NSE5_FSW_AD-7.6 Sample Questions

NSE5_FSW_AD-7.6 Sample Questions & Answers

VLAN, QoS, and stack-port configuration on FortiSwitch carries the most weight, alongside provisioning for multi-tenant deployments, port security, filtering, and ACLs, and monitoring or troubleshooting FortiLink with packet captures.

Launch the full NSE5_FSW_AD-7.6 simulator →

Showing 6 of 12 free samples.

  1. Question 1Intermediate

    Monitoring and Troubleshooting · Troubleshoot FortiLink issues

    While troubleshooting a FortiLink connection between a FortiGate and a newly deployed FortiSwitch, the administrator notices the switch is not appearing in the Managed FortiSwitches list. The physical link is up, and LLDP shows the devices are neighbors.

    What is the most likely reason the FortiSwitch is not yet managed, assuming NTP and global settings are correct?

    Show answer & explanation

    Correct answer: C

    By default, a FortiSwitch connected to a FortiLink interface must be authorized on the FortiGate before it becomes managed. It will appear in the 'Unmanaged' or 'Unauthorized' section until the administrator explicitly authorizes it, unless 'Auto-authorize' is enabled.

  2. Question 2Intermediate

    FortiSwitch Concepts · Configure STP to prevent network loops

    A FortiSwitch administrator needs to configure Multiple Spanning Tree Protocol (MSTP) to load balance traffic across redundant links. They want VLANs 10 and 20 to use one path, and VLANs 30 and 40 to use another.

    Which configuration step is critical to achieving this load balancing behavior?

    Show answer & explanation

    Correct answer: A

    MSTP allows load balancing by mapping different VLANs to different MST instances (MSTIs). By configuring different root bridges or path costs for Instance 1 versus Instance 2, traffic for the associated VLANs will take different paths.

  3. Question 3Beginner

    Layer 2 Control and Security · Use filtering and antispoofing techniques on FortiSwitch

    A company requires strict security on their access layer switches. They want to prevent 'Man-in-the-Middle' attacks where a malicious user spoofs the gateway's IP address. The administrator plans to implement Dynamic ARP Inspection (DAI).

    Which prerequisite feature MUST be enabled and functioning correctly for DAI to validate ARP packets on untrusted ports?

    Show answer & explanation

    Correct answer: C

    DAI relies on the DHCP Snooping binding database to validate ARP packets. It checks if the MAC-IP mapping in the ARP packet matches the binding entry created when the device requested an IP via DHCP. Without DHCP Snooping, DAI has no reference database for validation.

  4. Question 4IntermediateSelect 2

    Layer 2 Control and Security · Use port security options on FortiSwitch

    Select TWO correct statements regarding the implementation of 802.1X authentication on FortiSwitch ports managed by a FortiGate. (Select TWO)

    Show answer & explanation

    Correct answers: C, D

    MAB is a common fallback mechanism. If a device (like a printer) does not support 802.1X or the handshake times out, the switch can attempt to authenticate the device using its MAC address.

    Dynamic VLAN assignment is a key feature where the RADIUS server returns standard attributes (Tunnel-Type, Tunnel-Medium-Type, Tunnel-Private-Group-ID) to assign the authenticated port to a specific VLAN.

  5. Question 5Intermediate

    Monitoring and Troubleshooting · Use packet capturing methods to monitor and troubleshoot traffic issues

    A network administrator needs to capture traffic from a specific port on Switch-A (Access Layer) but analyze it on a sniffer connected to Switch-C (Core Layer). Both switches are FortiSwitch devices managed by the same FortiGate.

    Which feature should be configured to accomplish this?

    Show answer & explanation

    Correct answer: C

    RSPAN (Remote SPAN) allows traffic mirroring from a source port on one switch to a destination port on a different switch by encapsulating the mirrored traffic in a special RSPAN VLAN that traverses the trunk links between switches.

  6. Question 6Intermediate

    Deployment and Management · Configure and provision FortiSwitch

    In a FortiSwitch deployment using FortiLink, an administrator wants to increase the bandwidth between a FortiSwitch 400 series and the FortiGate. The current connection is a single 10Gbps link. The administrator connects a second 10Gbps cable between the devices.

    What configuration is required on the FortiGate to utilize both links as a single logical aggregate interface?

    Show answer & explanation

    Correct answer: C

    To create a LAG (Link Aggregation Group) for FortiLink, the FortiLink interface on the FortiGate must be configured as an 802.3ad Aggregate interface, and the physical ports connecting to the switch must be added as members. FortiSwitch will automatically detect this via FortiLink auto-discovery (provided LLDP is functional) and form the LAG on its side.

Ready for the real thing?

The full NSE5_FSW_AD-7.6 simulator has every exam-style question, timed mode, and instant scoring.