Fortinet NSE 5 - FortiSwitch 7.6 Administrator
|
|
Title of test:
![]() Fortinet NSE 5 - FortiSwitch 7.6 Administrator Description: Fortinet NSE 5 - FortiSwitch 7.6 Administrator |



| New Comment |
|---|
NO RECORDS |
|
Which two statements about DHCP snooping enabled on a FortiSwitch VLAN are true? (Choose two.). Enabling DHCP snooping on a FortiSwitch VLAN ensures requests and replies are seen by all DHCP servers. switch-controller-dhcp-snooping-verify-mac verifies the destination MAC address to protect against. By default, all FortiSwitch ports are set to forward client DHCP requests to untrusted ports. switch-controller-dhcp-snooping-verify-mac verifies the destination MAC address to protect against. Which statement about the quarantine VLAN on FortiSwitch is true?. Quarantine VLAN has no DHCP server. Users who fail 802.1X authentication can be placed on the quarantine VLAN. It is only used for quarantined devices if global setting is set to quarantine by VLAN. FortiSwitch can block devices without configuring quarantine VLAN to be part of the allowed VLANs. (Full question statement start from here) Refer to the exhibits. You enable Dynamic Host Configuration Protocol (DHCP) snooping on the VLAN,Student. The Linux- Client VM sends DHCP requests, and tcpdump confirms the broadcasts. However, the Linux-Server VM, acting as a DHCP server, receives no DHCP traffic. What is the most likely cause of this intra- VLAN traffic being blocked? (Choose one answer). The DHCP requests are being sent on the wrong VLAN. Port1 is configured as an untrusted port. Port4 is not configured as a trusted port. The Student VLAN must be configured as an allowed VLAN on port1. Which is a requirement to enable SNMP v2c on a managed FortiSwitch?. Create an SNMP user to use for authentication and encryption. Specify an SNMP host to send traps to. Enable an SNMP v3 to handle traps messages with SNMP hosts. Configure SNMP agent and communities. Which two statements about managing a FortiSwitch stack on FortiGate are true? (Choose two.). A FortiLink interface must be enabled on FortiGate. The switch controller feature must be enabled on FortiGate. Only a hardware-based FortiGate can manage a FortiSwitch stack. FortiSwitch must be operating in standalone mode before authorization. Refer to the exhibits. An IP phone is connected to port1 of FortiSwitch Access-1. The IP phone tags its traffic with VLAN ID 20. On FortiGate, VLAN IP_Phone (VLAN ID 20) has been configured, and port1 of Access-1 is set with VLAN 20 as the native VLAN. However, the IP phone cannot reach the network. The exhibit shows the partial VLAN configuration and the port1 configuration on Access-1. Which configuration change must you make on FortiSwitch to allow ingress and egress traffic for the IP phone? (Choose one answer). On VLAN IP_Phone, enable vlanforward. On VLAN IP_Phone, enable l2forward. On port1, add VLAN 20 to the allowed_vlans list. On port1, disable the edge_port. Refer to the exhibit. The profile shown in the exhibit is assigned to a group of managed FortiSwitch ports, and these ports are connected to endpoints which are powered by PoE. Which configuration action can you perform on the LLDP profile to cause these endpoints to exchange PoE information and negotiate power with the managed FortiSwitch?. Create new a LLDP-MED application type to define the PoE parameters. Assign a new LLDP profile to handle different LLDP-MED TLVs. Define an LLDP-MED location ID to use standard protocols for power. Add power management as part of LLDP-MED TLVs to advertise. Which two are valid traffic processing actions that a FortiSwitch access control list (ACL) can apply to matching traffic? (Choose two answers). Redirect frames to another port. Assign traffic to a high-priority egress queue. Encrypt frames. Drop frames. Which statement about the IGMP snooping querier when enabled on a VLAN is true?. Active multicast receiver entries are aging on each IGMP query sent on the VLAN. IGMP reports on the VLAN are forwarded to all switch ports. The setting can only be enabled using the FortiSwitch CLI. All other indirectly connected switches will be unable to get IGMP multicast traffic. The security port policy is configured as shown in the exhibit. Which behavior occurs if a device connected to the port that does not support 802.1X? (Choose one answer). The device is blocked from accessing the network. The device is placed into the onboarding VLAN. The device is placed into the quarantine VLAN. The device is assigned to the default management VLAN. Which drop policy mode, if assigned to a congested port, will drop incoming packets until there is no congestion on the egress port?. Tail-drop mode. Weighted round robin mode. Random early detection mode. Strict mode. On supported FortiSwitch models, which access control list (ACL) stage is recommended for applying actions before the switch performs any layer 2 or layer 3 processing? (Choose one answer). Ingress. Forwarding. Egress. Prelookup. How does FortiSwitch determine the route for traffic traversing its interfaces? (Choose one answer. Hardware-based routing on FortiSwitch is handled by the CPU. ASIC hardware routing can handle only dynamic routing, if supported. FortiSwitch looks up the hardware routing table and then the forwarding information base (FIB. FortiSwitch forwards all traffic to FortiGate for routing decisions. Which statement about the use of the switch port analyzer (SPAN) packet capture method is true?. Mirrored traffic can be sent across multiple switches. SPAN can be configured only on a standalone FortiSwitch. Traffic on the management interface can be mirrored and captured by the monitoring device. The monitoring device must be connected to the same switch where the traffic is being mirrored. When Dynamic Host Configuration Protocol (DHCP) snooping is enabled on a FortiSwitch VLAN, which two statements are true? (Choose two answers). . DHCP replies are accepted only on trusted ports. DHCP snooping blocks all unicast traffic. Option 82 can be inserted into DHCP requests. DHCP requests are dropped if sent from trusted ports. PC1 connected to port1 has joined multicast group 225.1.2.3 on VLAN 10 with IGMP snooping enabled. What will happen if you disable IGMP snooping on FortiSwitch? (Choose one answer). PC1 will be removed from the multicast group 225.1.2.3. The FortiSwitch will stop processing IGMP report join messages. Multicast traffic for 225.1.2.3 will be flooded to all ports. Multicast traffic will stop until a multicast receiver is detected. Traffic arriving on port2 on FortiSwitch is tagged with VLAN ID 10 and destined for PC1 connected on port1. PC1 expects to receive traffic untagged from port1 on FortiSwitch. Which two configurations can you perform on FortiSwitch to ensure PC1 receives untagged traffic on port1? (Choose two.). Add the MAC address of PC1 as a member of VLAN 10. Add VLAN ID 10 as a member of the untagged VLANs on port1. Remove VLAN 10 from the allowed VLANs and add it to untagged VLANs on port1. Enable Private VLAN on VLAN 10 and add VLAN 20 as an isolated VLAN. Which two requirements must be met before FortiGate can manage a FortiSwitch stack? (Choose two answers). The latest FortiOS and FortiSwitchOS versions must be running. The switch controller feature must be enabled. All existing FortiLink interfaces must be disabled. The FortiSwitchOS version must be compatible with FortiOS. You are configuring VLANs on a FortiSwitch device managed by FortiGate. Which two statements accurately describe VLAN assignment requirements and behavior on FortiSwitch ports? (Choose two answers). Untagged defines the list of VLANs that are allowed on the port for both ingress and egress traffic. Untagged VLAN applies to egress traffic only. You can assign only one native VLAN on a port. VLAN assignments must be configured directly on the FortiSwitch. Which QoS mechanism maps packets with specific CoS or DSCP markings to an egress queue. Queuing for egress traffic. Classification for ingress traffic. . Rate limiting for egress traffic. Marking for ingress traffic. Exhibit. LAG and MCLAG are used to increase the available network bandwidth and enable redundancy. How does spanning tree protocol see MCLAG and LAG if they are configured based on the physi-cal view shown in the exhibit? (Choose two). Switch 1. Switch 2, and Switch 3 are seen as one MCLAG peer group. Switch 3 and Switch 4 uplinks are treated as single interfaces. Switch 3 and switch 4 are seen as one MCLAG switch client. Switch 1 and Switch 2 both seen as one single switch. Which two types of Layer 3 interfaces can participate in dynamic routing on FortiSwitch? (Choose two.). Detected management interfaces. Loopback interfaces. Switch virtual interfaces. Physical interfaces. Which Ethernet frame can create Layer 2 flooding due to all bytes on the destination MAC address being set to all FF?. The broadcast Ethernet frame. The unicast Ethernet frame. The multicast Ethernet frame. The anycast Ethernet frame. Refer to the configuration: Which two conditions does FortiSwitch need to meet to successfully configure the options shown in the exhibit above? (Choose two.). The FortiSwitch model is equipped with a maximum of 54 interfaces. FortiSwitch would need to be rebooted. The split port can be assigned to a native VLAN. . The Dort full speed prior to the split was 100G QSFP+. What feature can network administrators use to segment network operations and the administration of managed FortiSwitch devices on FortiGate?. FortiGate multi-tenancy. Multi-chassis link aggregation trunk. FortiGate clustering protocol. FortiLink split interface. You are designing a FortiSwitch backbone where every FortiSwitch device must connect to every other FortiSwitch for maximum redundancy. To maintain connectivity while preventing loops, which protocol or feature must you configure on the switches? (Choose one answer). Multichassis link aggregation group (MCLAG). Spanning Tree Protocol (STP). Full mesh high availability (HA). Link aggregation group (LAG). An administrator must deploy managed FortiSwitch devices in a remote location where multiple VLANs must be used to segment devices. No layer 3 switch or router is present at the site, and the only WAN connectivity is an ISP-provided router connected to the public internet. Which two components are required to enable VLAN segmentation across this remote site? (Choose two answers). FortiGate and FortiSwitch configured with VXLAN to tunnel VLANs over the WAN. A layer 3 router at the remote location to handle inter-VLAN routing. A FortiSwitch model that supports VXLAN hardware acceleration. FortiSwitch and FortiGate devices configured with IPsec interfaces. FortiGate with a layer 3 interface to terminate the VXLAN overlay. You are deploying a new FortiSwitch device in a branch office and you want it to be automatically detected and managed by FortiGate. Which FortiSwitch feature enables automatic detection during deployment? (Choose one answer). Zero-touch deployment. Auto-discovery. Link Layer Discovery Protocol (LLDP). FortiLink heartbeat. You have just authorized a new FortiSwitch on your FortiGate, and it appears online in the GUI. To verify that FortiLink connectivity is healthy, what should you check next? (Choose one answer). Check that the switch automatically disables all unused ports. Look for FortiLink heartbeat messages sent from FortiSwitch to FortiGate every few seconds and confirm FortiGate acknowledges them. Verify that FortiGate has pushed a new firmware image to FortiSwitch immediately. Ensure the FortiSwitch is automatically sending log events to FortiAnalyzer. Which two statements about 802.1X authentication on FortiSwitch ports are true? (Choose two.). All hosts behind an authenticated port are allowed access after a successful authentication. A security policy is used to apply 802.1 authentication on a port. A local user database must be used to authenticate devices using the 802.1X authentication protocol. All devices connecting to FortiSwitch must support 802.1X authentication. Port1 and port2 are the only ports configured with the same native VLAN 10. What are two reasons that can trigger port1 to shut down? (Choose two.). port1 was shut down by loop guard protection. STP triggered a loop and applied loop guard protection on port1. An endpoint sent a BPDU on port1 that it received from another interface. Loop guard frame sourced from port 1 was received on port 1. The command diagnose switch physical-ports summary is executed on FortiSwitch. Based on the VLAN assignments shown in the output, what is the most likely management configuration of this FortiSwitch? (Choose one answer). FortiSwitch is managed by FortiSwitch Cloud. FortiSwitch is managed by FortiGate. FortiSwitch is operating in standalone mode. FortiSwitch is operating in local mode. An administrator has deployed two FortiSwitch devices, Core-1 and Core-2, as multichassis link aggregation group (MCLAG) peers. These switches are connected to FortiGate for FortiLink and to an access switch (Access-1) using an inter-switch link (ISL). After configuration, the administrator notices that both Core-1 and Core-2 are claiming to be the root bridge in the Multiple Spanning Tree Protocol (MSTP) topology. What explains this behavior? (Choose one answer). FortiGate participates in MSTP and causes both switches to assume the root bridge role. The ISL was not configured correctly, leading to MSTP inconsistency. Both switches share the same bridge ID because MCLAG treats them as one logical switch. MCLAG automatically disables STP on all peer switches. Which interfaces on FortiSwitch send out FortiLink discovery frames by default in order to detect a FortiGate with an enabled FortiLink interface?. All ports have auto-discovery enabled by default. No ports are enabled by default for auto-discovery. This must be configured under config switch interface. The ports with auto-discovery enabled by default are dependent upon the FortiSwitch model. The last four switch ports on FortiSwitch have auto-discovery enabled by default. You are deploying a FortiSwitch virtual stack in a network that contains Cisco devices. You want the Cisco devices toautomatically discover the FortiSwitch devices and exchange device information. Which two protocols must be enabled on the FortiSwitch devices to achieve this? (Choose two answers). Unidirectional Link Detection. Cisco Discovery Protocol. Link Layer Discovery Protocol. LLDP “ Media Endpoint Discovery. Which packet capture method allows FortiSwitch to capture traffic on trunks and management interfaces?. SPAN. Sniffer profile. sFlow. TCP dump. Which feature should you enable to reduce the number or unwanted IGMP reports processed by the IGMP querier?. A. Enable the IGMP flood setting on the static port for all multicast groups. B. Enable the IGMP flood reports setting on the mRouter port. C. Enable IGMP snooping proxy. D. Enable IGMP flood unknown multicast traffic on the global setting. The FortiSwitch CLI output of the diagnose switch-controller switch-info poe summary command for the switch Access-1 is shown. It shows that two ports have Power over Ethernet (PoE) enabled and are already in use. What is the most important consideration if you want to connect additional PoE devices to FortiSwitch? (Choose one answer). All plugged devices use the same PoE standard: 802.3af/at. The FortiSwitch model supports the number of PoE devices that you want to connect. The PoE power mode matches the PoE standard of the device. The total PoE consumption must not exceed the FortiSwitch power budget. What two conclusions can be made regarding DHCP snooping configuration? (Choose two.). Maximum value to accept clients DHCP request is configured as per DHCP server range. FortiSwitch is configured to trust DHCP replies coming on FortiLink interface. DHCP clients that are trusted by DHCP snooping configured is only one. Global configuration for DHCP snooping is set to forward DHCP client requests on all ports in the VLAN. A FortiGate is connected to a pair of FortiSwitch devices. For redundancy, FortiGate must use uplinks on both switches simultaneouslywithout depending on Spanning Tree Protocol (STP). Which configuration is required? (Choose one answer). Multi-tier topology. Multichassis link aggregation group (MCLAG). Full mesh high availability (HA). Link aggregation group (LAG). What happens when a routed VLAN interface (RVI) is configured on a FortiSwitch port or trunk? (Choose one answer). VLAN 1 is automatically assigned for management. The port becomes a layer 3 interface with VLAN 4095 assigned automatically.1. All VLANs on the port are terminated in a trunk by default. The port becomes a layer 3 interface and assigned to VLAN 1. Exhibit. The exhibit shows the current status of the ports on the managed FortiSwitch. Access-1. Why would FortiGate display a serial number in the Native VLAN column associated with the port23 entry?. Port23 is a member of a trunk that uses the Access-1 FortiSwitch senal number as the name of the trunk. Port23 is configured as the dedicated management interface. A standalone switch with the showm serial number is connected on por123. Ports connect to adjacent FortiSwitch devices will show their.serial number as the na-tive VLAN. Exhibit. port1 and port2 are the only ports configured with the same native VLAN 10. What are two reasons that can trigger port1 to shut down? (Choose two.). port1 was shut down by loop guard protection. STP triggered a loop and applied loop guard protection on port1. An endpoint sent a BPDU on port1 that it received from another interface. Loop guard frame sourced from port1 was received on port1. What conditions does a FortiSwitch need to have to successfully configure the options shown in the exhibit above? (Choose two.). The FortiSwitch model is equipped with a maximum of 54 interfaces. The CLI commands are enabling a splitpo rt into four 10Gbps interfaces. The port full speed prior the split was 100G SFP+. The split port can be assigned to native VLAN. The exhibit shows the current status of the ports on the managed FortiSwitch. Access-1. Why would FortiGate display a serial number in the Native VLAN column associated with the port23 entry?. port23 is configured as the dedicated management interface. Ports connected to adjacent FortiSwitch devices show their serial number as the native VLAN. port23 is a member of a trunk that uses the Access-1 FortiSwitch serial number as the name of the trunk. A standalone switch with the shown serial number is connected on port23. Two routes in the routing monitor are marked as available but are not installed in the forwarding information base (FIB). Which statement correctly explains why the routes have this status? (Choose one answer). They are excluded from the FIB because a more preferred route exists for the same destination. They are unavailable due to invalid next-hop addresses. They are not included in the FIB due to route-policy filtering. They are installed in the FIB but cannot be offloaded to hardware. PC1 and PC2 are connected to port1 on FortiSwitch. Which VLAN tags will FortiSwitch apply when forwarding PC1 and PC2 traffic out of port2? (Choose one answer). A. FortiSwitch will tag PC1 and PC2 frames with VLAN 20. B. FortiSwitch will tag both PC1 and PC2 frames with VLAN 10, due to MAC override. C. FortiSwitch will tag PC1 frames with VLAN 10 and PC2 frames with VLAN 20. D. FortiSwitch will leave PC1 frames untagged and will tag PC2 frames with VLAN 10. You are deploying a multitier FortiSwitch topology with redundant links between access and aggregation switches. The team is considering Multiple Spanning Tree Protocol (MSTP) to manage spanning tree across multiple VLANs. Which two Rapid STP (RSTP) features would be useful in this deployment to ensure fast convergence and predictable port roles? (Choose two answers). The process for selecting the root bridge. Recalculating paths after a topology change. Automatic VLAN assignment. The rules for determining port roles. You need to mirror traffic from a source port on Switch A to a monitoring device on Switch C. For that purpose, youre configuring Remote Switched Port Analyzer (RSPAN).1Due to the nature of RSPAN, what is the best practice when setting it up? (Choose one answer). Use the same VLAN already configured for regular data traffic. Use a dedicated VLAN assigned only to monitoring devices. Use a dynamic VLAN that includes all switch ports. Use the RSPAN VLAN as a native VLAN on all trunk ports. The LLDP profile shown in the exhibit was configured to detect IP phones and automatically assign them to the appropriate VLAN. You apply this LLDP profile on a FortiSwitch port. Which configuration should you enable on the FortiSwitch profile to collect detailed information about all the connected IP phones? (Choose one answer). Create a new LLDP profile to handle different LLDP-MED TLVs. Configure a dedicated voice VLAN with DSCP 46. Enable LLDP-MED inventory management TLVs. Enable auto-isl. In which two ways can you assign a FortiSwitch port to a VDOM using a multi-tenancy setup? (Choose two answers). Assign the switch port to a VLAN on FortiGate and perform VDOM mapping. Create a virtual port pool on the FortiGate CLI. Assign a port to a VDOM directly on the managed FortiSwitch. Switch the FortiLink interface to the target VDOM. All three FortiSwitch-connected ports are configured in VLAN 10. FortiGate acts as the Dynamic Host Configuration Protocol (DHCP) server and is connected to a DHCP snooping trusted trunk port. PC1 and PC2 are connected to ports configured as untrusted for Dynamic ARP Inspection (DAI), and no static bindings are configured in the IP source guard (IPSG) database. PC2 is compromised and attempts to spoof the FortiGate IP address by sending forged Address Resolution Protocol (ARP) replies with its own MAC address. What will FortiSwitch do with the ARP packets from PC2? (Choose one answer). Forward the ARP replies because there are no IPSG bindings blocking them. Accept the ARP replies because the VLAN has DAI enabled and FortiGate is a trusted DHCP server. Forward the ARP replies to all VLAN 10 ports because DAI is only active on trusted ports. Drop the ARP replies because they fail DAI validation against the DHCP snooping database. You just connected three FortiSwitch devices:Core-1,Core-2, andAccess-1. Core-1 and Core-2 both connect to Access-1 for redundancy. All switches are managed by FortiGate, which uses port4 as the FortiLink interface. After you enable the uplink ports on Core-2, you notice that port3 on Access-1 enters the Discarding STP state. What is the most likely cause of this behavior? (Choose one answer). Bridge Protocol Data Unit (BPDU) Guard is enabled, which shuts down the port after it receives BPDUs. Access-1 is not authorized by FortiGate. Core-2 has the lowest bridge priority. FortiGate is not running Spanning Tree Protocol (STP) on the FortiLink interface. Which three are valid actions that a FortiSwitch access control list (ACL) can apply to matching traffic? (Choose three answers). Assign the VLAN ID. Quarantine devices. Traffic processing. Set outer VLAN tags. QoS. Which statement about using MAC, IP, and protocol-based VLANs on FortiSwitch is true?. lt is a scalable and secure solution in comparison to other Layer 2 security measures. FortiSwitch uses only the Ethernet type to assign traffic to VLANs. It provides benefits that can be obtained when using 802.1X authentication. Endpoints are required to use the same FortiSwitch port to remain members of the VLAN. Which two statements best describe what is displayed in the FortiLink debug output shown in the exhibit? (Choose two.). FortiSwitch is sending FortiLink heartbeats to FortiGate. FortiSwitch is discovered and authorized by FortiGate. FortiSwitch is in a waiting state to join the stack group on FortiGate. FortiSwitch is ready to push its new hostname to FortiGate. What is one key advantage of using a sniffer profile on FortiSwitch compared to using the sniffer command? (Choose one answer). It allows packet capture on all switch ports without limitations. It eliminates the need to use access control lists (ACLs) or port mirroring for analysis. It automatically filters irrelevant traffic types. It automatically decrypts SSL/TLS traffic for full packet inspection. What is the role of a device that is simultaneously functioning as both the distribution and core in the hierarchy network model?. POE with high density FortiSwitch. FortiGate managing FortiSwitch. FortiSwitch functioning as standalone. HA backup FortiGate managing FortiSwitch. You are planning to deploy FortiSwitch devices on your network. Your goal is to simplify management and ensure integration with the Security Fabric. Which deployment approach should you choose? (Choose one answer). Use the FortiSwitch-Manager device for centralized management. Manage FortiSwitch from FortiManager for large-scale enterprise deployments. Use FortiEdge Cloud for centralized management with advanced analytics. Manage FortiSwitch on FortiGate using FortiLink. Which statement about the configuration of VLANs on a managed FortiSwitch port is true?. Untagged VLANs must be part of the allowed VLANs: ingress and egress. FortiSwitch VLAN interfaces are created only when FortiSwitch is managed by Forti-Gate. The native VLAN is implicitly part of the allowed VLAN on the port. Allowed VLANS expand the collision domain to the port. You are configuring FortiSwitch to perform layer 3 inter-VLAN routing while managed by FortiGate over FortiLink. On supported hardware models, FortiSwitch can offload routing decisions for better performance.1How does FortiSwitch perform routing between VLANs? (Choose one answer). By using a hardware forwarding table (FIB) programmed into ASIC. By supporting only dynamic routing protocols in hardware. By disabling routing when managed by FortiGate. By relying entirely on the CPU in software. What type of multimode transceiver can be used to split a 40G port?. QSFP+ transceiver. SFP transceiver. QSFP transceiver. SFP+ transceiver. VLANs must be utilized to segment devices. No Layer 3 switch or router is present. The the only WAN connectivity is the router provided by the ISP connected to the public internet. Which two items will the administrator need to use? (Choose two.). A FortiSwitch interface connected to the ISP router configured with fortilink-13-mode enabled. FortiSwitch and FortiGate devices configured with VXLAN interfaces. FortiSwitch devices configured with NAT disabled. FortiSwitch devices that have the required internal hardware for this configuration. FortiSwitch and FortiGate devices configured with IPsec interfaces. How does enabling an IGMP snooping proxy on FortiSwitch help reduce the number of IGMP reports processed by the IGMP querier? (Choose one answer). By converting IGMP reports into broadcast packets to reach all VLAN members. By converting IGMP traffic to unicast. By suppressing duplicate IGMP reports within the VLAN. By forwarding IGMP reports only when the first member joins and the last member leaves. Your team is deploying a single FortiGate and a single FortiSwitch across 100 branch offices. The goal is to expedite deployment while avoiding manual configuration errors. Which method would allow you to achieve this goal most efficiently? (Choose one answer). Push FortiGate and FortiSwitch configurations through FortiEdge Cloud. Use the cloud Model-as-a-Service (MaaS) to push the configuration of both FortiGate and FortiSwitch. Use zero-touch provisioning (ZTP) through FortiManager. Ensure that devices engage FortiSwitch Manager to retrieve their configurations. To enhance service in emergency situations, to which LLDP-MED Type-Length-Values does Forti- Switch advertise to IP phones?. Network policy. Inventory management. Location. Power management. (Full question statement start from here) Refer to the exhibit. Which information does FortiGate use to generate the port details in the FortiSwitch Faceplates view? (Choose one answer). The FortiSwitch model. The Cisco Discovery Protocol (CDP) advertisements from FortiSwitch. The LLDP advertisements received from the FortiSwitch. The FortiLink discovery frames sent by FortiSwitch. How does FortiSwitch perform actions on ingress and egress traffic using the access control list (ACL)?. Only high-end FortiSwitch models support ACL. ACL can be used only at the prelookup stage in the traffic processing pipeline. Classifiers enable matching traffic based only on the VLAN ID. FortiSwitch checks ACL policies only from top to bottom. How is traffic routed on FortiSwitch?. Hardware-based routing on FortiSwitch is handled by the CPU. FortiSwitch looks up the hardware routing table and then the forwarding information base (FIB). ASIC hardware routing can only handle dynamic routing, if supported. Layer 3 routing can be configured on FortiSwitch, while managed by FortiGate. Which two statements about the FortiLink authorization process are true? (Choose two.). The administrator must manually pre-authorize FortiGate on FortiSwitch by adding the FortiGate serial number. FortiSwitch requires a reboot to complete the authorization process. A FortiLink frame is sent by FortiGate to FortiSwitch to complete the authorization. FortiLink authorization sets the FortiSwitch management mode to FortiLink. Two entries in the exhibit show that the same MAC address has been used in two different VLANs. Which MAC address is shown in the above output?. It is a MAC address of FortiLink interface on FortiGate. It is a MAC address of a switch that accepts multiple VLANs. It is a MAC address of an upstream FortiSwitch. It is a MAC address of FortiGate in HA configuration. Which statement best describes a benefit of using MAC, IP address, or protocol-based VLAN assignments on FortiSwitch? (Choose one answer). It disables 802.1X authentication while preserving user access control.1. It requires devices to authenticate through a RADIUS server before VLAN tagging. It assigns ports to VLANs regardless of device type or traffic. It offers dynamic segmentation benefits similar to 802.1X authentication.2. Two routes are not installed in the forwarding information base (FIB) as shown in the exnibit. Which two statements about these two route entries are true? (Choose two.). These two routes have a higher administrative distance value available to the destination networks. These two routes will become primary, if the best routes are removed. These two routes will be used as load-balancing routes. These two routes are available in the hardware routing table. Which LLDP-MED Type-Length-Values does FortiSwitch collect from endpoints to track network devices and determine their characteristics?. Network policy. Power management. Location. Inventory management. You need to deploy routing on a standalone FortiSwitch and want to maximize routing performance. Which type of routing is best for this deployment? (Choose one answer). Hardware-based routing because it relies on ASIC for faster performance1. Software-based routing because it bypasses the CPU to increase routing speed. Hardware-based routing because the routing is performed directly by the kernel. Software-based routing because it is preferred for high-speed backbone networks. When you change FortiSwitch management mode fromstandalonetomanaged, what happens to the existing standalone configuration? (Choose one answer). FortiSwitch registers to FortiSwitch Cloud to save a copy before managing with FortiGate. FortiSwitch merges the existing standalone configuration with the default FortiLink configuration. FortiSwitch saves the standalone configuration and changes to the default FortiLink configuration. FortiGate automatically saves the existing FortiSwitch configuration during the FortiLink management process. What can an administrator do to maintain the existing standalone FortlSwltch configuration while changing the management mode to FortLink?. Use a migration tool based on python script to convert the configuration. Enable the Forti-link setting on FortiSwitch before the authorization process. FortiGate will automatically save the existing FortiSwitch configuration during the Forti-link management process. Register FortiSwitch to For1ISwitch Cloud to save a copy before managing by Forti-Gate. FortiSwitch 802.1X port security configuration is shown. A user connects their laptop to the port and attempts to authenticate using 802.1X, but enters the wrong credentials multiple times. What will the result to the device be? (Choose one answer). The device will be placed into the VLAN quarantine. The port will shut down for security reasons. The device will be placed into the VLAN onboarding. The device will be assigned to the default management VLAN. You enable Dynamic Host Configuration Protocol (DHCP) snooping on a VLAN and configure a FortiSwitch port astrustedfor DHCP snooping. What additional step is required to configure the port as trusted forDynamic ARP Inspection (DAI)? (Choose one answer). Manually set the port as trusted for DAI through the CLI. DAI implicitly trusts the port. Enable IP Source Guard (IPSG) on the port. Enable static MAC learning on the port. You configured Switched Port Analyzer (SPAN) to monitor traffic from a source port on FortiSwitch 1, but the monitoring device is connected to FortiSwitch 2. After port mirroring configuration on FortiSwitch 1, the monitoring device is not receiving any mirrored traffic. What is the most likely reason the mirrored traffic is not reaching the monitoring device? (Choose one answer). SPAN does not support forwarding mirrored traffic across multiple switches. SPAN traffic must be filtered with an access control list (ACL). The SPAN session must be restarted after configuration. The monitoring device must use a management IP in the same subnet. You are managing FortiSwitch ports from a FortiGate device with multiple VDOMs. Which two methods can you use to assign FortiSwitch ports to VDOMs? (Choose two answers). Assigning the port directly to a specific VDOM for dedicated physical isolation. Use FortiGate policies to control inter-VDOM traffic for FortiSwitch ports. Use interface role mapping to dynamically assign FortiSwitch ports to VDOMs based on Dynamic Host Configuration Protocol (DHCP) scope. Using a virtual port pool (VPP) to create virtualized ports that can be assigned to different VDOMs. A periodic heartbeat message sent from a managed FortiSwitch and corresponding acknowledgments from FortiGate is shown. What does this behavior indicate? (Choose one answer). The FortiLink connection between FortiGate and FortiSwitch is healthy and active. FortiGate is unable to establish a FortiLink session with FortiSwitch. FortiSwitch is expecting an authorization from FortiGate. FortiSwitch has not been authorized yet. Refer to the diagnostic output: What makes the use of the sniffer command on the FortiSwitch CLI unreliable on__port__23?. The types of packets captured is limited. Just the port egress payloads are printed on CLI. Only untagged VLAN traffic can be captured. The switch port might be used as a trunk member. In which two ways can you assign a FortiSwitch port to a VDOM using multi-tenancy setup? (Choose two.). Switch the FortiLink interface to the target VDOM. Remove the managed FortiSwitch and allocate ports directly on FortiSwitch. Create a virtual port pool on the FortiGate CLI. Assign a port to a VDOM directly on the managed FortiSwitch. Which two statements about VLAN assignments on FortiSwitch ports are true? (Choose two. Configure a native VLAN on the FortiLink. Assign an IP address and subnet mask to FortiSwitch VLANs. Only assign one native VLAN on a port. Assign untagged VLANs using FortiGate CLI. What are two reasons why time synchronization between FortiGate and its managed FortiSwitch is critical in switch management? (Choose two.). FortiSwitch does not retain its time after a reboot, which gets reset after each reboot. FortiSwitch will not be able to become an NTP server for downstream devices. FortiSwitch cannot complete the DTLS handshake used in the CAPWAP tunnel. FortiSwitch will not allow other FortiSwitch devices in the chain be discovered by FortiGate. What happens if FortiSwitch fails to discover either FortiEdge Cloud or a FortiGate with FortiLink?. It switches to FortiLink mode by default. It remains in local management mode. It requires manual reimaging. It disables auto-network. Exhibit. port24 is the only uplink port connected to the network where access to FortiSwitch management services is possible. However, FortiSwitch is still not accessible on the management interface. Which two actions should you take to fix the issue and access FortiSwitch? (Choose two.). You must add port24 native VLAN as an allowed VLAN on internal. You must add VLAN ID 200 to the allowed VLANS on internal. You must allow VLAN ID 4094 on port24, if management traffic is tagged. You should use VLAN ID 4094 as the native VLAN on port24. Exhibit. Which configuration change will allow the managed FortiSwitch to accept SNMP requests from any source?. Create a new local access profile for SNMP only. Enable SNMP on the internal interface of the switch. Configure an SNMP host to send SNMP traps. Add SNMP service on the management interface of the switch. What does the switchauto-networksetting control on FortiSwitch? (Choose one answer). The automatic VLAN assignment based on connected devices. The automatic discovery of the FortiGate->FortiLink interface. The root bridge priority for Multiple Spanning Tree Protocol (MSTP). Whether the FortiSwitch can be managed by FortiManager. Refer to the exhibit. Core-1 and Access-1 are managed and authorized by FortiGate-1. which uses port4 as the FortiLink interface. After FortiGate authorizes and manages Core-2. Port1 status becomes STP discarding. Why is port1 in the discarding state. port1 on Core-2 is discarding only management traffic. Core-1 and Core-2 do not have MCLAG configuration. Access-1 is the root bridge and can only have one root port. Core-2 has the lowest bridge priority. How are the 'by VLAN redirect MAC address quarantine' mode and the 'by redirect MAC address quarantine' mode on FortiGate similar?. Both modes move quarantined devices to the quarantine VLAN. Both modes require firewall policies to block inter-VLAN traffic. Both modes add quarantined device MAC addresses to the blocked firewall address group. Both modes block intra-VLAN traffic by FortiGate automatically. Which statement about 802.1X security profiles using MAC-based authentication mode is true?. FortiSwitch allows connectivity to all hosts connected to a port, if one host is authenticated. FortiSwitch can grant each device a different access level based on the credentials provided. FortiSwitch performs faster when using this security mode on the ports. FortiSwitch must communicate with the RADIUS server to authenticate devices. and an OSPF route with destination 0.0.0.0/0 [110]. The OSPF route is marked with a checkmark in the FIB column, while the Static route has a dash.] The routing monitor displays multiple route entries, but only some are installed in the forwarding information base (FIB). After analyzing the two route entries with the destination 0.0.0.0/0, which statement correctly describe why one of these routes is not installed in the FIB? (Choose one answer). The OSPF route has a higher metric, making it less preferred than the static route. The interface V100 for the OSPF route is down, preventing its installation. The OSPF route with a lower administrative distance is preferred over the static route. The two routes have identical destination prefixes, causing a conflict where only one is selected. Which QoS mechanism maps packets with specific class of service (COS) or Differentiated Services Code Point (DSCP) markings to an egress queue? (Choose one answer). Classification for ingress traffic. Queuing for egress traffic. Policing for ingress traffic. Shaping for egress traffic. How does FortiGate handle configuration of flow tracking sampling if you export the settings to a managed FortiSwitch stack with sampling mode set to perimeter is true?. FortiGate configures FortiSwitch to perform ingress sampling on all switch interfaces. FortiGate configures FortiSwitch to perform ingress sampling on all switch interfaces, except ICL and ISL interfaces. FortiGate configures and enables flow sampling on FortiSwitch but does not change existing sampling settings of interfaces. FortiGate configures and enables egress sampling on all management interfaces. You are deploying a small office network with a single FortiGate and a single FortiSwitch. The office currently has moderate traffic, but the IT team expects the network to grow in the near future, adding more FortiSwitch devices and endpoints. Which FortiLink configuration should you deploy to provide the best combination of current performance and scalability for future growth? (Choose one answer). Configure FortiLink using hardware-based switch interfaces.1. Configure FortiLink using software-based switch interfaces. Configure FortiLink as a link aggregation group (LAG) interface. Configure FortiLink as a multichassis LAG (MCLAG) interface.2. What are two ways in which automatic MAC address quarantine works on FortiSwitch? (Choose two.). FortiSwitch supports only by VLAN quarantine mode. FortiGate applies the quarantine-related configuration only on FortiGate. FortiAnalyzer with a threat detection services license is required. MAC address quarantine can be enabled through the FortiGate CLI only. You are designing a multi-tenant network using FortiSwitch devices in standalone mode. Security is a priority and each tenants servers must be completely isolated from one another, and from all other servers in the network, to prevent lateral communication. However, all servers must have access to the shared FortiGate firewall for internet access. Which type of private VLAN (PVLAN) configuration should you apply to meet these security requirements? (Choose one answer). Standalone VLAN. Community VLAN. Isolated VLAN. Primary VLAN. What is an advantage of using a FortiSwitch stack in managed switch mode with FortiGate when deploying VLANs? (Choose one answer). FortiGate executing the routing and FortiSwitch managing its configuration. Ensuring VLAN traffic can pass between connected switches in the stack. FortiGate no longer needing to manage any VLAN configuration. FortiGate provides visibility and control for inter-vlan traffic. After reviewing the CLI command output, which two conclusions can you make about the Dynamic Host Configuration Protocol (DHCP) snooping configuration? (Choose two answers). DHCP snooping is disabled globally. All ports are untrusted, except port2. Option 82 is enabled on VLAN 10. DHCP broadcasts are not restricted. You are asked to ensure that managed FortiSwitch devices are reachable by other devices, such as SNMP and other management tools across your network. Which setting must you configure to ensure traffic from other devices in the network reaches FortiSwitch?. Select a specific default gateway provided to FortiSwitch as an upstream device. Change the FortiLink interface IP address and DHCP server address range. Recreate the FortiLink interface with a nonaggregate setting. Enable NAC settings to select the onboarding VLAN. Exhibit. You need to manage three FortiSwitch devices using a FortiGate device. Two of the FortiSwitch devices initiated a reboot after the authorization process. However, the FortiSwitch device with the configuration shown in the exhibit. did not reboot All three devices completed FortiLink management authorization successfully. Why did the FortiSwitch device shown in the exhibit not reboot to complete the authorization process? The management mode was set to use FortiLink mode. Switch auto-discovery is enabled. The management mode was set to use FortiLink mode. The FortiSwitch device is scheduled to reboot as part the authorization process. The system time is not in-sync and is using a non-default value. Which two rules used by MSTP are similar to rules used by other STP methods? (Choose two.). MSTP uses port role election, similar to rapid STP on the instances. MSTP uses alternate path and primary path, similar to regular STP. MSTP uses root bridge selection, similar to rapid STP. MSTP uses timers for transitioning the ports, similar to regular STP. You run the command diagnose switch-controller switch-info loopguard access-1 and see that theMAC-Movecolumn displays a value of0forport1. What does this indicate? (Choose one answer). Loop guard is disabled on port1. Port1 is not being monitored by loop guard. The MAC move feature is not enabled. Port1 will shut down if a loop occurs on any VLAN. Port24 is the only uplink port connected to the network where you need access to FortiSwitch management services. However, FortiSwitch is not accessible on its management interface with IP address 10.0.13.3. Based on the configuration shown in the exhibit, which two actions should you take to fix the issue and access FortiSwitch? (Choose two answers). Change the management IP address to use the VLAN 100 subnet. Change the native VLAN on port24 to VLAN 4094. Remove VLAN 200 from the allowed VLANs on port24. Add VLAN 4094 to the allowed VLANs on port24. Three FortiSwitch devices were recently configured to be managed by FortiGate. Two are managed successfully, butFortiSwitch Access-1is not. Based on the configuration output, whichinitial changeis required for FortiSwitch Access-1 to be managed? (Choose one answer). Assign a static IP on FortiSwitch Access-1. Change its Control and Provisioning of Wireless Access Points (CAPWAP) settings. Set Access-1 internal interface mode to DHCP. Change the NTP server. What can an administrator do to maintain a FortiGate-compatible FortiSwitch configuration when changing the management mode from standalone to FortiLinK?. Use a migration tool based on Python script to convert the configuration. Enable the FortiLink setting on FortiSwitch before the authorization process. FortiGate automatically saves the existing FortiSwitch configuration during the FortiLink management process. Register FortiSwitch to FortiSwitch Cloud to save a copy before managing with FortiGate. Three FortiSwitch devices in standalone mode are interconnected. The CLI command diagnose stp instance list is executed on Core-2. Based on the output shown in the exhibit, what can you conclude about Core-2? (Choose one answer). Core-2 has received Bridge Protocol Data Unit (BPDU) from the root bridge. Core-2 is the designated bridge for all VLANs. Core-2 is blocking all ports in the Spanning Tree Protocol (STP) topology. Core-2 provides an alternate path to the root bridge. |





