View Full Fortinet NSE5_FSW_AD-7.6 Exam Dumps and Practice Test Dumps.
Question 241
What is a key benefit of assigning FortiSwitch devices to logical device groups in centralized management?
- It allows every switch to use a different management platform.
- It automatically disables switch security features.
- It helps organize devices and apply common configurations more efficiently.
- It removes the need for device authorization.
Correct Answer: 3
Explanation:
Logical device groups help administrators organize FortiSwitch devices according to locations, functions, or other operational requirements. Grouping devices makes centralized administration easier because common settings and configuration policies can be managed consistently. Instead of configuring every switch individually, administrators can use group-level organization and templates where supported. This is especially useful in environments containing many switches across multiple offices or network segments. Device grouping does not replace authorization or eliminate security controls. Its main purpose is improving manageability, organization, and configuration consistency in larger FortiSwitch deployments.
Question 242
During FortiSwitch onboarding, what should an administrator verify if the switch does not appear as expected in centralized management?
- Management connectivity and the switch’s authorization/status.
- Only the switch’s PoE budget.
- Only the number of connected clients.
- The MAC aging timer only.
Correct Answer: 1
Explanation:
When a FortiSwitch does not appear correctly in centralized management, the administrator should first verify basic management connectivity and the device’s authorization or onboarding status. A switch must be able to communicate with its management system before centralized configuration and monitoring can function properly. Depending on the deployment, administrators may also need to check FortiLink connectivity, interfaces, addressing, and device discovery status. PoE capacity, client count, and MAC aging are unrelated to the initial management connection. Checking connectivity and authorization provides the most appropriate first troubleshooting step.
Question 243
Which STP role is normally associated with a port that provides the best path toward the root bridge?
- Designated port
- Alternate port
- Disabled port
- Root port
Correct Answer: 4
Explanation:
In Spanning Tree Protocol, the root port is the port on a non-root switch that provides the best path toward the root bridge. Each non-root switch normally selects one root port based on the best path cost and other STP criteria. Designated ports provide the best path from a network segment toward the root, while alternate ports provide backup paths in certain STP implementations. Understanding port roles is important when troubleshooting Layer 2 topology and unexpected forwarding or blocking behavior. The root port therefore represents the preferred path toward the elected root bridge.
Question 244
What is the primary purpose of BPDU Guard on an edge/access port?
- To increase the port’s bandwidth.
- To protect the STP topology if unexpected BPDUs are received.
- To assign a native VLAN automatically.
- To negotiate LACP.
Correct Answer: 2
Explanation:
BPDU Guard is commonly applied to edge or access ports where network administrators do not expect STP Bridge Protocol Data Units from connected devices. If an unexpected BPDU is received, BPDU Guard can place the interface into a protective state, helping prevent an unauthorized or incorrectly connected switch from influencing the STP topology. This is particularly useful on ports connected to end-user devices. BPDU Guard is not designed for bandwidth management, VLAN assignment, or link aggregation. Its main security and stability benefit is protecting the intended Layer 2 topology from unexpected STP participation.
Question 245
What is the main difference between BPDU Guard and BPDU Filtering?
- BPDU Guard protects an edge port when BPDUs are received, while BPDU Filtering suppresses BPDU processing/transmission depending on configuration.
- BPDU Guard is used only for PoE, while BPDU Filtering is used only for SNMP.
- BPDU Guard creates VLANs, while BPDU Filtering removes VLANs.
- Both features always perform exactly the same function.
Correct Answer: 1
Explanation:
BPDU Guard and BPDU Filtering serve different purposes. BPDU Guard is a protective mechanism generally used on edge ports; when an unexpected BPDU is received, the port can be placed into an error or protective state depending on the configuration. BPDU Filtering is intended to suppress or filter BPDUs under specific configurations. Because filtering can hide STP information, it must be used carefully. These features should not be treated as interchangeable. Administrators should understand the intended topology before enabling either feature, especially on access ports where accidental Layer 2 loops can have significant effects.
Question 246
Which feature helps prevent a downstream switch from becoming an unexpected STP root?
- BPDU Filtering
- Port mirroring
- Root Guard
- DHCP snooping
Correct Answer: 3
Explanation:
Root Guard is designed to protect the intended STP root bridge placement. It can prevent a port from accepting superior BPDUs from a downstream device and thereby becoming an unexpected path toward a new root. This is useful at network boundaries where administrators know that a connected switch should not influence root bridge selection. BPDU Guard has a different purpose and is typically associated with edge ports where BPDUs should not appear at all. DHCP snooping protects against rogue DHCP behavior, while port mirroring is used for traffic analysis. Root Guard is therefore the appropriate STP protection feature here.
Question 247
In an LACP configuration, what is the purpose of using active mode on a link?
- It disables link aggregation.
- It prevents the interface from negotiating.
- It converts the interface into an access port.
- It actively sends LACP negotiation packets to establish aggregation.
Correct Answer: 4
Explanation:
LACP active mode allows an interface to actively participate in link aggregation negotiation by sending LACP protocol information. This helps establish an aggregated link when the connected device is configured compatibly. Passive mode can respond to LACP messages but does not actively initiate negotiation. At least one side generally needs to operate actively for dynamic negotiation to take place. Properly configured LACP can provide increased aggregate bandwidth and redundancy across multiple physical links. However, the participating interfaces must have compatible configuration parameters for successful aggregation.
Question 248
What is a common cause of a trunk link failing to carry a particular VLAN?
- The VLAN is not included in the trunk’s allowed VLAN list.
- NTP is configured on the switch.
- SNMP polling is enabled.
- The switch has a management IP address.
Correct Answer: 1
Explanation:
A VLAN may fail to traverse a trunk when that VLAN is not permitted by the trunk’s allowed VLAN configuration. Trunk interfaces can carry multiple VLANs, but administrators often restrict which VLAN IDs are allowed for security and operational reasons. If the required VLAN is omitted, devices on that VLAN may lose connectivity across the trunk even though the physical link itself remains operational. When troubleshooting VLAN connectivity, administrators should verify VLAN existence, tagging, trunk mode, allowed VLANs, and configuration consistency on both ends of the link.
Question 249
Which technology can help an IP phone automatically learn voice VLAN information from a network switch?
- STP
- LLDP-MED
- LACP
- DHCP snooping
Correct Answer: 2
Explanation:
LLDP-MED extends LLDP functionality for devices such as IP phones and can provide network policy information, including voice VLAN details, to compatible endpoints. This can simplify voice network deployment because the phone can learn relevant network parameters from the switch rather than requiring every phone port to be manually configured in the same way. LLDP-MED is particularly useful in environments where voice and data traffic share physical switch ports. STP handles loop prevention, LACP handles link aggregation, and DHCP snooping provides protection against unauthorized DHCP servers.
Question 250
What should an administrator check first when a PoE-powered device unexpectedly loses power?
- The STP root bridge priority only.
- The SNMP manager address only.
- The switch’s PoE status, available power budget, and port settings.
- The MAC address aging timer only.
Correct Answer: 3
Explanation:
When a PoE device loses power, the administrator should examine the switch’s PoE status and determine whether sufficient power is available. The configured state of the affected port should also be checked, along with the total PoE budget and power consumption of other connected devices. A switch can have multiple PoE ports but still have a limited overall power budget. If that budget is exceeded, devices may not receive power as expected. Checking PoE-related information provides a much more relevant troubleshooting path than examining STP, SNMP, or MAC aging settings.
Question 251
What is the main purpose of DHCP relay in a routed network?
- To forward DHCP requests between clients and a DHCP server across Layer 3 boundaries.
- To block all DHCP traffic.
- To replace VLAN tagging.
- To create LACP groups.
Correct Answer: 1
Explanation:
DHCP relay allows DHCP client requests to reach a DHCP server when the server is located on a different IP subnet. Because DHCP discovery messages are normally broadcast and routers do not forward broadcasts by default, a relay function receives the request and forwards it toward the configured DHCP server. The server can then respond through the relay to the client. This is different from DHCP snooping, which is primarily a security feature used to inspect DHCP traffic and build binding information. DHCP relay is therefore particularly important in routed VLAN environments with centralized DHCP servers.
Question 252
Which statement best describes the relationship between DHCP snooping and Dynamic ARP Inspection?
- DHCP snooping disables ARP inspection.
- DAI replaces the need for VLANs.
- DHCP snooping can provide IP-MAC binding information that DAI can use for validation.
- DAI is required before DHCP snooping can operate.
Correct Answer: 3
Explanation:
Dynamic ARP Inspection can use trusted IP-to-MAC binding information learned through DHCP snooping to validate ARP packets. This helps detect and prevent certain ARP spoofing attacks because the switch can compare ARP information against known legitimate bindings. DHCP snooping itself focuses on DHCP traffic and helps identify legitimate address assignments. When these security mechanisms are combined, they provide stronger protection against Layer 2 attacks. Administrators should also correctly configure trusted interfaces and understand whether static bindings are needed for devices using manually assigned addresses.
Question 253
What is a major difference between a static MAC entry and a dynamically learned MAC entry?
- A static MAC entry is manually configured and does not rely on normal MAC learning.
- A static MAC entry can only be used for wireless devices.
- Dynamic MAC entries never expire.
- Dynamic MAC entries cannot be associated with interfaces.
Correct Answer: 1
Explanation:
A static MAC address entry is manually configured by an administrator and associates a specific MAC address with a designated interface or forwarding behavior. Dynamic MAC entries are learned automatically when the switch receives frames and observes source MAC addresses. Dynamic entries can age out when they are no longer seen, while static entries are generally intended to remain configured until manually changed or removed. Static entries can be useful in specific security or forwarding scenarios, but they should be used carefully because incorrect static assignments can interfere with normal switching behavior.
Question 254
What is the purpose of storm control on a FortiSwitch interface?
- To synchronize system clocks.
- To limit excessive broadcast, multicast, or related traffic on an interface.
- To authenticate users through RADIUS.
- To negotiate an LACP session.
Correct Answer: 2
Explanation:
Storm control helps protect the network from excessive traffic such as broadcast or multicast storms. A Layer 2 loop, malfunctioning device, or other network condition can generate unusually high volumes of traffic that consume switch resources and degrade connectivity. Storm control allows administrators to establish thresholds so that excessive traffic can be controlled according to the configured behavior. This helps reduce the impact of abnormal traffic on other devices and interfaces. Storm control is therefore a traffic-protection mechanism, not an authentication, synchronization, or link aggregation feature.
Question 255
What is the primary difference between SNMP polling and SNMP traps?
- Polling is initiated by the monitoring system, while traps are notifications sent by the monitored device.
- Polling is used only for VLANs, while traps are used only for PoE.
- Traps require LACP, while polling requires STP.
- Polling and traps are exactly identical mechanisms.
Correct Answer: 1
Explanation:
SNMP polling occurs when an SNMP manager periodically requests information from a network device. This can be used to collect interface statistics, CPU information, status values, and other management data. An SNMP trap works differently: the monitored device sends a notification to the SNMP manager when a configured event occurs. Traps can provide faster event awareness without waiting for the next polling interval. Both mechanisms can complement each other in network monitoring. Polling is request-driven, whereas traps are notification-driven from the managed device.
Question 256
Which configuration approach is most useful for maintaining consistent settings across many similar FortiSwitch devices?
- Configuring every port manually with no standard template.
- Using centralized configuration templates or standardized device policies.
- Disabling centralized management.
- Changing each switch’s settings randomly.
Correct Answer: 2
Explanation:
Centralized configuration templates and standardized policies help administrators maintain consistent settings across multiple FortiSwitch devices. This reduces repetitive manual work and lowers the chance of configuration mistakes. For example, common VLAN, interface, security, or management settings can be standardized according to the organization’s design. Administrators can still make device-specific changes where required, but using a consistent baseline makes troubleshooting and auditing easier. In larger deployments, centralized configuration also improves scalability because changes can be managed systematically instead of requiring administrators to log into every switch individually.
Question 257
What should an administrator examine when a switch interface shows a high number of physical errors?
- Only the DHCP lease duration.
- Only the SNMP community name.
- The cable, transceiver, interface statistics, and speed/duplex configuration.
- Only the VLAN name.
Correct Answer: 3
Explanation:
A high number of physical interface errors can indicate problems with cabling, transceivers, connectors, physical ports, or incompatible speed and duplex settings. Interface statistics can provide useful evidence about the type and frequency of errors. Administrators should inspect both ends of the connection and verify that the physical components and interface settings are compatible. Replacing a suspected cable or transceiver can help isolate the problem. VLAN configuration is important for logical connectivity but generally does not explain a high rate of physical-layer errors on an otherwise operational interface.
Question 258
What is the purpose of trusted hosts or management access restrictions on a network device?
- To restrict administrative access to approved source addresses or networks.
- To increase PoE output.
- To automatically create voice VLANs.
- To disable all switch logging.
Correct Answer: 1
Explanation:
Management access restrictions help reduce the attack surface of a network device by limiting administrative access to known or trusted source addresses or networks. Instead of allowing management services to be reachable from anywhere, administrators can restrict access to designated management stations or trusted subnets. This is an important management-plane security practice. Depending on the deployment, additional controls such as secure protocols, authentication, role-based administrative profiles, and firewall policies can provide further protection. Management restrictions do not affect PoE, voice VLAN creation, or logging functionality.
Question 259
Why is configuration backup important before performing major FortiSwitch changes or upgrades?
- It guarantees that every upgrade will succeed.
- It provides a recovery point if the new configuration or upgrade causes problems.
- It automatically increases switch memory.
- It eliminates the need for testing.
Correct Answer: 2
Explanation:
A configuration backup provides a recovery point before significant changes such as firmware upgrades, topology modifications, or major configuration updates. If an unexpected problem occurs, administrators have a known configuration state that can assist with restoration or troubleshooting. A backup does not guarantee that an upgrade will succeed, nor does it replace proper testing and planning. Administrators should also consider firmware compatibility, supported upgrade paths, and maintenance windows. Maintaining reliable backups is an important operational practice for reducing the risk associated with major network changes.
Question 260
What is a major advantage of centralized FortiSwitch management in a multi-switch environment?
- It requires administrators to configure every switch independently.
- It prevents the use of VLANs.
- It removes the need for network monitoring.
- It provides centralized visibility, configuration, and operational management.
Correct Answer: 4
Explanation:
Centralized FortiSwitch management allows administrators to manage multiple switches from a common management environment. This can provide centralized visibility into device status, interfaces, connected devices, configuration, and events while reducing the need for repetitive individual switch administration. Standardized templates and policies can further improve consistency across the network. Centralized management does not eliminate VLANs, monitoring, or the need for sound network design. Instead, it makes these functions easier to administer at scale. This is particularly valuable when an organization operates multiple FortiSwitch devices across different network segments or locations.