View Full Fortinet NSE5_FSW_AD-7.6 Exam Dumps and Practice Test Dumps.
Question 261
What is the primary purpose of a FortiSwitch device group in centralized management?
- To replace all VLAN configurations
- To disable switch monitoring
- To organize switches for easier administration and policy application
- To prevent switches from communicating with FortiGate
Correct Answer: 3
Explanation:
Device groups help administrators organize FortiSwitch devices logically within a centralized management environment. Switches can be grouped according to location, function, department, or another operational requirement. This makes it easier to manage large deployments and maintain consistent configurations. Grouping devices does not replace VLANs or prevent communication with FortiGate. Instead, it improves administrative organization and can support applying common settings or policies where appropriate. This becomes increasingly useful as the number of managed FortiSwitch devices grows.
Question 262
Which interface configuration is normally appropriate for a user workstation that belongs to a single VLAN?
- Access interface
- Trunk interface
- LACP interface
- Mirror destination
Correct Answer: 1
Explanation:
An access interface is normally used for an endpoint such as a workstation that belongs to a single VLAN. The switch associates untagged traffic received from the workstation with the configured access VLAN. A trunk interface is generally used when multiple VLANs need to traverse the same link, such as between switches or between a switch and another VLAN-aware device. LACP is related to link aggregation, while a mirror destination is used for traffic analysis. Correctly selecting access or trunk mode is important for maintaining expected VLAN connectivity.
Question 263
What happens when a switch receives a frame with a destination MAC address that is not currently in its MAC address table?
- The frame is always discarded immediately.
- The switch sends the frame only to the management interface.
- The switch converts the frame into a broadcast.
- The switch generally floods the frame within the appropriate VLAN.
Correct Answer: 4
Explanation:
When a switch does not have the destination MAC address in its forwarding table, it generally treats the frame as an unknown unicast. The switch forwards or floods the frame out appropriate ports within the same VLAN, excluding the interface on which the frame arrived. When the destination device responds, the switch can learn its source MAC address and add it to the MAC address table. This normal Layer 2 behavior allows communication to continue while the switch learns where devices are located.
Question 264
Which feature helps prevent a rogue DHCP server from responding to client requests?
- LACP
- DHCP snooping
- LLDP
- Port mirroring
Correct Answer: 2
Explanation:
DHCP snooping helps protect a Layer 2 network from unauthorized or rogue DHCP servers. Interfaces can be classified as trusted or untrusted. DHCP server responses are expected to come from trusted interfaces, such as an uplink toward the legitimate DHCP server. Client-facing interfaces are generally configured as untrusted. If unauthorized DHCP responses arrive through an untrusted interface, the switch can block them according to the configured behavior. DHCP snooping can also create DHCP binding information that other security mechanisms may use for validation.
Question 265
Which STP mechanism is designed to protect the topology from a port receiving superior BPDUs where that port should not become part of the root path?
- Root Guard
- DHCP snooping
- IP Source Guard
- Storm Control
Correct Answer: 1
Explanation:
Root Guard helps maintain the intended STP topology by preventing a downstream device from influencing root bridge selection through superior BPDUs. It is useful on interfaces where the administrator expects the local network hierarchy to remain authoritative. If superior BPDUs are received on a protected interface, the interface can enter an appropriate STP protective state rather than allowing the downstream device to influence the root. DHCP snooping and IP Source Guard provide different security functions, while storm control limits excessive traffic.
Question 266
What is a key advantage of using LACP with multiple physical links between network devices?
- It converts all traffic into broadcast traffic.
- It removes the need for VLAN configuration.
- It can provide link redundancy and aggregate available bandwidth.
- It prevents the switch from learning MAC addresses.
Correct Answer: 3
Explanation:
LACP allows multiple physical links to operate as a logical aggregated connection when both devices are configured compatibly. This can provide redundancy because traffic may continue using remaining member links if one physical connection fails. Link aggregation can also increase the aggregate capacity available to the logical connection, although individual traffic flows are distributed according to the hashing and load-balancing method. LACP does not eliminate VLAN configuration or MAC learning. Its primary benefits are improved resiliency and efficient use of multiple physical links.
Question 267
What should be checked if an IP phone receives data connectivity but does not obtain the expected voice VLAN configuration through LLDP-MED?
- Only the MAC aging timer
- LLDP-MED configuration and the voice VLAN settings
- Only the STP root priority
- Only the SNMP polling interval
Correct Answer: 2
Explanation:
If an IP phone does not receive the expected voice VLAN information through LLDP-MED, the administrator should verify that LLDP-MED is enabled and correctly configured on the relevant switch interface. The voice VLAN and associated network policy should also be checked. The phone must support the relevant LLDP-MED functionality for automatic policy discovery to work as expected. MAC aging, STP root priority, and SNMP polling do not normally determine whether the phone receives its voice VLAN information through LLDP-MED.
Question 268
Which configuration is most appropriate when a server needs to communicate on several VLANs through one physical switch interface?
- Access mode with one VLAN
- Disabled interface
- Trunk configuration with the required VLANs
- Mirror destination mode
Correct Answer: 3
Explanation:
A trunk interface is generally appropriate when a VLAN-aware server or other network device needs to communicate with multiple VLANs through a single physical connection. The required VLANs can be permitted on the trunk, and traffic is distinguished using VLAN tagging. The server must also be configured appropriately to understand the VLANs, often through VLAN subinterfaces or another supported mechanism. An access interface is normally associated with one VLAN, while a mirror destination is intended for traffic analysis rather than normal production connectivity.
Question 269
What is the main purpose of an interface description on a FortiSwitch port?
- To document the connected device or purpose of the interface
- To enable DHCP snooping automatically
- To create an STP root bridge
- To increase the interface bandwidth
Correct Answer: 1
Explanation:
An interface description is an administrative label used to document the purpose or connected device of a network interface. For example, an administrator might describe a port as an uplink to another switch, a particular server, or a specific department. Clear descriptions make troubleshooting and network administration easier because administrators can understand the intended role of a port without physically tracing every cable. Interface descriptions do not change bandwidth, automatically enable DHCP snooping, or determine STP root bridge selection.
Question 270
What is the purpose of a management IP address on a FortiSwitch?
- To assign an IP address to every connected endpoint
- To provide IP-based access for management and monitoring functions
- To replace all Layer 2 switching
- To automatically configure every VLAN
Correct Answer: 2
Explanation:
A management IP address provides IP-based connectivity for administrative and monitoring functions. Administrators can use the management network to access the switch through supported management protocols and monitor its status. In centrally managed environments, management connectivity is also important for communication between the switch and its management system. A management IP does not replace normal Layer 2 switching and does not automatically configure every VLAN. Proper management-plane design can also include access restrictions, secure protocols, and dedicated management networks.
Question 271
Which FortiSwitch feature can provide visibility into traffic by sending a copy of selected packets to another interface?
- DHCP relay
- LACP
- Port mirroring
- Root Guard
Correct Answer: 3
Explanation:
Port mirroring allows selected traffic from one or more source interfaces or VLANs to be copied to a designated destination interface. A monitoring device, packet analyzer, or intrusion detection system can then inspect the copied traffic without being directly in the production traffic path. Port mirroring is useful for troubleshooting, security analysis, and performance investigation. The destination interface should be configured appropriately because excessive mirrored traffic can affect the monitoring setup. DHCP relay, LACP, and Root Guard perform completely different network functions.
Question 272
What is the purpose of configuring an appropriate native VLAN on a trunk?
- To define how untagged traffic on the trunk is handled
- To disable all tagged VLAN traffic
- To enable SNMP traps
- To provide PoE power
Correct Answer: 1
Explanation:
The native VLAN on a trunk determines which VLAN is associated with untagged traffic received on that trunk, depending on the device and configuration. A mismatch in native VLAN settings between connected devices can result in unexpected connectivity or security issues. Administrators should ensure that trunk configurations are consistent and that the native VLAN is intentionally selected. Tagged traffic for other permitted VLANs remains identified by VLAN tags. Native VLAN configuration is unrelated to SNMP traps or PoE power delivery.
Question 273
Which setting can help reduce unnecessary VLAN exposure across a trunk link?
- Increasing the MAC aging timer
- Allowing every possible VLAN
- Disabling interface descriptions
- Restricting the trunk’s allowed VLAN list
Correct Answer: 4
Explanation:
Restricting the allowed VLAN list on a trunk ensures that only required VLANs can traverse the link. This reduces unnecessary Layer 2 exposure and can simplify troubleshooting by making the intended topology clearer. Allowing every VLAN may create unnecessary connectivity and increase the potential impact of configuration mistakes. Administrators should review which VLANs are actually required between the connected devices and permit only those VLANs where practical. This is a useful network segmentation and configuration-hardening practice.
Question 274
What is the main function of IP Source Guard on a switch port?
- To provide PoE power
- To restrict traffic based on validated IP-to-MAC bindings
- To elect the STP root bridge
- To negotiate an LACP group
Correct Answer: 2
Explanation:
IP Source Guard helps prevent a device from using an unauthorized source IP address on a protected switch interface. It can use binding information, commonly associated with DHCP snooping, to determine which IP and MAC address combinations are legitimate for a particular port. Traffic that does not match the expected binding can be restricted according to the configured security policy. This helps protect against certain IP spoofing attacks. IP Source Guard is a security feature and does not perform STP election, PoE delivery, or link aggregation.
Question 275
What is a likely result of a speed or duplex mismatch between connected Ethernet interfaces?
- Improved bandwidth automatically
- Elimination of packet errors
- Performance problems, errors, or unstable connectivity
- Automatic creation of a new VLAN
Correct Answer: 3
Explanation:
A speed or duplex mismatch can cause significant network performance problems. Depending on the interfaces and negotiation behavior, symptoms may include collisions, packet errors, retransmissions, low throughput, or unstable connectivity. When troubleshooting an interface with unusual errors or poor performance, administrators should compare the operational speed and duplex settings on both ends of the link. Physical cabling and transceiver compatibility should also be checked. Correctly negotiated or deliberately configured interface parameters help ensure reliable Ethernet communication.
Question 276
Which protocol is primarily used to discover neighboring network devices and advertise device/interface information?
- LLDP
- LACP
- RADIUS
- NTP
Correct Answer: 1
Explanation:
Link Layer Discovery Protocol, or LLDP, is used by network devices to advertise information about themselves to directly connected neighbors. Information can include device identity, interface information, capabilities, and other supported details. This makes LLDP useful for topology discovery and troubleshooting. LLDP-MED extends LLDP functionality for certain endpoint types, especially IP phones. LACP is used for link aggregation, RADIUS for centralized authentication, and NTP for time synchronization. LLDP therefore provides the appropriate functionality for discovering neighboring network devices.
Question 277
Why is accurate NTP configuration important for FortiSwitch monitoring and troubleshooting?
- It increases PoE power capacity.
- It synchronizes device clocks so logs and events have consistent timestamps.
- It changes VLAN IDs automatically.
- It prevents all Layer 2 loops.
Correct Answer: 2
Explanation:
Accurate time synchronization is important because network logs and events need reliable timestamps. When multiple FortiSwitch devices use synchronized clocks, administrators can correlate events across devices more easily during troubleshooting or security investigations. Without consistent time, it can be difficult to determine the sequence of events or compare logs from different systems. NTP provides a standardized mechanism for synchronizing device clocks with an appropriate time source. It does not increase PoE capacity, change VLAN IDs, or directly prevent Layer 2 loops.
Question 278
What should an administrator verify if a FortiSwitch firmware upgrade is being planned?
- Only the interface description
- Only the MAC address aging timer
- Firmware compatibility, supported upgrade path, and configuration backup
- Only the number of connected IP phones
Correct Answer: 3
Explanation:
Before upgrading FortiSwitch firmware, administrators should verify that the target firmware is compatible with the switch model and management environment. They should also review the supported upgrade path and relevant release information. Creating a configuration backup before the change provides a recovery point if unexpected problems occur. A maintenance window may also be required because the switch can experience service interruption during an upgrade or reboot. Checking only interface descriptions, MAC aging, or phone count does not provide sufficient preparation for a firmware change.
Question 279
What is the purpose of configuration revision or change history in centralized network management?
- To track configuration changes and assist with troubleshooting or rollback
- To increase Ethernet cable speed
- To automatically replace failed hardware
- To disable all administrative accounts
Correct Answer: 1
Explanation:
Configuration revision or change history helps administrators understand what modifications have been made to a managed device or configuration. This is valuable when troubleshooting because a newly introduced problem may be associated with a recent configuration change. Maintaining revisions can also support controlled rollback when a previous known-good configuration needs to be restored. Change tracking improves accountability and operational visibility in larger environments. It does not increase physical link speed or automatically replace hardware. Administrators should still maintain appropriate backups and follow formal change-management procedures.
Question 280
Which practice best improves security for FortiSwitch administrative access?
- Allowing management access from every network without restrictions
- Using unrestricted plain-text management wherever possible
- Sharing one administrator account among all users
- Restricting management access and using appropriate secure authentication and protocols
Correct Answer: 4
Explanation:
FortiSwitch administrative access should be protected using appropriate management-plane security controls. Restricting management access to trusted networks or administrator sources reduces exposure. Secure management protocols and strong authentication help protect administrative credentials and configuration information. Individual administrator accounts or appropriate role-based profiles also improve accountability compared with sharing a single account. Leaving management services broadly accessible or relying on insecure protocols increases the attack surface. A layered management-security approach therefore provides stronger protection for the switch and its configuration.