View Full Fortinet NSE5_FSW_AD-7.6 Exam Dumps and Practice Test Dumps.
Question 21
Which FortiSwitch feature can help prevent a device from using an unauthorized source IP address on a network port?
- IP source guard
- LLDP
- LACP
- Port mirroring
Correct Answer: 1
Explanation:
IP source guard is a security feature that helps restrict traffic based on approved IP and MAC address bindings. It can prevent a connected endpoint from spoofing an unauthorized source IP address. This is particularly useful in access-layer environments where administrators want to reduce risks associated with IP spoofing. The feature can work with information learned through mechanisms such as DHCP snooping. LLDP is mainly used for neighbor discovery, LACP is used for link aggregation, and port mirroring copies traffic for monitoring purposes. Therefore, IP source guard is the most appropriate feature for controlling the validity of source IP addresses on switch ports.
Question 22
What is the primary purpose of Dynamic ARP Inspection (DAI) on a FortiSwitch?
- To aggregate multiple physical links
- To validate ARP packets and help prevent ARP spoofing
- To synchronize switch clocks
- To discover neighboring switches
Correct Answer: 2
Explanation:
Dynamic ARP Inspection helps protect a Layer 2 network from malicious or incorrect ARP information. It examines ARP packets and can compare their IP-to-MAC information against trusted bindings. This helps reduce attacks such as ARP spoofing, where an attacker attempts to associate its MAC address with another device’s IP address. DAI is therefore an important security control in access networks. Link aggregation is handled by LACP, time synchronization is handled by NTP, and neighbor discovery can use LLDP. By validating ARP information, DAI can help maintain correct communication between hosts and reduce the possibility of man-in-the-middle attacks based on forged ARP responses.
Question 23
Which FortiSwitch feature is designed to limit excessive broadcast, multicast, or unknown-unicast traffic on a port?
- 802.1X
- LLDP
- Storm control
- RADIUS
Correct Answer: 3
Explanation:
Storm control is designed to protect a switched network from excessive Layer 2 traffic. A broadcast, multicast, or unknown-unicast storm can consume significant bandwidth and processing resources, potentially affecting other devices on the network. Storm control allows administrators to establish traffic thresholds and take action when those thresholds are exceeded. This helps maintain network stability during abnormal traffic conditions. 802.1X provides network access authentication, LLDP discovers neighboring devices, and RADIUS commonly provides centralized authentication services. Therefore, when the objective is to limit excessive Layer 2 traffic and protect switch resources, storm control is the appropriate feature.
Question 24
What is the main function of a FortiSwitch access port?
- Carry traffic for a single VLAN without requiring VLAN tags from the endpoint
- Carry multiple tagged VLANs between switches
- Authenticate users through RADIUS only
- Aggregate multiple physical interfaces
Correct Answer: 1
Explanation:
An access port is generally used to connect an endpoint such as a workstation, printer, IP phone, or similar device to a specific VLAN. Traffic received from the endpoint is normally untagged, while the switch associates that traffic with the configured VLAN. In contrast, trunk ports are commonly used to carry traffic belonging to multiple VLANs using VLAN tags. RADIUS is related to centralized authentication, while link aggregation combines multiple physical interfaces. Proper access-port configuration is important because it determines which VLAN an endpoint belongs to and therefore affects both connectivity and network segmentation.
Question 25
Which protocol is commonly used to authenticate network users or devices through a centralized authentication server when implementing 802.1X?
- STP
- LACP
- SNMP
- RADIUS
Correct Answer: 4
Explanation:
RADIUS is commonly used as the authentication protocol in 802.1X-based network access control. When an endpoint attempts to access the network, the switch can act as the authenticator and communicate with a RADIUS server to verify the user’s or device’s credentials. The RADIUS server can then return an authentication decision and, depending on the configuration, authorization information such as VLAN assignment. STP prevents Layer 2 loops, LACP manages link aggregation, and SNMP is primarily used for monitoring and management. Using RADIUS with 802.1X provides centralized control over authenticated network access across multiple switch ports.
Question 26
What is the primary purpose of Power over Ethernet (PoE) on a FortiSwitch?
- To encrypt Ethernet frames
- To provide electrical power to compatible devices through Ethernet cabling
- To create a routing table
- To synchronize VLAN databases
Correct Answer: 2
Explanation:
Power over Ethernet allows compatible devices to receive electrical power through Ethernet cabling instead of requiring a separate power adapter. Common PoE-powered devices include wireless access points, IP phones, and certain network cameras. A FortiSwitch with appropriate PoE capabilities can supply power directly to connected devices while also providing network connectivity. PoE simplifies deployment because fewer power outlets and separate power cables may be required at the endpoint location. Ethernet encryption, routing-table creation, and VLAN synchronization are unrelated to the fundamental purpose of PoE. Administrators should also consider the switch’s available PoE budget when deploying multiple powered devices.
Question 27
Which feature allows multiple physical Ethernet links to operate together as a logical aggregated connection?
- LACP
- DHCP snooping
- LLDP
- 802.1X
Correct Answer: 1
Explanation:
LACP, or Link Aggregation Control Protocol, allows multiple physical Ethernet links to be combined into a logical link aggregation group. This can provide increased aggregate bandwidth and redundancy between supported devices. If one physical link fails, other links in the aggregation can continue carrying traffic, depending on the configuration and available capacity. DHCP snooping is a security mechanism for validating DHCP-related traffic, LLDP provides neighbor information, and 802.1X controls authenticated network access. LACP is especially useful for switch-to-switch connections where administrators want greater resilience and improved utilization of multiple physical interfaces.
Question 28
What information can the MAC address table on a FortiSwitch primarily provide?
- DNS records for connected clients
- User passwords
- Learned MAC addresses and their associated switch ports
- RADIUS server certificates
Correct Answer: 3
Explanation:
A switch’s MAC address table contains information about MAC addresses that the switch has learned and the interfaces associated with those addresses. The switch uses this information to make Layer 2 forwarding decisions. When a frame arrives, the switch can determine whether the destination MAC address is known and, if so, forward the frame toward the appropriate port rather than flooding it to every interface. Administrators can inspect the MAC address table when troubleshooting connectivity, identifying where a device is connected, or investigating unexpected Layer 2 behavior. DNS records, passwords, and RADIUS certificates are not the primary information stored in a switch MAC address table.
Question 29
Which protocol can provide centralized time synchronization for FortiSwitch devices?
- SNMP
- NTP
- LACP
- STP
Correct Answer: 2
Explanation:
NTP, or Network Time Protocol, is used to synchronize the system clocks of network devices with an authoritative time source. Accurate time is important for network operations because logs, authentication events, troubleshooting records, and security investigations depend on reliable timestamps. In a managed FortiSwitch environment, consistent time settings make it easier to correlate events across multiple devices. SNMP is mainly used for monitoring and management, LACP provides link aggregation, and STP prevents Layer 2 loops. Configuring an appropriate NTP source therefore helps ensure that FortiSwitch event information has accurate and consistent timestamps.
Question 30
What is the main purpose of a switch trunk interface?
- To disable VLAN tagging
- To connect only one endpoint to one VLAN
- To carry traffic for multiple VLANs over a single physical link
- To provide electrical power to endpoints
Correct Answer: 3
Explanation:
A trunk interface is commonly used to transport traffic belonging to multiple VLANs across a single physical connection. VLAN tagging allows the receiving device to identify which VLAN each frame belongs to. Trunks are frequently used between switches or between a switch and another network device that needs access to several VLANs. An access port generally serves a single VLAN for an endpoint, while PoE provides electrical power and does not define the purpose of a trunk. Correct trunk configuration is important because mismatched allowed VLANs, tagging, or native VLAN settings can cause connectivity problems between network segments.
Question 31
Which FortiSwitch capability can help administrators identify neighboring network devices and their connection information?
- LLDP
- LACP
- DHCP
- NTP
Correct Answer: 1
Explanation:
LLDP, or Link Layer Discovery Protocol, allows network devices to advertise information about themselves to directly connected neighboring devices. Administrators can use LLDP information to understand physical topology, identify neighboring switches, and determine which devices are connected to particular interfaces. This can be especially useful in larger environments where manually documenting every physical connection is difficult. LACP is intended for link aggregation, DHCP provides address configuration services, and NTP synchronizes device clocks. LLDP does not replace network management, but it provides useful Layer 2 discovery information that can assist with topology visibility and troubleshooting.
Question 32
Which feature can help prevent unauthorized DHCP servers from responding to clients on a FortiSwitch network?
- Port mirroring
- DHCP snooping
- LACP
- LLDP
Correct Answer: 2
Explanation:
DHCP snooping is a Layer 2 security mechanism designed to distinguish trusted DHCP server-facing interfaces from untrusted client-facing interfaces. This helps prevent unauthorized or rogue DHCP servers from supplying incorrect network configuration information to clients. A rogue DHCP server could potentially provide an attacker-controlled gateway or DNS information, redirecting network traffic. By controlling which ports are trusted for DHCP server responses, administrators can reduce this risk. Port mirroring is intended for traffic analysis, LACP provides link aggregation, and LLDP provides neighbor discovery. DHCP snooping can therefore play an important role in securing access-layer networks.
Question 33
What is the purpose of a port mirror configuration on a FortiSwitch?
- To duplicate selected traffic to another interface for monitoring
- To increase PoE power
- To authenticate a user
- To synchronize switch clocks
Correct Answer: 1
Explanation:
Port mirroring, sometimes called SPAN, copies selected network traffic from one or more source interfaces or VLANs to a designated monitoring interface. A security appliance, packet analyzer, or troubleshooting workstation connected to the monitoring interface can then inspect the copied traffic. This can help administrators investigate connectivity problems, analyze protocols, or observe suspicious network activity without directly interrupting the original traffic flow. Port mirroring does not increase PoE capacity, perform user authentication, or synchronize time. Because mirrored traffic can consume significant bandwidth, administrators should configure the source and destination interfaces carefully and consider the capabilities of the monitoring device.
Question 34
Which authentication method can be used when a device does not support an interactive 802.1X supplicant?
- LACP
- STP
- LLDP
- MAC Authentication Bypass (MAB)
Correct Answer: 4
Explanation:
MAC Authentication Bypass, commonly called MAB, can provide an alternative authentication mechanism for devices that cannot perform normal 802.1X authentication. Instead of using an interactive 802.1X supplicant, the switch can use the device’s MAC address as an identity and send authentication information to a configured authentication server. This approach is often considered for devices such as certain printers, cameras, phones, or specialized equipment. MAB should not automatically be considered as strong as certificate- or credential-based 802.1X authentication because MAC addresses can potentially be spoofed. Nevertheless, it provides a practical method for integrating non-802.1X-capable devices into controlled access environments.
Question 35
Which FortiSwitch mechanism is primarily used to prevent Layer 2 switching loops in redundant Ethernet topologies?
- SNMP
- STP
- RADIUS
- NTP
Correct Answer: 2
Explanation:
Spanning Tree Protocol, or STP, helps prevent Layer 2 loops when redundant paths exist between switches. Without loop prevention, Ethernet frames can circulate continuously through redundant links, potentially creating broadcast storms and consuming network resources. STP builds a logical loop-free topology by placing certain redundant paths into a blocking or alternate state while keeping them available for potential use if the active path fails. RADIUS is used for authentication, SNMP provides management and monitoring capabilities, and NTP synchronizes clocks. STP is therefore a fundamental mechanism for maintaining network stability in environments with redundant Layer 2 connections.
Question 36
What is one benefit of assigning different departments to separate VLANs?
- It eliminates the need for IP addressing
- It increases the physical cable length
- It provides logical network segmentation
- It disables all broadcast traffic
Correct Answer: 3
Explanation:
VLANs provide logical segmentation within a switched network. For example, an organization can place finance, sales, guest, and management devices into separate VLANs even when those devices are connected to the same physical switching infrastructure. This separation can reduce unnecessary broadcast traffic and provide a foundation for applying different security and access policies. VLANs do not eliminate IP addressing, increase cable length, or automatically disable all broadcast traffic. Communication between different VLANs generally requires Layer 3 routing and can then be controlled with appropriate firewall or routing policies. Proper VLAN design therefore improves network organization and can strengthen security.
Question 37
Which technology is commonly used to collect network-management information from FortiSwitch devices?
- SNMP
- STP
- LACP
- PoE
Correct Answer: 1
Explanation:
SNMP, or Simple Network Management Protocol, is commonly used by network-management platforms to monitor and manage network devices. It can provide information such as interface status, traffic counters, errors, device statistics, and other operational data depending on the supported MIBs and configuration. This information helps administrators monitor device health and identify abnormal behavior. STP is responsible for Layer 2 loop prevention, LACP manages link aggregation, and PoE provides electrical power to compatible endpoints. When properly configured with appropriate access controls, SNMP can provide centralized visibility into FortiSwitch infrastructure and support ongoing network monitoring.
Question 38
What is the primary role of an 802.1X authenticator in a wired network?
- It supplies PoE power to the endpoint
- It forwards DNS queries
- It acts as the intermediary between the endpoint and authentication server
- It creates IPsec tunnels
Correct Answer: 3
Explanation:
In an 802.1X deployment, the authenticator is typically the network switch that controls whether a connected endpoint is allowed network access. The endpoint acts as the supplicant, while an authentication server such as a RADIUS server performs the authentication decision. The switch communicates with the endpoint and authentication server and controls access to the network based on the authentication result. This architecture provides centralized access control without requiring every endpoint to be manually configured with a static switch-port policy. PoE, DNS forwarding, and IPsec tunnels serve different networking functions and are not the primary role of an 802.1X authenticator.
Question 39
Why is a consistent VLAN configuration important across interconnected FortiSwitch devices?
- To ensure VLAN traffic can be correctly carried across the switching infrastructure
- To increase the RADIUS password length
- To disable all Layer 2 protocols
- To prevent NTP synchronization
Correct Answer: 1
Explanation:
Consistent VLAN configuration is important because interconnected switches must agree on how VLAN traffic is identified and transported. If a VLAN is configured on one switch but is missing from the appropriate trunk or allowed-VLAN configuration on another switch, devices in that VLAN may lose connectivity across the network. Proper VLAN configuration includes considerations such as VLAN IDs, access-port assignments, trunk permissions, and native or untagged VLAN behavior where applicable. RADIUS password length, disabling Layer 2 protocols, and preventing NTP synchronization are unrelated to VLAN consistency. Good VLAN management therefore helps maintain predictable connectivity throughout a multi-switch environment.
Question 40
Which configuration approach is most appropriate for connecting an ordinary workstation that should belong only to the employee VLAN?
- Configure the workstation port as a trunk carrying every VLAN
- Configure the workstation port as an access port assigned to the employee VLAN
- Configure the port as an LACP member without VLAN assignment
- Configure the port as an LLDP-only interface
Correct Answer: 2
Explanation:
An ordinary workstation that needs access to a single employee VLAN would normally be connected through an access port assigned to that VLAN. The endpoint generally sends and receives untagged Ethernet frames, while the switch internally associates those frames with the configured employee VLAN. A trunk is normally intended for carrying multiple VLANs and is therefore unnecessary for a standard single-VLAN workstation. LACP is used to combine multiple physical links, while LLDP is a discovery protocol rather than a port-access configuration. Assigning the workstation interface as an access port provides a simple and controlled Layer 2 connection to the intended employee network.