New Year Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

NSE5_FSW_AD-7.6 Fortinet NSE 5 - FortiSwitch 7.6 Administrator Questions and Answers

Questions 4

Which is a requirement to enable SNMP v2c on a managed FortiSwitch?

Options:

A.

Create an SNMP user to use for authentication and encryption.

B.

Specify an SNMP host to send traps to.

C.

Enable an SNMP v3 to handle traps messages with SNMP hosts.

D.

Configure SNMP agent and communities.

Buy Now
Questions 5

Which two statements about managing a FortiSwitch stack on FortiGate are true? (Choose two.)

Options:

A.

A FortiLink interface must be enabled on FortiGate.

B.

The switch controller feature must be enabled on FortiGate.

C.

Only a hardware-based FortiGate can manage a FortiSwitch stack.

D.

FortiSwitch must be operating in standalone mode before authorization.

Buy Now
Questions 6

Refer to the exhibits. An IP phone is connected to port1 of FortiSwitch Access-1. The IP phone tags its traffic with VLAN ID 20. On FortiGate, VLAN IP_Phone (VLAN ID 20) has been configured, and port1 of Access-1 is set with VLAN 20 as the native VLAN. However, the IP phone cannot reach the network. The exhibit shows the partial VLAN configuration and the port1 configuration on Access-1.

Which configuration change must you make on FortiSwitch to allow ingress and egress traffic for the IP phone? (Choose one answer)

Options:

A.

On VLAN IP_Phone, enable vlanforward

B.

On VLAN IP_Phone, enable l2forward

C.

On port1, add VLAN 20 to the allowed_vlans list

D.

On port1, disable the edge_port

Buy Now
Questions 7

Refer to the exhibit.

NSE5_FSW_AD-7.6 Question 7

The profile shown in the exhibit is assigned to a group of managed FortiSwitch ports, and these ports are connected to endpoints which are powered by PoE.

Which configuration action can you perform on the LLDP profile to cause these endpoints to exchange PoE information and negotiate power with the managed FortiSwitch?

Options:

A.

Create new a LLDP-MED application type to define the PoE parameters.

B.

Assign a new LLDP profile to handle different LLDP-MED TLVs.

C.

Define an LLDP-MED location ID to use standard protocols for power.

D.

Add power management as part of LLDP-MED TLVs to advertise.

Buy Now
Questions 8

Which two are valid traffic processing actions that a FortiSwitch access control list (ACL) can apply to matching traffic? (Choose two answers)

Options:

A.

Redirect frames to another port.

B.

Assign traffic to a high-priority egress queue.

C.

Encrypt frames.

D.

Drop frames.

Buy Now
Questions 9

Which statement about the IGMP snooping querier when enabled on a VLAN is true?

Options:

A.

Active multicast receiver entries are aging on each IGMP query sent on the VLAN

B.

IGMP reports on the VLAN are forwarded to all switch ports.

C.

The setting can only be enabled using the FortiSwitch CLI.

D.

All other indirectly connected switches will be unable to get IGMP multicast traffic.

Buy Now
Questions 10

Refer to the exhibit.

NSE5_FSW_AD-7.6 Question 10

The security port policy is configured as shown in the exhibit. Which behavior occurs if a device connected to the port that does not support 802.1X? (Choose one answer)

Options:

A.

The device is blocked from accessing the network.

B.

The device is placed into the onboarding VLAN.

C.

The device is placed into the quarantine VLAN.

D.

The device is assigned to the default management VLAN.

Buy Now
Questions 11

Which drop policy mode, if assigned to a congested port, will drop incoming packets until there is no congestion on the egress port?

Options:

A.

Tail-drop mode

B.

Weighted round robin mode.

C.

Random early detection mode

D.

Strict mode

Buy Now
Questions 12

On supported FortiSwitch models, which access control list (ACL) stage is recommended for applying actions before the switch performs any layer 2 or layer 3 processing? (Choose one answer)

Options:

A.

Ingress

B.

Forwarding

C.

Egress

D.

Prelookup

Buy Now
Questions 13

(Full question statement start from here)

How does FortiSwitch determine the route for traffic traversing its interfaces? (Choose one answer)

Options:

A.

Hardware-based routing on FortiSwitch is handled by the CPU.

B.

ASIC hardware routing can handle only dynamic routing, if supported.

C.

FortiSwitch looks up the hardware routing table and then the forwarding information base (FIB).

D.

FortiSwitch forwards all traffic to FortiGate for routing decisions.

Buy Now
Questions 14

Which statement about the use of the switch port analyzer (SPAN) packet capture method is true?

Options:

A.

Mirrored traffic can be sent across multiple switches.

B.

SPAN can be configured only on a standalone FortiSwitch.

C.

Traffic on the management interface can be mirrored and captured by the monitoring device.

D.

The monitoring device must be connected to the same switch where the traffic is being mirrored

Buy Now
Questions 15

When Dynamic Host Configuration Protocol (DHCP) snooping is enabled on a FortiSwitch VLAN, which two statements are true? (Choose two answers)

Options:

A.

DHCP replies are accepted only on trusted ports.

B.

DHCP snooping blocks all unicast traffic.

C.

Option 82 can be inserted into DHCP requests.

D.

DHCP requests are dropped if sent from trusted ports.

Buy Now
Questions 16

Refer to the exhibit.

NSE5_FSW_AD-7.6 Question 16

PC1 connected to port1 has joined multicast group 225.1.2.3 on VLAN 10 with IGMP snooping enabled. What will happen if you disable IGMP snooping on FortiSwitch? (Choose one answer)

Options:

A.

PC1 will be removed from the multicast group 225.1.2.3.

B.

The FortiSwitch will stop processing IGMP report join messages.

C.

Multicast traffic for 225.1.2.3 will be flooded to all ports.

D.

Multicast traffic will stop until a multicast receiver is detected.

Buy Now
Questions 17

Refer to the exhibits

NSE5_FSW_AD-7.6 Question 17

NSE5_FSW_AD-7.6 Question 17

Traffic arriving on port2 on FortiSwitch is tagged with VLAN ID 10 and destined for PC1 connected on port1. PC1 expects to receive traffic untagged from port1 on FortiSwitch. Which two configurations can you perform on FortiSwitch to ensure PC1 receives untagged traffic on port1? (Choose two.)

Options:

A.

Add the MAC address of PC1 as a member of VLAN 10.

B.

Add VLAN ID 10 as a member of the untagged VLANs on port1.

C.

Remove VLAN 10 from the allowed VLANs and add it to untagged VLANs on port1.

D.

Enable Private VLAN on VLAN 10 and add VLAN 20 as an isolated VLAN.

Buy Now
Questions 18

Which two requirements must be met before FortiGate can manage a FortiSwitch stack? (Choose two answers)

Options:

A.

The latest FortiOS and FortiSwitchOS versions must be running.

B.

The switch controller feature must be enabled.

C.

All existing FortiLink interfaces must be disabled.

D.

The FortiSwitchOS version must be compatible with FortiOS.

Buy Now
Questions 19

You are configuring VLANs on a FortiSwitch device managed by FortiGate. Which two statements accurately describe VLAN assignment requirements and behavior on FortiSwitch ports? (Choose two answers)

Options:

A.

Untagged defines the list of VLANs that are allowed on the port for both ingress and egress traffic.

B.

Untagged VLAN applies to egress traffic only.

C.

You can assign only one native VLAN on a port.

D.

VLAN assignments must be configured directly on the FortiSwitch.

Buy Now
Questions 20

Which QoS mechanism maps packets with specific CoS or DSCP markings to an egress queue?

Options:

A.

Queuing for egress traffic

B.

Classification for ingress traffic

C.

Rate limiting for egress traffic

D.

Marking for ingress traffic

Buy Now
Questions 21

Exhibit.

LAG and MCLAG are used to increase the available network bandwidth and enable redundancy. How does spanning tree protocol see MCLAG and LAG if they are configured based on the physi-cal view shown in the exhibit? (Choose two)

Options:

A.

Switch 1. Switch 2, and Switch 3 are seen as one MCLAG peer group

B.

Switch 3 and Switch 4 uplinks are treated as single interfaces.

C.

Switch 3 and switch 4 are seen as one MCLAG switch client

D.

Switch 1 and Switch 2 both seen as one single switch.

Buy Now
Questions 22

Which two types of Layer 3 interfaces can participate in dynamic routing on FortiSwitch? (Choose two.)

Options:

A.

Detected management interfaces

B.

Loopback interfaces

C.

Switch virtual interfaces

D.

Physical interfaces

Buy Now
Questions 23

Which Ethernet frame can create Layer 2 flooding due to all bytes on the destination MAC address being set to all FF?

Options:

A.

The broadcast Ethernet frame

B.

The unicast Ethernet frame

C.

The multicast Ethernet frame

D.

The anycast Ethernet frame

Buy Now
Questions 24

Refer to the configuration:

Which two conditions does FortiSwitch need to meet to successfully configure the options shown in the exhibit above? (Choose two.)

Options:

A.

The FortiSwitch model is equipped with a maximum of 54 interfaces

B.

FortiSwitch would need to be rebooted.

C.

The split port can be assigned to a native VLAN.

D.

The Dort full speed prior to the split was 100G QSFP+.

Buy Now
Questions 25

What feature can network administrators use to segment network operations and the administration of managed FortiSwitch devices on FortiGate?

Options:

A.

FortiGate multi-tenancy

B.

Multi-chassis link aggregation trunk

C.

FortiGate clustering protocol

D.

FortiLink split interface

Buy Now
Questions 26

You are designing a FortiSwitch backbone where every FortiSwitch device must connect to every other FortiSwitch for maximum redundancy. To maintain connectivity while preventing loops, which protocol or feature must you configure on the switches? (Choose one answer)

Options:

A.

Multichassis link aggregation group (MCLAG)

B.

Spanning Tree Protocol (STP)

C.

Full mesh high availability (HA)

D.

Link aggregation group (LAG)

Buy Now
Questions 27

An administrator must deploy managed FortiSwitch devices in a remote location where multiple VLANs must be used to segment devices. No layer 3 switch or router is present at the site, and the only WAN connectivity is an ISP-provided router connected to the public internet. Which two components are required to enable VLAN segmentation across this remote site? (Choose two answers)

Options:

A.

FortiGate and FortiSwitch configured with VXLAN to tunnel VLANs over the WAN

B.

A layer 3 router at the remote location to handle inter-VLAN routing

C.

A FortiSwitch model that supports VXLAN hardware acceleration

D.

FortiSwitch and FortiGate devices configured with IPsec interfaces

E.

FortiGate with a layer 3 interface to terminate the VXLAN overlay

Buy Now
Questions 28

You are deploying a new FortiSwitch device in a branch office and you want it to be automatically detected and managed by FortiGate. Which FortiSwitch feature enables automatic detection during deployment? (Choose one answer)

Options:

A.

Zero-touch deployment

B.

Auto-discovery

C.

Link Layer Discovery Protocol (LLDP)

D.

FortiLink heartbeat

Buy Now
Questions 29

Refer to the exhibit.

NSE5_FSW_AD-7.6 Question 29

You have just authorized a new FortiSwitch on your FortiGate, and it appears online in the GUI. To verify that FortiLink connectivity is healthy, what should you check next? (Choose one answer)

Options:

A.

Check that the switch automatically disables all unused ports.

B.

Look for FortiLink heartbeat messages sent from FortiSwitch to FortiGate every few seconds and confirm FortiGate acknowledges them.

C.

Verify that FortiGate has pushed a new firmware image to FortiSwitch immediately.

D.

Ensure the FortiSwitch is automatically sending log events to FortiAnalyzer.

Buy Now
Questions 30

Which two statements about 802.1X authentication on FortiSwitch ports are true? (Choose two.)

Options:

A.

All hosts behind an authenticated port are allowed access after a successful authentication.

B.

A security policy is used to apply 802.1 authentication on a port.

C.

A local user database must be used to authenticate devices using the 802.1X authentication protocol.

D.

All devices connecting to FortiSwitch must support 802.1X authentication.

Buy Now
Questions 31

Refer to the exhibits.

NSE5_FSW_AD-7.6 Question 31

Port1 and port2 are the only ports configured with the same native VLAN 10.

What are two reasons that can trigger port1 to shut down? (Choose two.)

Options:

A.

port1 was shut down by loop guard protection.

B.

STP triggered a loop and applied loop guard protection on port1.

C.

An endpoint sent a BPDU on port1 that it received from another interface.

D.

Loop guard frame sourced from port 1 was received on port 1.

Buy Now
Questions 32

Refer to the exhibit.

NSE5_FSW_AD-7.6 Question 32

The command diagnose switch physical-ports summary is executed on FortiSwitch.

Based on the VLAN assignments shown in the output, what is the most likely management configuration of this FortiSwitch? (Choose one answer)

Options:

A.

FortiSwitch is managed by FortiSwitch Cloud.

B.

FortiSwitch is managed by FortiGate.

C.

FortiSwitch is operating in standalone mode.

D.

FortiSwitch is operating in local mode.

Buy Now
Questions 33

Refer to the exhibits.

NSE5_FSW_AD-7.6 Question 33

An administrator has deployed two FortiSwitch devices, Core-1 and Core-2, as multichassis link aggregation group (MCLAG) peers. These switches are connected to FortiGate for FortiLink and to an access switch (Access-1) using an inter-switch link (ISL). After configuration, the administrator notices that both Core-1 and Core-2 are claiming to be the root bridge in the Multiple Spanning Tree Protocol (MSTP) topology. What explains this behavior? (Choose one answer)

Options:

A.

FortiGate participates in MSTP and causes both switches to assume the root bridge role.

B.

The ISL was not configured correctly, leading to MSTP inconsistency.

C.

Both switches share the same bridge ID because MCLAG treats them as one logical switch.

D.

MCLAG automatically disables STP on all peer switches.

Buy Now
Exam Code: NSE5_FSW_AD-7.6
Exam Name: Fortinet NSE 5 - FortiSwitch 7.6 Administrator
Last Update: Dec 26, 2025
Questions: 111

PDF + Testing Engine

$63.52  $181.49

Testing Engine

$50.57  $144.49
buy now NSE5_FSW_AD-7.6 testing engine

PDF (Q&A)

$43.57  $124.49
buy now NSE5_FSW_AD-7.6 pdf