Fortinet NSE5_FSW_AD-7.6 Practice Test Questions and Exam Dumps Part8 Q141-160

View Full Fortinet NSE5_FSW_AD-7.6 Exam Dumps and Practice Test Dumps.

 

Question 141

What is the primary benefit of using configuration templates when managing multiple FortiSwitch devices?

  1. To increase physical port speed
  2. To provide electrical power to endpoints
  3. To apply consistent configuration settings across devices
  4. To replace VLANs

Correct Answer: 3

Explanation:

Configuration templates help administrators apply standardized settings to multiple FortiSwitch devices. Instead of manually configuring the same parameters on every switch, common settings can be defined once and applied consistently. This reduces configuration errors and simplifies administration in larger environments. Templates can be particularly useful when multiple switches require similar VLAN, interface, security, or operational settings. They do not increase the physical speed of interfaces or provide PoE, and they do not replace VLAN technology. Centralized configuration is especially useful when an organization needs predictable settings across a large number of managed switches.

Question 142

Which FortiSwitch feature is most useful for detecting a physical interface that is operating at an unexpected speed or duplex setting?

  1. Interface status information
  2. RADIUS accounting
  3. DHCP snooping
  4. VLAN tagging

Correct Answer: 1

Explanation:

Interface status information can show operational details such as link state, negotiated speed, duplex mode, and other interface parameters. This information is useful when troubleshooting connectivity or performance problems caused by an incorrect or unexpected physical link negotiation. For example, if a port expected to operate at a higher speed is negotiating at a lower speed, an administrator can investigate the endpoint, cable, transceiver, or configuration. RADIUS accounting, DHCP snooping, and VLAN tagging address different functions. Therefore, checking the interface status is the most appropriate first step for identifying physical-link negotiation issues.

Question 143

What is the purpose of BPDU Guard on an edge switch port?

  1. To increase the MTU
  2. To protect the topology from unexpected spanning-tree BPDUs
  3. To provide DHCP addresses
  4. To synchronize switch clocks

Correct Answer: 2

Explanation:

BPDU Guard is designed to protect edge ports from unexpected Bridge Protocol Data Units. Edge ports are normally intended for end devices rather than other switches. If a device connected to such a port begins sending BPDUs, it may indicate that another switching device has been connected and could potentially create a Layer 2 topology problem. BPDU Guard can take protective action according to the configured behavior, helping prevent unauthorized or accidental participation in the spanning-tree topology. MTU configuration, DHCP addressing, and NTP synchronization are unrelated to BPDU Guard.

Question 144

Which LACP mode actively attempts to establish an aggregated link with another device?

  1. Passive
  2. Disabled
  3. Monitor
  4. Active

Correct Answer: 4

Explanation:

In LACP, the active mode actively sends LACP protocol information and attempts to negotiate an aggregated connection with a compatible peer. Passive mode generally waits for the peer to initiate negotiation. For an aggregation to form correctly, the connected devices must have compatible LACP configurations and the physical interfaces must meet the requirements for aggregation. LACP provides redundancy and can increase aggregate bandwidth by combining multiple physical links into a logical connection. The other listed modes are not the appropriate LACP negotiation mode for actively initiating an aggregation.

Question 145

What is a key purpose of assigning an administrative description to a FortiSwitch interface?

  1. To document the purpose or connected device of the interface
  2. To enable ARP inspection
  3. To authenticate the connected endpoint
  4. To create a new VLAN

Correct Answer: 1

Explanation:

An interface description provides useful administrative documentation about a switch port. An administrator can use it to record information such as the connected server, workstation, access point, IP phone, uplink, or physical location. Clear descriptions make troubleshooting and network administration easier, particularly in environments with many switch interfaces. A description does not itself enable ARP inspection, perform endpoint authentication, or create a VLAN. Those functions require separate configuration. Maintaining accurate interface descriptions is a simple operational practice that can significantly improve the ability of administrators to understand and manage the physical network.

Question 146

Which technology can provide additional information about an IP phone and its network capabilities through neighbor discovery?

  1. NTP
  2. LLDP-MED
  3. STP
  4. LACP

Correct Answer: 2

Explanation:

LLDP-MED extends LLDP with capabilities useful for endpoint devices such as IP phones. It can provide information related to network policy, device identification, and other characteristics that help with automated network configuration and management. In voice deployments, LLDP-MED can assist in identifying phones and supporting appropriate voice-network policies. NTP provides time synchronization, STP prevents Layer 2 loops, and LACP handles link aggregation. Therefore, LLDP-MED is the most appropriate technology when additional discovery information and network policy support for IP phones is required.

Question 147

What should an administrator verify first when a FortiSwitch connected device cannot communicate with other hosts in the expected VLAN?

  1. The NTP server
  2. The switch hostname
  3. The interface VLAN assignment
  4. The SNMP community

Correct Answer: 3

Explanation:

The interface VLAN assignment is one of the first configuration elements to verify when an endpoint cannot communicate within its expected VLAN. If an access port is assigned to the wrong VLAN, the connected device may be placed into an incorrect broadcast domain and therefore lose access to the expected resources. On trunk links, administrators should also verify allowed VLANs and tagging behavior. NTP, hostname, and SNMP settings generally do not determine the endpoint’s Layer 2 VLAN membership. Checking the VLAN assignment can quickly identify a common configuration problem before more advanced troubleshooting is performed.

Question 148

What happens when a switch receives a frame destined for an unknown unicast MAC address within a VLAN?

  1. It is normally flooded within the relevant VLAN
  2. It is always dropped immediately
  3. It is converted into a broadcast packet
  4. It is sent to the RADIUS server

Correct Answer: 1

Explanation:

When a Layer 2 switch does not have the destination MAC address in its forwarding table, the destination is considered an unknown unicast. The switch normally floods the frame out appropriate forwarding interfaces within the same VLAN, excluding the interface on which the frame arrived. This gives the destination device an opportunity to respond and allows the switch to learn the destination MAC address from subsequent traffic. Unknown-unicast handling is different from broadcast processing and has nothing to do with RADIUS authentication. Understanding MAC learning and flooding behavior is important for diagnosing Layer 2 connectivity issues.

Question 149

Which setting is most important when replacing a failed FortiSwitch in a centrally managed environment?

  1. Ensuring the replacement receives the intended configuration
  2. Changing all VLAN IDs
  3. Disabling all security controls
  4. Removing the management network

Correct Answer: 1

Explanation:

When replacing a failed FortiSwitch in a centrally managed environment, the replacement device should receive the intended configuration so that network connectivity and security policies remain consistent. Depending on the deployment, centralized management can simplify the provisioning and configuration process. Administrators should verify device identity, firmware compatibility, interface assignments, VLANs, and other relevant settings before placing the replacement into production. Changing VLAN IDs or disabling security controls can introduce additional problems, while removing the management network would make administration more difficult. Proper provisioning helps minimize downtime during hardware replacement.

Question 150

Which feature can help administrators receive notifications or monitoring information when specific network events occur?

  1. PoE
  2. SNMP traps
  3. VLAN tagging
  4. LACP

Correct Answer: 2

Explanation:

SNMP traps allow a managed device to send event notifications to an SNMP management system without requiring the management system to continuously poll for every event. Depending on the supported configuration, traps can be used for events such as interface state changes or other operational conditions. This can improve monitoring responsiveness because the management platform can receive important event information when it occurs. PoE provides power, VLAN tagging identifies VLAN traffic, and LACP manages link aggregation. SNMP traps are therefore the most appropriate feature for event-driven network monitoring notifications.

Question 151

What is a primary purpose of setting an appropriate MAC address aging time on a switch?

  1. To determine how long learned MAC entries remain in the forwarding table
  2. To define the DHCP lease duration
  3. To determine the RADIUS timeout
  4. To control NTP synchronization

Correct Answer: 1

Explanation:

MAC address aging determines how long dynamically learned MAC addresses can remain in the switch’s forwarding table without being refreshed by traffic. Aging allows the switch to adapt when devices move between ports or when previously active devices leave the network. If the aging period is too long, stale entries may remain longer than desired. If it is too short, the switch may need to relearn addresses more frequently, potentially increasing flooding. MAC aging is independent of DHCP lease duration, RADIUS authentication timers, and NTP synchronization.

Question 152

Which configuration is most appropriate for a workstation that should belong to only one VLAN?

  1. Trunk port carrying all VLANs
  2. Access port assigned to the required VLAN
  3. LACP interface with multiple VLANs
  4. Mirror destination port

Correct Answer: 2

Explanation:

An access port is normally used for an endpoint such as a workstation that belongs to a single VLAN. The switch associates untagged traffic received from the workstation with the configured access VLAN. A trunk is generally used to carry multiple VLANs, while LACP combines physical links and a mirror destination is used for traffic analysis. Assigning a workstation’s interface to the correct access VLAN ensures that its traffic is placed into the intended Layer 2 broadcast domain. This is one of the most common configurations for end-user devices connected directly to a FortiSwitch.

Question 153

What is one reason to configure a dedicated management VLAN for network devices?

  1. To separate administrative traffic from ordinary user traffic
  2. To eliminate all broadcast traffic
  3. To increase Ethernet cable length
  4. To disable device authentication

Correct Answer: 1

Explanation:

A dedicated management VLAN provides logical separation for administrative traffic used to access switches and other network infrastructure. Separating management traffic from normal user traffic can improve security and simplify access-control policies. Administrators can restrict management access to authorized systems or networks while reducing exposure to ordinary endpoints. A management VLAN does not eliminate broadcasts, increase physical cable length, or disable authentication. It is a logical segmentation mechanism that supports better network organization and security. Proper firewalling and administrative access controls should still be used to protect management interfaces.

Question 154

Which protocol is commonly used to provide accounting information for authenticated network-access sessions?

  1. LLDP
  2. RADIUS
  3. STP
  4. NTP

Correct Answer: 2

Explanation:

RADIUS can provide authentication, authorization, and accounting capabilities. In network-access deployments, accounting can record information related to user or endpoint sessions, such as session start and stop events and other supported attributes. This information can help administrators monitor network access and investigate authentication activity. LLDP is used for neighbor discovery, STP prevents Layer 2 loops, and NTP synchronizes clocks. RADIUS is therefore the appropriate choice when centralized network-access authentication and accounting are required. Accurate time synchronization through NTP can also improve the usefulness of accounting records.

Question 155

What is the purpose of configuring a native VLAN on a trunk?

  1. To identify traffic that is transmitted without an 802.1Q VLAN tag
  2. To provide PoE power
  3. To authenticate users through RADIUS
  4. To create a MAC address table

Correct Answer: 1

Explanation:

The native VLAN on an 802.1Q trunk is associated with traffic that is transmitted without a VLAN tag under the applicable trunk configuration. Both ends of a trunk should normally have compatible native VLAN settings. A mismatch can cause unexpected traffic behavior and may create security or connectivity concerns. Native VLAN configuration does not provide PoE, perform RADIUS authentication, or create the MAC address table. Administrators should carefully document and control native VLAN usage, especially in environments where multiple switches and network devices are interconnected through trunk interfaces.

Question 156

Which feature can prevent a switch port from accepting DHCP server responses from an untrusted interface?

  1. Port mirroring
  2. DHCP snooping
  3. LLDP
  4. LACP

Correct Answer: 2

Explanation:

DHCP snooping allows switch interfaces to be classified as trusted or untrusted for DHCP operations. Client-facing interfaces are commonly treated as untrusted, while the interface toward a legitimate DHCP server or appropriate upstream network is trusted. DHCP server responses arriving from an unauthorized untrusted interface can then be blocked according to the configured policy. This helps defend against rogue DHCP servers that could provide incorrect gateway, DNS, or IP configuration to clients. Port mirroring, LLDP, and LACP perform different functions and do not provide this specific DHCP security control.

Question 157

Which STP concept determines which switch becomes the central reference point for the spanning-tree topology?

  1. Root bridge election
  2. RADIUS authentication
  3. DHCP snooping
  4. MAC aging

Correct Answer: 1

Explanation:

STP elects a root bridge that serves as the reference point for calculating the loop-free Layer 2 topology. The election is based on bridge identification information, with the device having the preferred bridge ID becoming the root according to STP rules. Other switches calculate their best paths toward the root and determine which ports should forward or remain blocked. Proper root bridge placement is important because it influences traffic paths and the overall topology. RADIUS, DHCP snooping, and MAC aging address authentication, DHCP security, and MAC-table maintenance respectively and are unrelated to root bridge election.

Question 158

What should an administrator check if a PoE-powered access point unexpectedly loses power?

  1. The SNMP community only
  2. The NTP timezone only
  3. The PoE status and available power budget
  4. The RADIUS accounting records only

Correct Answer: 3

Explanation:

When a PoE-powered device loses power, the administrator should first examine the PoE status of the switch interface and the available power budget. The switch may have reached its overall PoE capacity, the interface may have a PoE configuration issue, or the connected device may be drawing power outside expected parameters. Physical cabling and compatibility should also be checked. SNMP, NTP, and RADIUS can provide useful supporting information but do not directly determine whether the switch is delivering electrical power. Checking PoE status and power availability is therefore the most relevant first troubleshooting step.

Question 159

Which feature can help protect against ARP spoofing when used together with DHCP snooping information?

  1. DAI
  2. LACP
  3. LLDP
  4. NTP

Correct Answer: 1

Explanation:

Dynamic ARP Inspection can use trusted IP-to-MAC binding information to validate ARP packets. DHCP snooping can build a database of legitimate IP-to-MAC bindings learned from DHCP activity. DAI can then use those bindings to determine whether ARP messages are consistent with expected endpoint information. This combination provides a stronger defense against ARP spoofing and related Layer 2 attacks. LACP provides link aggregation, LLDP provides neighbor discovery, and NTP synchronizes time. Therefore, DAI is the appropriate feature for validating ARP traffic using binding information.

Question 160

Which action is most appropriate when troubleshooting a FortiSwitch trunk where one VLAN works but another VLAN does not?

  1. Replace the NTP server
  2. Check the allowed VLAN configuration on the trunk
  3. Disable all STP features
  4. Change the RADIUS authentication method

Correct Answer: 2

Explanation:

If one VLAN works across a trunk but another does not, checking the allowed VLAN configuration is an important troubleshooting step. The missing VLAN may not be permitted on the trunk, or the VLAN may not exist or be configured consistently on the connected devices. Administrators should verify the VLAN ID, trunk allowed list, tagging behavior, native VLAN settings where relevant, and the corresponding configuration on the remote side. NTP and RADIUS do not control VLAN transport, while disabling STP can introduce Layer 2 loops. Therefore, verifying the allowed VLAN configuration is the most appropriate first action.