{"id":12880,"date":"2026-09-15T12:56:33","date_gmt":"2026-09-15T12:56:33","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=12880"},"modified":"2026-09-15T12:56:33","modified_gmt":"2026-09-15T12:56:33","slug":"fortinet-nse5_fsw_ad-7-6-practice-test-questions-and-exam-dumps-part18-q341-360","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/fortinet-nse5_fsw_ad-7-6-practice-test-questions-and-exam-dumps-part18-q341-360\/","title":{"rendered":"Fortinet NSE5_FSW_AD-7.6 Practice Test Questions and Exam Dumps Part18 Q341-360"},"content":{"rendered":"<h2><b>View Full <a href=\"https:\/\/www.examlabs.com\/nse5-fsw-ad-7-6-exam-dumps\">Fortinet NSE5_FSW_AD-7.6 Exam Dumps<\/a> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 341<\/b><\/h3>\n<p><b>Which feature allows an administrator to identify the capabilities and identity of a directly connected network device?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LLDP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP snooping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">LLDP is designed to allow network devices to exchange information with directly connected neighbors. Depending on the implementation, this information can include the device name, interface identification, capabilities, and other attributes. Administrators can use LLDP information to understand physical topology and troubleshoot incorrect connections. RADIUS is primarily used for authentication, DHCP snooping provides DHCP security, and NTP synchronizes system clocks. LLDP is therefore the appropriate feature when the goal is to discover and identify neighboring network devices.<\/span><\/p>\n<h3><b>Question 342<\/b><\/h3>\n<p><b>What is the primary benefit of using FortiSwitch templates in centralized management?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">They eliminate the need for VLANs.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">They provide consistent configuration across applicable switches.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">They disable all switch security functions.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">They automatically repair hardware failures.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Configuration templates help administrators apply standardized settings to multiple FortiSwitch devices. This improves consistency and reduces the amount of repetitive manual configuration required. Templates are particularly useful when multiple switches perform similar roles and require common VLAN, interface, security, or management settings. They do not eliminate VLANs, disable security functions, or repair hardware failures. Administrators should still review device-specific requirements before applying a template because not every setting will necessarily be appropriate for every switch.<\/span><\/p>\n<h3><b>Question 343<\/b><\/h3>\n<p><b>What should be verified when a FortiSwitch is successfully connected physically but cannot be managed centrally?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Only the PoE budget<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Only the MAC aging timer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Management connectivity and authorization status<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Only the interface description<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A physical link being operational does not necessarily mean that centralized management communication is functioning. Administrators should verify management connectivity, FortiLink-related configuration where applicable, and whether the switch has been properly discovered and authorized. Device status in the centralized management interface can also provide useful information. PoE budget and MAC aging affect different aspects of switching and would not normally explain a management relationship failure. Checking connectivity and authorization is therefore an appropriate first step when a physically connected switch cannot be centrally managed.<\/span><\/p>\n<h3><b>Question 344<\/b><\/h3>\n<p><b>Which feature is useful for protecting an STP topology from unexpected superior BPDUs on a designated network boundary?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Root Guard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port mirroring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SNMP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP relay<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Root Guard protects the intended STP hierarchy by preventing a connected downstream device from influencing root bridge selection through superior BPDUs. It is useful on interfaces where the administrator expects the local network to remain authoritative for the STP topology. When an unexpected superior BPDU is detected, the protected interface can enter an appropriate state rather than allowing the downstream switch to become a path toward a new root. Port mirroring, SNMP, and DHCP relay provide monitoring or network services and do not perform this STP protection function.<\/span><\/p>\n<h3><b>Question 345<\/b><\/h3>\n<p><b>What is the main purpose of configuring BPDU Guard on an edge interface?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To increase interface bandwidth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To provide DHCP addresses<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To protect the STP topology from unexpected BPDUs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To establish a trunk automatically<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">BPDU Guard is commonly enabled on edge interfaces that are expected to connect to end devices rather than switches. If a BPDU arrives on such an interface, BPDU Guard can place the port into a protective state according to the configured behavior. This helps prevent an incorrectly connected switch from influencing the STP topology and potentially creating a Layer 2 loop. BPDU Guard is not intended to increase bandwidth, provide DHCP services, or automatically create trunks. It is specifically an STP protection mechanism.<\/span><\/p>\n<h3><b>Question 346<\/b><\/h3>\n<p><b>What does an LACP aggregated interface represent?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Multiple physical links operating together as one logical connection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A collection of unrelated VLANs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A DHCP server group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A collection of SNMP traps<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">LACP allows multiple compatible physical Ethernet links to operate as a logical aggregated connection. This provides redundancy and can increase the aggregate bandwidth available across the participating links. Traffic is distributed according to the device&#8217;s supported load-balancing mechanism. If one member link fails, the remaining links can continue carrying traffic when the configuration supports this behavior. LACP does not represent VLANs, DHCP servers, or SNMP events. Its primary purpose is dynamic link aggregation and improved connection resilience.<\/span><\/p>\n<h3><b>Question 347<\/b><\/h3>\n<p><b>What should an administrator check if one LACP member interface remains inactive?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Only the NTP server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Interface compatibility and LACP configuration on both ends<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Only the DHCP lease duration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Only the switch hostname<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">If an LACP member does not become active, the administrator should compare the configuration of the participating interfaces on both devices. Important factors can include LACP mode, link status, speed, duplex, VLAN configuration, and other aggregation-related parameters. The physical connection should also be checked to ensure the interface is operational. A mismatch between member interfaces can prevent successful aggregation. NTP, DHCP lease duration, and the switch hostname do not normally determine whether a physical interface can participate in an LACP group.<\/span><\/p>\n<h3><b>Question 348<\/b><\/h3>\n<p><b>What is the main function of an access control list applied to a FortiSwitch interface or relevant traffic path?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To control traffic according to defined matching and action rules<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To synchronize switch clocks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To provide PoE power<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To discover neighboring switches<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An access control list, or ACL, can be used to control network traffic according to defined criteria and actions. Depending on the supported FortiSwitch functionality and configuration, rules can identify traffic based on characteristics such as addresses, protocols, or other parameters and then permit or deny it. ACLs provide an additional layer of traffic control within the network. NTP handles time synchronization, PoE provides electrical power, and LLDP performs neighbor discovery. ACL configuration should be carefully planned because incorrect rules can unintentionally block legitimate traffic.<\/span><\/p>\n<h3><b>Question 349<\/b><\/h3>\n<p><b>Why is it useful to restrict a trunk to only the VLANs that are actually required?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To increase the number of broadcast domains automatically<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To reduce unnecessary VLAN propagation and improve segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To disable STP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To prevent MAC learning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Restricting a trunk to only the VLANs that are required reduces unnecessary VLAN propagation across the network. This can improve segmentation, simplify troubleshooting, and reduce the potential impact of configuration errors. If every VLAN is permitted across every trunk, devices may have broader Layer 2 reachability than necessary. Administrators should therefore define allowed VLANs based on the actual requirements of the connected devices. Restricting VLANs does not disable STP or prevent MAC learning; those functions continue independently.<\/span><\/p>\n<h3><b>Question 350<\/b><\/h3>\n<p><b>What is a likely symptom of a VLAN being incorrectly assigned to a workstation access port?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The workstation may receive an IP address from an unintended subnet<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The switch automatically increases PoE power<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The workstation becomes an STP root bridge<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The switch stops learning all MAC addresses<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">If a workstation access port is assigned to the wrong VLAN, the workstation may be placed into an unintended network segment. As a result, it could receive an IP address from a different DHCP scope or fail to reach the resources expected for its correct VLAN. Troubleshooting should include checking the interface&#8217;s access VLAN, VLAN existence, DHCP scope, and upstream connectivity. Incorrect VLAN assignment does not normally affect PoE power or make the workstation an STP root bridge.<\/span><\/p>\n<h3><b>Question 351<\/b><\/h3>\n<p><b>Which protocol is commonly used with 802.1X to provide centralized authentication?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SNMP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LLDP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">RADIUS is commonly used as the centralized authentication server protocol in 802.1X deployments. The switch acts as an authenticator and communicates with the RADIUS server to validate the endpoint&#8217;s authentication information. Based on the authentication and authorization result, the network can permit access and potentially apply additional access policies. SNMP is primarily used for monitoring, LLDP for neighbor discovery, and NTP for time synchronization. RADIUS therefore provides the appropriate centralized authentication function for an 802.1X environment.<\/span><\/p>\n<h3><b>Question 352<\/b><\/h3>\n<p><b>What is one important advantage of using 802.1X instead of relying only on MAC address filtering?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">802.1X can provide stronger identity-based authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">802.1X removes the need for switches<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">802.1X automatically prevents every Layer 2 loop<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">802.1X increases physical cable bandwidth<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">802.1X can provide stronger access control because it authenticates an endpoint or user through an authentication framework rather than relying only on a device&#8217;s MAC address. MAC addresses can potentially be spoofed, so MAC-based controls alone may not provide strong identity assurance. With 802.1X, the switch can communicate with a RADIUS server and enforce authorization policies after successful authentication. 802.1X does not prevent Layer 2 loops or increase physical link capacity. Its primary benefit is stronger identity-based network access control.<\/span><\/p>\n<h3><b>Question 353<\/b><\/h3>\n<p><b>What is the purpose of a management VLAN?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To carry administrative traffic for managing network devices<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To replace every access VLAN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To disable switch logging<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To provide LACP negotiation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A management VLAN is commonly used to separate administrative traffic from ordinary user or application traffic. Network devices can use this VLAN for management connectivity, depending on the network design. Separating management traffic can make it easier to apply access restrictions and security controls to administrative services. A management VLAN does not replace all other VLANs or provide LACP negotiation. Administrators should also protect management access through appropriate authentication, secure protocols, and network restrictions.<\/span><\/p>\n<h3><b>Question 354<\/b><\/h3>\n<p><b>What should be checked if an administrator cannot reach the FortiSwitch management interface from an authorized management workstation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Management IP addressing, routing, interface status, and access restrictions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Only the MAC aging timer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Only the PoE budget<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Only the STP root priority<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When management access fails, administrators should verify the switch&#8217;s management IP address, subnet configuration, interface status, and routing path between the workstation and the switch. Management access restrictions such as trusted hosts or allowed management networks should also be reviewed. If the device is centrally managed, its management relationship should be checked as well. MAC aging, PoE budget, and STP root priority do not normally determine whether an authorized workstation can reach a management interface. A structured Layer 2 and Layer 3 connectivity check is appropriate.<\/span><\/p>\n<h3><b>Question 355<\/b><\/h3>\n<p><b>Which feature can help detect a rogue DHCP server connected to an access port?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LACP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP snooping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LLDP-MED<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Root Guard<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DHCP snooping can distinguish trusted interfaces from untrusted interfaces and help prevent unauthorized DHCP server responses from reaching clients. Legitimate DHCP server traffic is expected to arrive through trusted interfaces, while client-facing access ports are generally untrusted. If a rogue device attempts to respond as a DHCP server from an untrusted interface, the switch can restrict the response according to the configured policy. This protects clients from receiving incorrect network configuration. LACP, LLDP-MED, and Root Guard address different network functions.<\/span><\/p>\n<h3><b>Question 356<\/b><\/h3>\n<p><b>What is the primary benefit of using PoE on a FortiSwitch?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It allows compatible devices to receive electrical power through Ethernet cabling<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It eliminates the need for VLANs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It prevents all broadcast storms<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It replaces RADIUS authentication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Power over Ethernet, or PoE, allows compatible devices to receive electrical power through Ethernet cabling rather than requiring a separate power connection. This is particularly useful for devices such as IP phones, wireless access points, and certain cameras. The switch must have sufficient PoE capacity and the port must support the required power characteristics. PoE does not replace VLAN segmentation, broadcast protection, or authentication. Administrators should monitor the overall power budget when deploying multiple PoE devices.<\/span><\/p>\n<h3><b>Question 357<\/b><\/h3>\n<p><b>What can happen if a FortiSwitch exceeds its available PoE power budget?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Additional PoE devices may fail to receive the required power<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The switch automatically creates a new VLAN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">STP is permanently disabled<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS authentication is automatically removed<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A FortiSwitch has a defined total PoE power budget. If the power requirements of connected devices exceed that available budget, the switch may be unable to provide power to additional devices or may take other configured actions. Administrators should therefore monitor PoE consumption and available capacity when adding powered endpoints. The exact behavior depends on the hardware and configuration. Exceeding the PoE budget does not create VLANs, disable STP, or remove RADIUS configuration.<\/span><\/p>\n<h3><b>Question 358<\/b><\/h3>\n<p><b>What is the purpose of MAC address learning in Ethernet switching?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To associate source MAC addresses with the interfaces where they were observed<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To assign IP addresses to clients<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To authenticate administrators<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To synchronize system clocks<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">MAC address learning allows a switch to build its forwarding table by examining the source MAC address of incoming Ethernet frames. The switch associates the source MAC address with the receiving interface and VLAN context. Later, when a frame is destined for that MAC address, the switch can forward it toward the learned interface rather than flooding it throughout the VLAN. This improves switching efficiency. MAC learning is a Layer 2 function and does not assign IP addresses, authenticate administrators, or synchronize clocks.<\/span><\/p>\n<h3><b>Question 359<\/b><\/h3>\n<p><b>Which feature is most useful for investigating the actual packets exchanged on a switch interface?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port mirroring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS accounting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MAC aging<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Port mirroring can copy selected traffic from one or more source interfaces to a designated monitoring interface. A packet analyzer or security monitoring device connected to the destination can then inspect the copied packets. This is useful when troubleshooting application behavior, protocol problems, unexpected traffic, or security events. Port mirroring should be configured carefully because a large amount of mirrored traffic can exceed the capacity of the destination interface. NTP, RADIUS accounting, and MAC aging provide different types of network functionality.<\/span><\/p>\n<h3><b>Question 360<\/b><\/h3>\n<p><b>What is a recommended practice before deploying a major FortiSwitch configuration change to production?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Apply it everywhere immediately without testing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove all existing backups<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Validate the configuration, test where practical, and maintain a recovery option<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable logging before the change<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Major configuration changes should be planned and validated before being applied broadly to production switches. Where practical, administrators should test the configuration in a controlled environment or on a limited number of devices first. Existing configuration backups or known-good revisions should be retained so the environment can be recovered if unexpected behavior occurs. Administrators should also document the change and monitor the network afterward. Disabling logging or removing backups would reduce visibility and increase operational risk rather than improving the change process.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Fortinet NSE5_FSW_AD-7.6 Exam Dumps and Practice Test Dumps. &nbsp; Question 341 Which feature allows an administrator to identify the capabilities and identity of a directly connected network device? LLDP RADIUS DHCP snooping NTP Correct Answer: 1 Explanation: LLDP is designed to allow network devices to exchange information with directly connected neighbors. Depending on [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/12880"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=12880"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/12880\/revisions"}],"predecessor-version":[{"id":12886,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/12880\/revisions\/12886"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=12880"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=12880"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=12880"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}