Spring Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

NSE5_FSW_AD-7.6 Fortinet NSE 5 - FortiSwitch 7.6 Administrator Questions and Answers

Questions 4

Which LLDP-MED Type-Length-Values does FortiSwitch collect from endpoints to track network devices and determine their characteristics?

Options:

A.

Network policy

B.

Power management

C.

Location

D.

Inventory management

Buy Now
Questions 5

You are configuring FortiSwitch to perform layer 3 inter-VLAN routing while managed by FortiGate over FortiLink. On supported hardware models, FortiSwitch can offload routing decisions for better performance. 1 How does FortiSwitch perform routing between VLANs? (Choose one answer)

Options:

A.

By using a hardware forwarding table (FIB) programmed into ASIC.

B.

By supporting only dynamic routing protocols in hardware.

C.

By disabling routing when managed by FortiGate.

D.

By relying entirely on the CPU in software.

Buy Now
Questions 6

(Full question statement start from here)

You are deploying a FortiSwitch virtual stack in a network that contains Cisco devices. You want the Cisco devices to automatically discover the FortiSwitch devices and exchange device information . Which two protocols must be enabled on the FortiSwitch devices to achieve this? (Choose two answers)

Options:

A.

Unidirectional Link Detection

B.

Cisco Discovery Protocol

C.

Link Layer Discovery Protocol

D.

LLDP – Media Endpoint Discovery

Buy Now
Questions 7

Refer to the exhibit.

What two conclusions can be made regarding DHCP snooping configuration? (Choose two.)

Options:

A.

Maximum value to accept clients DHCP request is configured as per DHCP server range.

B.

FortiSwitch is configured to trust DHCP replies coming on FortiLink interface.

C.

DHCP clients that are trusted by DHCP snooping configured is only one.

D.

Global configuration for DHCP snooping is set to forward DHCP client requests on all ports in the VLAN.

Buy Now
Questions 8

Which two types of Layer 3 interfaces can participate in dynamic routing on FortiSwitch? (Choose two.)

Options:

A.

Detected management interfaces

B.

Loopback interfaces

C.

Switch virtual interfaces

D.

Physical interfaces

Buy Now
Questions 9

(Full question statement start from here)

You enable Dynamic Host Configuration Protocol (DHCP) snooping on a VLAN and configure a FortiSwitch port as trusted for DHCP snooping. What additional step is required to configure the port as trusted for Dynamic ARP Inspection (DAI) ? (Choose one answer)

Options:

A.

Manually set the port as trusted for DAI through the CLI.

B.

DAI implicitly trusts the port.

C.

Enable IP Source Guard (IPSG) on the port.

D.

Enable static MAC learning on the port.

Buy Now
Questions 10

Exhibit.

NSE5_FSW_AD-7.6 Question 10

Two routes are not installed in the forwarding information base (FIB) as shown in the exnibit. Which two statements about these two route entries are true? (Choose two.)

Options:

A.

These two routes have a higher administrative distance value available to the destination networks.

B.

These two routes will become primary, if the best routes are removed.

C.

These two routes will be used as load-balancing routes.

D.

These two routes are available in the hardware routing table.

Buy Now
Questions 11

Which two statements about the FortiLink authorization process are true? (Choose two.)

Options:

A.

The administrator must manually pre-authorize FortiGate on FortiSwitch by adding the FortiGate serial number.

B.

FortiSwitch requires a reboot to complete the authorization process.

C.

A FortiLink frame is sent by FortiGate to FortiSwitch to complete the authorization.

D.

FortiLink authorization sets the FortiSwitch management mode to FortiLink.

Buy Now
Questions 12

What can an administrator do to maintain the existing standalone FortlSwltch configuration while changing the management mode to FortLink?

Options:

A.

Use a migration tool based on python script to convert the configuration

B.

Enable the Forti-link setting on FortiSwitch before the authorization process

C.

FortiGate will automatically save the existing FortiSwitch configuration during the Forti-link management process.

D.

Register FortiSwitch to For1ISwitch Cloud to save a copy before managing by Forti-Gate.

Buy Now
Questions 13

Refer to the exhibit.

NSE5_FSW_AD-7.6 Question 13

PC1 connected to port1 has joined multicast group 225.1.2.3 on VLAN 10 with IGMP snooping enabled. What will happen if you disable IGMP snooping on FortiSwitch? (Choose one answer)

Options:

A.

PC1 will be removed from the multicast group 225.1.2.3.

B.

The FortiSwitch will stop processing IGMP report join messages.

C.

Multicast traffic for 225.1.2.3 will be flooded to all ports.

D.

Multicast traffic will stop until a multicast receiver is detected.

Buy Now
Questions 14

What is the role of a device that is simultaneously functioning as both the distribution and core in the hierarchy network model?

Options:

A.

POE with high density FortiSwitch

B.

FortiGate managing FortiSwitch

C.

FortiSwitch functioning as standalone

D.

HA backup FortiGate managing FortiSwitch

Buy Now
Questions 15

You are designing a multi-tenant network using FortiSwitch devices in standalone mode. Security is a priority and each tenant’s servers must be completely isolated from one another, and from all other servers in the network, to prevent lateral communication. However, all servers must have access to the shared FortiGate firewall for internet access. Which type of private VLAN (PVLAN) configuration should you apply to meet these security requirements? (Choose one answer)

Options:

A.

Standalone VLAN

B.

Community VLAN

C.

Isolated VLAN

D.

Primary VLAN

Buy Now
Questions 16

Which Ethernet frame can create Layer 2 flooding due to all bytes on the destination MAC address being set to all FF?

Options:

A.

The broadcast Ethernet frame

B.

The unicast Ethernet frame

C.

The multicast Ethernet frame

D.

The anycast Ethernet frame

Buy Now
Questions 17

(Full question statement start from here)

What is one key advantage of using a sniffer profile on FortiSwitch compared to using the sniffer command? (Choose one answer)

Options:

A.

It allows packet capture on all switch ports without limitations.

B.

It eliminates the need to use access control lists (ACLs) or port mirroring for analysis.

C.

It automatically filters irrelevant traffic types.

D.

It automatically decrypts SSL/TLS traffic for full packet inspection.

Buy Now
Questions 18

Which statement about the configuration of VLANs on a managed FortiSwitch port is true?

Options:

A.

Untagged VLANs must be part of the allowed VLANs: ingress and egress.

B.

FortiSwitch VLAN interfaces are created only when FortiSwitch is managed by Forti-Gate.

C.

The native VLAN is implicitly part of the allowed VLAN on the port.

D.

Allowed VLANS expand the collision domain to the port.

Buy Now
Questions 19

Refer to the exhibit.

NSE5_FSW_AD-7.6 Question 19

Two routes in the routing monitor are marked as available but are not installed in the forwarding information base (FIB). Which statement correctly explains why the routes have this status? (Choose one answer)

Options:

A.

They are excluded from the FIB because a more preferred route exists for the same destination.

B.

They are unavailable due to invalid next-hop addresses.

C.

They are not included in the FIB due to route-policy filtering.

D.

They are installed in the FIB but cannot be offloaded to hardware.

Buy Now
Questions 20

Exhibit.

port1 and port2 are the only ports configured with the same native VLAN 10.

What are two reasons that can trigger port1 to shut down? (Choose two.)

Options:

A.

port1 was shut down by loop guard protection.

B.

STP triggered a loop and applied loop guard protection on port1.

C.

An endpoint sent a BPDU on port1 that it received from another interface.

D.

Loop guard frame sourced from port1 was received on port1.

Buy Now
Questions 21

Refer to the configuration:

Which two conditions does FortiSwitch need to meet to successfully configure the options shown in the exhibit above? (Choose two.)

Options:

A.

The FortiSwitch model is equipped with a maximum of 54 interfaces

B.

FortiSwitch would need to be rebooted.

C.

The split port can be assigned to a native VLAN.

D.

The Dort full speed prior to the split was 100G QSFP+.

Buy Now
Questions 22

You are configuring VLANs on a FortiSwitch device managed by FortiGate. Which two statements accurately describe VLAN assignment requirements and behavior on FortiSwitch ports? (Choose two answers)

Options:

A.

Untagged defines the list of VLANs that are allowed on the port for both ingress and egress traffic.

B.

Untagged VLAN applies to egress traffic only.

C.

You can assign only one native VLAN on a port.

D.

VLAN assignments must be configured directly on the FortiSwitch.

Buy Now
Questions 23

Refer to the exhibit.

NSE5_FSW_AD-7.6 Question 23

Core-1 and Access-1 are managed and authorized by FortiGate-1. which uses port4 as the FortiLink interface. After FortiGate authorizes and manages Core-2. Port1 status becomes STP discarding.

Why is port1 in the discarding state?

Options:

A.

port1 on Core-2 is discarding only management traffic.

B.

Core-1 and Core-2 do not have MCLAG configuration.

C.

Access-1 is the root bridge and can only have one root port.

D.

Core-2 has the lowest bridge priority.

Buy Now
Questions 24

Which two statements about managing a FortiSwitch stack on FortiGate are true? (Choose two.)

Options:

A.

A FortiLink interface must be enabled on FortiGate.

B.

The switch controller feature must be enabled on FortiGate.

C.

Only a hardware-based FortiGate can manage a FortiSwitch stack.

D.

FortiSwitch must be operating in standalone mode before authorization.

Buy Now
Questions 25

When Dynamic Host Configuration Protocol (DHCP) snooping is enabled on a FortiSwitch VLAN, which two statements are true? (Choose two answers)

Options:

A.

DHCP replies are accepted only on trusted ports.

B.

DHCP snooping blocks all unicast traffic.

C.

Option 82 can be inserted into DHCP requests.

D.

DHCP requests are dropped if sent from trusted ports.

Buy Now
Questions 26

(Full question statement start from here)

When you change FortiSwitch management mode from standalone to managed , what happens to the existing standalone configuration? (Choose one answer)

Options:

A.

FortiSwitch registers to FortiSwitch Cloud to save a copy before managing with FortiGate.

B.

FortiSwitch merges the existing standalone configuration with the default FortiLink configuration.

C.

FortiSwitch saves the standalone configuration and changes to the default FortiLink configuration.

D.

FortiGate automatically saves the existing FortiSwitch configuration during the FortiLink management process.

Buy Now
Questions 27

Exhibit.

LAG and MCLAG are used to increase the available network bandwidth and enable redundancy. How does spanning tree protocol see MCLAG and LAG if they are configured based on the physi-cal view shown in the exhibit? (Choose two)

Options:

A.

Switch 1. Switch 2, and Switch 3 are seen as one MCLAG peer group

B.

Switch 3 and Switch 4 uplinks are treated as single interfaces.

C.

Switch 3 and switch 4 are seen as one MCLAG switch client

D.

Switch 1 and Switch 2 both seen as one single switch.

Buy Now
Questions 28

What are two reasons why time synchronization between FortiGate and its managed FortiSwitch is critical in switch management? (Choose two.)

Options:

A.

FortiSwitch does not retain its time after a reboot, which gets reset after each reboot.

B.

FortiSwitch will not be able to become an NTP server for downstream devices.

C.

FortiSwitch cannot complete the DTLS handshake used in the CAPWAP tunnel.

D.

FortiSwitch will not allow other FortiSwitch devices in the chain be discovered by FortiGate.

Buy Now
Questions 29

Refer to the exhibits.

NSE5_FSW_AD-7.6 Question 29

NSE5_FSW_AD-7.6 Question 29

You are asked to ensure that managed FortiSwitch devices are reachable by other devices, such as SNMP and other management tools across your network.

Which setting must you configure to ensure traffic from other devices in the network reaches FortiSwitch?

Options:

A.

Select a specific default gateway provided to FortiSwitch as an upstream device.

B.

Change the FortiLink interface IP address and DHCP server address range.

C.

Recreate the FortiLink interface with a nonaggregate setting.

D.

Enable NAC settings to select the onboarding VLAN.

Buy Now
Questions 30

(Full question statement start from here)

Refer to the exhibits.

NSE5_FSW_AD-7.6 Question 30

Three FortiSwitch devices were recently configured to be managed by FortiGate. Two are managed successfully, but FortiSwitch Access-1 is not.

Based on the configuration output, which initial change is required for FortiSwitch Access-1 to be managed? (Choose one answer)

Options:

A.

Assign a static IP on FortiSwitch Access-1.

B.

Change its Control and Provisioning of Wireless Access Points (CAPWAP) settings.

C.

Set Access-1 internal interface mode to DHCP.

D.

Change the NTP server.

Buy Now
Questions 31

Which two rules used by MSTP are similar to rules used by other STP methods? (Choose two.)

Options:

A.

MSTP uses port role election, similar to rapid STP on the instances.

B.

MSTP uses alternate path and primary path, similar to regular STP.

C.

MSTP uses root bridge selection, similar to rapid STP

D.

MSTP uses timers for transitioning the ports, similar to regular STP.

Buy Now
Questions 32

Refer to the exhibit.

NSE5_FSW_AD-7.6 Question 32

You have just authorized a new FortiSwitch on your FortiGate, and it appears online in the GUI. To verify that FortiLink connectivity is healthy, what should you check next? (Choose one answer)

Options:

A.

Check that the switch automatically disables all unused ports.

B.

Look for FortiLink heartbeat messages sent from FortiSwitch to FortiGate every few seconds and confirm FortiGate acknowledges them.

C.

Verify that FortiGate has pushed a new firmware image to FortiSwitch immediately.

D.

Ensure the FortiSwitch is automatically sending log events to FortiAnalyzer.

Buy Now
Questions 33

You need to mirror traffic from a source port on Switch A to a monitoring device on Switch C. For that purpose, you’re configuring Remote Switched Port Analyzer (RSPAN). 1 Due to the nature of RSPAN, what is the best practice when setting it up? (Choose one answer)

Options:

A.

Use the same VLAN already configured for regular data traffic.

B.

Use a dedicated VLAN assigned only to monitoring devices.

C.

Use a dynamic VLAN that includes all switch ports.

D.

Use the RSPAN VLAN as a native VLAN on all trunk ports.

Buy Now
Exam Code: NSE5_FSW_AD-7.6
Exam Name: Fortinet NSE 5 - FortiSwitch 7.6 Administrator
Last Update: May 11, 2026
Questions: 111

PDF + Testing Engine

$63.52  $181.49

Testing Engine

$50.57  $144.49
buy now NSE5_FSW_AD-7.6 testing engine

PDF (Q&A)

$43.57  $124.49
buy now NSE5_FSW_AD-7.6 pdf