NSE5_FSW_AD-7.6 Fortinet NSE 5 - FortiSwitch 7.6 Administrator Practice Questions
Prepare for NSE5_FSW_AD-7.6 with more than an answer.
- Exam fee
- $200 USD
- Time limit
- 70 minutes
- Questions on the exam
- 35-40
- Passing score
- Pass/Fail (exact score not publicly disclosed)
- Level
- NSE 5 - Professional
- Valid for
- 2 years
Domains covered on the exam 4
- FortiSwitch Concepts30%
- Deployment and Management25%
- Layer 2 Control and Security25%
- Monitoring and Troubleshooting20%
- 1
True or False: When configuring a FortiSwitch in a multi-tenant environment using VDOMs on a FortiGate, a single FortiSwitch can be shared across multiple VDOMs with different ports assigned to different VDOMs.
Show answer details
Correct answer: A
True. FortiSwitch ports can be assigned to different VDOMs on the FortiGate. The FortiLink interface usually resides in the management/root VDOM (or a dedicated infrastructure VDOM), but the switch ports themselves can be virtually assigned to other VDOMs, allowing per-tenant segmentation at the port level.
- 2
A FortiSwitch administrator is observing high CPU usage on the switch due to excessive broadcast traffic. They decide to implement Storm Control.
What are the three traffic types that Storm Control can independently monitor and suppress? (Select THREE)
Show answer details
Correct answer: A, C, D
Storm control typically monitors Unknown Unicast traffic (DLF - Destination Lookup Failure).
Storm control typically monitors Broadcast traffic.
Storm control typically monitors Multicast traffic.
- 3
Case Study:
Scenario
GlobalCorp is deploying a new branch office using a FortiGate 100F and two FortiSwitch 424E switches. The switches will be deployed in a high-availability ring topology managed by the FortiGate.Requirements
- The switches must be managed via FortiLink.
- If one link in the ring breaks, traffic must failover in less than 1 second.
- The topology must allow for the addition of a third switch in the future without breaking the ring architecture.
- VLAN 10 (Voice) and VLAN 20 (Data) must be available on all switches.
Problem
The administrator connects the switches in a ring: Port 24 of Switch 1 to Port 24 of Switch 2, and Port 23 of Switch 2 back to the FortiGate (along with the initial uplink from Switch 1). However, the FortiGate only shows one switch online at a time. As soon as the second uplink is connected, network instability occurs.Question
Which configuration is most likely missing or incorrect on the FortiGate's FortiLink interface to support this ring topology?Show answer details
Correct answer: B
In a ring topology connected to the FortiGate, the FortiLink interface on the FortiGate is typically an aggregate interface. However, because the links connect to different switches (Switch 1 and Switch 2), the 'fortilink-split-interface' setting (or disable split-interface depending on version context, effectively enabling Split-Link or MCLAG logic) must be correctly configured so the FortiGate knows these links go to different chassis. If it expects a standard LACP aggregate to a single peer, the negotiation will fail or cause loops.
- 4
A network architect is designing a high-availability campus network using FortiSwitch devices managed by a FortiGate. The design requires an MCLAG (Multi-Chassis Link Aggregation Group) pair at the distribution layer. During the configuration planning, the architect must ensure loop prevention and proper traffic handling if the Inter-Chassis Link (ICL) fails but the peer keepalive link remains active.
Based on standard FortiSwitch MCLAG behavior, which action does the secondary MCLAG peer take in this split-brain scenario?
Show answer details
Correct answer: B
In an MCLAG split-brain scenario where the ICL fails but the keepalive link is up, the secondary switch detects that the primary is still alive via the keepalive. To prevent Layer 2 loops and inconsistent forwarding, the secondary switch shuts down its MCLAG member ports (and typically other non-management ports, depending on configuration).
- 5
A network administrator is configuring a FortiSwitch in standalone mode to support a VoIP deployment. The IP phones require specific LLDP-MED TLVs to function correctly, specifically for VLAN assignment and power management. Which CLI command context should the administrator access to configure the LLDP-MED network policy profiles?
Show answer details
Correct answer: C
In FortiSwitch standalone mode, LLDP profiles are configured under
config switch lldp profile. Within this profile, you define the LLDP-MED network policies and TLVs that will be advertised to connected devices. - 6
An organization is implementing a Private VLAN (PVLAN) solution on their FortiSwitch infrastructure to isolate servers within the same subnet. The requirements are as follows:
- Database servers must not communicate with each other.
- Web servers must not communicate with each other.
- All servers must communicate with the Gateway/Firewall.
- A Backup server must be able to communicate with all Database and Web servers.
Which PVLAN port type should be assigned to the Backup server to satisfy these requirements?
Show answer details
Correct answer: A
A Promiscuous port in a Private VLAN can communicate with all other port types (Isolated, Community, and Promiscuous) within the same primary VLAN. Since the Backup server needs to talk to all other servers (which are likely on Isolated or Community ports), it must be on a Promiscuous port.
