View Full Fortinet NSE5_FSW_AD-7.6 Exam Dumps and Practice Test Dumps.
Question 61
Which FortiSwitch feature can help limit the impact of excessive broadcast traffic on a network interface?
- RADIUS
- NTP
- Storm control
- LLDP
Correct Answer: 3
Explanation:
Storm control helps protect a switched network from excessive Layer 2 traffic such as broadcasts, multicasts, and unknown unicasts. A traffic storm can consume switch resources and bandwidth, potentially affecting legitimate users and network services. By configuring appropriate thresholds, administrators can control how much of this traffic is allowed through an interface. Storm control is particularly useful in access-layer environments where a malfunctioning device or network loop could generate unusually high traffic levels. RADIUS is used for authentication, NTP synchronizes clocks, and LLDP provides neighbor information. Therefore, storm control is the appropriate feature for limiting excessive Layer 2 traffic.
Question 62
What is the primary purpose of MAC Authentication Bypass (MAB) in a network access-control environment?
- To provide an alternative authentication method for devices that do not support 802.1X
- To aggregate multiple Ethernet links
- To prevent Layer 2 loops
- To synchronize switch clocks
Correct Answer: 1
Explanation:
MAC Authentication Bypass provides an alternative method of controlling access for devices that cannot perform standard 802.1X authentication. Instead of using an 802.1X supplicant, the network can use the device’s MAC address as part of the authentication process, commonly involving a RADIUS server. MAB is useful for devices such as some printers, cameras, phones, and specialized equipment that may not support interactive authentication. However, MAC addresses can potentially be spoofed, so MAB generally should not be considered equivalent to stronger identity-based authentication methods. Its main purpose is to extend access-control capabilities to non-802.1X-capable devices.
Question 63
Which protocol can be used to dynamically negotiate link aggregation between compatible network devices?
- STP
- DHCP
- LACP
- SNMP
Correct Answer: 3
Explanation:
LACP, or Link Aggregation Control Protocol, allows compatible network devices to dynamically establish and maintain a link aggregation group. Multiple physical Ethernet interfaces can then operate together as a logical connection. This can provide additional aggregate bandwidth and redundancy compared with a single physical connection. STP is designed for preventing Layer 2 loops, DHCP provides IP configuration information, and SNMP is primarily used for monitoring and management. LACP is especially useful when multiple physical links connect switches or other supported network devices. Both ends of the aggregation should be configured consistently to ensure that the intended links participate correctly.
Question 64
Which feature allows an administrator to identify whether a directly connected device supports LLDP?
- Port mirroring
- LLDP neighbor information
- DHCP snooping
- RADIUS accounting
Correct Answer: 2
Explanation:
LLDP neighbor information provides details advertised by directly connected devices that support the Link Layer Discovery Protocol. Depending on the device and configuration, information can include the neighboring device identity, interface, system capabilities, and other topology-related details. This makes LLDP useful when administrators need to understand how switches, access points, phones, and other network devices are physically connected. Port mirroring is used for traffic analysis, DHCP snooping protects DHCP operations, and RADIUS accounting records authentication-related activity. LLDP neighbor information is therefore the most appropriate way to determine what a directly connected LLDP-capable device is advertising.
Question 65
Why would an administrator configure DHCP snooping on access switches?
- To protect clients from unauthorized DHCP server responses
- To increase the number of physical switch ports
- To encrypt all Ethernet frames
- To provide NTP synchronization
Correct Answer: 1
Explanation:
DHCP snooping helps protect clients from rogue or unauthorized DHCP servers. In a properly configured environment, interfaces connected toward legitimate DHCP servers are treated as trusted, while typical client-facing interfaces are considered untrusted. DHCP server responses received from an untrusted interface can be blocked according to the configured policy. This reduces the risk of an attacker connecting an unauthorized DHCP server and providing clients with malicious or incorrect gateway, DNS, or IP configuration information. DHCP snooping does not increase physical port capacity, encrypt Ethernet frames, or provide time synchronization. Its primary role is improving the security and integrity of DHCP traffic.
Question 66
What is the purpose of an IP address and subnet mask assigned to a switch management interface?
- To define the switch’s management connectivity on an IP network
- To create additional physical Ethernet ports
- To aggregate links automatically
- To replace all VLAN tags
Correct Answer: 1
Explanation:
A management IP address allows administrators and management systems to communicate with the switch over an IP network. The associated subnet mask determines which IP addresses are considered part of the local network and therefore helps define how the device communicates with other hosts. Proper management addressing is important for remote administration, monitoring, configuration, and troubleshooting. Assigning a management IP does not create physical ports, automatically establish link aggregation, or replace VLAN tagging. In a production environment, management access should also be appropriately secured using authorized management networks, authentication, and access-control policies.
Question 67
Which FortiSwitch feature can help enforce a maximum number of learned MAC addresses on an access port?
- NTP
- Port security
- LLDP
- SNMP
Correct Answer: 2
Explanation:
Port security can be configured to restrict MAC address usage on a switch interface. One possible policy is to limit the number of MAC addresses that can be learned on an access port. This can help prevent unauthorized devices from being connected to a network port and can reduce certain MAC flooding or unauthorized-access risks. The exact behavior depends on the configured security options and supported FortiSwitch features. NTP is used for time synchronization, LLDP provides device-discovery information, and SNMP provides monitoring and management. Therefore, port security is the appropriate feature when controlling the number of MAC addresses associated with an interface.
Question 68
Which statement best describes the relationship between an access port and a VLAN?
- An access port normally associates endpoint traffic with a single VLAN
- An access port must always carry every VLAN
- An access port can only carry routed IP traffic
- An access port is used exclusively for SNMP
Correct Answer: 1
Explanation:
An access port is generally associated with a single VLAN and is commonly used for endpoint devices. The connected endpoint usually sends untagged Ethernet frames, and the switch assigns those frames to the VLAN configured on the port. This provides straightforward Layer 2 segmentation for devices such as workstations and printers. A trunk port, by contrast, is normally used when multiple VLANs need to traverse the same physical connection. Access ports are not limited to routed IP traffic and are not specifically related to SNMP. Correctly assigning access ports to the appropriate VLAN is an important part of implementing network segmentation.
Question 69
What is one reason administrators may use a dedicated management network for FortiSwitch devices?
- To separate administrative traffic from ordinary user traffic
- To disable switch monitoring
- To prevent administrators from accessing the switches
- To eliminate the requirement for authentication
Correct Answer: 1
Explanation:
A dedicated management network separates administrative communication from ordinary user traffic. This can improve security by limiting which devices or networks are able to reach management interfaces. It can also make troubleshooting and monitoring easier because management traffic follows a defined network path. A dedicated management network does not disable monitoring, prevent legitimate administrators from accessing the switches, or eliminate authentication requirements. Instead, it provides another layer of network segmentation that can be combined with strong authentication and access-control policies. Separating management traffic is especially useful in larger environments containing many switches and other infrastructure devices.
Question 70
Which feature can provide traffic statistics and interface counters to a network-management system?
- STP
- PoE
- SNMP
- LACP
Correct Answer: 3
Explanation:
SNMP can provide network-management systems with operational information about supported devices and interfaces. Depending on the configured MIBs and monitoring system, administrators can obtain statistics such as interface status, packet counters, errors, and traffic levels. This information can be used to monitor network health and identify potential performance issues. STP focuses on loop prevention, PoE supplies power to compatible devices, and LACP manages link aggregation. SNMP is therefore the most suitable option when the objective is to collect interface statistics and operational information from FortiSwitch devices.
Question 71
What is the primary purpose of Dynamic ARP Inspection in a secured Layer 2 network?
- To inspect and validate ARP messages
- To provide electrical power
- To aggregate switch ports
- To synchronize system clocks
Correct Answer: 1
Explanation:
Dynamic ARP Inspection helps protect Layer 2 networks by examining ARP messages and validating them against trusted IP-to-MAC binding information. ARP is vulnerable to spoofing because hosts generally trust ARP information received on the local network. An attacker can exploit this by sending forged ARP messages that associate its MAC address with another device’s IP address. DAI can help identify and block invalid ARP traffic based on the configured security policy. PoE provides power, LACP aggregates links, and NTP synchronizes clocks. Therefore, ARP inspection is the correct mechanism for validating ARP messages and reducing ARP-spoofing risks.
Question 72
Which protocol is commonly used to synchronize the clocks of FortiSwitch devices with a reliable time source?
- RADIUS
- NTP
- LLDP
- LACP
Correct Answer: 2
Explanation:
Network Time Protocol, or NTP, is used to synchronize device clocks with a configured time source. Accurate time is important for network infrastructure because logs, authentication events, monitoring records, and security investigations rely on reliable timestamps. If different switches have significantly different system times, correlating events across multiple devices can become difficult. RADIUS is commonly used for authentication, LLDP provides neighbor discovery, and LACP manages link aggregation. Configuring NTP consistently across the switching environment helps maintain accurate timestamps and makes operational troubleshooting and security analysis more reliable.
Question 73
Which configuration is most appropriate for a switch-to-switch link carrying VLAN 10, VLAN 20, and VLAN 30?
- Access port assigned only to VLAN 10
- Trunk allowing VLANs 10, 20, and 30
- Port-security-only configuration
- Port mirroring with no VLAN configuration
Correct Answer: 2
Explanation:
A trunk interface is normally used when multiple VLANs need to traverse the same physical connection between switches. In this example, VLANs 10, 20, and 30 should be permitted on the trunk so that their traffic can move between the connected switches. VLAN tagging allows the receiving switch to identify which VLAN each frame belongs to. An access port would normally associate traffic with a single VLAN, while port security and port mirroring serve different purposes. Restricting the trunk to only the VLANs actually required is generally preferable to unnecessarily allowing every VLAN in the network.
Question 74
What is a major risk of connecting redundant Layer 2 switch links without an appropriate loop-prevention mechanism?
- Excessive circulating traffic and broadcast storms
- Automatic RADIUS authentication
- Improved NTP accuracy
- Increased PoE capacity
Correct Answer: 1
Explanation:
Redundant Layer 2 links can create switching loops if no appropriate loop-prevention mechanism is present. Ethernet frames can circulate repeatedly through the loop, causing excessive broadcasts, unknown unicasts, and multicast traffic. This can consume switch resources and bandwidth and may severely degrade or completely disrupt network connectivity. STP and related mechanisms are designed to prevent such loops by creating a loop-free logical topology while retaining redundancy. RADIUS authentication, NTP synchronization, and PoE capacity are unrelated to the problem of Layer 2 loops. Therefore, excessive circulating traffic and broadcast storms are major risks of unmanaged redundant Layer 2 connections.
Question 75
Which feature is useful when an administrator needs to inspect packets passing through a FortiSwitch interface?
- NTP
- Port mirroring
- RADIUS
- LACP
Correct Answer: 2
Explanation:
Port mirroring allows an administrator to copy selected traffic from a source interface or VLAN to a designated monitoring interface. A packet-capture tool or network analyzer can then inspect the mirrored traffic. This is useful for troubleshooting connectivity, investigating application behavior, identifying unusual traffic patterns, and analyzing protocol exchanges. The mirrored traffic is a copy, allowing the original endpoint communication to continue normally. NTP is responsible for time synchronization, RADIUS handles authentication, and LACP manages link aggregation. Therefore, port mirroring is the most appropriate feature when packet inspection is required without placing the analyzer directly in the normal traffic path.
Question 76
What is the main purpose of assigning a specific VLAN to an access port?
- To determine the logical network segment to which the connected endpoint belongs
- To configure the device’s DNS server automatically
- To enable link aggregation
- To create an NTP server
Correct Answer: 1
Explanation:
Assigning a VLAN to an access port determines the logical Layer 2 network segment associated with the connected endpoint. Devices connected to different access VLANs remain separated at Layer 2 unless routing or another appropriate mechanism allows communication between them. VLAN segmentation can be used to separate departments, guest devices, voice endpoints, management systems, and other categories of traffic. VLAN assignment does not automatically configure DNS, enable link aggregation, or create an NTP server. Proper access-VLAN configuration is therefore fundamental to implementing logical network segmentation and ensuring that endpoints receive connectivity to the intended network.
Question 77
Which feature can help ensure that an endpoint receives network access only after successful authentication?
- LLDP
- 802.1X
- NTP
- LACP
Correct Answer: 2
Explanation:
802.1X provides port-based network access control. A switch can place an interface into an unauthorized state until the connected endpoint successfully completes the configured authentication process. In a typical deployment, the endpoint acts as the supplicant, the switch acts as the authenticator, and a RADIUS server performs centralized authentication. This allows organizations to control network access based on authenticated users or devices. LLDP provides neighbor discovery, NTP synchronizes time, and LACP provides link aggregation. Therefore, 802.1X is the appropriate feature when access should be controlled according to authentication status.
Question 78
Which technology can provide power and network connectivity to a compatible IP phone using a single Ethernet cable?
- STP
- SNMP
- PoE
- RADIUS
Correct Answer: 3
Explanation:
Power over Ethernet, or PoE, allows a compatible endpoint to receive electrical power through its Ethernet connection while also using the same cable for network communication. IP phones are a common example of PoE-powered devices. This can simplify deployment because the phone may not require a separate local electrical adapter or outlet. PoE availability and power budgets depend on the specific FortiSwitch model and configuration. STP prevents Layer 2 loops, SNMP provides monitoring capabilities, and RADIUS provides centralized authentication. Therefore, PoE is the technology that combines Ethernet connectivity with power delivery for compatible network endpoints.
Question 79
What is the primary advantage of limiting the VLANs allowed on a trunk to only those that are required?
- It reduces unnecessary VLAN traffic and improves segmentation
- It disables all Layer 2 protocols
- It automatically encrypts the trunk
- It removes the need for IP addressing
Correct Answer: 1
Explanation:
Restricting a trunk to only the VLANs that are actually required can reduce unnecessary Layer 2 traffic and improve network segmentation. For example, if a switch-to-switch link needs to carry only employee and voice VLANs, there may be no reason to permit unrelated guest or management VLANs. This approach can reduce the scope of accidental traffic propagation and make the network design easier to understand and troubleshoot. VLAN restrictions do not automatically encrypt a trunk, eliminate IP addressing, or disable all Layer 2 protocols. Maintaining an explicit allowed-VLAN list is therefore a useful configuration and security practice.
Question 80
Which FortiSwitch feature provides information about neighboring devices and can assist with network topology discovery?
- RADIUS
- LLDP
- DHCP snooping
- Storm control
Correct Answer: 2
Explanation:
LLDP, or Link Layer Discovery Protocol, provides information exchanged between directly connected network devices. This information can help administrators determine which devices are connected to particular switch interfaces and can assist with building or verifying the physical network topology. LLDP is particularly valuable in environments with many switches, access points, phones, and other network devices because manually tracking every connection can be difficult. RADIUS is used for authentication, DHCP snooping protects DHCP operations, and storm control limits excessive Layer 2 traffic. Therefore, LLDP is the appropriate feature for discovering neighboring devices and improving topology visibility.