Fortinet NSE5_FSW_AD-7.6問題集で必ず試験合格させる [Q68-Q86]

Share

Fortinet NSE5_FSW_AD-7.6問題集で必ず試験合格させる

NSE5_FSW_AD-7.6試験問題(更新されたのは2026年)100%リアル問題解答


Fortinet NSE5_FSW_AD-7.6 認定試験の出題範囲:

トピック出題範囲
トピック 1
  • レイヤ2の制御とセキュリティ:このセクションでは、スイッチドネットワークを保護するためのポートセキュリティ、フィルタリング、なりすまし対策、ACL、セキュリティプロファイル、VLANセキュリティメカニズムなどのレイヤ2セキュリティ機能に焦点を当てます。
トピック 2
  • 監視とトラブルシューティング:この分野では、パケットキャプチャ方法、FortiLinkのトラブルシューティング、およびトラフィックの監視とネットワーク問題の解決に使用される診断ツールについて説明します。
トピック 3
  • 導入と管理:この領域では、マルチテナント環境を含む、サポートされているトポロジーにおけるFortiSwitchのプロビジョニングと導入について説明します。適切な設定、拡張性、および集中管理を重視します。
トピック 4
  • FortiSwitchの概念:このドメインでは、VLAN構成、QoS、LLDP-MED、スタッキング、スイッチングとルーティング、ループ防止のためのSTP、ポートとトランシーバーの構成など、FortiSwitchのコア機能を扱います。基本的なスイッチング操作とネットワーク統合に重点を置いています。

 

質問 # 68
Refer to the diagnostic output:

Two entries in the exhibit show that the same MAC address has been used in two different VLANs. Which MAC address is shown in the above output?

  • A. It is a MAC address of FortiLink interface on FortiGate.
  • B. It is a MAC address of a switch that accepts multiple VLANs.
  • C. It is a MAC address of an upstream FortiSwitch.
  • D. It is a MAC address of FortiGate in HA configuration.

正解:B

解説:
The MAC address "00:50:56:96:e3:fc" appearing in two different VLANs (4089 and 4094) in the diagnostic output indicates it is a MAC address associated with a device that supports traffic from multiple VLANs.
Such a behavior is typical of network infrastructure devices like switches or routers, which are configured to allow traffic from various VLANs to pass through a single physical or logical interface. This is essential in network designs that utilize VLANs to segregate network traffic for different departments or use cases while using the same physical infrastructure.
References:
For more detailed information on MAC table diagnostics and VLAN configurations in FortiGate devices, refer to the official Fortinet documentation:Fortinet Product Documentation.


質問 # 69
You are configuring VLANs on a FortiSwitch device managed by FortiGate. Which two statements accurately describe VLAN assignment requirements and behavior on FortiSwitch ports? (Choose two answers)

  • A. You can assign only one native VLAN on a port.
  • B. Untagged VLAN applies to egress traffic only.
  • C. Untagged defines the list of VLANs that are allowed on the port for both ingress and egress traffic.
  • D. VLAN assignments must be configured directly on the FortiSwitch.

正解:A、B

解説:
According to theFortiSwitchOS 7.6 Administration Guideand theFortiSwitch 7.6 Study Guide, understanding how VLANs are processed on a switch port is fundamental to network segmentation. A FortiSwitch port behaves differently depending on whether traffic is entering (ingress) or leaving (egress) the interface.
First,you can assign only one native VLAN on a port (Option C). The Native VLAN (often called the PVID or Port VLAN ID) is the default internal ID assigned to any untagged frames arriving at the port. In a managed environment, this is typically set via the FortiGate's switch controller. By design, a single physical interface can only belong to one primary broadcast domain for untagged ingress traffic to ensure there is no ambiguity in the switch's internal forwarding logic.
Second, theuntagged VLAN setting applies to egress traffic only (Option B). While the "Allowed VLANs" list defines which tagged traffic can pass through the port, the "Untagged VLANs" list specifies which of those VLAN tags should beremovedby the switch before the frame is transmitted out of the physical port.
This is crucial for connecting devices that do not support 802.1Q tagging, such as standard PCs or printers.
Regarding the incorrect options:Option Ais incorrect because the "Untagged" list does not define ingress rules; ingress is governed by the Native VLAN for untagged packets and the Allowed list for tagged packets.
Option Dis incorrect because, in a managed FortiLink environment, all VLAN assignments should be performed through theFortiGate's Switch Controllerto ensure centralized management and consistency.


質問 # 70
Refer to the configuration:
Which two conditions does FortiSwitch need to meet to successfully configure the options shown in the exhibit above? (Choose two.)

  • A. The split port can be assigned to a native VLAN.
  • B. The FortiSwitch model is equipped with a maximum of 54 interfaces
  • C. The Dort full speed prior to the split was 100G QSFP+.
  • D. FortiSwitch would need to be rebooted.

正解:B、D


質問 # 71
In which two ways can you assign a FortiSwitch port to a VDOM using a multi-tenancy setup? (Choose two answers)

  • A. Create a virtual port pool on the FortiGate CLI.
  • B. Assign a port to a VDOM directly on the managed FortiSwitch.
  • C. Switch the FortiLink interface to the target VDOM.
  • D. Assign the switch port to a VLAN on FortiGate and perform VDOM mapping.

正解:A、D

解説:
According to theFortiOS 7.6 Administration Guideand theFortiSwitch 7.6 Study Guide, multi-tenancy in a FortiLink-managed environment allows a central FortiGate to partition a managed FortiSwitch fabric so that different ports can belong to different Virtual Domains (VDOMs). This is essential for Managed Service Providers (MSPs) who need to isolate client traffic at the hardware layer.
The documentation identifies two primary methods for achieving this assignment:
* Assign to a VLAN and Perform VDOM Mapping (Option A):This is the most common method. The administrator creates a VLAN on the FortiLink interface and assigns it to a specific VDOM on the FortiGate. By assigning a physical FortiSwitch port to that specific VLAN, the port's traffic is logically terminated within the target VDOM. TheVDOM mappingensures that the switch-controller identifies which VDOM "owns" the traffic originating from that specific port/VLAN combination.
* Create a Virtual Port Pool (Option B):For more advanced multi-tenancy, administrators can use the FortiGate CLI to create aVirtual Port Pool. This feature allows the FortiGate to "pool" physical switch ports and present them as logical resources that can be distributed across various VDOMs. This method provides greater flexibility in resource allocation without requiring the entire FortiLink interface to be moved.
Regarding the incorrect options:Option Cis incorrect because in a managed environment, the FortiSwitch CLI is not used for VDOM assignments; all orchestration must happen from the FortiGate.Option Dis incorrect because while you can move a FortiLink interface to a VDOM, this would move theentireswitch management and all its ports to that VDOM, which does not support a multi-tenant setup where different ports need to reside in different VDOMs.


質問 # 72
(Full question statement start from here)
Refer to the exhibits.

Three FortiSwitch devices were recently configured to be managed by FortiGate. Two are managed successfully, butFortiSwitch Access-1is not.
Based on the configuration output, whichinitial changeis required for FortiSwitch Access-1 to be managed?
(Choose one answer)

  • A. Assign a static IP on FortiSwitch Access-1.
  • B. Set Access-1 internal interface mode to DHCP.
  • C. Change the NTP server.
  • D. Change its Control and Provisioning of Wireless Access Points (CAPWAP) settings.

正解:B

解説:
In a FortiGate-managed switching deployment usingFortiLink, FortiSwitch devices rely on theirinternal interfaceto establish management connectivity with the FortiGate. According to the FortiSwitchOS 7.6 Administrator Guide, when a FortiSwitch operates in FortiLink mode, theinternal interface must obtain an IP address dynamically via DHCPfrom the FortiGate over the FortiLink interface. This IP address is required for control-plane communication, including CAPWAP-based management messaging.
From the exhibit, FortiGate successfully managesCore-1andCore-2, whileAccess-1remains offline. The FortiGate diagnostic output explicitly reports that itcannot detect Access-1 at the FortiLink interface, even though CAPWAP is enabled and the switch is in FortiLink mode. This eliminates CAPWAP configuration (Option B) as the root cause.
Examining the FortiSwitch Access-1 CLI output reveals the key issue:
* Theinternal interfaceis configured withmode: staticand an IP address of0.0.0.0.
This configuration prevents Access-1 from obtaining a valid FortiLink management IP address, which is mandatory for FortiGate discovery and authorization. In contrast, FortiSwitch devices managed by FortiGate must have their internal interface set toDHCP, allowing the FortiGate to automatically assign an address from the FortiLink subnet.
Assigning a static IP (Option A) is not recommended or required in FortiLink-managed mode, NTP configuration (Option D) has no impact on discovery, and CAPWAP is already enabled as shown in the FortiGate output.
Therefore, theinitial and required corrective actionis toset the Access-1 internal interface mode to DHCP
, makingOption Cthe correct and fully verified answer based on FortiOS 7.6 and FortiSwitchOS 7.6 documentation.


質問 # 73
Which feature should you enable to reduce the number or unwanted IGMP reports processed by the IGMP querier?

  • A. Enable IGMP flood unknown multicast traffic on the global setting.
  • B. Enable the IGMP flood setting on the static port for all multicast groups.
  • C. Enable the IGMP flood reports setting on the mRouter port.
  • D. Enable IGMP snooping proxy.

正解:D

解説:
Enable IGMP snooping proxy (C): To reduce the number of unwanted IGMP reports processed by the IGMP querier, enabling IGMP snooping proxy is effective. This feature acts as an intermediary between multicast routers and hosts, optimizing the management of IGMP messages by handling report messages locally and reducing unnecessary IGMP traffic across the network. This minimizes the processing load on the IGMP querier and improves overall network efficiency.


質問 # 74
Refer to the exhibit.

The profile shown in the exhibit is assigned to a group of managed FortiSwitch ports, and these ports are connected to endpoints which are powered by PoE.
Which configuration action can you perform on the LLDP profile to cause these endpoints to exchange PoE information and negotiate power with the managed FortiSwitch?

  • A. Create new a LLDP-MED application type to define the PoE parameters.
  • B. Define an LLDP-MED location ID to use standard protocols for power.
  • C. Assign a new LLDP profile to handle different LLDP-MED TLVs.
  • D. Add power management as part of LLDP-MED TLVs to advertise.

正解:D

解説:
To cause endpoints to exchange PoE information and negotiate power with the managed FortiSwitch via LLDP, you should configure the LLDP profile to include power management in the advertised LLDP-MED TLVs. Here are the steps:
* Access the LLDP Profile Configuration:Start by entering the LLDP profile configuration mode with the command:
config switch-controller lldp-profile
edit "LLDP-PROFILE"
* Enable MED-TLVs:Ensure that MED-TLVs (Media Endpoint Discovery TLVs) are enabled. These TLVs are used for extended discovery relating to network policies, including PoE, and are essential for PoE negotiation. They include power management which is crucial for the negotiation of PoE parameters between devices. The command to ensure network policies are set might look like:
set med-tlvs network-policy
* Add Power Management TLV:Specifically add or ensure the power management TLV is part of the configuration. This will advertise the PoE capabilities and requirements, enabling dynamic power allocation between the FortiSwitch and the connected devices (like VoIP phones or wireless access points). This can typically be done within the network-policy settings:
config med-network-policy
edit <policy_index>
set poe-capability
next
end
* Save and Apply Changes:Exit the configuration blocks properly ensuring changes are saved:
End
* Verify Configuration:It's always good practice to verify that your configurations have been applied correctly. Use the appropriateshoworgetcommands to review the LLDP profile settings.
By adding the power management as part of LLDP-MED TLVs, the FortiSwitch will be able to communicate its power requirements and capabilities to the endpoints, thereby facilitating a dynamic power negotiation that is crucial for efficient PoE utilization.
References:For more detailed information and additional configurations, you can refer to the FortiSwitch Managed Switches documentation available on Fortinet's official documentation site:Fortinet Product Documentation


質問 # 75
(Full question statement start from here)
Refer to the exhibit.



Which information does FortiGate use to generate the port details in the FortiSwitch Faceplates view?
(Choose one answer)

  • A. The LLDP advertisements received from the FortiSwitch
  • B. The Cisco Discovery Protocol (CDP) advertisements from FortiSwitch
  • C. The FortiSwitch model
  • D. The FortiLink discovery frames sent by FortiSwitch

正解:A

解説:
In a FortiLink-managed switching architecture, the FortiGate firewall acts as the centralized controller for downstream FortiSwitch devices. TheFortiSwitch Faceplatesview in the FortiGate GUI provides a physical- style representation of switch ports, including port numbers, operational status, link state, speed, duplex, and connected neighbor information. According to FortiOS 7.6 and FortiSwitchOS 7.6 documentation from Fortinet, this port-level intelligence is derived fromLink Layer Discovery Protocol (LLDP)advertisements received from the FortiSwitch.
LLDP is an IEEE 802.1AB standard protocol used for vendor-neutral Layer 2 neighbor discovery.
FortiSwitch periodically sends LLDP frames that include detailed port descriptors such as chassis ID, port ID, port description, system name, system capabilities, and VLAN-related attributes. When FortiGate receives these LLDP advertisements over the FortiLink interface, it correlates the information with the managed FortiSwitch inventory and renders accurate port details in the Faceplates view.
Other options are incorrect for the following reasons. The FortiSwitch model alone is insufficient to populate per-port operational details. Cisco Discovery Protocol (CDP) is a Cisco-proprietary protocol and is not used by FortiGate for Faceplates visualization. FortiLink discovery frames are used to establish and maintain the FortiLink management relationship, but they do not carry the granular per-port metadata required for the Faceplates display.
Therefore, the Faceplates view relies specifically onLLDP advertisements received from the FortiSwitch, making optionCthe correct and fully verified answer based on FortiOS 7.6 and FortiSwitchOS 7.6 behavior.


質問 # 76
Your team is deploying a single FortiGate and a single FortiSwitch across 100 branch offices. The goal is to expedite deployment while avoiding manual configuration errors. Which method would allow you to achieve this goal most efficiently? (Choose one answer)

  • A. Ensure that devices engage FortiSwitch Manager to retrieve their configurations.
  • B. Use the cloud Model-as-a-Service (MaaS) to push the configuration of both FortiGate and FortiSwitch.
  • C. Use zero-touch provisioning (ZTP) through FortiManager.
  • D. Push FortiGate and FortiSwitch configurations through FortiEdge Cloud.

正解:C

解説:
According to theFortiOS 7.6 Administration Guideand theFortiManager 7.6 Study Guide, the most efficient and scalable method for deploying standardized configurations across a high volume of sites (such as
100 branch offices) isZero-Touch Provisioning (ZTP) through FortiManager.
ZTP allows administrators to createModel DevicesandProvisioning Templateswithin FortiManager before the physical hardware is even unboxed. When a factory-reset FortiGate at a branch office is connected to the internet, it automatically reaches out toFortiCloud(FortiDeploy) to discover its assigned management entity.
Once redirected to the centralFortiManager, the FortiGate retrieves its full configuration, including the FortiLinksettings required to manage the local FortiSwitch.
The 7.6 documentation highlights that because the FortiSwitch is managed via FortiLink, its configuration is technically part of the FortiGate's managed objects. Therefore, by using FortiManager to push a single template that includes both the FortiGate settings and theSwitch Controllerconfigurations, the team can ensure that every branch office is configured identically and without manual CLI intervention. This method significantly reduces the risk of human error and ensures rapid, consistent deployment across the entire fabric.
Options A and B refer to cloud management platforms that are effective but do not offer the same level of integrated, template-driven orchestration for large-scale enterprise ZTP as FortiManager. Option D is incorrect as "FortiSwitch Manager" is not the primary orchestration tool for branch-wide ZTP in a FortiLink- integrated environment.


質問 # 77
On supported FortiSwitch models, which access control list (ACL) stage is recommended for applying actions before the switch performs any layer 2 or layer 3 processing? (Choose one answer)

  • A. Prelookup
  • B. Ingress
  • C. Egress
  • D. Forwarding

正解:A

解説:
According to theFortiSwitchOS 7.6 Administration Guideand theNSE 5 FortiSwitch 7.6 Administrator Study Guide, FortiSwitch supports a multi-stage ACL pipeline that allows for granular traffic control at different points in a packet's journey through the switch.1The documentation identifies three primary stages for ACL application:Prelookup,Ingress, andEgress.
* Prelookup (Option D):This is the earliest stage in the switching pipeline. The documentation explicitly states thatPrelookup ACLsare processedbefore any Layer 2 or Layer 3 lookupsare performed by the switch hardware. This stage is highly recommended for high-performance security actions, such as dropping unwanted traffic immediately upon arrival, because it prevents the switch from wasting internal resources (CPU and ASIC lookup cycles) on frames that are destined to be discarded anyway.
* Ingress (Option A):This stage occursafterthe switch has completed its Layer 2 (MAC table) and Layer
3 (routing table) lookups butbeforethe packet is queued for the egress port. While powerful, actions here occur after initial processing has already taken place.
* Egress (Option C):This stage is processed just before the frame leaves the switch through the destination port. It is typically used for final modifications or filtering based on the outgoing interface context.
Therefore, to achieve the goal of applying actionsbeforeany Layer 2 or Layer 3 processing occurs, the Prelookupstage is the technically correct and recommended choice in FortiSwitchOS 7.6.Forwarding (Option B)is a general functional stage of a switch but is not a specific ACL stage type in the FortiSwitch configuration hierarchy.


質問 # 78
(Full question statement start from here)
You are deploying a FortiSwitch virtual stack in a network that contains Cisco devices. You want the Cisco devices toautomatically discover the FortiSwitch devices and exchange device information. Which two protocols must be enabled on the FortiSwitch devices to achieve this? (Choose two answers)

  • A. Cisco Discovery Protocol
  • B. Unidirectional Link Detection
  • C. LLDP - Media Endpoint Discovery
  • D. Link Layer Discovery Protocol

正解:A、D

解説:
In mixed-vendor network environments, such as deployments that include bothFortiSwitchandCiscodevices, properLayer 2 discovery protocolsmust be enabled to allow devices to automatically discover neighbors and exchange essential device and interface information. FortiSwitchOS 7.6 supports bothCisco Discovery Protocol (CDP)andLink Layer Discovery Protocol (LLDP)to ensure interoperability.
Cisco Discovery Protocol (CDP)is a Cisco-proprietary Layer 2 discovery protocol widely used by Cisco switches, routers, and IP phones. When CDP is enabled on FortiSwitch interfaces, Cisco devices can discover FortiSwitch neighbors and receive information such as device ID, port ID, platform, and capabilities. This is particularly important in Cisco-centric networks where CDP is the primary discovery mechanism.
Link Layer Discovery Protocol (LLDP), defined by IEEE 802.1AB, is a vendor-neutral discovery protocol supported by both Fortinet and Cisco devices. Enabling LLDP allows FortiSwitch and Cisco devices to exchange standardized information including system name, port description, VLAN information, and management address. LLDP is essential for cross-vendor compatibility and is commonly enabled by default in modern enterprise networks.
The remaining options are incorrect.Unidirectional Link Detection (UDLD)is used to detect unidirectional fiber or copper link failures and does not provide device discovery or information exchange.LLDP-MEDis an extension of LLDP specifically designed for media endpoints such as IP phones and is not required for general switch-to-switch discovery.
Therefore, to ensure automatic discovery and information exchange between FortiSwitch and Cisco devices, both CDP and LLDP must be enabled, makingOptions B and Cthe correct and fully verified answers based on FortiSwitchOS 7.6 documentation.


質問 # 79
Which drop policy mode, if assigned to a congested port, will drop incoming packets until there is no congestion on the egress port?

  • A. Tail-drop mode
  • B. Strict mode
  • C. Weighted round robin mode.
  • D. Random early detection mode

正解:A

解説:
Tail-drop mode is a congestion management technique used in network devices, including FortiSwitches, to handle congestion on network ports:
* Tail-Drop Mode (A):
* Behavior:When a queue reaches its maximum capacity on a congested port, tail-drop mode simply drops any incoming packets that arrive after the buffer is full. This continues until the congestion is alleviated and there is space in the queue to accommodate new packets.
* Application:This is a straightforward approach used when the device's buffer allocated to the port becomes full due to sustained high traffic, preventing buffer overflow and maintaining system stability.
References:For more details on congestion management techniques and settings on FortiSwitch, you can refer to the configuration manuals available on:Fortinet Product Documentation


質問 # 80
Which is a requirement to enable SNMP v2c on a managed FortiSwitch?

  • A. Create an SNMP user to use for authentication and encryption.
  • B. Enable an SNMP v3 to handle traps messages with SNMP hosts.
  • C. Specify an SNMP host to send traps to.
  • D. Configure SNMP agent and communities.

正解:D

解説:
To enable SNMP v2c on a managed FortiSwitch, the essential requirement involves configuring the SNMP agent and community strings:
* Configure SNMP Agent and Communities (D):
* SNMP Agent:Activating the SNMP agent on FortiSwitch allows it to respond to SNMP requests.
* Community Strings:SNMP v2c uses community strings for authentication. These strings function as passwords to grant read-only or read-write access to the SNMP data.
* Understanding Other Options:
* Create an SNMP user (A)is necessary for SNMP v3, not v2c, as it involves user-based authentication and encryption.
* Specify an SNMP host (B)is typically a part of SNMP configuration but not a requirement just to enable SNMP.
* Enable SNMP v3 (C)is not related to enabling SNMP v2c.
References:For detailed instructions on configuring SNMP on FortiSwitch, you can refer to the SNMP configuration section in the FortiSwitch administration guide available on:Fortinet Product Documentation


質問 # 81
Exhibit.
You need to manage three FortiSwitch devices using a FortiGate device. Two of the FortiSwitch devices initiated a reboot after the authorization process. However, the FortiSwitch device with the configuration shown in the exhibit. did not reboot All three devices completed FortiLink manage-ment authorization successfully.
Why did the FortiSwitch device shown in the exhibit not reboot to complete the authorization pro-cess?
The management mode was set to use FortiLink mode.

  • A. Switch auto-discovery is enabled.
  • B. The system time is not in-sync and is using a non-default value
  • C. The management mode was set to use FortiLink mode.
  • D. The FortiSwitch device is scheduled to reboot as part the authorization process

正解:C

解説:
Regarding the scenario where a FortiSwitch did not reboot after the authorization process while the other devices did, the most likely cause, given the configuration settings in the exhibit, is:
* The management mode was set to use FortiLink mode (Option B): If the FortiSwitch was already configured to use FortiLink for its management mode, it may not require a reboot to complete the authorization process as its management interface settings are already aligned with FortiLink requirements. This is unlike switches that might be transitioning from a standalone or another management mode, which would typically require a reboot to apply new management settings fully.
References:
FortiLink mode specifically tailors FortiSwitch to be managed via a FortiGate device, integrating its operation into the wider security fabric without needing a reboot if it is already set to this mode before authorization.
This contrasts with other management modes where transitioning to FortiLink could necessitate a system restart to initialize the new configuration.


質問 # 82
You are deploying a new FortiSwitch device in a branch office and you want it to be automatically detected and managed by FortiGate. Which FortiSwitch feature enables automatic detection during deployment?
(Choose one answer)

  • A. Zero-touch deployment
  • B. Link Layer Discovery Protocol (LLDP)
  • C. FortiLink heartbeat
  • D. Auto-discovery

正解:B

解説:
According to theFortiOS 7.6 Study Guideand theFortiSwitch 7.6 FortiLink Guide, the automatic discovery and subsequent management of a FortiSwitch by a FortiGate controller is primarily facilitated by theLink Layer Discovery Protocol (LLDP). LLDP is an industry-standard, layer-2 protocol that allows network devices to advertise their identities and capabilities to neighbors on the same physical link.
When a factory-default FortiSwitch is connected to a FortiGate port (specifically one configured as a FortiLink interface), the switch automatically sends outLLDP advertisements. These advertisements include specificOrganizationally Specific TLVs (Type-Length-Values)that identify the device as a FortiSwitch and provide its management MAC address and current state. The FortiGate "listens" for these LLDP frames; once it receives a frame from a compatible FortiSwitch, it automatically lists the switch in theManaged FortiSwitchinventory as a "discovered" device awaiting authorization.
WhileZero-touch deployment (Option A)describes the overall goal of deploying a switch without manual CLI configuration, it is the underlyingLLDPprotocol that provides the technical mechanism for the initial detection. Once the switch is discovered via LLDP and authorized, the FortiGate uses a DHCP server on the FortiLink interface to assign an IP address to the switch and establishes a secureCAPWAP(Control and Provisioning of Wireless Access Points) tunnel for management. TheFortiLink heartbeat (Option D)is a secondary mechanism usedafterthe connection is established to monitor the health and status of the link, rather than for the initial detection of the device.


質問 # 83
Which two statements about 802.1X authentication on FortiSwitch ports are true? (Choose two.)

  • A. All devices connecting to FortiSwitch must support 802.1X authentication.
  • B. A security policy is used to apply 802.1 authentication on a port.
  • C. A local user database must be used to authenticate devices using the 802.1X authentication protocol.
  • D. All hosts behind an authenticated port are allowed access after a successful authentication.

正解:A、D

解説:
* All hosts behind an authenticated port are allowed access after a successful authentication (A): Once a device on a port successfully authenticates using 802.1X, all other devices connected behind that port also gain network access. This is typical in scenarios where a switch is behind an authenticated port and not each device individually authenticates.
* All devices connecting to FortiSwitch must support 802.1X authentication (D): For a network secured with 802.1X, all devices attempting to connect through the FortiSwitch must support and participate in
802.1X authentication to gain access. This ensures that all devices on the network are authenticated before they are allowed to communicate on the network.


質問 # 84
Refer to the exhibit.

Two routes in the routing monitor are marked as available but are not installed in the forwarding information base (FIB). Which statement correctly explains why the routes have this status? (Choose one answer)

  • A. They are unavailable due to invalid next-hop addresses.
  • B. They are excluded from the FIB because a more preferred route exists for the same destination.
  • C. They are not included in the FIB due to route-policy filtering.
  • D. They are installed in the FIB but cannot be offloaded to hardware.

正解:B

解説:
According to theFortiSwitchOS 7.6 Administration Guideand theFortiSwitch 7.6 Study Guide, the Routing Monitor provides a comprehensive view of the Routing Information Base (RIB), which includes all routes learned via static configuration or dynamic protocols (OSPF, BGP, etc.). However, not every route present in the RIB is active for traffic forwarding. The switch must select the "best" path for any given destination to be installed into theForwarding Information Base (FIB).
The provided exhibit shows a routing table with multiple sources for the same destination. Specifically, there is aStaticdefault route ($0.0.0.0/0$) with an administrative distance of 220, and anOSPFdefault route ($0.0.0.0/0$) with an administrative distance of 110. In FortiSwitchOS routing logic, when multiple routes to the exact same destination exist, the system compares theirAdministrative Distance (AD). The route with the lowest AD is considered the most "preferred" or "trustworthy".
In this case, the OSPF route ($AD 110$) is more preferred than the Static route ($AD 220$). Consequently, the OSPF route is marked with a green checkmark in theFIBcolumn, while the Static route-despite being
"Available" in the RIB-is excluded from the FIB. The same logic applies to the $10.0.100.0/30$ subnet, where theConnectedroute is preferred over the OSPF learned route for the same destination. Therefore, the status reflects standard route selection behavior where less-preferred routes remain in the RIB as backups but are not used for active forwarding.


質問 # 85
What does the switchauto-networksetting control on FortiSwitch? (Choose one answer)

  • A. The automatic discovery of the FortiGate->FortiLink interface
  • B. The root bridge priority for Multiple Spanning Tree Protocol (MSTP)
  • C. Whether the FortiSwitch can be managed by FortiManager
  • D. The automatic VLAN assignment based on connected devices

正解:A

解説:
According to theFortiSwitchOS 7.6 Administration Guideand theFortiSwitch 7.6 Study Guide, the auto- network setting (configured via config switch auto-network) is a global feature introduced to simplify the initial deployment of switches. Starting inFortiSwitchOS 7.2.0and continuing through7.6, this feature is enabled by defaulton all new and factory-reset units.1 The primary function of theauto-networksetting is to facilitate theautomatic discovery of the FortiGate and the establishment of the FortiLink interface (Option B). When enabled, the switch automatically scans its physical ports to detect a management entity, such as a FortiGate controller. This "zero-touch" discovery mechanism allows the switch to identify the correct uplink ports and automatically configure them as members of theFortiLinkfabric without manual CLI or GUI intervention.
Furthermore, the documentation notes that auto-network also managesauto-topology, which allows two switches to automatically form anInter-Switch Link (ISL)trunk between them.2This includes setting the management VLAN (typically VLAN 4094) and ensuring that DHCP snooping is trusted on these discovered links.3If an administrator intends to use the switch in a strictly standalone mode without any auto-discovery or FortiLink features, the documentation specifies that they must manually disable the auto-network status and the auto-fortilink-discovery global settings to prevent the switch from attempting to join a managed fabric.
4
Regarding other options:Option Arefers to Dynamic Port Policy or NAC features.Option Cis a standard STP configuration unrelated to the auto-network discovery suite.Option Dis a broader management capability that depends on successful network discovery but is not the specific control point for the auto-network setting.


質問 # 86
......

合格させるFortinet NSE5_FSW_AD-7.6試験最速合格にはFast2test:https://jp.fast2test.com/NSE5_FSW_AD-7.6-premium-file.html

準備NSE5_FSW_AD-7.6問題解答でNSE5_FSW_AD-7.6試験問題集:https://drive.google.com/open?id=1WD1jJISmt7Qe4ZoHtNOh5VwfOHI92_zI


弊社を連絡する

我々は12時間以内ですべてのお問い合わせを答えます。

我々の働いている時間: ( GMT 0:00-15:00 )
月曜日から土曜日まで

サポート: 現在連絡 

English Deutsch 繁体中文 한국어