Pre-Winter Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

Free Practice Questions for the Fortinet Network Security Expert NSE5_FSW_AD-7.6 Exam (2026 Updated)

At Marks4sure, we are dedicated to providing IT professionals with the most accurate and reliable preparation materials for the Fortinet NSE5_FSW_AD-7.6 exam. To support your certification journey, we have made a selection of our premium 2026 Fortinet Network Security Expert practice questions and answers available completely free. You can take this practice test as many times as you need. Every question includes a detailed, expertly verified explanation to ensure you fully grasp the core security concepts before test day.

Questions 4

You are deploying a new FortiSwitch device in a branch office and you want it to be automatically detected and managed by FortiGate. Which FortiSwitch feature enables automatic detection during deployment? (Choose one answer)

Options:

A.

Zero-touch deployment

B.

Auto-discovery

C.

Link Layer Discovery Protocol (LLDP)

D.

FortiLink heartbeat

Buy Now
Questions 5

Exhibit.

port24 is the only uplink port connected to the network where access to FortiSwitch management services is possible. However, FortiSwitch is still not accessible on the management interface. Which two actions should you take to fix the issue and access FortiSwitch? (Choose two.)

Options:

A.

You must add port24 native VLAN as an allowed VLAN on internal.

B.

You must add VLAN ID 200 to the allowed VLANS on internal.

C.

You must allow VLAN ID 4094 on port24, if management traffic is tagged.

D.

You should use VLAN ID 4094 as the native VLAN on port24.

Buy Now

NSE5_FSW_AD-7.6 Report Card

Questions 6

(Full question statement start from here)

You enable Dynamic Host Configuration Protocol (DHCP) snooping on a VLAN and configure a FortiSwitch port astrustedfor DHCP snooping. What additional step is required to configure the port as trusted forDynamic ARP Inspection (DAI)? (Choose one answer)

Options:

A.

Manually set the port as trusted for DAI through the CLI.

B.

DAI implicitly trusts the port.

C.

Enable IP Source Guard (IPSG) on the port.

D.

Enable static MAC learning on the port.

Buy Now
Questions 7

Which two statements about 802.1X authentication on FortiSwitch ports are true? (Choose two.)

Options:

A.

All hosts behind an authenticated port are allowed access after a successful authentication.

B.

A security policy is used to apply 802.1 authentication on a port.

C.

A local user database must be used to authenticate devices using the 802.1X authentication protocol.

D.

All devices connecting to FortiSwitch must support 802.1X authentication.

Buy Now
Questions 8

Which drop policy mode, if assigned to a congested port, will drop incoming packets until there is no congestion on the egress port?

Options:

A.

Tail-drop mode

B.

Weighted round robin mode.

C.

Random early detection mode

D.

Strict mode

Buy Now
Questions 9

Refer to the diagnostic output:

NSE5_FSW_AD-7.6 Question 9

Two entries in the exhibit show that the same MAC address has been used in two different VLANs. Which MAC address is shown in the above output?

Options:

A.

It is a MAC address of FortiLink interface on FortiGate.

B.

It is a MAC address of a switch that accepts multiple VLANs.

C.

It is a MAC address of an upstream FortiSwitch.

D.

It is a MAC address of FortiGate in HA configuration.

Buy Now
Questions 10

You are configuring FortiSwitch to perform layer 3 inter-VLAN routing while managed by FortiGate over FortiLink. On supported hardware models, FortiSwitch can offload routing decisions for better performance.1How does FortiSwitch perform routing between VLANs? (Choose one answer)

Options:

A.

By using a hardware forwarding table (FIB) programmed into ASIC.

B.

By supporting only dynamic routing protocols in hardware.

C.

By disabling routing when managed by FortiGate.

D.

By relying entirely on the CPU in software.

Buy Now
Questions 11

Refer to the exhibit.

NSE5_FSW_AD-7.6 Question 11

The security port policy is configured as shown in the exhibit. Which behavior occurs if a device connected to the port that does not support 802.1X? (Choose one answer)

Options:

A.

The device is blocked from accessing the network.

B.

The device is placed into the onboarding VLAN.

C.

The device is placed into the quarantine VLAN.

D.

The device is assigned to the default management VLAN.

Buy Now
Questions 12

(Full question statement start from here)

Refer to the exhibit.

NSE5_FSW_AD-7.6 Question 12

You run the command diagnose switch-controller switch-info loopguard access-1 and see that theMAC-Movecolumn displays a value of0forport1.

What does this indicate? (Choose one answer)

Options:

A.

Loop guard is disabled on port1.

B.

Port1 is not being monitored by loop guard.

C.

The MAC move feature is not enabled.

D.

Port1 will shut down if a loop occurs on any VLAN.

Buy Now
Questions 13

Which two statements about managing a FortiSwitch stack on FortiGate are true? (Choose two.)

Options:

A.

A FortiLink interface must be enabled on FortiGate.

B.

The switch controller feature must be enabled on FortiGate.

C.

Only a hardware-based FortiGate can manage a FortiSwitch stack.

D.

FortiSwitch must be operating in standalone mode before authorization.

Buy Now
Questions 14

How does FortiSwitch perform actions on ingress and egress traffic using the access control list (ACL)?

Options:

A.

Only high-end FortiSwitch models support ACL.

B.

ACL can be used only at the prelookup stage in the traffic processing pipeline.

C.

Classifiers enable matching traffic based only on the VLAN ID.

D.

FortiSwitch checks ACL policies only from top to bottom.

Buy Now
Questions 15

(Full question statement start from here)

When you change FortiSwitch management mode fromstandalonetomanaged, what happens to the existing standalone configuration? (Choose one answer)

Options:

A.

FortiSwitch registers to FortiSwitch Cloud to save a copy before managing with FortiGate.

B.

FortiSwitch merges the existing standalone configuration with the default FortiLink configuration.

C.

FortiSwitch saves the standalone configuration and changes to the default FortiLink configuration.

D.

FortiGate automatically saves the existing FortiSwitch configuration during the FortiLink management process.

Buy Now
Questions 16

You are designing a multi-tenant network using FortiSwitch devices in standalone mode. Security is a priority and each tenant’s servers must be completely isolated from one another, and from all other servers in the network, to prevent lateral communication. However, all servers must have access to the shared FortiGate firewall for internet access. Which type of private VLAN (PVLAN) configuration should you apply to meet these security requirements? (Choose one answer)

Options:

A.

Standalone VLAN

B.

Community VLAN

C.

Isolated VLAN

D.

Primary VLAN

Buy Now
Questions 17

You need to mirror traffic from a source port on Switch A to a monitoring device on Switch C. For that purpose, you’re configuring Remote Switched Port Analyzer (RSPAN).1Due to the nature of RSPAN, what is the best practice when setting it up? (Choose one answer)

Options:

A.

Use the same VLAN already configured for regular data traffic.

B.

Use a dedicated VLAN assigned only to monitoring devices.

C.

Use a dynamic VLAN that includes all switch ports.

D.

Use the RSPAN VLAN as a native VLAN on all trunk ports.

Buy Now
Questions 18

Refer to the exhibits.

NSE5_FSW_AD-7.6 Question 18

You are reviewing a FortiSwitch configuration where port1 and port2 are connected to a switched network. Loop guard is enabled on port1.

The CLI output shows that the port1 status is triggered due to loop guard. Which two conditions could have caused this shutdown? (Choose two.)

Options:

A.

A loop guard frame sent from port1 is received on port2.

B.

A loop guard frame sent from port1 is received back on port1.

C.

Loop guard is triggered because port2 did not send any bridge protocol data units (BPDU).

D.

Loop guard is triggered because the port detected excessive traffic.

Buy Now
Questions 19

What feature can network administrators use to segment network operations and the administration of managed FortiSwitch devices on FortiGate?

Options:

A.

FortiGate multi-tenancy

B.

Multi-chassis link aggregation trunk

C.

FortiGate clustering protocol

D.

FortiLink split interface

Buy Now
Questions 20

Refer to the exhibits. An IP phone is connected to port1 of FortiSwitch Access-1. The IP phone tags its traffic with VLAN ID 20. On FortiGate, VLAN IP_Phone (VLAN ID 20) has been configured, and port1 of Access-1 is set with VLAN 20 as the native VLAN. However, the IP phone cannot reach the network. The exhibit shows the partial VLAN configuration and the port1 configuration on Access-1.

Which configuration change must you make on FortiSwitch to allow ingress and egress traffic for the IP phone? (Choose one answer)

Options:

A.

On VLAN IP_Phone, enable vlanforward

B.

On VLAN IP_Phone, enable l2forward

C.

On port1, add VLAN 20 to the allowed_vlans list

D.

On port1, disable the edge_port

Buy Now
Questions 21

(Full question statement start from here)

Refer to the exhibit.

NSE5_FSW_AD-7.6 Question 21

NSE5_FSW_AD-7.6 Question 21

NSE5_FSW_AD-7.6 Question 21

Which information does FortiGate use to generate the port details in the FortiSwitch Faceplates view? (Choose one answer)

Options:

A.

The FortiSwitch model

B.

The Cisco Discovery Protocol (CDP) advertisements from FortiSwitch

C.

The LLDP advertisements received from the FortiSwitch

D.

The FortiLink discovery frames sent by FortiSwitch

Buy Now
Questions 22

Which feature should you enable to reduce the number or unwanted IGMP reports processed by the IGMP querier?

Options:

A.

Enable the IGMP flood setting on the static port for all multicast groups.

B.

Enable the IGMP flood reports setting on the mRouter port.

C.

Enable IGMP snooping proxy.

D.

Enable IGMP flood unknown multicast traffic on the global setting.

Buy Now
Questions 23

Refer to the exhibit.

NSE5_FSW_AD-7.6 Question 23

Which two configurations can you use for the FortiLink interface in a basic single FortiGate-single FortiSwitch topology? (Choose two.)

Options:

A.

Single physical port

B.

Port channel

C.

Switchport mode trunk

D.

Link aggregation group (LAG)

Buy Now
Questions 24

Refer to the exhibit.

NSE5_FSW_AD-7.6 Question 24

Two routes in the routing monitor are marked as available but are not installed in the forwarding information base (FIB). Which statement correctly explains why the routes have this status? (Choose one answer)

Options:

A.

They are excluded from the FIB because a more preferred route exists for the same destination.

B.

They are unavailable due to invalid next-hop addresses.

C.

They are not included in the FIB due to route-policy filtering.

D.

They are installed in the FIB but cannot be offloaded to hardware.

Buy Now
Questions 25

Refer to the exhibits.

NSE5_FSW_AD-7.6 Question 25

Port1 and port2 are the only ports configured with the same native VLAN 10.

What are two reasons that can trigger port1 to shut down? (Choose two.)

Options:

A.

port1 was shut down by loop guard protection.

B.

STP triggered a loop and applied loop guard protection on port1.

C.

An endpoint sent a BPDU on port1 that it received from another interface.

D.

Loop guard frame sourced from port 1 was received on port 1.

Buy Now
Questions 26

(Full question statement start from here)

A FortiGate is connected to a pair of FortiSwitch devices.

For redundancy, FortiGate must use uplinks on both switches simultaneouslywithout depending on Spanning Tree Protocol (STP).

Which configuration is required? (Choose one answer)

Options:

A.

Multi-tier topology

B.

Multichassis link aggregation group (MCLAG)

C.

Full mesh high availability (HA)

D.

Link aggregation group (LAG)

Buy Now
Questions 27

What happens when a routed VLAN interface (RVI) is configured on a FortiSwitch port or trunk? (Choose one answer)

Options:

A.

VLAN 1 is automatically assigned for management.

B.

The port becomes a layer 3 interface with VLAN 4095 assigned automatically.1

C.

All VLANs on the port are terminated in a trunk by default.

D.

The port becomes a layer 3 interface and assigned to VLAN 1.

Buy Now
Questions 28

Which statement about the IGMP snooping querier when enabled on a VLAN is true?

Options:

A.

Active multicast receiver entries are aging on each IGMP query sent on the VLAN

B.

IGMP reports on the VLAN are forwarded to all switch ports.

C.

The setting can only be enabled using the FortiSwitch CLI.

D.

All other indirectly connected switches will be unable to get IGMP multicast traffic.

Buy Now
Questions 29

Which statement about using MAC, IP, and protocol-based VLANs on FortiSwitch is true?

Options:

A.

lt is a scalable and secure solution in comparison to other Layer 2 security measures.

B.

FortiSwitch uses only the Ethernet type to assign traffic to VLANs.

C.

It provides benefits that can be obtained when using 802.1X authentication.

D.

Endpoints are required to use the same FortiSwitch port to remain members of the VLAN.

Buy Now
Questions 30

Which is a requirement to enable SNMP v2c on a managed FortiSwitch?

Options:

A.

Create an SNMP user to use for authentication and encryption.

B.

Specify an SNMP host to send traps to.

C.

Enable an SNMP v3 to handle traps messages with SNMP hosts.

D.

Configure SNMP agent and communities.

Buy Now
Questions 31

Which statement about 802.1X security profiles using MAC-based authentication mode is true?

Options:

A.

FortiSwitch allows connectivity to all hosts connected to a port, if one host is authenticated.

B.

FortiSwitch can grant each device a different access level based on the credentials provided

C.

FortiSwitch performs faster when using this security mode on the ports.

D.

FortiSwitch must communicate with the RADIUS server to authenticate devices

Buy Now
Questions 32

Which two rules used by MSTP are similar to rules used by other STP methods? (Choose two.)

Options:

A.

MSTP uses port role election, similar to rapid STP on the instances.

B.

MSTP uses alternate path and primary path, similar to regular STP.

C.

MSTP uses root bridge selection, similar to rapid STP

D.

MSTP uses timers for transitioning the ports, similar to regular STP.

Buy Now
Questions 33

What are two reasons why time synchronization between FortiGate and its managed FortiSwitch is critical in switch management? (Choose two.)

Options:

A.

FortiSwitch does not retain its time after a reboot, which gets reset after each reboot.

B.

FortiSwitch will not be able to become an NTP server for downstream devices.

C.

FortiSwitch cannot complete the DTLS handshake used in the CAPWAP tunnel.

D.

FortiSwitch will not allow other FortiSwitch devices in the chain be discovered by FortiGate.

Buy Now
Questions 34

Refer to the exhibits.

NSE5_FSW_AD-7.6 Question 34

Three FortiSwitch devices in standalone mode are interconnected. The CLI command diagnose stp instance list is executed on Core-2. Based on the output shown in the exhibit, what can you conclude about Core-2? (Choose one answer)

Options:

A.

Core-2 has received Bridge Protocol Data Unit (BPDU) from the root bridge.

B.

Core-2 is the designated bridge for all VLANs.

C.

Core-2 is blocking all ports in the Spanning Tree Protocol (STP) topology.

D.

Core-2 provides an alternate path to the root bridge.

Buy Now
Exam Code: NSE5_FSW_AD-7.6
Exam Name: Fortinet NSE 5 - FortiSwitch 7.6 Administrator
Last Update: Sep 29, 2026
Questions: 114

PDF + Testing Engine

$64.99   $185.69

Testing Engine

$49.99   $142.83

PDF (Q&A)

$54.99   $157.11