DON'T WANT TO MISS A THING?

Certification Exam Passing Tips

Latest exam news and discount info

Curated and up-to-date by our experts

Yes, send me the newsletter

Free Fortinet NSE5_FSW_AD-7.6 Practice Questions & Answers 2026 Part1 | Fortinet NSE 5 - FortiSwitch 7.6 Administrator

Are you preparing for the Fortinet NSE 5 - FortiSwitch 7.6 Administrator certification exam? SPOTO offers the Fortinet NSE 5 - FortiSwitch 7.6 Administrator Premium File; all questions are aligned with the latest exam content and come with expert-provided answers. Our question banks cover the latest question types, core concepts, and detailed explanations, helping you familiarize yourself with the exam format and difficulty level. Whether you are reviewing core concepts or simulating a real exam environment, these resources will rapidly boost your confidence and readiness.
For over two decades, SPOTO has successfully helped numerous IT professionals secure their ideal positions at Fortune 500 companies. Download now to start practicing efficiently and ensure a high score on the actual exam. Don't miss this opportunity to pass your certification exam with ease!
Take other online exams

Question #1
When Dynamic Host Configuration Protocol (DHCP) snooping is enabled on a FortiSwitch VLAN, which two statements are true? (Choose two answers)
A. DHCP replies are accepted only on trusted ports
B. DHCP snooping blocks all unicast traffic
C. Option 82 can be inserted into DHCP requests
D. DHCP requests are dropped if sent from trusted ports
View answer
Correct Answer: AC
Question #2
When Dynamic Host Configuration Protocol (DHCP) snooping is enabled on a FortiSwitch VLAN, which two statements are true? (Choose two answers)
A. DHCP replies are accepted only on trusted ports
B. DHCP snooping blocks all unicast traffic
C. Option 82 can be inserted into DHCP requests
D. DHCP requests are dropped if sent from trusted ports
View answer
Correct Answer: AC
Question #3
(Full question statement start from here)How does FortiSwitch determine the route for traffic traversing its interfaces? (Choose one answer)
A. Hardware-based routing on FortiSwitch is handled by the CPU
B. ASIC hardware routing can handle only dynamic routing, if supported
C. FortiSwitch looks up the hardware routing table and then the forwarding information base (FIB)
D. FortiSwitch forwards all traffic to FortiGate for routing decisions
View answer
Correct Answer: C
Question #4
Refer to the exhibit.The profile shown in the exhibit is assigned to a group of managed FortiSwitch ports, and these ports are connected to endpoints which are powered by PoE.Which configuration action can you perform on the LLDP profile to cause these endpoints to exchange PoE information and negotiate power with the managed FortiSwitch?
A. Create new a LLDP-MED application type to define the PoE parameters
B. Assign a new LLDP profile to handle different LLDP-MED TLVs
C. Define an LLDP-MED location ID to use standard protocols for power
D. Add power management as part of LLDP-MED TLVs to advertise
View answer
Correct Answer: D
Question #5
Which statement about the use of the switch port analyzer (SPAN) packet capture method is true?
A. Mirrored traffic can be sent across multiple switches
B. SPAN can be configured only on a standalone FortiSwitch
C. Traffic on the management interface can be mirrored and captured by the monitoring device
D. The monitoring device must be connected to the same switch where the traffic is being mirrored
View answer
Correct Answer: A
Question #6
Refer to the exhibit.The security port policy is configured as shown in the exhibit.Which behavior occurs if a device connected to the port that does not support 802.1X? (Choose one answer)
A. The device is blocked from accessing the network
B. The device is placed into the onboarding VLAN
C. The device is placed into the quarantine VLAN
D. The device is assigned to the default management VLAN
View answer
Correct Answer: B
Question #7
(Full question statement start from here)How does FortiSwitch determine the route for traffic traversing its interfaces? (Choose one answer)
A. Hardware-based routing on FortiSwitch is handled by the CPU
B. ASIC hardware routing can handle only dynamic routing, if supported
C. FortiSwitch looks up the hardware routing table and then the forwarding information base (FIB)
D. FortiSwitch forwards all traffic to FortiGate for routing decisions
View answer
Correct Answer: C
Question #8
On supported FortiSwitch models, which access control list (ACL) stage is recommended for applying actions before the switch performs any layer 2 or layer 3 processing? (Choose one answer)
A. Ingress
B. Forwarding
C. Egress
D. Prelookup
View answer
Correct Answer: D
Question #9
Which drop policy mode, if assigned to a congested port, will drop incoming packets until there is no congestion on the egress port?
A. Tail-drop mode
B. Weighted round robin mode
C. Random early detection mode
D. Strict mode
View answer
Correct Answer: A
Question #10
Which drop policy mode, if assigned to a congested port, will drop incoming packets until there is no congestion on the egress port?
A. Tail-drop mode
B. Weighted round robin mode
C. Random early detection mode
D. Strict mode
View answer
Correct Answer: A
Question #11
(Full question statement start from here)How does FortiSwitch determine the route for traffic traversing its interfaces? (Choose one answer)
A. Hardware-based routing on FortiSwitch is handled by the CPU
B. ASIC hardware routing can handle only dynamic routing, if supported
C. FortiSwitch looks up the hardware routing table and then the forwarding information base (FIB)
D. FortiSwitch forwards all traffic to FortiGate for routing decisions
View answer
Correct Answer: C
Question #12
Refer to the exhibits. An IP phone is connected to port1 of FortiSwitch Access-1. The IP phone tags its traffic with VLAN ID 20. On FortiGate, VLAN IP_Phone (VLAN ID 20) has been configured, and port1 of Access-1 is set with VLAN 20 as the native VLAN. However, the IP phone cannot reach the network. The exhibit shows the partial VLAN configuration and the port1 configuration on Access-1.Which configuration change must you make on FortiSwitch to allow ingress and egress traffic for the IP phone? (Choose one answer)
A. On VLAN IP_Phone, enable vlanforward
B. On VLAN IP_Phone, enable l2forward
C. On port1, add VLAN 20 to the allowed_vlans list
D. On port1, disable the edge_port
View answer
Correct Answer: C
Question #13
Refer to the exhibit.Which information does FortiGate use to generate the port details in the FortiSwitch Faceplates view?
A. The FortiSwitch model
B. The Cisco Discovery Protocol (CDP) advertisements from FortiSwitch
C. The LLDP advertisements received from the FortiSwitch
D. The FortiLink discovery frames sent by FortiSwitch
View answer
Correct Answer: C
Question #14
Which statement about the IGMP snooping querier when enabled on a VLAN is true?
A. Active multicast receiver entries are aging on each IGMP query sent on the VLAN
B. IGMP reports on the VLAN are forwarded to all switch ports
C. The setting can only be enabled using the FortiSwitch CLI
D. All other indirectly connected switches will be unable to get IGMP multicast traffic
View answer
Correct Answer: A
Question #15
Which two are valid traffic processing actions that a FortiSwitch access control list (ACL) can apply to matching traffic? (Choose two answers)
A. Redirect frames to another port
B. Assign traffic to a high-priority egress queue
C. Encrypt frames
D. Drop frames
View answer
Correct Answer: AD
Question #16
Which statement about the use of the switch port analyzer (SPAN) packet capture method is true?
A. Mirrored traffic can be sent across multiple switches
B. SPAN can be configured only on a standalone FortiSwitch
C. Traffic on the management interface can be mirrored and captured by the monitoring device
D. The monitoring device must be connected to the same switch where the traffic is being mirrored
View answer
Correct Answer: A
Question #17
When Dynamic Host Configuration Protocol (DHCP) snooping is enabled on a FortiSwitch VLAN, which two statements are true? (Choose two answers)
A. DHCP replies are accepted only on trusted ports
B. DHCP snooping blocks all unicast traffic
C. Option 82 can be inserted into DHCP requests
D. DHCP requests are dropped if sent from trusted ports
View answer
Correct Answer: AC
Question #18
You are deploying a new FortiSwitch device in a branch office and you want it to be automatically detected and managed by FortiGate. Which FortiSwitch feature enables automatic detection during deployment?(Choose one answer)
A. uto-discovery
B. ero-touch deployment
C. ink Layer Discovery Protocol (LLDP)
D. ortiLink heartbeat
View answer
Correct Answer: C
Question #19
Which drop policy mode, if assigned to a congested port, will drop incoming packets until there is no congestion on the egress port?
A. Tail-drop mode
B. Weighted round robin mode
C. Random early detection mode
D. Strict mode
View answer
Correct Answer: A
Question #20
Which drop policy mode, if assigned to a congested port, will drop incoming packets until there is no congestion on the egress port?
A. Tail-drop mode
B. Weighted round robin mode
C. Random early detection mode
D. Strict mode
View answer
Correct Answer: A
Question #21
What happens when a routed VLAN interface (RVI) is configured on a FortiSwitch port or trunk? (Choose one answer)
A. he port becomes a layer 3 interface with VLAN 4095 assigned automatically
B. LAN 1 is automatically assigned for management
C. he port becomes a layer 3 interface and assigned to VLAN 1
D. ll VLANs on the port are terminated in a trunk by default
View answer
Correct Answer: A
Question #22
How are the 'by VLAN redirect MAC address quarantine' mode and the 'by redirect MAC address quarantine' mode on FortiGate similar?
A. oth modes move quarantined devices to the quarantine VLAN
B. oth modes require firewall policies to block inter-VLAN traffic
C. oth modes add quarantined device MAC addresses to the blocked firewall address group
D. oth modes block intra-VLAN traffic by FortiGate automatically
View answer
Correct Answer: A
Question #23
Which statement about the use of the switch port analyzer (SPAN) packet capture method is true?
A. Mirrored traffic can be sent across multiple switches
B. SPAN can be configured only on a standalone FortiSwitch
C. Traffic on the management interface can be mirrored and captured by the monitoring device
D. The monitoring device must be connected to the same switch where the traffic is being mirrored
View answer
Correct Answer: A
Question #24
Which is a requirement to enable SNMP v2c on a managed FortiSwitch?
A. Create an SNMP user to use for authentication and encryption
B. Specify an SNMP host to send traps to
C. Enable an SNMP v3 to handle traps messages with SNMP hosts
D. Configure SNMP agent and communities
View answer
Correct Answer: D
Question #25
Which drop policy mode, if assigned to a congested port, will drop incoming packets until there is no congestion on the egress port?
A. Tail-drop mode
B. Weighted round robin mode
C. Random early detection mode
D. Strict mode
View answer
Correct Answer: A
Question #26
On supported FortiSwitch models, which access control list (ACL) stage is recommended for applying actions before the switch performs any layer 2 or layer 3 processing? (Choose one answer)
A. Ingress
B. Forwarding
C. Egress
D. Prelookup
View answer
Correct Answer: D
Question #27
An administrator must deploy managed FortiSwitch devices in a remote location where multiple VLANs must be used to segment devices. No layer 3 switch or router is present at the site, and the only WAN connectivity is an ISP-provided router connected to the public internet.Which two components are required to enable VLAN segmentation across this remote site? (Choose two.)
A. FortiGate and FortiSwitch configured with VXLAN to tunnel VLANs over the WAN
B. A layer 3 router at the remote location to handle inter-VLAN routing
C. A FortiSwitch model that supports VXLAN hardware acceleration
D. FortiSwitch and FortiGate devices configured with IPsec interfaces
E. FortiGate with a layer 3 interface to terminate the VXLAN overlay
View answer
Correct Answer: DE
Question #28
Which statement about the use of the switch port analyzer (SPAN) packet capture method is true?
A. Mirrored traffic can be sent across multiple switches
B. SPAN can be configured only on a standalone FortiSwitch
C. Traffic on the management interface can be mirrored and captured by the monitoring device
D. The monitoring device must be connected to the same switch where the traffic is being mirrored
View answer
Correct Answer: A
Question #29
Refer to the exhibit.Diagnose outputThe command diagnose switch physical-ports summary is executed on FortiSwitch.Based on the VLAN assignments shown in the output, what is the most likely management configuration of this FortiSwitch?
A. FortiSwitch is managed by FortiSwitch Cloud
B. FortiSwitch is managed by FortiGate
C. FortiSwitch is operating in standalone mode
D. FortiSwitch is operating in local mode
View answer
Correct Answer: B
Question #30
Which statement about the quarantine VLAN on FortiSwitch is true?
A. Quarantine VLAN has no DHCP server
B. Users who fail 802
C. It is only used for quarantined devices if global setting is set to quarantine by VLAN
D. FortiSwitch can block devices without configuring quarantine VLAN to be part of the allowed VLANs
View answer
Correct Answer: B
Question #31
What is the role of a device that is simultaneously functioning as both the distribution and core in the hierarchy network model?
A. ortiSwitch functioning as standalone
B. ortiGate managing FortiSwitch
C. A backup FortiGate managing FortiSwitch
D. OE with high density FortiSwitch
View answer
Correct Answer: B
Question #32
Which three are valid actions that a FortiSwitch access control list (ACL) can apply to matching traffic? (Choose three answers)
A. Assign the VLAN ID
B. Quarantine devices
C. Traffic processing
D. Set outer VLAN tags
E. QoS
View answer
Correct Answer: CDE
Question #33
Which is a requirement to enable SNMP v2c on a managed FortiSwitch?
A. reate an SNMP user to use for authentication and encryption
B. nable an SNMP v3 to handle traps messages with SNMP hosts
C. onfigure SNMP agent and communities
D. pecify an SNMP host to send traps to
View answer
Correct Answer: C
Question #34
When Dynamic Host Configuration Protocol (DHCP) snooping is enabled on a FortiSwitch VLAN, which two statements are true? (Choose two answers)
A. DHCP replies are accepted only on trusted ports
B. DHCP snooping blocks all unicast traffic
C. Option 82 can be inserted into DHCP requests
D. DHCP requests are dropped if sent from trusted ports
View answer
Correct Answer: AC
Question #35
(Full question statement start from here)How does FortiSwitch determine the route for traffic traversing its interfaces? (Choose one answer)
A. Hardware-based routing on FortiSwitch is handled by the CPU
B. ASIC hardware routing can handle only dynamic routing, if supported
C. FortiSwitch looks up the hardware routing table and then the forwarding information base (FIB)
D. FortiSwitch forwards all traffic to FortiGate for routing decisions
View answer
Correct Answer: C
Question #36
Refer to the exhibits.Topology viewCore-1 CLI outputCore-2 CLI outputAn administrator has deployed two FortiSwitch devices, Core-1 and Core-2, as multichassis link aggregation group (MCLAG) peers. These switches are connected to FortiGate for FortiLink and to an access switch (Access-1) using an inter-switch link (ISL). After configuration, the administrator notices that both Core-1 and Core-2 are claiming to be the root bridge in the Multiple Spanning Tree Protocol (MSTP) topology.What explains this behavior?
A. FortiGate participates in MSTP and causes both switches to assume the root bridge role
B. The ISL was not configured correctly, leading to MSTP inconsistency
C. Both switches share the same bridge ID because MCLAG treats them as one logical switch
D. MCLAG automatically disables STP on all peer switches
View answer
Correct Answer: C
Question #37
When Dynamic Host Configuration Protocol (DHCP) snooping is enabled on a FortiSwitch VLAN, which two statements are true? (Choose two answers)
A. DHCP replies are accepted only on trusted ports
B. DHCP snooping blocks all unicast traffic
C. Option 82 can be inserted into DHCP requests
D. DHCP requests are dropped if sent from trusted ports
View answer
Correct Answer: AC
Question #38
On supported FortiSwitch models, which access control list (ACL) stage is recommended for applying actions before the switch performs any layer 2 or layer 3 processing? (Choose one answer)
A. Ingress
B. Forwarding
C. Egress
D. Prelookup
View answer
Correct Answer: D
Question #39
On supported FortiSwitch models, which access control list (ACL) stage is recommended for applying actions before the switch performs any layer 2 or layer 3 processing? (Choose one answer)
A. Ingress
B. Forwarding
C. Egress
D. Prelookup
View answer
Correct Answer: D
Question #40
When Dynamic Host Configuration Protocol (DHCP) snooping is enabled on a FortiSwitch VLAN, which two statements are true? (Choose two answers)
A. DHCP replies are accepted only on trusted ports
B. DHCP snooping blocks all unicast traffic
C. Option 82 can be inserted into DHCP requests
D. DHCP requests are dropped if sent from trusted ports
View answer
Correct Answer: AC

View The Updated Fortinet Exam Questions

SPOTO Provides 100% Real Fortinet Exam Questions for You to Pass Your Fortinet Exam!

View Answers after Submission

Please submit your email and WhatsApp to get the answers of questions.

Note: Please make sure your email ID and Whatsapp are valid so that you can get the correct exam results.

Email:
Whatsapp/phone number:
Contact Us