Fortinet NSE5_FSW_AD-7.6 Practice Test Questions and Exam Dumps Part10 Q181-200

View Full Fortinet NSE5_FSW_AD-7.6 Exam Dumps and Practice Test Dumps.

 

Question 181

What is the primary purpose of an access control list applied to a FortiSwitch interface?

  1. To increase PoE capacity
  2. To control permitted network traffic according to defined rules
  3. To synchronize device clocks
  4. To discover neighboring devices

Correct Answer: 2

Explanation:

An access control list can be used to control network traffic according to configured criteria and actions. Depending on the supported FortiSwitch functionality and deployment, policies can help restrict or permit traffic based on characteristics such as source, destination, protocol, or other attributes. This provides an additional layer of traffic control within the switching environment. PoE manages electrical power, NTP handles time synchronization, and LLDP provides neighbor discovery. Administrators should carefully design access-control policies to avoid unintentionally blocking legitimate communication while restricting unwanted traffic.

Question 182

Which switch behavior allows a device to learn the location of a source MAC address?

  1. The switch records the source MAC address and ingress interface
  2. The switch sends the address to a DHCP server
  3. The switch converts the MAC address into an IP address
  4. The switch forwards the address to a RADIUS server

Correct Answer: 1

Explanation:

A Layer 2 switch learns source MAC addresses by examining incoming Ethernet frames. When a frame arrives, the switch records the source MAC address and associates it with the ingress interface and relevant VLAN in its forwarding database. This information allows the switch to make more efficient forwarding decisions for future traffic destined for that MAC address. DHCP, RADIUS, and IP addressing perform different functions and are not responsible for normal MAC address learning. Understanding this learning process is important when troubleshooting switching and forwarding behavior.

Question 183

What is a major benefit of using a management system to monitor FortiSwitch interface utilization?

  1. It automatically replaces failed cables
  2. It can help identify congested or heavily utilized interfaces
  3. It disables unused VLANs
  4. It provides physical power to endpoints

Correct Answer: 2

Explanation:

Monitoring interface utilization helps administrators identify interfaces that are carrying unusually high traffic volumes or experiencing congestion. This information can assist with capacity planning, troubleshooting, and identifying potential network bottlenecks. For example, a heavily utilized uplink may indicate that additional capacity or a different network design is needed. Monitoring systems can collect interface statistics and present them over time, helping administrators recognize trends. They cannot automatically replace physical cables, disable VLANs without configuration, or provide electrical power. Interface utilization monitoring is therefore valuable for network performance management.

Question 184

Which configuration is required for a switch port that must carry traffic for multiple VLANs between network devices?

  1. Access VLAN only
  2. Trunk configuration
  3. Port security only
  4. DHCP relay

Correct Answer: 2

Explanation:

A trunk configuration is used when a physical link needs to transport traffic belonging to multiple VLANs between network devices. VLAN tags allow the receiving device to identify the VLAN associated with tagged frames. Administrators can normally specify which VLANs are permitted across the trunk to reduce unnecessary traffic and improve control. An access port is generally intended for a single VLAN, while port security controls endpoint access and DHCP relay forwards DHCP requests across Layer 3 boundaries. Therefore, a properly configured trunk is required for multi-VLAN transport between network devices.

Question 185

What is the purpose of configuring a switch port as trusted for DHCP snooping?

  1. To allow expected DHCP server responses through the interface
  2. To prevent all DHCP traffic
  3. To disable VLAN tagging
  4. To enable STP root election

Correct Answer: 1

Explanation:

DHCP snooping distinguishes between trusted and untrusted interfaces. A trusted interface is normally connected toward a legitimate DHCP server or an upstream device through which valid DHCP server responses are expected. This allows legitimate DHCP replies to pass while helping prevent unauthorized DHCP servers from responding through untrusted client-facing ports. Administrators should carefully identify trusted interfaces because incorrectly trusting an untrusted endpoint could reduce the effectiveness of DHCP snooping. VLAN tagging and STP root election are unrelated to this particular trust classification.

Question 186

Which technology can help identify whether two network devices are directly connected?

  1. LACP
  2. LLDP
  3. NTP
  4. DHCP snooping

Correct Answer: 2

Explanation:

LLDP allows network devices to advertise identifying information to their directly connected neighbors. A switch can use the received information to determine details about neighboring devices and interfaces. This makes LLDP particularly useful for network discovery, topology visualization, and troubleshooting physical connections. LACP is used for link aggregation, NTP synchronizes time, and DHCP snooping protects DHCP operations. Therefore, LLDP is the most appropriate technology for discovering directly connected network devices and understanding their relationship within the physical network topology.

Question 187

What can happen if two connected switches have inconsistent VLAN configurations on a trunk?

  1. VLAN traffic may fail to reach the expected destination
  2. NTP automatically corrects the VLAN configuration
  3. RADIUS changes the VLAN IDs automatically
  4. PoE increases the trunk bandwidth

Correct Answer: 1

Explanation:

If the VLAN configuration on the two ends of a trunk is inconsistent, traffic for certain VLANs may not be transported correctly. For example, a VLAN may be permitted on one switch but excluded from the trunk on the other. Incorrect tagging or native VLAN configuration can also produce unexpected behavior. Administrators should compare the VLAN IDs, allowed VLAN lists, tagging behavior, and relevant trunk settings on both ends. NTP, RADIUS, and PoE do not automatically resolve VLAN configuration mismatches. Consistent trunk configuration is essential for reliable multi-VLAN communication.

Question 188

Which feature is most useful for identifying the physical port to which a particular MAC address is currently learned?

  1. MAC address table
  2. NTP status
  3. RADIUS accounting
  4. PoE budget

Correct Answer: 1

Explanation:

The MAC address table records dynamically learned MAC addresses along with the associated switch interface and VLAN information. Administrators can use this table to determine where a particular Layer 2 endpoint is currently connected or where its traffic has most recently been learned. This is particularly useful when tracing devices, troubleshooting unexpected connectivity, or investigating unauthorized connections. NTP status, RADIUS accounting, and PoE budgets provide different types of information and do not normally identify the switch port associated with a learned MAC address.

Question 189

What is the main purpose of a switch management IP address?

  1. To provide an address through which the switch can be administratively accessed over IP
  2. To assign addresses to all connected clients
  3. To replace all VLANs
  4. To determine the PoE power level

Correct Answer: 1

Explanation:

A management IP address allows administrators or management systems to communicate with the switch over an IP network for administrative and monitoring purposes. The management interface may be used for supported management protocols and centralized administration. It does not automatically assign IP addresses to client devices, replace VLANs, or determine PoE power levels. Proper management addressing should be combined with appropriate access controls, routing, and secure management protocols. A reliable management path is especially important in larger networks where administrators need centralized visibility and configuration capabilities.

Question 190

Which mechanism can provide centralized authentication for users or devices connecting through network access controls?

  1. STP
  2. RADIUS
  3. LLDP
  4. LACP

Correct Answer: 2

Explanation:

RADIUS provides centralized authentication and authorization services and is commonly used with network-access mechanisms such as 802.1X. Instead of maintaining authentication information independently on every switch, the network device can communicate with a central RADIUS server. This provides a more manageable and consistent approach to access control. RADIUS can also support accounting functionality where configured. STP manages Layer 2 topology, LLDP provides neighbor discovery, and LACP manages link aggregation. Therefore, RADIUS is the appropriate choice for centralized network-access authentication.

Question 191

What is a key purpose of 802.1X on an access port?

  1. To authenticate an endpoint before granting network access
  2. To combine multiple physical links
  3. To synchronize switch clocks
  4. To prevent all broadcast traffic

Correct Answer: 1

Explanation:

802.1X provides port-based network access control and can require an endpoint to authenticate before normal network access is granted. In a typical deployment, the endpoint acts as the supplicant, the switch acts as the authenticator, and an authentication server such as RADIUS validates the credentials. This allows organizations to enforce identity-based access policies at the network edge. LACP combines physical links, NTP synchronizes time, and storm-control mechanisms can limit excessive broadcast traffic. Therefore, 802.1X is primarily an authentication and access-control technology.

Question 192

What should be verified when a FortiSwitch is not appearing as expected in a centralized management environment?

  1. Only the workstation wallpaper
  2. Device connectivity and management status
  3. The user’s browser bookmarks
  4. The keyboard layout

Correct Answer: 2

Explanation:

If a FortiSwitch is not appearing correctly in centralized management, administrators should first verify that the device has appropriate connectivity and that its management status is operational. Depending on the deployment, this can include checking the physical link, FortiLink connectivity, device authorization or registration state, addressing, and compatibility with the management platform. Unrelated workstation settings such as wallpaper, bookmarks, or keyboard layout have no meaningful role in switch management discovery. Checking connectivity and management status helps narrow the issue to the actual communication path between the switch and management system.

Question 193

Which feature can help protect a switch network from excessive multicast or broadcast traffic?

  1. Storm control
  2. NTP
  3. RADIUS accounting
  4. LLDP

Correct Answer: 1

Explanation:

Storm control can limit the impact of excessive Layer 2 traffic such as broadcast or multicast traffic, depending on the supported configuration. Excessive traffic can consume interface bandwidth and switch resources and may affect other devices on the network. By configuring suitable thresholds and protective actions, administrators can reduce the potential impact of abnormal traffic conditions. NTP is used for time synchronization, RADIUS accounting records access activity, and LLDP provides neighbor information. Storm control is therefore the feature most directly associated with protecting the switching environment from traffic storms.

Question 194

Why should administrators avoid allowing unnecessary VLANs across a trunk?

  1. It can reduce unnecessary traffic exposure and simplify network control
  2. It increases the number of physical ports
  3. It disables all Layer 2 security
  4. It forces every endpoint to authenticate

Correct Answer: 1

Explanation:

Restricting a trunk to only the VLANs that are actually required improves network organization and reduces unnecessary VLAN traffic across the link. It can also reduce the potential exposure of traffic to devices or segments that do not need access to a particular VLAN. Administrators should maintain consistent allowed-VLAN configurations on both ends of the trunk and document the intended VLANs. Limiting VLANs does not increase physical port count or force endpoint authentication. Proper trunk filtering is a simple way to maintain better control over VLAN propagation.

Question 195

Which feature can help prevent an endpoint from using a manually configured IP address that does not match its expected binding?

  1. IP source guard
  2. LLDP
  3. LACP
  4. NTP

Correct Answer: 1

Explanation:

IP source guard can help restrict traffic based on expected IP-to-MAC or related binding information, depending on the implementation and configuration. It can help prevent a device from using an unauthorized source IP address on a protected interface. DHCP snooping information is commonly used to establish trusted bindings that can support related Layer 2 security controls. LLDP, LACP, and NTP serve discovery, link aggregation, and time synchronization purposes respectively. IP source guard is therefore the most relevant feature when administrators want to restrict unauthorized source addressing on access interfaces.

Question 196

What is the primary role of a FortiSwitch uplink interface?

  1. To connect the switch toward another network device or upstream network
  2. To authenticate users through a web browser
  3. To synchronize only the switch clock
  4. To provide a dedicated DHCP server

Correct Answer: 1

Explanation:

An uplink interface connects a switch toward another network device, such as an upstream switch, FortiGate, router, or other network infrastructure. Uplinks often carry traffic for multiple VLANs and may therefore be configured as trunks when required by the network design. They can also be configured as aggregated links when redundancy or additional aggregate bandwidth is needed. An uplink is not inherently a DHCP server, authentication portal, or time-synchronization interface. Understanding uplink roles is important when designing and troubleshooting the connectivity between access switches and the rest of the network.

Question 197

What is the main advantage of using link aggregation for redundant switch connections?

  1. It can provide resilience if one member link fails
  2. It disables all VLAN traffic
  3. It prevents MAC learning
  4. It removes the need for physical cables

Correct Answer: 1

Explanation:

Link aggregation combines multiple physical links into a logical connection. When properly configured with a supported aggregation protocol such as LACP, the connection can continue operating if one member link fails, provided that sufficient remaining capacity exists. Aggregation can also provide increased aggregate bandwidth across multiple active members. It does not eliminate physical cables, disable VLAN traffic, or prevent MAC learning. Administrators should ensure that member interfaces have compatible configurations on both sides because inconsistent settings can prevent the aggregate from forming or cause unexpected behavior.

Question 198

Which protocol is most appropriate for maintaining consistent time across FortiSwitch devices and other network systems?

  1. SNMP
  2. NTP
  3. LLDP
  4. LACP

Correct Answer: 2

Explanation:

Network Time Protocol, or NTP, is used to synchronize system clocks across network devices and other systems. Consistent time is important for accurate event logging, troubleshooting, monitoring, authentication-related processes, and correlation of events across multiple devices. If clocks differ significantly, it can become difficult to determine the correct sequence of network events. SNMP is primarily used for monitoring and management, LLDP provides neighbor discovery, and LACP handles link aggregation. Therefore, NTP is the appropriate protocol for maintaining consistent time across network infrastructure.

Question 199

What is the purpose of monitoring switch event logs?

  1. To identify operational events and assist with troubleshooting
  2. To physically increase port speed
  3. To create Ethernet cables
  4. To replace VLAN configuration

Correct Answer: 1

Explanation:

Switch event logs provide information about operational events that occur on the device. Depending on the platform and configuration, logs may include interface state changes, authentication events, configuration changes, system warnings, and other conditions. Reviewing these events can help administrators determine when a problem began and identify possible causes. Logs are particularly useful when investigating intermittent issues that may not be occurring while the administrator is actively troubleshooting. Event logs do not physically increase port speed, create cables, or replace VLAN configuration. They are primarily an operational visibility and troubleshooting resource.

Question 200

Which approach provides the best way to maintain consistent configurations across a large FortiSwitch deployment?

  1. Manually change each switch without documentation
  2. Disable configuration management
  3. Use centralized management and standardized configuration templates where appropriate
  4. Configure every switch with different VLANs

Correct Answer: 3

Explanation:

Centralized management combined with standardized configuration templates can help maintain consistency across a large FortiSwitch deployment. Administrators can define common settings and apply them to multiple devices while reducing repetitive manual configuration. This approach also helps minimize configuration errors and makes it easier to maintain a predictable network design. Device-specific settings should still be reviewed before deployment because not every switch or interface necessarily has identical requirements. Manually configuring every switch independently increases the chance of inconsistencies. Centralized configuration and standardization therefore provide a more scalable management approach.