. Layer 3 routing can be configured on FortiSwitch, while managed by FortiGate.
- C. ASIC hardware routing can only handle dynamic routing, if supported.
- D. FortiSwitch looks up the hardware routing table and then the forwarding information base (FIB).
Answer: B
Explanation:
Layer 3 routing can be configured on FortiSwitch, while managed by FortiGate (D): FortiSwitch, when managed by FortiGate, supports Layer 3 routing capabilities. This allows for routing between VLANs directly on the switch, enhancing network efficiency by reducing the need to pass traffic through higher network layers for inter-VLAN communication. This configuration enables more sophisticated network setups and efficient routing directly at the switch level.
NEW QUESTION # 42
Which two statements about DHCP snooping enabled on a FortiSwitch VLAN are true? (Choose two.)
- A. switch-controller-dhcp-snooping-verify-mac verifies the destination MAC address to protect against DHCP exhaustion attacks.
- B. Settings related to DHCP option 82 are only configurable through the CLI
- C. By default, all FortiSwitch ports are set to forward client DHCP requests to untrusted ports.
- D. Enabling DHCP snooping on a FortiSwitch VLAN ensures requests and replies are seen by all DHCP servers.
Answer: A,B
Explanation:
* Switch-controller-dhcp-snooping-verify-mac verifies the destination MAC address to protect against DHCP exhaustion attacks (B): This feature of DHCP snooping helps prevent DHCP exhaustion attacks by ensuring that the destination MAC addresses in DHCP packets match the MAC addresses learned by the switch. This check helps prevent attackers from overwhelming the DHCP server with requests from spoofed MAC addresses.
* Settings related to DHCP option 82 are only configurable through the CLI (D): DHCP Option 82 is used for "agent information," and it's typically used in network environments where additional information between DHCP clients and servers is necessary for policy and billing purposes.
Configuration of these settings in FortiSwitch is only available through the Command Line Interface (CLI), not the Graphical User Interface (GUI).
NEW QUESTION # 43
Which two types of Layer 3 interfaces can participate in dynamic routing on FortiSwitch? (Choose two.)
- A. Loopback interfaces
- B. Detected management interfaces
- C. Switch virtual interfaces
- D. Physical interfaces
Answer: A,C
Explanation:
In dynamic routing on FortiSwitch, certain types of interfaces are utilized to participate in the routing processes. The types of interfaces that can be used include:
* Loopback Interfaces (B):Loopback interfaces are virtual interfaces that are always up, making them ideal for use in routing protocols where a stable interface is necessary. They are commonly used to establish router IDs and manage routing information more reliably.
* Switch Virtual Interfaces (C):Switch Virtual Interfaces (SVIs) are assigned to VLANs and can have IP addresses assigned to them, making them capable of participating in Layer 3 routing. SVIs are essential for routing between different VLANs on a switch and can participate in dynamic routing protocols to advertise networks or make routing decisions.
Physical Interfaces (D)andDetected Management Interfaces (A)are not typically used directly by dynamic routing protocols for their operations in the context of FortiSwitch.
References:For more information on how these interfaces interact with dynamic routing protocols, you can check the FortiSwitch documentation on Fortinet's official documentation site:Fortinet Product Documentation
NEW QUESTION # 44
Refer to the exhibit.
After reviewing the CLI command output, which two conclusions can you make about the Dynamic Host Configuration Protocol (DHCP) snooping configuration? (Choose two answers)
- A. DHCP broadcasts are not restricted.
- B. All ports are untrusted, except port2.
- C. Option 82 is enabled on VLAN 10.
- D. DHCP snooping is disabled globally.
Answer: A,C
Explanation:
According to theFortiSwitchOS 7.6 Administration Guideand theFortiSwitch 7.6 Study Guide, DHCP snooping is a security feature that acts as a firewall between untrusted hosts and trusted DHCP servers. It validates DHCP messages from untrusted sources and filters out invalid messages.
The provided debug output reveals specific configuration details that support the correct answers:
* Option 82 Support (Option C):The output line option82-enabled-vlans : 10 explicitly indicates that DHCP Option 82 is active for that specific VLAN. When Option 82 is enabled on a VLAN, the FortiSwitch (acting as a relay agent or snooping device) inserts information about the physical port and VLAN into the DHCP request packet before it is forwarded to the server. This allows the server to apply location-based IP address allocation policies.
* Broadcast Traffic Handling (Option D):In the "DHCP Global Configuration" section, theDHCP Broadcast Modeis set toAll. In FortiSwitchOS 7.6, the default behavior for DHCP snooping is to forward DHCP broadcast traffic to all ports in the VLAN unless explicitly restricted. Setting the mode to "All" means the switch does not limit the propagation of DHCP broadcast packets solely to trusted interfaces; instead, they are flooded to both trusted and untrusted ports within the broadcast domain. To restrict broadcasts, the mode would need to be changed to "Trusted-Only".
Regarding the incorrect options:Option Ais false because the output shows snoop-enabled-vlans : 10, confirming it is active.Option Bis incorrect because the trusted ports list includes port2, FlInK1, and MLAG0, meaning multiple interfaces are trusted, not just port2.
NEW QUESTION # 45
What can an administrator do to maintain a FortiGate-compatible FortiSwitch configuration when changing the management mode from standalone to FortiLinK?
- A. Enable the FortiLink setting on FortiSwitch before the authorization process.
- B. Use a migration tool based on Python script to convert the configuration.
- C. Register FortiSwitch to FortiSwitch Cloud to save a copy before managing with FortiGate.
- D. FortiGate automatically saves the existing FortiSwitch configuration during the FortiLink management process.
Answer: D
NEW QUESTION # 46
FortiGate is unable to establish a tunnel with the FortiSwitch device it is supposed to manage Based on the debug output shown in the exhibit, what is the reason for the failure?
- A. The handshake process timed out before FortiSwitch responded.
- B. The CAPWAP tunnel failed to come up due to a mismatch in time.
- C. FortiSwitch has disabled FortiLink and is only managed as a standalone.
- D. DTLS client hello had the incorrect pre-shared key.
Answer: B
Explanation:
The issue described pertains to the establishment of a tunnel (likely a CAPWAP tunnel for management purposes between FortiGate and FortiSwitch).Based on typical error analysis in tunnel setup scenarios:
* The CAPWAP tunnel failed to come up due to a mismatch in time (Option C): This answer is plausible because time synchronization is crucial for security protocols that underpin tunnel establishments, such as DTLS (Datagram Transport Layer Security) used within CAPWAP tunnels. If the clocks on FortiGate and FortiSwitch are significantly out of sync, the security handshake (which can include timestamp validation) could fail, preventing the tunnel from coming up.
References:
Fortinet's technical documentation typically outlines the importance of time synchronization for secure communications. In CAPWAP/DLTS scenarios, precise time matching is crucial to ensure that the cryptographic parameters align correctly during the handshake process.
NEW QUESTION # 47
Which packet capture method allows FortiSwitch to capture traffic on trunks and management interfaces?
- A. Sniffer profile
- B. TCP dump
- C. SPAN
- D. sFlow
Answer: A
Explanation:
FortiSwitch supports packet capture through various methods, but the Sniffer profile is specifically capable of capturing traffic on both trunks and management interfaces.Here's why:
* Sniffer Profile (B):
* Versatile Capture:The sniffer profile in FortiSwitch is designed to capture traffic across different types of interfaces, including trunks (where multiple VLANs are present) and management interfaces (used for controlling and monitoring the switch).
* Configuration Flexibility:You can configure sniffer profiles to target specific traffic, offering flexibility in monitoring and troubleshooting network issues on both data and management planes.
* Other Options:
* SPAN (A)is used mainly for mirroring traffic to another port for analysis but is typically limited in its ability to capture management interface traffic.
* sFlow (C)andTCP dump (D)are useful tools but do not specifically align with the capability to universally capture traffic across trunks and management interfaces in the context described.
References:For further details on configuring and utilizing sniffer profiles on FortiSwitch, refer to the FortiSwitch management documentation:Fortinet Product Documentation
NEW QUESTION # 48
In which two ways can you assign a FortiSwitch port to a VDOM using multi-tenancy setup? (Choose two.)
- A. Remove the managed FortiSwitch and allocate ports directly on FortiSwitch.
- B. Assign a port to a VDOM directly on the managed FortiSwitch.
- C. Switch the FortiLink interface to the target VDOM.
- D. Create a virtual port pool on the FortiGate CLI.
Answer: C,D
Explanation:
In a multi-tenancy setup on FortiGate, you can assign a FortiSwitch port to a VDOM in two primary ways:
* Switch the FortiLink Interface to the Target VDOM (A): This method involves configuring the FortiLink interface, which is the dedicated interface used to manage FortiSwitch units from FortiGate, to operate within a specific VDOM. This effectively assigns all ports on the FortiSwitch, managed through that FortiLink interface, to the designated VDOM.
* Create a Virtual Port Pool on the FortiGate CLI (C): Virtual port pools are created on FortiGate and allow ports from FortiSwitch to be grouped and assigned to a VDOM. This method is more granular and flexible, as it allows specific ports on the FortiSwitch to be dedicated to different VDOMs without requiring the entire switch or FortiLink interface to be dedicated to a single VDOM.
NEW QUESTION # 49
What does the switchauto-networksetting control on FortiSwitch? (Choose one answer)
- A. The root bridge priority for Multiple Spanning Tree Protocol (MSTP)
- B. The automatic VLAN assignment based on connected devices
- C. Whether the FortiSwitch can be managed by FortiManager
- D. The automatic discovery of the FortiGate->FortiLink interface
Answer: D
Explanation:
According to theFortiSwitchOS 7.6 Administration Guideand theFortiSwitch 7.6 Study Guide, the auto- network setting (configured via config switch auto-network) is a global feature introduced to simplify the initial deployment of switches. Starting inFortiSwitchOS 7.2.0and continuing through7.6, this feature is enabled by defaulton all new and factory-reset units.1 The primary function of theauto-networksetting is to facilitate theautomatic discovery of the FortiGate and the establishment of the FortiLink interface (Option B). When enabled, the switch automatically scans its physical ports to detect a management entity, such as a FortiGate controller. This "zero-touch" discovery mechanism allows the switch to identify the correct uplink ports and automatically configure them as members of theFortiLinkfabric without manual CLI or GUI intervention.
Furthermore, the documentation notes that auto-network also managesauto-topology, which allows two switches to automatically form anInter-Switch Link (ISL)trunk between them.2This includes setting the management VLAN (typically VLAN 4094) and ensuring that DHCP snooping is trusted on these discovered links.3If an administrator intends to use the switch in a strictly standalone mode without any auto-discovery or FortiLink features, the documentation specifies that they must manually disable the auto-network status and the auto-fortilink-discovery global settings to prevent the switch from attempting to join a managed fabric.
4
Regarding other options:Option Arefers to Dynamic Port Policy or NAC features.Option Cis a standard STP configuration unrelated to the auto-network discovery suite.Option Dis a broader management capability that depends on successful network discovery but is not the specific control point for the auto-network setting.
NEW QUESTION # 50
Refer to the exhibits

Traffic arriving on port2 on FortiSwitch is tagged with VLAN ID 10 and destined for PC1 connected on port1. PC1 expects to receive traffic untagged from port1 on FortiSwitch. Which two configurations can you perform on FortiSwitch to ensure PC1 receives untagged traffic on port1? (Choose two.)
- A. Add VLAN ID 10 as a member of the untagged VLANs on port1.
- B. Enable Private VLAN on VLAN 10 and add VLAN 20 as an isolated VLAN.
- C. Add the MAC address of PC1 as a member of VLAN 10.
- D. Remove VLAN 10 from the allowed VLANs and add it to untagged VLANs on port1.
Answer: A,D
Explanation:
According to theFortiSwitchOS 7.6 Administration Guideand theFortiSwitch 7.6 Study Guide, the way a FortiSwitch handles VLAN tags on egress (outgoing) traffic is governed by the port'sNative VLANand its Untagged VLAN list. When traffic for VLAN 10 arrives at port2 (the uplink) and is forwarded to port1, the switch must determine whether to strip the 802.1Q tag before transmission.
* Untagged VLAN List (Option B):The documentation explicitly states that the "untagged VLAN list" specifies VLANs for which the port will transmit frameswithout the VLAN tag. By adding VLAN ID
10 to the untagged VLANs on port1, any traffic belonging to VLAN 10 will have its tag stripped at the egress point, ensuring PC1 receives a standard untagged frame.
* Configuration Logic (Option C):In FortiSwitch management, moving a VLAN from the "Allowed" list (which typically implies tagged delivery) to the "Untagged" list on a specific interface forces the switch to perform the tag-stripping action. This effectively converts the port from a trunked behavior for that VLAN to an "access" or untagged behavior.
Regarding the incorrect options:Option A (MAC-based assignment)is used primarily foringress classification. While it can assign a device to a VLAN when it sends trafficintothe switch, the documentation notes that by default, egress packets for MAC-based VLANs still include the tag unless the untagged list is configured.Option D(Private VLANs) is a security feature for isolating traffic between ports within the same VLAN and does not address the physical tagging requirements of the endpoint.
NEW QUESTION # 51
What happens when a routed VLAN interface (RVI) is configured on a FortiSwitch port or trunk? (Choose one answer)
- A. The port becomes a layer 3 interface with VLAN 4095 assigned automatically.1
- B. All VLANs on the port are terminated in a trunk by default.
- C. The port becomes a layer 3 interface and assigned to VLAN 1.
- D. VLAN 1 is automatically assigned for management.
Answer: A
Explanation:
According to theFortiSwitchOS 7.6 Administration Guideand theFortiSwitch 7.6.1 Administration Guide-Standalone Mode, aRouted VLAN Interface (RVI)is a physical port or trunk interface that is converted to support Layer 3 routing protocols.2This transformation changes the fundamental nature of the interface from a switching component to a routing component.
When an RVI is enabled on a specific physical port or trunk, the system automatically assignsVLAN 4095to that interface at the backend.3This specific VLAN ID is reserved across the FortiSwitch platform to signal that the interface is no longer operating as a standard Layer 2 switch port.4Once configured as an RVI, the interface supports advanced Layer 3 features such asOSPF, BGP, RIP, IS-IS, and static routing, as well as Virtual Routing and Forwarding (VRF)for routing isolation.5 Importantly, the documentation states that upon enabling RVI,Layer 2 protocols(such as Spanning Tree Protocol or 802.1X port-based security) and most standard switch interface features aredisabledon that port.
6This is because the port is now treated as a dedicated Layer 3 "routed" interface rather than a member of the Layer 2 switching fabric.7Additionally, if the underlying physical port or trunk interface is administratively shut down, the associated RVI will also transition to a "down" state.
NEW QUESTION # 52
(Full question statement start from here)
How does FortiSwitch determine the route for traffic traversing its interfaces? (Choose one answer)
- A. FortiSwitch looks up the hardware routing table and then the forwarding information base (FIB).
- B. ASIC hardware routing can handle only dynamic routing, if supported.
- C. Hardware-based routing on FortiSwitch is handled by the CPU.
- D. FortiSwitch forwards all traffic to FortiGate for routing decisions.
Answer: A
Explanation:
FortiSwitch determines how traffic is routed by leveraging atwo-tier routing lookup mechanismthat prioritizes hardware-based forwarding before software-based processing. According to theFortiSwitchOS 7.6 Administrator Guide, FortiSwitch first checks thehardware routing table, which is populated with a subset of routes installed from the Forwarding Information Base (FIB) and programmed directly into the switch ASIC.
The hardware routing table contains routes that are eligible for ASIC acceleration. When a packet arrives on a FortiSwitch interface, the switch performs a lookup in this hardware routing table. If a matching route is found, the packet is forwarded at wire speed using ASIC-based forwarding, which provides optimal performance and minimal latency. This process is referred to ashardware-based routing.
If no matching route exists in the hardware routing table, FortiSwitch then performs a lookup in the Forwarding Information Base (FIB), which resides in the kernel. Routes in the FIB are handled by the CPU and processed throughsoftware-based routing. This fallback mechanism ensures correct forwarding behavior even when routes cannot be offloaded to hardware.
The FortiSwitchOS documentation explicitly states that the hardware routing table indicates which routes in the FIB are installed in hardware. This confirms that routing decisions are not exclusively offloaded to FortiGate, nor are they limited to CPU-based processing alone. Instead, FortiSwitch uses ahierarchical lookup order: hardware routing table first, followed by the FIB.
Therefore, the correct and fully documented answer isC. FortiSwitch looks up the hardware routing table and then the forwarding information base (FIB).
NEW QUESTION # 53
Refer to the exhibit.
Core-1 and Access-1 are managed and authorized by FortiGate-1. which uses port4 as the FortiLink interface.
After FortiGate authorizes and manages Core-2. Port1 status becomes STP discarding.
Why is port1 in the discarding state?
- A. Access-1 is the root bridge and can only have one root port.
- B. port1 on Core-2 is discarding only management traffic.
- C. Core-2 has the lowest bridge priority.
- D. Core-1 and Core-2 do not have MCLAG configuration.
Answer: D
Explanation:
The STP (Spanning Tree Protocol) discarding state on port1 of Core-2, after Core-1 and Access-1 are managed and authorized by FortiGate-1, is likely due to the lack of an MCLAG (Multi-Chassis Link Aggregation Group) configuration between Core-1 and Core-2. In typical network configurations involving STP and MCLAG, the absence of MCLAG can lead to STP blocking one of the redundant paths to prevent loops, which is a critical function of STP. Port1 on Core-2 being in a discarding state suggests that it has been identified as providing a redundant path that could potentially create a network loop, hence STP has placed this port in a blocking (discarding) state to maintain a loop-free topology.
References:
For a deeper understanding of STP operations and MCLAG configurations in FortiGate managed environments, consult the Fortinet knowledge base:Fortinet Knowledge Base.
NEW QUESTION # 54
Refer to the exhibit.
The security port policy is configured as shown in the exhibit. Which behavior occurs if a device connected to the port that does not support 802.1X? (Choose one answer)
- A. The device is placed into the onboarding VLAN.
- B. The device is assigned to the default management VLAN.
- C. The device is placed into the quarantine VLAN.
- D. The device is blocked from accessing the network.
Answer: A
Explanation:
According to theFortiSwitchOS 7.6 Administration Guideand theFortiSwitch 7.6 Study Guide, the interaction between a managed switch and a connected endpoint depends on whether the endpoint can participate in the 802.1X authentication process. When a security policy is applied to a port, the switch sends EAP (Extensible Authentication Protocol) requests to the device to initiate the login.
The FortiSwitch handles two primary failure scenarios differently:
* Non-supplicant (No 802.1X Support):If a device, such as a legacy PC or a basic printer, does not have an 802.1X supplicant, it will not respond to the switch's EAP requests. In this case, the switch waits for the duration specified in theGuest authentication delayfield (30 seconds in the exhibit). Once this timer expires without a response, the switch places the device into theGuest VLAN. As shown in the exhibit, the Guest VLAN is explicitly set to"onboarding.fortilink (onboarding)".
* Authentication Failure:If a devicedoessupport 802.1X but the user provides incorrect credentials, the RADIUS server returns an Access-Reject message. In this scenario, the device is moved to the Authentication fail VLAN, which the exhibit identifies as"quarantine.fortilink (quarantine)".
Note:BecauseMAC authentication bypass (MAB)is disabled in the exhibit, the switch will not attempt to authenticate the device's MAC address against the RADIUS server before defaulting to the Guest VLAN.
Therefore, for any device lacking an 802.1X supplicant, the result is placement into theonboardingVLAN.
NEW QUESTION # 55
You are managing FortiSwitch ports from a FortiGate device with multiple VDOMs. Which two methods can you use to assign FortiSwitch ports to VDOMs? (Choose two answers)
- A. Assigning the port directly to a specific VDOM for dedicated physical isolation
- B. Use interface role mapping to dynamically assign FortiSwitch ports to VDOMs based on Dynamic Host Configuration Protocol (DHCP) scope
- C. Using a virtual port pool (VPP) to create virtualized ports that can be assigned to different VDOMs
- D. Use FortiGate policies to control inter-VDOM traffic for FortiSwitch ports
Answer: A,C
Explanation:
According to theFortiOS 7.6 Administration Guideand theFortiSwitch 7.6 FortiLink Guide, managing FortiSwitch units in a multi-VDOM environment allows for granular control over physical switch resources.
By default, when a FortiSwitch is discovered and authorized via FortiLink, its ports reside in the same VDOM as the FortiLink interface (typically the root or a dedicated management VDOM).
To allocate these ports to other VDOMs, administrators have two primary methods. The first method isdirect assignment(Option A). Using the FortiGate CLI or GUI, an administrator can export a specific physical port directly to a target VDOM. For example, the command set export-to <VDOM_name> under the config switch- controller managed-switch port settings physically isolates that port for use only by the specified VDOM.
This is ideal for multi-tenant scenarios where a specific physical connection must be dedicated to a single business unit.
The second method involves using aVirtual Port Pool (VPP)(Option D). This method provides a layer of virtualization for switch ports. An administrator first creates a pool (VPP) in the management VDOM and assigns physical ports to it. Then, from the tenant VDOM, an administrator can "request" a port from that specific pool. This allows for a more flexible "shared" infrastructure where ports are not permanently tethered to a single VDOM until they are claimed from the pool. Both methods ensure that traffic remains logically and physically isolated between VDOMs, supporting the security requirements of complex enterprise deployments. Options B and C are incorrect as they relate to traffic routing and device identification rather than the foundational assignment of hardware ports to virtual domains.
NEW QUESTION # 56
Refer to the exhibits. An IP phone is connected to port1 of FortiSwitch Access-1. The IP phone tags its traffic with VLAN ID 20. On FortiGate, VLAN IP_Phone (VLAN ID 20) has been configured, and port1 of Access-
1 is set with VLAN 20 as the native VLAN. However, the IP phone cannot reach the network. The exhibit shows the partial VLAN configuration and the port1 configuration on Access-1.
Which configuration change must you make on FortiSwitch to allow ingress and egress traffic for the IP phone? (Choose one answer)
- A. On port1, add VLAN 20 to the allowed_vlans list
- B. On port1, disable the edge_port
- C. On VLAN IP_Phone, enable l2forward
- D. On VLAN IP_Phone, enable vlanforward
Answer: A
Explanation:
According to theFortiSwitchOS 7.6 Administration GuideandFortiOS 7.6 FortiLink Guide, the processing of Ethernet frames on a managed FortiSwitch port depends on whether the frame is tagged or untagged upon arrival (ingress) and how the port's VLAN membership is defined.
In the provided exhibit,port1is configured with set vlan "IP_Phone" (VLAN 20) as itsnative VLAN. By definition, the native VLAN handles untagged traffic; any untagged frame arriving at the port is assigned to VLAN 20, and any egress traffic from VLAN 20 is sent out of the port without a tag. However, the scenario specifically states that theIP phone tags its traffic with VLAN ID 20.
When a FortiSwitch receives atagged frame, it checks the VLAN ID against theallowed-vlanslist configured on that port. Although VLAN 20 is the native VLAN, the exhibit shows that the port has been explicitly configured with set allowed-vlans "quarantine". This creates a restrictive filter that permits only tagged frames belonging to the "quarantine" VLAN to enter or exit the port. Because VLAN 20 (IP_Phone) is not present in the allowed-vlans list, the switch drops the tagged frames from the IP phone during ingress processing.
To resolve this, the administrator must modify theFortiSwitch port configurationby adding VLAN 20 to the allowed_vlans list (e.g., set allowed-vlans "quarantine" "IP_Phone" or set allowed-vlans-all enable). This ensures that the switch recognizes and permits tagged traffic for VLAN 20 on that physical interface. Option B is incorrect because l2forward is a Layer 3 interface setting on the FortiGate and does not address the physical port's ingress filtering logic on the switch. Disabling the edge_port (Option D) relates to Spanning Tree Protocol (STP) convergence and would not impact VLAN tag filtering.
NEW QUESTION # 57
Refer to the exhibits.
Port1 and port2 are the only ports configured with the same native VLAN 10.
What are two reasons that can trigger port1 to shut down? (Choose two.)
- A. STP triggered a loop and applied loop guard protection on port1.
- B. An endpoint sent a BPDU on port1 that it received from another interface.
- C. port1 was shut down by loop guard protection.
- D. Loop guard frame sourced from port 1 was received on port 1.
Answer: A,C
Explanation:
When loop guard is enabled on port1 and port2 configured with the same native VLAN (VLAN 10), there are specific scenarios under which port1 can be shut down due to loop guard operation:
A).port1 was shut down by loop guard protection.Loop guard is a specific feature used in network environments to prevent alternative or redundant loops. When loop guard is active, it can shut down a port if it stops receiving BPDU (Bridge Protocol Data Units) on a port that is expected to receive them, assuming a loop or link failure and putting the port into an inconsistent state to prevent potential loops.
B).STP triggered a loop and applied loop guard protection on port1.If the Spanning Tree Protocol (STP) detects a loop or loss of BPDU transmissions while loop guard is enabled, it will proactively shut down the port to prevent network instability or a broadcast storm. This is an essential function of loop guard within the context of STP, providing additional protection against topology changes that could introduce loops.
References:
Additional details about loop guard functionality and STP interaction can be found in the FortiSwitch administration guides, accessible viaFortinet Documentation.
NEW QUESTION # 58
(Full question statement start from here)
How does enabling an IGMP snooping proxy on FortiSwitch help reduce the number of IGMP reports processed by the IGMP querier? (Choose one answer)
- A. By converting IGMP reports into broadcast packets to reach all VLAN members
- B. By forwarding IGMP reports only when the first member joins and the last member leaves
- C. By converting IGMP traffic to unicast
- D. By suppressing duplicate IGMP reports within the VLAN
Answer: B
Explanation:
In FortiSwitchOS 7.6,IGMP snooping proxyis an enhancement to standard IGMP snooping that optimizes multicast control-plane traffic between hosts, switches, and the upstream IGMP querier. Its primary purpose is toreduce the number of IGMP membership reportsthat the querier must process, thereby improving scalability and efficiency in multicast-enabled networks.
Without an IGMP snooping proxy, every multicast receiver on a VLAN independently sends IGMP membership reports to the querier. In environments with many hosts subscribing to the same multicast groups, this behavior can generate a large volume of redundant IGMP reports, unnecessarily increasing control-plane load on both the querier and intermediate network devices.
When the IGMP snooping proxy feature is enabled, the FortiSwitch acts as anIGMP proxy agenton behalf of hosts within the VLAN. The switch tracks multicast group membership locally andsuppresses individual IGMP reports from downstream hosts. Instead, the FortiSwitch forwards an IGMP report upstreamonly when the first host joins a multicast group. Likewise, when hosts leave the group, the switch sends an IGMP leave message or reportonly when the last remaining member leaves.
This aggregation mechanism dramatically reduces IGMP signaling traffic while preserving correct multicast forwarding behavior. Importantly, the switch does not alter IGMP packet types or convert them to broadcast or unicast traffic. It simply optimizes reporting behavior based on group membership state.
Therefore, the correct explanation is that IGMP snooping proxy reduces IGMP report processingby forwarding IGMP reports only when the first member joins and the last member leaves, makingOption Dthe correct and fully verified answer according to FortiSwitchOS 7.6 documentation.
NEW QUESTION # 59
Which two are valid traffic processing actions that a FortiSwitch access control list (ACL) can apply to matching traffic? (Choose two answers)
- A. Redirect frames to another port.
- B. Drop frames.
- C. Encrypt frames.
- D. Assign traffic to a high-priority egress queue.
Answer: A,B
Explanation:
According to theFortiSwitchOS 7.6 Administration Guideand theNSE 5 FortiSwitch Study Guide, Access Control Lists (ACLs) are used to provide granular control over the traffic entering or leaving a switch port.
ACLs function by definingclassifiers(to match specific traffic based on criteria like MAC address, IP address, or VLAN ID) and then applying specificactionsto that matched traffic.
The documentation explicitly categorizes ACL actions into three distinct groups:
* Traffic Processing:This category includes actions that dictate the physical handling of the frame. Valid actions listed in the official documents under this header includecount(to track packet volume),drop(to block the traffic),redirect(to forward the frame to a specific physical port or interface instead of its original destination), andmirror(to send a copy to a monitoring port).
* Quality of Service (QoS):This category focuses on traffic prioritization and bandwidth management. It includes actions such asrate limiting,remarking CoS/DSCP values, andsetting the egress queue(e.g., assigning a packet to a specific queue number from 0 to 7).
* VLAN:This allows for modifications such as setting anouter VLAN tagon frames.
The question specifically asks for "traffic processing actions." Based on the 7.6 documentation,Redirect frames to another port(Option A) andDrop frames(Option D) are explicitly defined under the "Traffic Processing" action header. While "Assign traffic to a high-priority egress queue" (Option B) is a valid action an ACL can perform, it is technically categorized as aQoS action, not a traffic processing action.Encrypt frames(Option C) is not a supported ACL action on FortiSwitch hardware, as encryption is typically handled at higher layers or via dedicated MACsec configurations on specific models.
NEW QUESTION # 60
Refer to the exhibit.
Port24 is the only uplink port connected to the network where you need access to FortiSwitch management services. However, FortiSwitch is not accessible on its management interface with IP address 10.0.13.3.
Based on the configuration shown in the exhibit, which two actions should you take to fix the issue and access FortiSwitch? (Choose two answers)
- A. Remove VLAN 200 from the allowed VLANs on port24.
- B. Change the native VLAN on port24 to VLAN 4094.
- C. Change the management IP address to use the VLAN 100 subnet.
- D. Add VLAN 4094 to the allowed VLANs on port24.
Answer: B,D
Explanation:
According to theFortiSwitchOS 7.6 Administration Guide (Page 320), management traffic on a FortiSwitch is associated with a specific logical interface, which in this case is the"internal"interface. The exhibit shows that the"internal"interface is configured onVLAN 4094(both as native and allowed). This means that for any management traffic (such as HTTPS, SSH, or SNMP) to reach the switch CPU, it must be able to traverse the physical uplink on VLAN 4094.
However, the configuration forport24(the uplink) is currently restricted. It is set withnative VLAN 100and an allowed-vlans list that only includes100 and 200. Because VLAN 4094 is not included in the allowed list of port24, all frames belonging to the management VLAN (4094) are dropped by the switch's ingress/egress filters on the uplink.
To resolve this and restore management access, the administrator has two valid configuration paths based on the provided options:
* Option B:Change thenative VLAN on port24 to VLAN 4094. By making 4094 the native VLAN, untagged management traffic can traverse the port, effectively allowing the "internal" interface to communicate with the network.
* Option D:Add VLAN 4094 to the allowed VLANs on port24. This ensures that VLAN 4094 is no longer filtered out, allowing management frames to pass through the uplink while maintaining the current native VLAN for other traffic.
Option C is irrelevant as removing a working VLAN (200) does not help the management traffic. While Option A describes an alternate architectural approach (moving management into an already-allowed VLAN), Options B and D represent the direct fixes for the mismatch described in the 7.6 administration documentation.
NEW QUESTION # 61
......
Latest NSE5_FSW_AD-7.6 Exam Dumps Fortinet Exam: https://www.examslabs.com/Fortinet/Fortinet-Network-Security-Expert/best-NSE5_FSW_AD-7.6-exam-dumps.html