View Full Fortinet NSE5_FSW_AD-7.6 Exam Dumps and Practice Test Dumps.
Question 361
What determines which switch becomes the root bridge in an STP topology?
- The switch with the highest MAC address
- The switch with the lowest Bridge ID
- The switch with the highest interface speed
- The switch with the most VLANs
Correct Answer: 2
Explanation:
STP elects a root bridge based primarily on the Bridge ID. The Bridge ID consists of a bridge priority and a MAC address, with the lowest Bridge ID winning the election. Administrators can influence the election by configuring an appropriate bridge priority on the desired root switch. Selecting a predictable root bridge helps create a stable and efficient Layer 2 topology. Interface speed, VLAN count, or the highest MAC address does not determine the root bridge. Proper STP design should intentionally identify which switches should serve as primary and secondary root bridges.
Question 362
After the STP root bridge is selected, what is the primary purpose of a root port on a non-root switch?
- To provide the best path toward the root bridge
- To provide PoE to neighboring devices
- To assign IP addresses
- To authenticate users
Correct Answer: 1
Explanation:
On a non-root switch, the root port is the interface that provides the best path toward the STP root bridge. STP evaluates available paths using factors such as path cost and tie-breaking rules. The selected root port becomes an important part of the active spanning-tree topology. Other interfaces may become designated, alternate, or blocked depending on the topology. Root ports do not provide DHCP services, user authentication, or PoE simply because they are root ports. Their primary role is to provide the preferred path toward the root bridge.
Question 363
Which STP parameter is commonly used to influence the preferred path toward the root bridge?
- DHCP lease time
- RADIUS timeout
- STP path cost
- SNMP community
Correct Answer: 3
Explanation:
STP path cost is used to evaluate the relative preference of paths toward the root bridge. A switch considers the accumulated path cost when selecting its best path. Generally, a lower total path cost is preferred. Link characteristics can influence default costs, and administrators can configure supported values when a particular topology requires a different preference. DHCP lease time, RADIUS timeout, and SNMP community settings do not determine the STP forwarding path. Understanding path cost is therefore important when troubleshooting unexpected STP port roles.
Question 364
What is the primary purpose of RSTP compared with traditional STP?
- To provide faster Layer 2 topology convergence
- To replace VLAN tagging
- To provide centralized user authentication
- To assign management IP addresses
Correct Answer: 1
Explanation:
Rapid Spanning Tree Protocol, or RSTP, improves convergence behavior compared with traditional STP. Its mechanisms allow the network to transition to a stable forwarding topology more quickly after certain topology changes. Faster convergence can reduce the duration of connectivity disruption caused by link or device failures. RSTP does not replace VLAN tagging, provide centralized authentication, or assign management IP addresses. It remains a Layer 2 loop-prevention technology designed to maintain a loop-free topology while responding efficiently to changes.
Question 365
Which STP protection feature is designed to help prevent a port from becoming an unintended path toward the root because of an unexpected topology condition?
- Port mirroring
- Loop Guard
- DHCP snooping
- RADIUS accounting
Correct Answer: 2
Explanation:
Loop Guard is an STP protection mechanism intended to help prevent certain conditions in which a port that should remain non-designated could incorrectly transition to a forwarding state because expected BPDUs are no longer being received. Such a situation can contribute to a Layer 2 loop. Loop Guard helps maintain the intended STP topology by protecting against failures involving BPDU reception. Port mirroring is used for traffic analysis, DHCP snooping provides DHCP security, and RADIUS accounting records authentication-related activity.
Question 366
What is the main purpose of LACP system or port priority settings?
- To influence link aggregation decisions when multiple links are available
- To assign VLAN IDs to clients
- To configure DHCP scopes
- To determine NTP time zones
Correct Answer: 1
Explanation:
LACP uses information exchanged between devices to negotiate and maintain link aggregation. Priority values can influence which device or ports are preferred when selecting links for an aggregation group, depending on the implementation and configuration. This can be useful when more candidate links exist than can participate in the logical bundle. VLAN IDs, DHCP scopes, and NTP time zones are unrelated to LACP selection. Administrators should ensure that both ends of an aggregate connection have compatible settings and that the intended member interfaces are properly configured.
Question 367
What should an administrator verify when configuring multiple physical interfaces as members of an LACP group?
- That the interfaces have compatible configuration and connectivity
- That each interface uses a different native VLAN
- That all interfaces have different IP addresses
- That each interface connects to an unrelated network
Correct Answer: 1
Explanation:
Interfaces participating in an LACP aggregation must be configured consistently enough for the device to treat them as members of the same logical connection. Administrators should verify physical connectivity, compatible speed and duplex behavior where applicable, VLAN configuration, LACP settings, and the configuration on the remote device. Giving each member an unrelated network configuration would defeat the purpose of aggregation. The exact requirements depend on the FortiSwitch and network design, but consistency between participating interfaces is a fundamental consideration.
Question 368
What information can LLDP-MED provide for compatible IP phones?
- Network policy information such as voice VLAN-related details
- User passwords
- DHCP server administrator credentials
- STP root bridge passwords
Correct Answer: 1
Explanation:
LLDP-MED extends LLDP capabilities for media endpoint devices such as IP phones. It can communicate network policy information that helps compatible endpoints understand how they should operate on the network. This can include voice VLAN-related information and other parameters supported by the LLDP-MED implementation. This approach can simplify voice endpoint provisioning and reduce manual configuration. LLDP-MED does not transmit administrator passwords or credentials. Authentication and security should be handled through appropriate dedicated mechanisms.
Question 369
Why can LLDP-MED be useful in a network containing IP phones and computers?
- It can help communicate voice-related network policy to supported phones
- It disables the data VLAN
- It converts every port into a trunk
- It replaces the need for PoE
Correct Answer: 1
Explanation:
In a network where an IP phone and a computer share a physical switch connection, LLDP-MED can help a supported phone learn network policy information, such as the appropriate voice VLAN. This can simplify deployment and reduce manual configuration. The data device can continue operating in its appropriate network segment while the phone uses the voice network according to the design. LLDP-MED does not automatically eliminate data VLANs, turn every port into a trunk, or replace PoE. It primarily provides useful discovery and policy information to compatible endpoints.
Question 370
What is one advantage of using static MAC address entries in a specific security-sensitive scenario?
- They can provide predictable MAC-to-interface forwarding behavior
- They automatically encrypt Ethernet traffic
- They replace all VLAN configuration
- They provide centralized RADIUS authentication
Correct Answer: 1
Explanation:
A static MAC address entry can associate a particular MAC address with a specified interface and VLAN context. This can provide predictable forwarding behavior and may be useful in selected controlled environments. Static entries should be used carefully because they require administration when devices or topology change. They do not encrypt Ethernet traffic, replace VLANs, or provide centralized authentication. Dynamic MAC learning remains appropriate for many ordinary switching environments, while static entries are generally reserved for specific operational or security requirements.
Question 371
What is a potential indication of MAC address flapping on a FortiSwitch?
- The same MAC address repeatedly appears on different interfaces
- The switch clock changes time zone
- A RADIUS server receives an authentication request
- A DHCP lease reaches renewal time
Correct Answer: 1
Explanation:
MAC address flapping can occur when the same source MAC address is repeatedly learned on different switch interfaces within a short period. This can indicate a Layer 2 loop, redundant connection problem, incorrect cabling, virtualization behavior, or another topology issue. Administrators can review switch logs, MAC address tables, and interface status to investigate the cause. A changing clock, RADIUS request, or DHCP lease renewal does not by itself indicate MAC flapping. Identifying the affected MAC and interfaces is an important troubleshooting step.
Question 372
What should an administrator investigate first when a switch interface repeatedly goes up and down?
- Physical connectivity and interface errors
- Only the SNMP community
- Only the VLAN name
- Only the administrator password
Correct Answer: 1
Explanation:
Repeated interface state changes, commonly called link flapping, should initially be investigated at the physical and interface levels. Administrators can inspect cables, transceivers, interface statistics, errors, speed and duplex negotiation, and the connected device. Hardware problems or unstable physical connections can cause repeated transitions. Logs may provide additional evidence about when the events occur. SNMP settings, VLAN names, or administrator passwords are not normally the first areas to investigate for a physically unstable Ethernet link.
Question 373
What is the purpose of interface error counters during FortiSwitch troubleshooting?
- To help identify physical or transmission problems
- To determine the user’s password
- To select a RADIUS server automatically
- To create new VLANs
Correct Answer: 1
Explanation:
Interface statistics and error counters can provide valuable evidence when troubleshooting network connectivity problems. Depending on the type of errors reported, they may indicate damaged cabling, physical-layer problems, negotiation issues, congestion, or other interface conditions. Administrators should compare counters over time rather than relying only on a single snapshot. They can also inspect the remote interface and physical components. Error counters do not create VLANs or select authentication servers. They are primarily diagnostic information for understanding interface behavior.
Question 374
Which approach provides the best protection against unauthorized administrative access to network management interfaces?
- Exposing management interfaces to every network
- Restricting management access to trusted hosts or networks and using strong authentication
- Disabling all logging
- Using the same password on every device
Correct Answer: 2
Explanation:
Management interfaces should be protected because unauthorized administrative access can compromise the entire network infrastructure. A strong approach is to restrict management access to approved hosts or management networks and use appropriate authentication and secure management protocols. Additional controls such as administrator profiles and monitoring can further reduce risk. Exposing management interfaces broadly increases the attack surface. Disabling logging removes useful security visibility, while reusing the same password across devices increases the impact of credential compromise.
Question 375
Which SNMP capability allows a monitoring system to periodically request information from a FortiSwitch?
- Polling
- Link aggregation
- Port security
- VLAN pruning
Correct Answer: 1
Explanation:
SNMP polling occurs when a management or monitoring system periodically requests information from a network device. The collected information can include interface statistics, device health information, counters, and other supported monitoring data. Polling allows the monitoring system to build a historical view of device performance and status. SNMP traps work differently because they allow the device to send event notifications to the management system. LACP, port security, and VLAN pruning do not provide SNMP monitoring functionality.
Question 376
What is the primary advantage of SNMP traps compared with continuous polling for certain events?
- The device can notify the monitoring system when a configured event occurs
- They automatically configure VLANs
- They replace all switch logs
- They provide physical PoE power
Correct Answer: 1
Explanation:
SNMP traps allow a network device to send notifications to an SNMP management system when particular events occur. This can provide faster awareness of events without requiring the monitoring system to repeatedly poll for every possible change. Polling remains useful for collecting regular statistics and historical data, while traps are valuable for event-driven notifications. SNMP traps do not configure VLANs, replace all switch logging, or provide electrical power. Administrators should configure monitoring appropriately so important events are detected without creating unnecessary noise.
Question 377
Why should switch configuration backups be retained before a major firmware upgrade?
- They provide a recovery reference if the upgrade causes configuration problems
- They automatically increase switch bandwidth
- They prevent every hardware failure
- They replace the firmware image
Correct Answer: 1
Explanation:
A configuration backup provides a known reference that can be used during recovery if an upgrade results in unexpected configuration problems. Before a major firmware change, administrators should also review compatibility requirements, document the current configuration, and maintain an appropriate rollback or recovery plan. A backup does not increase bandwidth or prevent hardware failures, and it is not a replacement for the firmware image itself. Keeping reliable backups is an important part of change management and helps reduce the operational risk associated with upgrades.
Question 378
What should be considered before upgrading FortiSwitch firmware in a production environment?
- Only the switch hostname
- Firmware compatibility, release requirements, and an appropriate recovery plan
- Only the number of connected PCs
- Only the MAC address aging timer
Correct Answer: 2
Explanation:
Firmware upgrades should be planned carefully because compatibility and operational requirements can vary between FortiSwitch models and management environments. Administrators should verify supported firmware relationships, review release information, confirm configuration backups, and plan an appropriate maintenance window. They should also consider whether connected FortiGate or centralized management components require compatible versions. A recovery or rollback plan should be available if unexpected behavior occurs. The switch hostname, number of PCs, or MAC aging timer alone does not provide sufficient information for safe firmware planning.
Question 379
What is configuration drift in a centrally managed switch environment?
- Differences that develop between intended standardized settings and the actual device configuration
- A physical cable disconnect
- A DHCP lease renewal
- An STP root bridge election
Correct Answer: 1
Explanation:
Configuration drift occurs when a device’s actual configuration gradually differs from the organization’s intended or standardized configuration. This can happen because of manual changes, inconsistent deployments, emergency modifications, or other administrative actions. Configuration drift can make troubleshooting more difficult and may introduce security or connectivity inconsistencies. Centralized management, configuration templates, revision tracking, and regular configuration reviews can help identify and reduce drift. A cable failure, DHCP renewal, or STP election is not itself an example of configuration drift.
Question 380
What is the main benefit of maintaining configuration revision history for FortiSwitch devices?
- It allows administrators to track changes and help identify when a configuration problem was introduced
- It automatically repairs every failed interface
- It increases PoE capacity
- It eliminates the need for monitoring
Correct Answer: 1
Explanation:
Configuration revision history provides useful operational visibility by allowing administrators to understand what changes were made and when. If a network problem appears after a configuration modification, revision information can help identify the change that may have contributed to the issue. It can also support controlled rollback or comparison with a known-good configuration when supported by the management system. Revision history does not repair physical interfaces, increase PoE capacity, or replace monitoring. It is an important component of effective configuration and change management.