Skip to content

NSE6-FSW-7-2 Fortinet NSE 6 - FortiSwitch 7.2 Practice Questions

Prepare for NSE6-FSW-7-2 with more than an answer.

187 questions in the full set20 sample questionsUpdated Dec 7, 2025
Exam fee
$200 USD
Level
NSE 6 - Specialist
Valid for
2 years
Domains covered on the exam 5
  1. Manage and Provision FortiSwitch20%
  2. Network Planning and Design25%
  3. FortiSwitch Essentials and Fundamentals20%
  4. Layer 2 Control and Security20%
  5. FortiSwitch Monitoring and Troubleshooting15%
  1. 1

    A retail company has a small branch office with a FortiSwitch 108F but no on-site FortiGate. The corporate IT team needs to manage the switch configuration, monitor its status, and apply security policies remotely. They want a cloud-based solution that does not require a VPN tunnel back to a central FortiGate. Which management operation mode should be used for the FortiSwitch?

    Show answer details

    Correct answer: B

    Standalone mode is used when a FortiSwitch is not managed by a FortiGate via FortiLink. To achieve centralized cloud-based management without a FortiGate, the switch can be configured in standalone mode and registered with FortiLAN Cloud. This allows for remote configuration, monitoring, and management directly from the FortiCloud portal. FortiLink mode requires a direct connection to a managing FortiGate. Standalone mode with only local access wouldn't meet the remote management requirement. FortiManager manages FortiGates, not standalone switches directly in this manner.

  2. 2

    A network administrator is securing the access layer of a campus network. To prevent network loops and instability caused by users accidentally connecting switches or hubs to wall jacks, which TWO Spanning Tree Protocol (STP) protection features should be enabled on all user-facing, edge ports? (Select TWO.)

    Show answer details

    Correct answer: A, B

    BPDU Guard should be enabled on all edge ports where no switches are expected. If a BPDU is received on such a port (indicating another switch has been connected), BPDU Guard will shut down the port to prevent potential loops.

    Root Guard should be enabled on ports where the switch should never become a root port, which includes user-facing access ports. It prevents a rogue switch with a lower bridge priority from becoming the root bridge and destabilizing the STP topology.

  3. 3

    An organization is deploying FortiSwitches to support a mixed environment of VoIP phones, IP security cameras, and corporate workstations. The goal is to use a single configuration policy that automatically places devices into their correct VLANs and applies appropriate QoS settings. Which FortiSwitch feature is designed for this purpose?

    Show answer details

    Correct answer: C

    Link Layer Discovery Protocol - Media Endpoint Discovery (LLDP-MED) is an extension to LLDP that is specifically designed for automated configuration of endpoints like VoIP phones and video devices. An administrator can create LLDP-MED policies on the FortiSwitch that define VLANs, QoS markings (CoS/DSCP), and power requirements. When a compatible device connects, it uses LLDP-MED to learn this policy from the switch and configure itself automatically, meeting all the requirements of the scenario.

  4. 4

    A FortiSwitch stack, managed by a FortiGate, has suddenly gone offline in the FortiGate GUI. The physical links are up, and there are no logs indicating a failure on either device. An administrator needs to perform initial CLI troubleshooting from the FortiGate to check the status of the FortiLink discovery process. Which command provides the most direct information about the LLDP-based discovery of connected FortiSwitches?

    Show answer details

    Correct answer: C

    The FortiLink protocol relies on LLDP for the initial discovery of connected FortiSwitches. The diagnose switch-controller lldp-port-info command on the FortiGate shows the LLDP information being received from devices connected to the FortiLink interface. This is a critical first step to verify if the FortiGate is 'seeing' the FortiSwitch at Layer 2. If no information appears here, it points to a physical or L2 issue preventing LLDP frames from being exchanged. The get switch-controller managed-switch command shows already authorized switches, which would be empty in this case. diagnose sys link-monitor status is for WAN link health, and diagnose hardware deviceinfo nic shows physical port info, not the L2 discovery protocol status.

  5. 5

    A data center requires connecting a high-density server with a 40GbE QSFP+ port to four separate 10GbE SFP+ ports on a FortiSwitch 448E. What must be configured on the FortiSwitch to enable this connectivity?

    Show answer details

    Correct answer: C

    Certain FortiSwitch models support splitting a high-speed port, like a 40GbE QSFP+ port, into multiple lower-speed logical interfaces. Using the CLI, an administrator can configure the physical 40GbE port to operate in split mode, which creates four independent 10GbE interfaces. This requires a breakout cable (e.g., QSFP+ to 4xSFP+). This allows a single physical switch port to connect to multiple server ports, increasing port density and flexibility. A LAG bundles multiple ports into one logical link, which is the opposite of this requirement. FortiLink split-port is for managing multiple downstream switches from a single FortiGate port, not for physical port splitting.

  6. 6

    A network architect is designing a resilient campus network using a FortiGate HA Active-Passive cluster connected to a pair of core FortiSwitches in a stack. The design requires that downstream access switches maintain connectivity during a FortiGate failover event. Which configuration is essential on the core FortiSwitch stack to ensure seamless failover and connectivity?

    Show answer details

    Correct answer: B

    For a resilient connection to a FortiGate HA cluster, the best practice is to configure the FortiLink interface as an 802.3ad aggregate interface on the FortiGate side. On the FortiSwitch stack, a corresponding LACP trunk (LAG) is created with member ports physically connecting to each core switch. This configuration, known as MCLAG FortiLink, ensures that the logical link remains up even if one of the core switches or one of the physical links to the FortiGate fails, aligning perfectly with the HA capabilities of the FortiGate cluster.

  7. 7

    A security administrator is hardening untrusted access-layer FortiSwitch ports against common Layer 2 spoofing attacks. To create a multi-layered defense, they plan to implement DHCP Snooping, Dynamic ARP Inspection (DAI), and IP Source Guard. Which THREE statements accurately describe the implementation and dependencies of these features? (Select THREE)

    Show answer details

    Correct answer: A, C, E

  8. 8

    An administrator manages a large-scale deployment of over 100 FortiSwitches using a global FortiSwitch Template on a FortiGate. A new requirement mandates that all switches in the engineering department's wiring closets must have PoE disabled on ports 1-12. What is the most efficient and scalable method to apply this specific configuration without affecting the other 80+ switches?

    Show answer details

    Correct answer: B

    The FortiSwitch Template model is designed for this type of scenario. While manual CLI changes or per-switch overrides work for single instances, they are not scalable or maintainable. The most efficient and correct method is to create a new template (often by cloning the base template) that contains the specific settings for the engineering group (PoE disabled). This new template is then assigned to all switches designated for the engineering department. This approach maintains centralized management, ensures consistency, and simplifies future changes for that group of switches.

  9. 9

    Case Study:

    A hospital is overhauling its campus network using a FortiGate 1800F cluster and multiple stacks of FortiSwitch 448E models. The primary goal is to enforce strict segmentation and security while ensuring high performance for critical systems. The network must support three main user groups: Medical Devices (IoMT), Administrative Staff, and a public Guest Wi-Fi network.

    Requirements:

    1. IoMT Network (VLAN 100): Devices must be completely isolated from each other at Layer 2 to prevent lateral movement of malware. However, they all need to communicate with a central IoMT management server located in the data center. This traffic is latency-sensitive.
    2. Admin Network (VLAN 200): Staff devices need to communicate with each other and with corporate servers. Access to the IoMT network is strictly forbidden.
    3. Guest Network (VLAN 300): Guest devices must be isolated from each other and only have access to the internet. They must not be able to reach any internal network resources.

    Current Plan:
    The administrator plans to use a single VDOM on the FortiGate and create separate VLANs for each group. All inter-VLAN routing will be handled by the FortiGate.

    Given these stringent requirements, which design modification provides the most robust and efficient solution for the IoMT and Guest networks on the FortiSwitch access layer?

    Show answer details

    Correct answer: B

    Private VLANs (PVLANs) are specifically designed for this use case. By configuring the IoMT and Guest VLANs as PVLANs, ports connected to end devices can be set as 'isolated'. This enforces strict Layer 2 isolation, preventing them from communicating with each other directly at the switch level. The uplink port to the central server and the FortiGate would be configured as 'promiscuous', allowing it to communicate with all isolated ports. This offloads the isolation task from the FortiGate, provides hardware-level enforcement, and is more secure and efficient than using ACLs for a large number of ports.

  10. 10

    An administrator is deploying a new fleet of VoIP phones and wants to leverage the FortiSwitch infrastructure to automatically provision them with the correct VLAN and Quality of Service (QoS) settings upon connection. Which protocol should be configured on the switch ports to achieve this?

    Show answer details

    Correct answer: B

    LLDP-MED is an extension of LLDP specifically designed for media endpoint devices like VoIP phones. It allows the switch to automatically discover the device type and exchange information, including VLAN ID for voice traffic (Voice VLAN), QoS marking values (CoS/DSCP), and power requirements over Ethernet (PoE). This automates the provisioning process, ensuring voice traffic is correctly segregated and prioritized.

Create an account to continue.