View Full Fortinet NSE5_FSW_AD-7.6 Exam Dumps and Practice Test Dumps.
Question 121
Which feature can help prevent unauthorized devices from connecting to a FortiSwitch port by restricting allowed MAC addresses?
- NTP
- LLDP
- Port security
- SNMP
Correct Answer: 3
Explanation:
Port security provides a mechanism for controlling which MAC addresses are permitted on a switch interface. An administrator can use it to limit the number of MAC addresses learned on an access port or specify authorized addresses, depending on the available configuration. This can reduce the risk of unauthorized devices being connected to network ports. NTP provides time synchronization, LLDP provides neighbor discovery, and SNMP provides monitoring information. Port security is therefore the most appropriate feature when the objective is to restrict endpoint access based on MAC addresses. It should be combined with stronger authentication mechanisms where identity-based access control is required.
Question 122
What is the primary purpose of using a FortiSwitch management interface?
- To provide administrative access to the switch
- To create physical Ethernet links
- To provide PoE to endpoints
- To aggregate multiple interfaces
Correct Answer: 1
Explanation:
A management interface provides a path through which administrators or management systems can communicate with the FortiSwitch for configuration, monitoring, and troubleshooting. The management interface can be associated with an IP address and appropriate network settings so that authorized administrators can reach the switch remotely. Management access should normally be protected with suitable authentication and network-access controls. A management interface does not create physical links, provide PoE, or aggregate interfaces. Those functions are handled by physical ports, PoE capabilities, and link aggregation respectively. Proper management connectivity is essential for maintaining and administering a FortiSwitch environment.
Question 123
Which feature can help identify whether a FortiSwitch interface is connected to another network device that supports neighbor discovery?
- STP
- LLDP
- RADIUS
- NTP
Correct Answer: 2
Explanation:
LLDP enables directly connected network devices to exchange identification and capability information. On a FortiSwitch, administrators can use LLDP information to determine what device is connected to an interface and to gather useful topology details. This can help with physical network documentation and troubleshooting, especially in environments containing many switches, access points, phones, and other infrastructure devices. STP is intended to prevent Layer 2 loops, RADIUS commonly handles authentication, and NTP synchronizes system time. Therefore, LLDP is the most suitable technology for discovering neighboring devices connected to FortiSwitch interfaces.
Question 124
Which configuration would normally be used for a port connecting a server that needs access to multiple VLANs?
- Access port assigned to one VLAN
- Trunk port allowing the required VLANs
- Port mirroring destination
- NTP client configuration
Correct Answer: 2
Explanation:
A trunk port is normally used when a device needs to communicate with multiple VLANs across a single physical connection. VLAN tagging allows the connected device and switch to distinguish traffic belonging to different VLANs. A server may require this type of configuration when it is performing services for multiple network segments and is designed to support VLAN tagging. An access port is normally associated with one VLAN, while port mirroring is intended for monitoring traffic and NTP is unrelated to VLAN transport. Trunk configuration should be implemented carefully and should permit only the VLANs that the server actually requires.
Question 125
Which feature is responsible for controlling access to a network port based on successful 802.1X authentication?
- STP
- 802.1X
- LACP
- LLDP
Correct Answer: 2
Explanation:
802.1X provides port-based network access control. It can place a switch interface into a restricted state until the connected endpoint successfully authenticates. In a typical deployment, the endpoint is the supplicant, the FortiSwitch is the authenticator, and a RADIUS server performs authentication. This allows administrators to enforce authentication before granting normal network access. STP is used to prevent Layer 2 loops, LACP provides link aggregation, and LLDP provides neighbor information. Therefore, 802.1X is the technology responsible for controlling network access based on successful authentication.
Question 126
What is a major benefit of using FortiLink to integrate FortiSwitch with FortiGate?
- It allows integrated management of switching and security infrastructure
- It eliminates Ethernet switching
- It removes the need for IP addressing
- It prevents all Layer 2 broadcasts
Correct Answer: 1
Explanation:
FortiLink provides an integrated connection between FortiGate and supported FortiSwitch devices, allowing switching infrastructure to be managed as part of the broader Fortinet environment. This can simplify deployment, configuration, monitoring, and policy administration. It also provides better visibility between the security gateway and connected switches. FortiLink does not eliminate Ethernet switching, remove IP addressing requirements, or prevent every Layer 2 broadcast. Instead, it creates an integrated management and control relationship between the FortiGate and FortiSwitch infrastructure. This can be especially useful when an organization wants centralized administration of its wired access network.
Question 127
Which feature can help detect and prevent excessive broadcast, multicast, or unknown-unicast traffic?
- Storm control
- RADIUS
- NTP
- LLDP
Correct Answer: 1
Explanation:
Storm control is designed to limit excessive Layer 2 traffic that could negatively affect network performance. Broadcast storms, multicast floods, and excessive unknown-unicast traffic can consume bandwidth and switch resources. By establishing appropriate thresholds, administrators can limit the amount of such traffic permitted through an interface. This can help prevent abnormal traffic from affecting other network users. RADIUS provides centralized authentication, NTP synchronizes device clocks, and LLDP provides neighbor discovery. Therefore, storm control is the most appropriate feature when the goal is to control excessive Layer 2 traffic and maintain network stability.
Question 128
Which protocol is most commonly associated with centralized authentication for FortiSwitch 802.1X clients?
- SNMP
- RADIUS
- LLDP
- STP
Correct Answer: 2
Explanation:
RADIUS is widely used to provide centralized authentication for 802.1X network-access deployments. The FortiSwitch acts as the authenticator and communicates with the RADIUS server when a client attempts to authenticate. The server evaluates the authentication request and returns an authorization result. Depending on the design, the response can also include additional authorization information. SNMP is primarily used for monitoring, LLDP provides neighbor discovery, and STP prevents switching loops. RADIUS therefore provides the centralized authentication function required by many 802.1X deployments and allows authentication decisions to be managed from a central server.
Question 129
What is the purpose of configuring an allowed-VLAN list on a trunk interface?
- To specify which VLANs can traverse the trunk
- To configure the device’s NTP server
- To provide PoE power
- To define RADIUS credentials
Correct Answer: 1
Explanation:
An allowed-VLAN list determines which VLANs are permitted to cross a trunk interface. This provides control over VLAN propagation and prevents unrelated VLAN traffic from unnecessarily traversing the link. For example, a switch-to-switch trunk may need to carry only employee, voice, and management VLANs. Restricting the list to those required VLANs improves network organization and can reduce unnecessary traffic. NTP configuration, PoE, and RADIUS credentials are separate functions. Administrators should ensure that the allowed VLANs are consistent with the network design and that both ends of the trunk are configured appropriately.
Question 130
Which FortiSwitch security feature can validate ARP packets using trusted IP-to-MAC bindings?
- DAI
- LACP
- NTP
- SNMP
Correct Answer: 1
Explanation:
Dynamic ARP Inspection, or DAI, validates ARP traffic against trusted IP-to-MAC binding information. This helps prevent malicious or incorrect ARP messages from being accepted by the network. ARP spoofing can allow an attacker to impersonate another host and potentially intercept traffic. DAI can reduce this risk by inspecting ARP packets and applying the configured validation policy. LACP is used for link aggregation, NTP synchronizes clocks, and SNMP provides monitoring and management. DAI is therefore the correct feature when the objective is to validate ARP information and protect the Layer 2 network against ARP spoofing.
Question 131
What is the main purpose of using MAC address learning on a FortiSwitch?
- To determine where Layer 2 frames should be forwarded
- To assign DNS servers
- To authenticate RADIUS users
- To provide electrical power
Correct Answer: 1
Explanation:
MAC address learning allows a switch to associate source MAC addresses with the interfaces where those addresses were observed. The switch stores this information in its MAC address table and uses it to make efficient Layer 2 forwarding decisions. When the destination MAC address is known, the switch can forward the frame toward the appropriate interface instead of flooding it throughout the VLAN. DNS configuration, RADIUS authentication, and PoE are separate functions. MAC learning is therefore fundamental to Ethernet switching because it allows the FortiSwitch to determine the appropriate interface for known destination MAC addresses.
Question 132
Which feature can provide a copy of selected network traffic to an analyzer connected to another switch interface?
- LACP
- Port mirroring
- DHCP snooping
- NTP
Correct Answer: 2
Explanation:
Port mirroring allows selected traffic from one or more source interfaces or VLANs to be copied to a designated monitoring interface. An administrator can connect a packet analyzer or monitoring device to that destination interface to inspect the traffic. This can be useful for troubleshooting, security investigations, protocol analysis, and application diagnostics. LACP combines physical links, DHCP snooping protects DHCP operations, and NTP provides time synchronization. Port mirroring is therefore the appropriate feature when an administrator needs to observe network traffic without directly placing the analysis device into the normal forwarding path.
Question 133
Which protocol is designed to prevent Layer 2 loops in redundant switching topologies?
- RADIUS
- NTP
- STP
- SNMP
Correct Answer: 3
Explanation:
Spanning Tree Protocol prevents Layer 2 switching loops by creating a loop-free logical topology from the available physical connections. When redundant paths exist, STP can place selected links into a non-forwarding state while retaining them as potential backup paths. Without a loop-prevention mechanism, redundant Ethernet connections can create broadcast storms and excessive frame circulation. RADIUS provides authentication, NTP synchronizes time, and SNMP provides monitoring and management information. STP is therefore essential in environments where redundant Layer 2 links are present and network stability must be maintained.
Question 134
What is one purpose of configuring a voice VLAN on a FortiSwitch?
- To logically separate IP phone traffic from ordinary data traffic
- To disable IP addressing
- To prevent all multicast traffic
- To replace the management interface
Correct Answer: 1
Explanation:
A voice VLAN provides a dedicated logical network segment for IP phone traffic. Separating voice traffic from ordinary workstation traffic makes it easier to apply appropriate security, quality-of-service, and management policies. It can also help administrators troubleshoot voice-related issues because voice endpoints are grouped into a known network segment. A voice VLAN does not disable IP addressing, prevent all multicast traffic, or replace the management interface. In many deployments, IP phones can also receive power through PoE. Proper voice VLAN configuration is therefore an important part of designing a structured and manageable IP telephony network.
Question 135
Which feature can help ensure that a device uses an expected source IP and MAC address combination?
- LLDP
- IP source guard
- LACP
- PoE
Correct Answer: 2
Explanation:
IP source guard helps enforce expected source IP information on a switch interface. It can use trusted IP-to-MAC bindings to determine whether traffic from an endpoint matches an authorized source identity. This helps protect against certain types of IP spoofing, where a device attempts to send traffic using an unauthorized source IP address. Depending on the network configuration, DHCP snooping can provide useful binding information for this type of security control. LLDP provides neighbor discovery, LACP manages link aggregation, and PoE provides power. IP source guard is therefore the most appropriate option for source identity validation.
Question 136
Which feature can provide information about the number and status of physical links participating in an aggregated connection?
- LACP
- NTP
- RADIUS
- DHCP snooping
Correct Answer: 1
Explanation:
LACP is used to establish and maintain link aggregation between compatible network devices. It provides information related to the member interfaces participating in an aggregation and helps ensure that links are correctly grouped. Link aggregation can increase aggregate bandwidth and provide redundancy if multiple physical links are available. NTP provides time synchronization, RADIUS provides authentication, and DHCP snooping protects DHCP traffic. Therefore, LACP is the most relevant technology when administrators need to manage or troubleshoot multiple physical links operating as a logical aggregated connection.
Question 137
Why should the VLAN configuration on both ends of an interconnected trunk be consistent?
- To ensure VLAN traffic is correctly transported between devices
- To increase the PoE budget
- To change RADIUS passwords automatically
- To synchronize device clocks
Correct Answer: 1
Explanation:
Trunk endpoints need compatible VLAN configurations so that VLAN traffic is correctly identified and transported between the connected devices. Problems can occur if one switch permits a VLAN while the other does not, or if the native VLAN settings do not match. Such inconsistencies can result in lost connectivity, incorrect traffic placement, or unexpected Layer 2 behavior. PoE budgets, RADIUS passwords, and NTP synchronization are unrelated to trunk VLAN consistency. Administrators should therefore verify VLAN IDs, allowed VLAN lists, tagging behavior, and native VLAN settings whenever troubleshooting connectivity across an interconnected FortiSwitch trunk.
Question 138
Which feature can help identify a rogue DHCP server connected to an access port?
- DHCP snooping
- LACP
- SNMP
- NTP
Correct Answer: 1
Explanation:
DHCP snooping helps identify and control DHCP server traffic based on trusted and untrusted interfaces. Legitimate DHCP server responses should normally arrive through trusted interfaces, while client-facing access ports are generally untrusted. If an unauthorized device attempts to provide DHCP server responses through an untrusted port, the switch can block or otherwise control that traffic according to the configured policy. LACP, SNMP, and NTP do not provide this specific protection. DHCP snooping is therefore an important security feature for identifying and limiting rogue DHCP server behavior in access networks.
Question 139
What is one advantage of using centralized configuration management for multiple FortiSwitch devices?
- It helps maintain consistent settings across switches
- It eliminates the need for network design
- It prevents all hardware failures
- It automatically encrypts every Ethernet frame
Correct Answer: 1
Explanation:
Centralized configuration management can make it easier to maintain consistent settings across multiple FortiSwitch devices. Administrators can manage common configuration elements from a centralized location instead of manually repeating the same changes on every switch. This can reduce administrative effort and help minimize configuration inconsistencies. Centralized management does not eliminate the need for network design, prevent physical hardware failures, or automatically encrypt all Ethernet traffic. Its primary benefit is operational consistency and simplified administration. This becomes increasingly valuable as the number of managed switches and network segments grows.
Question 140
Which combination is most suitable for providing network monitoring and accurate event timestamps on FortiSwitch devices?
- LACP and PoE
- LLDP and DAI
- SNMP and NTP
- RADIUS and STP
Correct Answer: 3
Explanation:
SNMP and NTP serve complementary operational functions. SNMP can provide monitoring systems with information such as interface status, traffic statistics, errors, and device health. NTP synchronizes the system clocks of network devices so that logs and events contain accurate and consistent timestamps. Using both technologies improves operational visibility and makes it easier to correlate events across multiple FortiSwitch devices. LACP and PoE address link aggregation and power delivery, LLDP and DAI address discovery and ARP security, while RADIUS and STP address authentication and loop prevention. Therefore, SNMP combined with NTP is the best option for monitoring and reliable event timing.