{"id":12871,"date":"2026-09-15T12:57:53","date_gmt":"2026-09-15T12:57:53","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=12871"},"modified":"2026-09-15T12:57:53","modified_gmt":"2026-09-15T12:57:53","slug":"fortinet-nse5_fsw_ad-7-6-practice-test-questions-and-exam-dumps-part9-q161-180","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/fortinet-nse5_fsw_ad-7-6-practice-test-questions-and-exam-dumps-part9-q161-180\/","title":{"rendered":"Fortinet NSE5_FSW_AD-7.6 Practice Test Questions and Exam Dumps Part9 Q161-180"},"content":{"rendered":"<h2><b>View Full <a href=\"https:\/\/www.examlabs.com\/nse5-fsw-ad-7-6-exam-dumps\">Fortinet NSE5_FSW_AD-7.6 Exam Dumps<\/a> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 161<\/b><\/h3>\n<p><b>Which FortiSwitch capability allows an administrator to centrally view the operational status of multiple managed switches?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Centralized monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP relay<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port mirroring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MAC aging<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Centralized monitoring allows administrators to view important operational information for multiple managed FortiSwitch devices from a centralized management environment. This can include device availability, interface status, alarms, configuration state, and other operational information depending on the deployment. Centralized visibility is particularly valuable when an organization has many switches distributed across different network segments or locations. DHCP relay is used to forward DHCP requests, port mirroring copies traffic for analysis, and MAC aging controls learned MAC entries. Centralized monitoring therefore provides the broadest operational visibility across managed switching infrastructure.<\/span><\/p>\n<h3><b>Question 162<\/b><\/h3>\n<p><b>What is the main purpose of a configuration backup for a FortiSwitch?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To increase PoE output<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To preserve configuration information for recovery or restoration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To replace firmware automatically<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To create additional Ethernet ports<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A configuration backup preserves important switch settings so they can be restored if the device experiences a failure, configuration error, or other operational problem. Depending on the management architecture, configurations may also be centrally maintained or backed up through management systems. Having a reliable backup can significantly reduce recovery time because administrators do not need to rebuild the configuration manually. Configuration backups do not increase PoE capacity, replace firmware by themselves, or create additional physical ports. Regular backup procedures are therefore an important part of operational resilience and network administration.<\/span><\/p>\n<h3><b>Question 163<\/b><\/h3>\n<p><b>Which condition can cause an Ethernet interface to repeatedly go up and down?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">An incorrect NTP server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A missing SNMP community<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">An unstable physical connection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">An incorrect RADIUS accounting setting<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An unstable physical connection can cause an Ethernet interface to repeatedly transition between up and down states. Possible causes include a damaged cable, faulty transceiver, loose connection, incompatible hardware, or a problem with the connected device. Administrators should examine interface event logs and operational statistics and test the physical components when troubleshooting link flapping. NTP, SNMP, and RADIUS settings generally do not directly cause a physical interface to lose and regain carrier repeatedly. Identifying the physical or Layer 1 cause is important because repeated link changes can also affect higher-level network protocols.<\/span><\/p>\n<h3><b>Question 164<\/b><\/h3>\n<p><b>What is the purpose of a switch configuration revision or change history in a centralized management environment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To provide a record of configuration changes<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To assign IP addresses automatically<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To increase interface bandwidth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To supply PoE to endpoints<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Configuration revision or change history helps administrators understand how a device&#8217;s configuration has changed over time. This information can be valuable when troubleshooting a problem that appeared after a configuration modification. It can also support operational accountability and make it easier to identify which settings were recently changed. Depending on the management platform, administrators may be able to compare or restore previous configuration states. IP address assignment, bandwidth increases, and PoE delivery are separate functions. Maintaining configuration history is therefore useful for controlled network administration and troubleshooting.<\/span><\/p>\n<h3><b>Question 165<\/b><\/h3>\n<p><b>Which protocol helps a switch discover directly connected network devices and their capabilities?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LLDP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LACP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Link Layer Discovery Protocol, or LLDP, allows network devices to advertise information about themselves to directly connected neighbors. A switch can learn details such as the neighboring device identity, port information, and supported capabilities when LLDP is enabled and supported. This information can help administrators build topology views and troubleshoot physical connectivity. DHCP provides IP configuration, RADIUS supports centralized authentication and accounting, and LACP manages link aggregation. LLDP is therefore the protocol most directly associated with discovering neighboring network devices at the data-link layer.<\/span><\/p>\n<h3><b>Question 166<\/b><\/h3>\n<p><b>What is a key advantage of using FortiLink to manage FortiSwitch devices with FortiGate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It provides integrated management and configuration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It removes the need for Ethernet connectivity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It disables VLAN functionality<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It converts every switch port into a WAN interface<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiLink provides an integrated management relationship between FortiGate and FortiSwitch. This allows administrators to manage switch configuration and monitor connected switching infrastructure through the FortiGate environment. Depending on the deployment, FortiLink can simplify tasks such as VLAN configuration, device authorization, interface management, and centralized visibility. It does not eliminate the physical network connection between the devices, disable VLANs, or convert switch ports into WAN interfaces. The major benefit is the integration of switching management with the broader Fortinet network-security architecture.<\/span><\/p>\n<h3><b>Question 167<\/b><\/h3>\n<p><b>Which STP protection feature can help prevent an edge port from becoming an unintended path to the root bridge?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Root Guard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP snooping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port mirroring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Root Guard is an STP protection mechanism designed to prevent an interface from accepting superior BPDUs that could cause an unexpected device to become part of the preferred root path. It is useful on ports where the administrator does not expect a downstream switch to influence the spanning-tree root topology. If an unexpected superior BPDU is received, the port can be placed into an appropriate protective state according to the implementation. DHCP snooping protects DHCP operations, port mirroring copies traffic, and NTP synchronizes time. Root Guard is therefore the appropriate STP protection feature.<\/span><\/p>\n<h3><b>Question 168<\/b><\/h3>\n<p><b>What is the primary function of DHCP relay in a routed network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To combine physical Ethernet links<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To forward DHCP requests between clients and a DHCP server on another network<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To inspect ARP packets<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To discover neighboring switches<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DHCP relay allows DHCP client requests to reach a DHCP server located on a different Layer 3 network. Because DHCP discovery traffic is normally broadcast-based, routers do not forward it as a normal broadcast. A DHCP relay agent receives the request and forwards the necessary information toward the configured DHCP server. This allows a centralized DHCP server to serve clients across multiple subnets or VLANs. LACP handles link aggregation, DAI handles ARP inspection, and LLDP performs neighbor discovery. DHCP relay is therefore essential when DHCP services are located outside the client&#8217;s local broadcast domain.<\/span><\/p>\n<h3><b>Question 169<\/b><\/h3>\n<p><b>What should be checked if an LACP aggregate does not form between two switches?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The NTP timezone<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The VLAN name only<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LACP mode and member-interface compatibility<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The SNMP trap destination only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When an LACP aggregate fails to form, administrators should verify that the member interfaces on both devices have compatible LACP configurations. This includes checking LACP mode, interface membership, speed and duplex compatibility, and other requirements for link aggregation. The physical links should also be operational. An incorrect or incompatible configuration on one member can prevent the logical aggregate from forming correctly. NTP, SNMP traps, and VLAN naming do not directly establish an LACP relationship. Verifying the aggregation settings on both ends is therefore an important troubleshooting step.<\/span><\/p>\n<h3><b>Question 170<\/b><\/h3>\n<p><b>Which feature can restrict a switch port so that only specific MAC addresses are permitted?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LLDP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP relay<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Port security can be used to control which MAC addresses are allowed to use a switch interface. This can help limit unauthorized devices from connecting through a particular port. Depending on the configuration, administrators may specify allowed MAC addresses or use dynamically learned addresses and define a maximum number of permitted addresses. This feature is particularly useful for endpoint access ports where the expected device population is known. LLDP provides discovery information, NTP synchronizes time, and DHCP relay forwards DHCP traffic across Layer 3 boundaries. Port security is therefore the correct choice.<\/span><\/p>\n<h3><b>Question 171<\/b><\/h3>\n<p><b>What is the purpose of SNMP polling in network management?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To aggregate Ethernet links<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To periodically retrieve device information from a managed device<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To assign VLAN IDs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To prevent ARP spoofing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">SNMP polling allows a management system to periodically query network devices for operational information. Depending on the supported MIBs and configuration, the management platform can collect information such as interface statistics, device status, resource utilization, and other monitoring data. Polling provides a regular view of device health and can help identify trends or abnormal conditions. LACP aggregates links, VLAN configuration handles Layer 2 segmentation, and DAI helps protect against ARP spoofing. SNMP polling is therefore primarily a monitoring and information-collection mechanism rather than a traffic-control feature.<\/span><\/p>\n<h3><b>Question 172<\/b><\/h3>\n<p><b>What is a potential benefit of configuring BPDU Guard on ports connected only to end-user devices?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It helps prevent an unauthorized switch from participating in STP through that port<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It increases the port&#8217;s PoE budget<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It creates a new management VLAN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It assigns IP addresses to clients<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">BPDU Guard is useful on ports that should connect only to end devices. If a user connects an unauthorized switch to such a port, the new switch may begin transmitting BPDUs and attempt to participate in the spanning-tree topology. BPDU Guard provides protection by detecting unexpected BPDUs and taking the configured protective action. This reduces the possibility that an accidental or unauthorized switch connection will affect the Layer 2 topology. BPDU Guard does not assign IP addresses, create VLANs, or increase PoE capacity.<\/span><\/p>\n<h3><b>Question 173<\/b><\/h3>\n<p><b>Which setting helps ensure that voice traffic from an IP phone is placed into the intended voice VLAN?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Voice VLAN configuration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MAC aging<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP configuration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS accounting<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Voice VLAN configuration allows network administrators to place IP phone traffic into a designated VLAN separate from ordinary data traffic. This separation can simplify network management and allow different policies to be applied to voice and user data. Depending on the environment, discovery mechanisms such as LLDP-MED may assist in communicating network policy information to supported phones. MAC aging, NTP, and RADIUS accounting serve different purposes. Correct voice VLAN configuration is therefore essential when an IP phone needs to operate within a dedicated voice network.<\/span><\/p>\n<h3><b>Question 174<\/b><\/h3>\n<p><b>What is the main purpose of an STP topology change notification?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To inform the spanning-tree system that the topology has changed<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To authenticate a user<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To assign a DHCP address<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To negotiate PoE power<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An STP topology change notification informs the spanning-tree system that a relevant Layer 2 topology change has occurred. Such changes can result from events such as interfaces going up or down and may require switches to adjust their handling of learned forwarding information. Propagating topology-change information helps switches adapt to changes in the network topology. User authentication, DHCP addressing, and PoE negotiation are unrelated processes. Understanding topology changes is important when diagnosing temporary connectivity changes or unusual MAC-table behavior following link-state events.<\/span><\/p>\n<h3><b>Question 175<\/b><\/h3>\n<p><b>Which configuration can help limit unnecessary broadcast traffic entering a switch network from a problematic endpoint?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storm control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS accounting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LLDP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Storm control can help protect a switched network from excessive broadcast, multicast, or related traffic depending on the supported configuration. A malfunctioning device, loop, or other abnormal condition can generate large amounts of Layer 2 traffic that consumes switch resources and affects other endpoints. Storm-control thresholds can limit the impact of such traffic by applying configured protective behavior when traffic exceeds the permitted level. NTP, RADIUS accounting, and LLDP perform completely different functions. Storm control is therefore an important mechanism for reducing the effect of excessive Layer 2 traffic.<\/span><\/p>\n<h3><b>Question 176<\/b><\/h3>\n<p><b>Why is firmware compatibility important when adding or replacing a FortiSwitch in a managed environment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It can affect management and feature compatibility<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It determines the Ethernet cable category<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It automatically creates every VLAN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It eliminates the need for authentication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Firmware compatibility is important because the switch firmware must work properly with the management platform and other components of the Fortinet deployment. Incompatible versions can result in unsupported features, provisioning problems, unexpected behavior, or management limitations. Before upgrading or replacing a device, administrators should review supported versions and consider compatibility with the relevant FortiGate or management environment. Firmware does not determine the physical category of Ethernet cable, automatically create every VLAN, or remove authentication requirements. Compatibility planning helps ensure a stable and supported deployment.<\/span><\/p>\n<h3><b>Question 177<\/b><\/h3>\n<p><b>Which feature provides a copy of network traffic from one switch interface to another interface for analysis?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP relay<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port mirroring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Root Guard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LACP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Port mirroring copies selected traffic from one or more source interfaces or traffic directions to a designated destination interface. A network administrator can connect a packet-analysis or monitoring device to the destination interface to inspect traffic without directly interrupting normal forwarding. Port mirroring is useful for troubleshooting, security analysis, and network visibility. DHCP relay forwards DHCP requests across Layer 3 networks, Root Guard protects STP topology, and LACP combines physical links. Therefore, port mirroring is the appropriate feature when traffic needs to be copied for analysis.<\/span><\/p>\n<h3><b>Question 178<\/b><\/h3>\n<p><b>What is the primary purpose of securing administrative access to a FortiSwitch?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To prevent unauthorized users from changing network configuration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To increase cable bandwidth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To create additional VLANs automatically<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To disable all monitoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Securing administrative access helps prevent unauthorized individuals from changing switch configuration or obtaining privileged information. Strong authentication, appropriate administrator permissions, secure management protocols, and restricted management access can reduce the risk of configuration tampering. Unauthorized changes can cause outages, security weaknesses, or loss of network connectivity. Administrative security does not increase physical bandwidth, automatically create VLANs, or require monitoring to be disabled. Protecting the management plane is therefore an important part of maintaining the security and reliability of a FortiSwitch deployment.<\/span><\/p>\n<h3><b>Question 179<\/b><\/h3>\n<p><b>What can an administrator use to identify whether a switch port is receiving excessive input errors?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Interface statistics<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS accounting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN names<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LLDP system name only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Interface statistics provide detailed operational counters that can help identify problems such as input errors, packet errors, dropped packets, or other abnormal interface conditions. These counters are useful when troubleshooting faulty cables, incompatible settings, damaged interfaces, or problematic connected devices. An administrator can compare error counters over time to determine whether the problem is persistent or increasing. RADIUS accounting and VLAN names do not provide physical interface error information, while LLDP primarily provides neighbor discovery information. Therefore, interface statistics are the appropriate source for investigating excessive input errors.<\/span><\/p>\n<h3><b>Question 180<\/b><\/h3>\n<p><b>Which approach is most appropriate when multiple FortiSwitch devices require the same standardized security and interface configuration?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configure every switch independently without documentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable centralized management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use centralized configuration or templates where supported<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove VLAN segmentation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Centralized configuration or reusable templates can help administrators apply standardized settings across multiple FortiSwitch devices. This approach reduces repetitive manual work and helps maintain consistency between switches. Standardized configurations can include interface settings, VLAN-related parameters, security controls, and other supported policies. Administrators should still verify device-specific requirements before applying a common configuration. Independently configuring every switch increases the possibility of human error, while disabling centralized management removes useful control and visibility. Removing VLAN segmentation would also weaken network organization. Centralized configuration is therefore the most efficient approach for consistent deployments.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Fortinet NSE5_FSW_AD-7.6 Exam Dumps and Practice Test Dumps. &nbsp; Question 161 Which FortiSwitch capability allows an administrator to centrally view the operational status of multiple managed switches? Centralized monitoring DHCP relay Port mirroring MAC aging Correct Answer: 1 Explanation: Centralized monitoring allows administrators to view important operational information for multiple managed FortiSwitch devices [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/12871"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=12871"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/12871\/revisions"}],"predecessor-version":[{"id":12895,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/12871\/revisions\/12895"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=12871"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=12871"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=12871"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}