{"id":12878,"date":"2026-09-15T12:56:50","date_gmt":"2026-09-15T12:56:50","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=12878"},"modified":"2026-09-15T12:56:50","modified_gmt":"2026-09-15T12:56:50","slug":"fortinet-nse5_fsw_ad-7-6-practice-test-questions-and-exam-dumps-part16-q301-320","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/fortinet-nse5_fsw_ad-7-6-practice-test-questions-and-exam-dumps-part16-q301-320\/","title":{"rendered":"Fortinet NSE5_FSW_AD-7.6 Practice Test Questions and Exam Dumps Part16 Q301-320"},"content":{"rendered":"<h2><b>View Full <a href=\"https:\/\/www.examlabs.com\/nse5-fsw-ad-7-6-exam-dumps\">Fortinet NSE5_FSW_AD-7.6 Exam Dumps<\/a> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 301<\/b><\/h3>\n<p><b>What is the main advantage of using a dedicated management network for FortiSwitch administration?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It increases the switching speed of all access ports.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It separates administrative traffic from normal user traffic.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It automatically creates VLANs.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It disables unauthorized DHCP servers.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A dedicated management network separates administrative access from ordinary user and application traffic. This can reduce the exposure of management services and make it easier to apply specific security controls to administrative connections. Management traffic can be restricted to approved administrators, systems, or network segments. A dedicated management network does not increase physical switching speed or automatically create VLANs. DHCP security is handled by features such as DHCP snooping. Separating management traffic is therefore an important network design and security practice.<\/span><\/p>\n<h3><b>Question 302<\/b><\/h3>\n<p><b>Which FortiSwitch feature can help identify the physical topology by showing information about directly connected neighboring devices?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LLDP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP relay<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storm control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port security<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">LLDP, or Link Layer Discovery Protocol, allows compatible network devices to exchange identification and capability information with directly connected neighbors. This information can help administrators understand physical network topology and troubleshoot incorrect cabling or unexpected connections. Depending on the device, LLDP information may include system name, interface details, capabilities, and other attributes. DHCP relay forwards DHCP requests across Layer 3 boundaries, storm control limits excessive traffic, and port security controls endpoint access. LLDP is therefore the most appropriate feature for neighbor discovery and topology visibility.<\/span><\/p>\n<h3><b>Question 303<\/b><\/h3>\n<p><b>What is a common purpose of an access VLAN on a FortiSwitch interface?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To determine the VLAN associated with untagged endpoint traffic<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To negotiate LACP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To synchronize device clocks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To provide SNMP notifications<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An access VLAN identifies the VLAN to which untagged traffic received on an access interface belongs. This is commonly used for endpoint devices such as workstations, printers, and other clients that do not normally send VLAN tags. The switch associates the incoming traffic with the configured VLAN and forwards it according to the Layer 2 switching table. LACP, NTP, and SNMP perform different functions. Correct access VLAN configuration is essential because assigning the wrong VLAN can place a device into an unintended network segment.<\/span><\/p>\n<h3><b>Question 304<\/b><\/h3>\n<p><b>What should an administrator verify when a trunk is carrying some VLANs successfully but another VLAN is not working?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Only the switch hostname<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Only the NTP configuration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The affected VLAN&#8217;s existence and the allowed VLAN configuration on the trunk<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Only the PoE budget<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">If some VLANs work across a trunk while another does not, the administrator should verify that the affected VLAN exists and is permitted on the trunk. The allowed VLAN list can restrict which VLAN IDs are forwarded across an interface. Administrators should also verify that the VLAN configuration is consistent on both sides of the connection and that tagging or native VLAN behavior is correct. Since the trunk already carries other VLANs, the physical connection is likely operational. Focusing on the affected VLAN&#8217;s configuration is therefore an appropriate troubleshooting step.<\/span><\/p>\n<h3><b>Question 305<\/b><\/h3>\n<p><b>Which feature is primarily responsible for preventing Layer 2 switching loops?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">STP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SNMP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LLDP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Spanning Tree Protocol, or STP, is designed to prevent Layer 2 loops in Ethernet networks. Redundant physical links are useful for resilience, but without a loop-prevention mechanism they can create broadcast storms, duplicate frames, and unstable MAC learning. STP logically blocks certain redundant paths while maintaining them as potential backup paths. If the active topology changes, STP can allow another path to become available. RADIUS provides authentication, SNMP provides management information, and LLDP provides neighbor discovery, so none of those protocols performs the primary loop-prevention function.<\/span><\/p>\n<h3><b>Question 306<\/b><\/h3>\n<p><b>What is the purpose of configuring an edge port for an end-user device?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To allow the port to transition quickly toward forwarding for an endpoint connection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To force the port to become the STP root<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To create a trunk automatically<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To enable DHCP relay<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An edge port is intended for interfaces connected to end devices rather than other switches. Such ports can transition toward forwarding more quickly because they are not expected to participate in the normal STP topology between switches. This reduces unnecessary waiting when an endpoint connects or the interface comes up. Edge-port configurations should be used carefully because connecting another switch to such a port can introduce topology risks. Protective features such as BPDU Guard can help detect unexpected STP participation on edge interfaces.<\/span><\/p>\n<h3><b>Question 307<\/b><\/h3>\n<p><b>Which feature can help protect an edge port when an unexpected switch sends BPDUs to it?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BPDU Guard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP relay<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SNMP polling<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">BPDU Guard is designed to protect ports that are expected to be connected only to end devices. If an unexpected BPDU is received on such a protected interface, the switch can place the interface into a protective state according to its configuration. This helps prevent an unauthorized or incorrectly connected switch from influencing the STP topology. BPDU Guard is especially useful when used with edge ports. NTP, DHCP relay, and SNMP polling do not provide protection against unexpected STP BPDUs.<\/span><\/p>\n<h3><b>Question 308<\/b><\/h3>\n<p><b>What does LACP primarily use to determine whether physical links can participate in an aggregation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Compatible link aggregation and interface parameters<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The DHCP server&#8217;s IP address<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The SNMP polling interval<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The native VLAN name only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">LACP requires compatible physical interfaces and aggregation settings before links can successfully operate as members of a logical aggregate. Administrators should verify that the member interfaces have compatible speed, duplex, VLAN, and aggregation-related settings. LACP then uses protocol exchanges to negotiate and maintain the aggregated relationship. A DHCP server address or SNMP polling interval does not determine whether two interfaces can form an LACP group. The native VLAN may be part of the broader interface configuration, but it is not the sole factor determining LACP compatibility.<\/span><\/p>\n<h3><b>Question 309<\/b><\/h3>\n<p><b>What is a key benefit of configuration backups before making major network changes?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">They provide a recovery point if the new configuration causes unexpected problems.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">They guarantee that no outage can occur.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">They automatically upgrade all connected switches.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">They increase available PoE power.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Configuration backups provide a known recovery point before administrators make significant changes. If a configuration modification introduces unexpected connectivity or operational problems, the saved configuration can help restore the device to a previous working state. Backups do not guarantee that an outage will never happen and do not upgrade devices or increase PoE capacity. They are one part of proper change management, along with testing, maintenance windows, compatibility checks, and documentation. Regular backups are particularly important in larger environments where configuration changes can affect multiple devices.<\/span><\/p>\n<h3><b>Question 310<\/b><\/h3>\n<p><b>What is the primary function of a FortiSwitch MAC address table?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To store mappings between learned MAC addresses and switch interfaces<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To store administrator passwords<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To store NTP server certificates<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To define RADIUS policies<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The MAC address table allows the switch to determine where Layer 2 frames should be forwarded. When a switch receives a frame, it can learn the source MAC address and associate it with the incoming interface and VLAN context. When traffic is later destined for that MAC address, the switch can use the table to forward the frame toward the appropriate interface instead of flooding it unnecessarily. MAC entries can be dynamically learned and can age out when they are no longer observed. This process is fundamental to Ethernet switching.<\/span><\/p>\n<h3><b>Question 311<\/b><\/h3>\n<p><b>What is the main purpose of MAC address aging?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To periodically remove stale dynamically learned MAC entries<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To increase PoE voltage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To create new VLANs automatically<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To authenticate administrators<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">MAC address aging allows a switch to remove dynamically learned MAC entries that have not been observed for a configured period. This keeps the forwarding table current when devices move between interfaces or leave the network. Without aging, stale information could remain in the table and potentially cause inefficient forwarding behavior. When a device sends traffic again, its MAC address can normally be learned on the current interface. MAC aging is therefore an important part of maintaining an accurate and efficient Layer 2 forwarding table.<\/span><\/p>\n<h3><b>Question 312<\/b><\/h3>\n<p><b>Which mechanism can be used to provide centralized authentication for administrators or network-access users?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LLDP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">STP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LACP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">RADIUS provides centralized authentication and authorization services for network environments. Instead of maintaining separate authentication databases on every device, administrators can configure network equipment to communicate with a centralized RADIUS server. RADIUS can be used in various access-control scenarios, including 802.1X authentication and certain administrative authentication deployments. LLDP is used for neighbor discovery, STP prevents Layer 2 loops, and LACP provides link aggregation. Centralized authentication can improve consistency and simplify account management across a network.<\/span><\/p>\n<h3><b>Question 313<\/b><\/h3>\n<p><b>What should be checked if an 802.1X-authenticated endpoint is still placed into an unexpected network segment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Only the physical cable<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authorization policy and VLAN assignment returned by the authentication system<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Only the MAC aging timer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Only the switch&#8217;s NTP configuration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Successful 802.1X authentication does not necessarily mean the endpoint will receive the expected network access. Authorization policies can determine which VLAN or other access parameters are assigned after authentication. If an endpoint authenticates successfully but appears in the wrong network segment, administrators should inspect the RADIUS authorization response, VLAN assignment, switch policy, and interface configuration. The physical cable and NTP settings are unlikely to explain a logically incorrect VLAN assignment. Reviewing authentication and authorization together is important when troubleshooting identity-based network access.<\/span><\/p>\n<h3><b>Question 314<\/b><\/h3>\n<p><b>What is the purpose of RADIUS accounting in an authenticated network environment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To provide records about authentication or session activity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To prevent Ethernet loops<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To create PoE classes<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To discover neighboring switches<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">RADIUS accounting can provide records related to user or device sessions and authentication activity. Depending on the implementation, accounting information may include session start and stop events, duration, identity information, and other attributes. This information can be useful for auditing, troubleshooting, and operational reporting. Authentication determines whether access is permitted, while accounting focuses on recording activity associated with sessions. RADIUS accounting does not perform STP loop prevention, PoE management, or neighbor discovery.<\/span><\/p>\n<h3><b>Question 315<\/b><\/h3>\n<p><b>Which traffic type is commonly controlled by storm control?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Excessive broadcast or multicast traffic<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP synchronization packets only<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS authentication packets only<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configuration backup files only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Storm control is designed to limit excessive Layer 2 traffic that can consume network resources. Broadcast traffic is a common target because a broadcast storm can affect many devices within a VLAN. Depending on platform capabilities and configuration, multicast or other traffic types may also be controlled. The goal is to prevent abnormal traffic volumes from overwhelming switch interfaces or connected devices. Storm control does not specifically target NTP, RADIUS, or configuration backup traffic. Proper thresholds should be selected carefully so legitimate traffic is not unnecessarily restricted.<\/span><\/p>\n<h3><b>Question 316<\/b><\/h3>\n<p><b>What is the main purpose of FortiSwitch interface statistics during troubleshooting?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To identify traffic levels, errors, drops, and other interface conditions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To automatically configure all VLANs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To replace configuration backups<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To determine an administrator&#8217;s password<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Interface statistics provide useful information about the operational condition of a switch port. Administrators can inspect values such as transmitted and received packets, errors, drops, and other counters to identify abnormal behavior. These statistics can help determine whether a problem is related to a physical link, congestion, configuration, or another network condition. Interface statistics do not automatically configure VLANs or replace configuration backups. They are an important diagnostic tool when investigating poor performance, packet loss, or unstable connectivity.<\/span><\/p>\n<h3><b>Question 317<\/b><\/h3>\n<p><b>What is a major reason to restrict management services to trusted networks?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To reduce the number of sources that can attempt administrative access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To increase VLAN broadcast traffic<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To disable MAC learning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To improve LACP negotiation speed<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Restricting management services to trusted networks reduces the number of locations from which attackers or unauthorized users can attempt to access network administration interfaces. This decreases the management-plane attack surface and makes access-control policies easier to enforce. Additional protections can include secure management protocols, strong authentication, individual administrator accounts, and trusted-host restrictions. Management restrictions do not affect MAC learning or directly improve LACP negotiation. They are primarily a security measure intended to protect administrative functions and sensitive configuration information.<\/span><\/p>\n<h3><b>Question 318<\/b><\/h3>\n<p><b>What is the purpose of a VLAN trunk between two FortiSwitch devices?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To carry traffic for multiple VLANs across a single physical connection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To provide only one untagged client VLAN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To disable STP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To provide centralized authentication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A VLAN trunk allows multiple VLANs to traverse the same physical connection between network devices. VLAN tags are used to distinguish traffic belonging to different VLANs, while the native VLAN may handle untagged traffic according to the configured design. Trunks are commonly used between switches, switches and routers, or other VLAN-aware devices. An access interface normally carries traffic for a single VLAN. Proper trunk configuration requires consistent VLAN definitions and appropriate allowed VLAN settings on both sides.<\/span><\/p>\n<h3><b>Question 319<\/b><\/h3>\n<p><b>Which feature can help a switch enforce that a specific MAC address is allowed on an interface?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LLDP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP relay<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Port security can be used to restrict which MAC addresses are permitted on a switch interface. Depending on the configuration, administrators may specify authorized MAC addresses or establish limits on the number of MAC addresses that can appear on a port. This can help reduce unauthorized device connections and strengthen access control at the Layer 2 edge. Port security is different from 802.1X, which provides identity-based authentication, although both mechanisms can be used as part of a broader access-control strategy.<\/span><\/p>\n<h3><b>Question 320<\/b><\/h3>\n<p><b>What should an administrator do before applying a major configuration change across many managed FortiSwitch devices?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable all monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove existing configuration backups<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Review the intended configuration, verify compatibility, and maintain a recovery option<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Allow the change without documentation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Before applying a major configuration change across multiple switches, administrators should review the intended settings and verify that they are compatible with the affected devices and network design. A backup or known-good configuration should be available so the environment can be recovered if the change produces unexpected results. Testing the change on a smaller scope before broad deployment can also reduce risk. Proper documentation and change control help track what was modified and why. This approach improves reliability and minimizes the impact of configuration errors.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Fortinet NSE5_FSW_AD-7.6 Exam Dumps and Practice Test Dumps. &nbsp; Question 301 What is the main advantage of using a dedicated management network for FortiSwitch administration? It increases the switching speed of all access ports. It separates administrative traffic from normal user traffic. It automatically creates VLANs. It disables unauthorized DHCP servers. Correct Answer: [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/12878"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=12878"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/12878\/revisions"}],"predecessor-version":[{"id":12888,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/12878\/revisions\/12888"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=12878"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=12878"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=12878"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}