{"id":12867,"date":"2026-09-15T12:58:52","date_gmt":"2026-09-15T12:58:52","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=12867"},"modified":"2026-09-15T12:58:52","modified_gmt":"2026-09-15T12:58:52","slug":"fortinet-nse5_fsw_ad-7-6-practice-test-questions-and-exam-dumps-part5-q81-100","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/fortinet-nse5_fsw_ad-7-6-practice-test-questions-and-exam-dumps-part5-q81-100\/","title":{"rendered":"Fortinet NSE5_FSW_AD-7.6 Practice Test Questions and Exam Dumps Part5 Q81-100"},"content":{"rendered":"<h2><b>View Full <a href=\"https:\/\/www.examlabs.com\/nse5-fsw-ad-7-6-exam-dumps\">Fortinet NSE5_FSW_AD-7.6 Exam Dumps<\/a> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 81<\/b><\/h3>\n<p><b>Which FortiSwitch feature can help protect a network from unauthorized devices by controlling the MAC addresses allowed on a port?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LLDP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SNMP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Port security can be used to restrict the MAC addresses that are permitted on a FortiSwitch interface. This can help prevent unauthorized devices from connecting to sensitive network ports. Depending on the configuration, an administrator may specify permitted MAC addresses or limit the number of MAC addresses that can be learned on an interface. If an unexpected device appears, the configured security action can be applied. NTP provides time synchronization, LLDP provides neighbor discovery, and SNMP provides monitoring and management. Port security is therefore the most relevant feature when the objective is to control which endpoint MAC addresses can use a switch interface.<\/span><\/p>\n<h3><b>Question 82<\/b><\/h3>\n<p><b>What is the primary function of a FortiSwitch VLAN?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To provide electrical power<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To synchronize device clocks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To create a logical Layer 2 network segment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To authenticate RADIUS users<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A VLAN, or Virtual Local Area Network, creates a logical Layer 2 network segment within switching infrastructure. VLANs allow administrators to separate different groups of devices without requiring a completely separate physical switch for every network segment. For example, employee, guest, voice, and management traffic can be placed into separate VLANs. This improves organization and can provide a foundation for applying different security and routing policies. VLANs do not provide electrical power, synchronize clocks, or directly authenticate users. PoE handles power delivery, NTP handles time synchronization, and RADIUS can provide centralized authentication.<\/span><\/p>\n<h3><b>Question 83<\/b><\/h3>\n<p><b>Which FortiSwitch feature can provide additional visibility into traffic statistics without directly interrupting normal packet forwarding?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SNMP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">STP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LACP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">SNMP can provide monitoring systems with operational information and statistics from FortiSwitch devices. Depending on the configured monitoring system and supported MIBs, administrators can view interface status, packet counters, errors, traffic levels, and other device information. This visibility helps identify congestion, failed interfaces, and unusual traffic patterns. SNMP does not itself prevent switching loops, aggregate physical links, or authenticate endpoints. STP is designed for loop prevention, LACP manages link aggregation, and RADIUS commonly provides centralized authentication. Therefore, SNMP is the best choice when the objective is to obtain network-management information and traffic statistics.<\/span><\/p>\n<h3><b>Question 84<\/b><\/h3>\n<p><b>Which component typically acts as the authenticator when implementing 802.1X on a FortiSwitch access port?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The endpoint&#8217;s web browser<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The FortiSwitch<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The DNS server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The NTP server<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">In an 802.1X deployment, the network switch typically acts as the authenticator. It controls access to the network port and communicates with the endpoint, which acts as the supplicant. The switch can also communicate with a RADIUS authentication server to validate the credentials or identity information provided by the endpoint. This architecture allows the switch to keep the port restricted until authentication succeeds. DNS servers and NTP servers perform completely different functions and are not responsible for controlling 802.1X port authorization. Therefore, the FortiSwitch is the component that normally performs the authenticator role.<\/span><\/p>\n<h3><b>Question 85<\/b><\/h3>\n<p><b>What is the main purpose of configuring an NTP server on FortiSwitch devices?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To synchronize system time<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To provide VLAN tagging<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To aggregate Ethernet links<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To authenticate network users<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">NTP, or Network Time Protocol, allows FortiSwitch devices to synchronize their system clocks with a configured time source. Accurate time is important for logging, monitoring, troubleshooting, and security investigations. If different network devices have significantly different clocks, administrators may find it difficult to correlate events accurately across the infrastructure. NTP does not provide VLAN tagging, link aggregation, or user authentication. VLAN configuration controls Layer 2 segmentation, LACP handles link aggregation, and RADIUS is commonly used for centralized authentication. Consistent NTP configuration therefore helps ensure reliable timestamps across the switching environment.<\/span><\/p>\n<h3><b>Question 86<\/b><\/h3>\n<p><b>Which feature can help prevent a malicious host from using a forged source IP address on a FortiSwitch network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP source guard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LLDP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">PoE<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LACP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">IP source guard is designed to help prevent unauthorized source IP addresses from being used on a switch interface. It can use trusted IP-to-MAC binding information to determine whether traffic arriving from an endpoint matches an expected source identity. This helps reduce certain IP-spoofing attacks, especially in access-layer environments. DHCP snooping can provide useful binding information for related security mechanisms. LLDP is used for neighbor discovery, PoE supplies electrical power, and LACP provides link aggregation. Therefore, IP source guard is the most appropriate feature when the objective is to restrict traffic using unauthorized source IP addresses.<\/span><\/p>\n<h3><b>Question 87<\/b><\/h3>\n<p><b>Which FortiSwitch feature can help protect against excessive unknown-unicast traffic?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storm control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">802.1X<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Storm control can be configured to limit excessive amounts of certain types of Layer 2 traffic, including unknown-unicast traffic. Excessive unknown-unicast, broadcast, or multicast traffic can consume network bandwidth and switch resources. In extreme situations, this behavior may affect legitimate communications across the network. Storm-control thresholds help administrators limit the impact of such traffic and improve network stability. RADIUS provides authentication, NTP synchronizes clocks, and 802.1X controls authenticated network access. Therefore, storm control is the most suitable feature when administrators want to control excessive Layer 2 traffic on switch interfaces.<\/span><\/p>\n<h3><b>Question 88<\/b><\/h3>\n<p><b>What is the primary benefit of using a centralized FortiSwitch management solution?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It makes every switch independent of configuration policies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It provides unified administration and monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It removes the requirement for network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It disables switch logs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Centralized management provides a unified method for administering and monitoring multiple FortiSwitch devices. Instead of repeatedly configuring individual switches, administrators can use centralized tools to maintain consistent settings, monitor operational status, review topology information, and simplify routine management tasks. This can become particularly valuable as the number of switches increases. Centralized management does not eliminate network segmentation, disable logging, or make each switch independent of policies. Its primary benefit is improving operational efficiency and consistency. By reducing repetitive administration, centralized management can also make troubleshooting and configuration auditing easier across a larger FortiSwitch deployment.<\/span><\/p>\n<h3><b>Question 89<\/b><\/h3>\n<p><b>Which configuration is normally used when a FortiSwitch interface connects to an IP phone and the attached workstation uses a separate data VLAN?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A configuration supporting separate voice and data VLANs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">An NTP-only configuration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A port-mirroring-only configuration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">An LACP configuration with no VLANs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When an IP phone and workstation share the same physical switch connection, separate voice and data VLANs can be used to logically isolate their traffic. The phone can use the voice VLAN while the attached workstation uses the appropriate data VLAN. This design allows administrators to apply different policies and quality-of-service considerations to voice and user traffic. The exact FortiSwitch configuration depends on the phone and network design, but the important concept is maintaining logical separation between voice and data. NTP, port mirroring, and LACP do not provide this voice\/data VLAN segmentation by themselves.<\/span><\/p>\n<h3><b>Question 90<\/b><\/h3>\n<p><b>What happens when a switch receives an Ethernet frame whose destination MAC address is not currently in its MAC address table?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It always sends the frame only to the management interface<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It normally floods the frame within the applicable VLAN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It immediately deletes the VLAN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It sends the frame to the NTP server<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When a switch does not know the destination MAC address for a frame, it generally treats the frame as an unknown unicast and floods it out appropriate ports within the same VLAN, excluding the port on which the frame was received. When the destination device responds, the switch can learn its source MAC address and associate it with the receiving interface. This allows future frames to be forwarded more efficiently. The frame is not sent specifically to the management interface or NTP server. Understanding MAC learning and unknown-unicast behavior is important when troubleshooting Layer 2 connectivity.<\/span><\/p>\n<h3><b>Question 91<\/b><\/h3>\n<p><b>Which protocol is commonly used to provide centralized authentication services for FortiSwitch 802.1X clients?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">STP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LLDP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LACP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">RADIUS is commonly used as the centralized authentication server protocol in 802.1X deployments. When a client attempts to access the network, the FortiSwitch can act as the authenticator and communicate with the RADIUS server to validate the endpoint&#8217;s authentication information. The authentication result can determine whether the port is authorized and, depending on the deployment, may provide additional authorization information. STP handles Layer 2 loop prevention, LLDP provides neighbor discovery, and LACP manages link aggregation. RADIUS therefore plays a central role when centralized authentication is required for 802.1X-controlled FortiSwitch ports.<\/span><\/p>\n<h3><b>Question 92<\/b><\/h3>\n<p><b>What is the primary purpose of a trunk&#8217;s native VLAN in a typical VLAN configuration?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To identify traffic that is transmitted untagged on the trunk<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To provide PoE power<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To authenticate RADIUS users<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To prevent all multicast traffic<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The native VLAN is commonly associated with untagged traffic transmitted over a trunk. While tagged traffic includes VLAN identification, untagged traffic requires the receiving device to have an agreed-upon VLAN context. Therefore, both ends of a trunk should be configured consistently when a native VLAN is used. Incorrect native-VLAN configurations can cause traffic to be placed into an unintended VLAN and may create connectivity or security problems. PoE handles power delivery, RADIUS supports authentication, and multicast control is a separate networking function. The native VLAN&#8217;s primary purpose is therefore to define the VLAN context for applicable untagged trunk traffic.<\/span><\/p>\n<h3><b>Question 93<\/b><\/h3>\n<p><b>Which FortiSwitch feature can help identify the physical port where a particular MAC address was learned?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MAC address table<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS accounting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP relay<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The MAC address table records learned Layer 2 addresses and the switch interfaces associated with them. By examining the table, an administrator can often determine which physical port currently has a particular MAC address associated with it. This is useful when locating an endpoint, troubleshooting unexpected connectivity, or identifying where a device is connected within the switching topology. NTP provides time synchronization, RADIUS accounting records authentication-related information, and DHCP relay forwards DHCP requests between network segments. Therefore, the MAC address table is the appropriate source for determining where a learned MAC address is associated within the switch.<\/span><\/p>\n<h3><b>Question 94<\/b><\/h3>\n<p><b>Why is DHCP snooping information useful for other Layer 2 security features?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It can provide trusted IP-to-MAC binding information<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It automatically creates encrypted tunnels<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It disables all VLANs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It increases PoE power capacity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DHCP snooping can build or maintain trusted bindings between client IP addresses, MAC addresses, VLANs, and switch interfaces based on legitimate DHCP activity. This information can be useful to other security mechanisms that need to validate whether traffic is using an expected IP-to-MAC relationship. For example, features such as Dynamic ARP Inspection and IP source guard can use trusted binding information as part of their security decisions. DHCP snooping does not create encrypted tunnels, disable VLANs, or increase PoE capacity. Its security value extends beyond blocking rogue DHCP servers because its learned information can support additional access-layer protections.<\/span><\/p>\n<h3><b>Question 95<\/b><\/h3>\n<p><b>Which FortiSwitch feature is most directly associated with preventing unauthorized ARP responses from reaching clients?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LACP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DAI<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SNMP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Dynamic ARP Inspection, or DAI, helps protect clients from forged or unauthorized ARP messages. It inspects ARP traffic and validates the information according to trusted IP-to-MAC bindings and configured policies. This can reduce the risk of ARP spoofing, where an attacker sends fraudulent ARP information to redirect traffic through the attacker&#8217;s device. LACP is used for link aggregation, NTP handles time synchronization, and SNMP is used for monitoring and management. Therefore, DAI is the most directly relevant security feature when the goal is to inspect and control ARP responses within a Layer 2 network.<\/span><\/p>\n<h3><b>Question 96<\/b><\/h3>\n<p><b>What is one purpose of using LLDP information in a FortiSwitch environment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To identify connected network devices and their capabilities<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To provide centralized password authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To assign DHCP addresses<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To prevent ARP spoofing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">LLDP allows directly connected network devices to exchange information about themselves. Depending on the implementation, this can include device identity, interface information, system capabilities, and other topology-related details. Administrators can use this information to understand how network devices are connected and to troubleshoot unexpected physical connections. LLDP does not provide centralized password authentication, assign DHCP addresses, or directly prevent ARP spoofing. RADIUS, DHCP, and DAI address those respective functions. LLDP is therefore especially useful for topology discovery and identifying the characteristics of neighboring devices connected to FortiSwitch interfaces.<\/span><\/p>\n<h3><b>Question 97<\/b><\/h3>\n<p><b>Which action can help reduce unnecessary traffic across a FortiSwitch trunk?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Allow only the VLANs required on the trunk<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Enable every VLAN on every trunk<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable all MAC learning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove all access ports<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Restricting a trunk to only the VLANs required by the network design can reduce unnecessary Layer 2 traffic. For example, a trunk between two switches may only need to carry employee, voice, and management VLANs. There is generally little reason to permit unrelated VLANs if their traffic does not need to cross that link. Allowing every VLAN can increase unnecessary traffic and make troubleshooting more difficult. Disabling MAC learning would negatively affect normal switching behavior, while removing access ports would not be a practical solution. Therefore, maintaining a controlled allowed-VLAN list is an effective way to limit unnecessary trunk traffic.<\/span><\/p>\n<h3><b>Question 98<\/b><\/h3>\n<p><b>What is the purpose of configuring a trusted interface for DHCP snooping?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To identify an interface from which legitimate DHCP server traffic is expected<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To disable all DHCP communication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To convert DHCP traffic into SNMP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To provide NTP synchronization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A trusted DHCP snooping interface is normally associated with a legitimate DHCP server or a path toward one. DHCP server responses are expected to arrive through trusted interfaces, while client-facing interfaces are generally treated as untrusted. This distinction allows the switch to help block unauthorized DHCP server responses arriving from inappropriate locations. DHCP snooping therefore helps protect clients from rogue DHCP servers. It does not disable DHCP entirely, convert DHCP into SNMP, or provide time synchronization. Correctly identifying trusted interfaces is important because incorrectly trusting a client-facing interface could weaken the intended protection against unauthorized DHCP responses.<\/span><\/p>\n<h3><b>Question 99<\/b><\/h3>\n<p><b>Which feature can provide redundancy when multiple physical links are combined between compatible switches?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LLDP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LACP link aggregation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">LACP-based link aggregation can combine multiple physical Ethernet links into a logical aggregated connection. This provides redundancy because traffic can continue using remaining links if one participating physical link fails, assuming the aggregation remains operational. It can also provide increased aggregate bandwidth when multiple links are active. LLDP provides neighbor discovery, NTP provides time synchronization, and RADIUS provides centralized authentication. Link aggregation should be configured consistently on the participating devices, and administrators should verify that the physical interfaces have compatible characteristics. LACP is therefore the most appropriate feature when multiple links are being combined for resilience and capacity.<\/span><\/p>\n<h3><b>Question 100<\/b><\/h3>\n<p><b>Which combination provides a strong foundation for controlling authenticated wired network access on FortiSwitch?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LLDP and NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">STP and PoE<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">802.1X and RADIUS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LACP and SNMP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">802.1X combined with RADIUS provides a common architecture for authenticated wired network access. The FortiSwitch can act as the 802.1X authenticator, controlling access to the switch port, while the RADIUS server performs centralized authentication and authorization. This allows organizations to make access decisions based on authenticated users or devices instead of relying solely on physical port configuration. LLDP and NTP provide discovery and time synchronization, STP and PoE address loop prevention and power delivery, while LACP and SNMP provide link aggregation and monitoring. Therefore, 802.1X with RADIUS is the most appropriate combination for authenticated wired access control.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Fortinet NSE5_FSW_AD-7.6 Exam Dumps and Practice Test Dumps. &nbsp; Question 81 Which FortiSwitch feature can help protect a network from unauthorized devices by controlling the MAC addresses allowed on a port? NTP Port security LLDP SNMP Correct Answer: 2 Explanation: Port security can be used to restrict the MAC addresses that are permitted [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/12867"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=12867"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/12867\/revisions"}],"predecessor-version":[{"id":12899,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/12867\/revisions\/12899"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=12867"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=12867"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=12867"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}