{"id":12881,"date":"2026-09-15T12:56:25","date_gmt":"2026-09-15T12:56:25","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=12881"},"modified":"2026-09-15T12:56:25","modified_gmt":"2026-09-15T12:56:25","slug":"fortinet-nse5_fsw_ad-7-6-practice-test-questions-and-exam-dumps-part19-q361-380","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/fortinet-nse5_fsw_ad-7-6-practice-test-questions-and-exam-dumps-part19-q361-380\/","title":{"rendered":"Fortinet NSE5_FSW_AD-7.6 Practice Test Questions and Exam Dumps Part19 Q361-380"},"content":{"rendered":"<h2><b>View Full <a href=\"https:\/\/www.examlabs.com\/nse5-fsw-ad-7-6-exam-dumps\">Fortinet NSE5_FSW_AD-7.6 Exam Dumps<\/a> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 361<\/b><\/h3>\n<p><b>What determines which switch becomes the root bridge in an STP topology?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The switch with the highest MAC address<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The switch with the lowest Bridge ID<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The switch with the highest interface speed<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The switch with the most VLANs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">STP elects a root bridge based primarily on the Bridge ID. The Bridge ID consists of a bridge priority and a MAC address, with the lowest Bridge ID winning the election. Administrators can influence the election by configuring an appropriate bridge priority on the desired root switch. Selecting a predictable root bridge helps create a stable and efficient Layer 2 topology. Interface speed, VLAN count, or the highest MAC address does not determine the root bridge. Proper STP design should intentionally identify which switches should serve as primary and secondary root bridges.<\/span><\/p>\n<h3><b>Question 362<\/b><\/h3>\n<p><b>After the STP root bridge is selected, what is the primary purpose of a root port on a non-root switch?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To provide the best path toward the root bridge<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To provide PoE to neighboring devices<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To assign IP addresses<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To authenticate users<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">On a non-root switch, the root port is the interface that provides the best path toward the STP root bridge. STP evaluates available paths using factors such as path cost and tie-breaking rules. The selected root port becomes an important part of the active spanning-tree topology. Other interfaces may become designated, alternate, or blocked depending on the topology. Root ports do not provide DHCP services, user authentication, or PoE simply because they are root ports. Their primary role is to provide the preferred path toward the root bridge.<\/span><\/p>\n<h3><b>Question 363<\/b><\/h3>\n<p><b>Which STP parameter is commonly used to influence the preferred path toward the root bridge?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP lease time<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS timeout<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">STP path cost<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SNMP community<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">STP path cost is used to evaluate the relative preference of paths toward the root bridge. A switch considers the accumulated path cost when selecting its best path. Generally, a lower total path cost is preferred. Link characteristics can influence default costs, and administrators can configure supported values when a particular topology requires a different preference. DHCP lease time, RADIUS timeout, and SNMP community settings do not determine the STP forwarding path. Understanding path cost is therefore important when troubleshooting unexpected STP port roles.<\/span><\/p>\n<h3><b>Question 364<\/b><\/h3>\n<p><b>What is the primary purpose of RSTP compared with traditional STP?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To provide faster Layer 2 topology convergence<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To replace VLAN tagging<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To provide centralized user authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To assign management IP addresses<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Rapid Spanning Tree Protocol, or RSTP, improves convergence behavior compared with traditional STP. Its mechanisms allow the network to transition to a stable forwarding topology more quickly after certain topology changes. Faster convergence can reduce the duration of connectivity disruption caused by link or device failures. RSTP does not replace VLAN tagging, provide centralized authentication, or assign management IP addresses. It remains a Layer 2 loop-prevention technology designed to maintain a loop-free topology while responding efficiently to changes.<\/span><\/p>\n<h3><b>Question 365<\/b><\/h3>\n<p><b>Which STP protection feature is designed to help prevent a port from becoming an unintended path toward the root because of an unexpected topology condition?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port mirroring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Loop Guard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP snooping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS accounting<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Loop Guard is an STP protection mechanism intended to help prevent certain conditions in which a port that should remain non-designated could incorrectly transition to a forwarding state because expected BPDUs are no longer being received. Such a situation can contribute to a Layer 2 loop. Loop Guard helps maintain the intended STP topology by protecting against failures involving BPDU reception. Port mirroring is used for traffic analysis, DHCP snooping provides DHCP security, and RADIUS accounting records authentication-related activity.<\/span><\/p>\n<h3><b>Question 366<\/b><\/h3>\n<p><b>What is the main purpose of LACP system or port priority settings?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To influence link aggregation decisions when multiple links are available<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To assign VLAN IDs to clients<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To configure DHCP scopes<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To determine NTP time zones<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">LACP uses information exchanged between devices to negotiate and maintain link aggregation. Priority values can influence which device or ports are preferred when selecting links for an aggregation group, depending on the implementation and configuration. This can be useful when more candidate links exist than can participate in the logical bundle. VLAN IDs, DHCP scopes, and NTP time zones are unrelated to LACP selection. Administrators should ensure that both ends of an aggregate connection have compatible settings and that the intended member interfaces are properly configured.<\/span><\/p>\n<h3><b>Question 367<\/b><\/h3>\n<p><b>What should an administrator verify when configuring multiple physical interfaces as members of an LACP group?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">That the interfaces have compatible configuration and connectivity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">That each interface uses a different native VLAN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">That all interfaces have different IP addresses<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">That each interface connects to an unrelated network<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Interfaces participating in an LACP aggregation must be configured consistently enough for the device to treat them as members of the same logical connection. Administrators should verify physical connectivity, compatible speed and duplex behavior where applicable, VLAN configuration, LACP settings, and the configuration on the remote device. Giving each member an unrelated network configuration would defeat the purpose of aggregation. The exact requirements depend on the FortiSwitch and network design, but consistency between participating interfaces is a fundamental consideration.<\/span><\/p>\n<h3><b>Question 368<\/b><\/h3>\n<p><b>What information can LLDP-MED provide for compatible IP phones?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network policy information such as voice VLAN-related details<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">User passwords<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP server administrator credentials<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">STP root bridge passwords<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">LLDP-MED extends LLDP capabilities for media endpoint devices such as IP phones. It can communicate network policy information that helps compatible endpoints understand how they should operate on the network. This can include voice VLAN-related information and other parameters supported by the LLDP-MED implementation. This approach can simplify voice endpoint provisioning and reduce manual configuration. LLDP-MED does not transmit administrator passwords or credentials. Authentication and security should be handled through appropriate dedicated mechanisms.<\/span><\/p>\n<h3><b>Question 369<\/b><\/h3>\n<p><b>Why can LLDP-MED be useful in a network containing IP phones and computers?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It can help communicate voice-related network policy to supported phones<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It disables the data VLAN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It converts every port into a trunk<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It replaces the need for PoE<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">In a network where an IP phone and a computer share a physical switch connection, LLDP-MED can help a supported phone learn network policy information, such as the appropriate voice VLAN. This can simplify deployment and reduce manual configuration. The data device can continue operating in its appropriate network segment while the phone uses the voice network according to the design. LLDP-MED does not automatically eliminate data VLANs, turn every port into a trunk, or replace PoE. It primarily provides useful discovery and policy information to compatible endpoints.<\/span><\/p>\n<h3><b>Question 370<\/b><\/h3>\n<p><b>What is one advantage of using static MAC address entries in a specific security-sensitive scenario?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">They can provide predictable MAC-to-interface forwarding behavior<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">They automatically encrypt Ethernet traffic<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">They replace all VLAN configuration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">They provide centralized RADIUS authentication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A static MAC address entry can associate a particular MAC address with a specified interface and VLAN context. This can provide predictable forwarding behavior and may be useful in selected controlled environments. Static entries should be used carefully because they require administration when devices or topology change. They do not encrypt Ethernet traffic, replace VLANs, or provide centralized authentication. Dynamic MAC learning remains appropriate for many ordinary switching environments, while static entries are generally reserved for specific operational or security requirements.<\/span><\/p>\n<h3><b>Question 371<\/b><\/h3>\n<p><b>What is a potential indication of MAC address flapping on a FortiSwitch?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The same MAC address repeatedly appears on different interfaces<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The switch clock changes time zone<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A RADIUS server receives an authentication request<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A DHCP lease reaches renewal time<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">MAC address flapping can occur when the same source MAC address is repeatedly learned on different switch interfaces within a short period. This can indicate a Layer 2 loop, redundant connection problem, incorrect cabling, virtualization behavior, or another topology issue. Administrators can review switch logs, MAC address tables, and interface status to investigate the cause. A changing clock, RADIUS request, or DHCP lease renewal does not by itself indicate MAC flapping. Identifying the affected MAC and interfaces is an important troubleshooting step.<\/span><\/p>\n<h3><b>Question 372<\/b><\/h3>\n<p><b>What should an administrator investigate first when a switch interface repeatedly goes up and down?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Physical connectivity and interface errors<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Only the SNMP community<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Only the VLAN name<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Only the administrator password<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Repeated interface state changes, commonly called link flapping, should initially be investigated at the physical and interface levels. Administrators can inspect cables, transceivers, interface statistics, errors, speed and duplex negotiation, and the connected device. Hardware problems or unstable physical connections can cause repeated transitions. Logs may provide additional evidence about when the events occur. SNMP settings, VLAN names, or administrator passwords are not normally the first areas to investigate for a physically unstable Ethernet link.<\/span><\/p>\n<h3><b>Question 373<\/b><\/h3>\n<p><b>What is the purpose of interface error counters during FortiSwitch troubleshooting?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To help identify physical or transmission problems<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To determine the user&#8217;s password<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To select a RADIUS server automatically<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To create new VLANs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Interface statistics and error counters can provide valuable evidence when troubleshooting network connectivity problems. Depending on the type of errors reported, they may indicate damaged cabling, physical-layer problems, negotiation issues, congestion, or other interface conditions. Administrators should compare counters over time rather than relying only on a single snapshot. They can also inspect the remote interface and physical components. Error counters do not create VLANs or select authentication servers. They are primarily diagnostic information for understanding interface behavior.<\/span><\/p>\n<h3><b>Question 374<\/b><\/h3>\n<p><b>Which approach provides the best protection against unauthorized administrative access to network management interfaces?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exposing management interfaces to every network<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Restricting management access to trusted hosts or networks and using strong authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabling all logging<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Using the same password on every device<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Management interfaces should be protected because unauthorized administrative access can compromise the entire network infrastructure. A strong approach is to restrict management access to approved hosts or management networks and use appropriate authentication and secure management protocols. Additional controls such as administrator profiles and monitoring can further reduce risk. Exposing management interfaces broadly increases the attack surface. Disabling logging removes useful security visibility, while reusing the same password across devices increases the impact of credential compromise.<\/span><\/p>\n<h3><b>Question 375<\/b><\/h3>\n<p><b>Which SNMP capability allows a monitoring system to periodically request information from a FortiSwitch?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Polling<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Link aggregation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN pruning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">SNMP polling occurs when a management or monitoring system periodically requests information from a network device. The collected information can include interface statistics, device health information, counters, and other supported monitoring data. Polling allows the monitoring system to build a historical view of device performance and status. SNMP traps work differently because they allow the device to send event notifications to the management system. LACP, port security, and VLAN pruning do not provide SNMP monitoring functionality.<\/span><\/p>\n<h3><b>Question 376<\/b><\/h3>\n<p><b>What is the primary advantage of SNMP traps compared with continuous polling for certain events?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The device can notify the monitoring system when a configured event occurs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">They automatically configure VLANs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">They replace all switch logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">They provide physical PoE power<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">SNMP traps allow a network device to send notifications to an SNMP management system when particular events occur. This can provide faster awareness of events without requiring the monitoring system to repeatedly poll for every possible change. Polling remains useful for collecting regular statistics and historical data, while traps are valuable for event-driven notifications. SNMP traps do not configure VLANs, replace all switch logging, or provide electrical power. Administrators should configure monitoring appropriately so important events are detected without creating unnecessary noise.<\/span><\/p>\n<h3><b>Question 377<\/b><\/h3>\n<p><b>Why should switch configuration backups be retained before a major firmware upgrade?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">They provide a recovery reference if the upgrade causes configuration problems<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">They automatically increase switch bandwidth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">They prevent every hardware failure<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">They replace the firmware image<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A configuration backup provides a known reference that can be used during recovery if an upgrade results in unexpected configuration problems. Before a major firmware change, administrators should also review compatibility requirements, document the current configuration, and maintain an appropriate rollback or recovery plan. A backup does not increase bandwidth or prevent hardware failures, and it is not a replacement for the firmware image itself. Keeping reliable backups is an important part of change management and helps reduce the operational risk associated with upgrades.<\/span><\/p>\n<h3><b>Question 378<\/b><\/h3>\n<p><b>What should be considered before upgrading FortiSwitch firmware in a production environment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Only the switch hostname<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firmware compatibility, release requirements, and an appropriate recovery plan<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Only the number of connected PCs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Only the MAC address aging timer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Firmware upgrades should be planned carefully because compatibility and operational requirements can vary between FortiSwitch models and management environments. Administrators should verify supported firmware relationships, review release information, confirm configuration backups, and plan an appropriate maintenance window. They should also consider whether connected FortiGate or centralized management components require compatible versions. A recovery or rollback plan should be available if unexpected behavior occurs. The switch hostname, number of PCs, or MAC aging timer alone does not provide sufficient information for safe firmware planning.<\/span><\/p>\n<h3><b>Question 379<\/b><\/h3>\n<p><b>What is configuration drift in a centrally managed switch environment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Differences that develop between intended standardized settings and the actual device configuration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A physical cable disconnect<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A DHCP lease renewal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">An STP root bridge election<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Configuration drift occurs when a device&#8217;s actual configuration gradually differs from the organization&#8217;s intended or standardized configuration. This can happen because of manual changes, inconsistent deployments, emergency modifications, or other administrative actions. Configuration drift can make troubleshooting more difficult and may introduce security or connectivity inconsistencies. Centralized management, configuration templates, revision tracking, and regular configuration reviews can help identify and reduce drift. A cable failure, DHCP renewal, or STP election is not itself an example of configuration drift.<\/span><\/p>\n<h3><b>Question 380<\/b><\/h3>\n<p><b>What is the main benefit of maintaining configuration revision history for FortiSwitch devices?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It allows administrators to track changes and help identify when a configuration problem was introduced<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It automatically repairs every failed interface<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It increases PoE capacity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It eliminates the need for monitoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Configuration revision history provides useful operational visibility by allowing administrators to understand what changes were made and when. If a network problem appears after a configuration modification, revision information can help identify the change that may have contributed to the issue. It can also support controlled rollback or comparison with a known-good configuration when supported by the management system. Revision history does not repair physical interfaces, increase PoE capacity, or replace monitoring. It is an important component of effective configuration and change management.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Fortinet NSE5_FSW_AD-7.6 Exam Dumps and Practice Test Dumps. &nbsp; Question 361 What determines which switch becomes the root bridge in an STP topology? The switch with the highest MAC address The switch with the lowest Bridge ID The switch with the highest interface speed The switch with the most VLANs Correct Answer: 2 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/12881"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=12881"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/12881\/revisions"}],"predecessor-version":[{"id":12885,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/12881\/revisions\/12885"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=12881"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=12881"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=12881"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}