DON'T WANT TO MISS A THING?

Certification Exam Passing Tips

Latest exam news and discount info

Curated and up-to-date by our experts

Yes, send me the newsletter

Free Fortinet NSE5_FSW_AD-7.6 Practice Questions & Answers 2026 Part2 | Fortinet NSE 5 - FortiSwitch 7.6 Administrator

Are you preparing for the Fortinet NSE 5 - FortiSwitch 7.6 Administrator certification exam? SPOTO offers the Fortinet NSE 5 - FortiSwitch 7.6 Administrator Premium File; all questions are aligned with the latest exam content and come with expert-provided answers. Our question banks cover the latest question types, core concepts, and detailed explanations, helping you familiarize yourself with the exam format and difficulty level. Whether you are reviewing core concepts or simulating a real exam environment, these resources will rapidly boost your confidence and readiness.
For over two decades, SPOTO has successfully helped numerous IT professionals secure their ideal positions at Fortune 500 companies. Download now to start practicing efficiently and ensure a high score on the actual exam. Don't miss this opportunity to pass your certification exam with ease!
Take other online exams

Question #1
On supported FortiSwitch models, which access control list (ACL) stage is recommended for applying actions before the switch performs any layer 2 or layer 3 processing? (Choose one answer)
A. Ingress
B. Forwarding
C. Egress
D. Prelookup
View answer
Correct Answer: D
Question #2
Refer to the exhibits.Network topologyInterface configurationVLAN configurationTraffic arriving on port2 on FortiSwitch is tagged with VLAN ID 10 and destined for PC1 connected on port1. PC1 expects to receive traffic untagged from port1 on FortiSwitch.Which two configurations can you perform on FortiSwitch to ensure PC1 receives untagged traffic on port1? (Choose two.)
A. Add VLAN ID 10 as a member of the untagged VLANs on port1
B. Include VLAN 10 and VLAN 20 as allowed VLANs on port1
C. Add the MAC address of PC1 as a member of VLAN 10
D. Remove VLAN 10 from the allowed VLANs and add it to untagged VLANs on port1
View answer
Correct Answer: AC
Question #3
On supported FortiSwitch models, which access control list (ACL) stage is recommended for applying actions before the switch performs any layer 2 or layer 3 processing? (Choose one answer)
A. Ingress
B. Forwarding
C. Egress
D. Prelookup
View answer
Correct Answer: D
Question #4
When Dynamic Host Configuration Protocol (DHCP) snooping is enabled on a FortiSwitch VLAN, which two statements are true? (Choose two answers)
A. DHCP replies are accepted only on trusted ports
B. DHCP snooping blocks all unicast traffic
C. Option 82 can be inserted into DHCP requests
D. DHCP requests are dropped if sent from trusted ports
View answer
Correct Answer: AC
Question #5
When Dynamic Host Configuration Protocol (DHCP) snooping is enabled on a FortiSwitch VLAN, which two statements are true? (Choose two answers)
A. DHCP replies are accepted only on trusted ports
B. DHCP snooping blocks all unicast traffic
C. Option 82 can be inserted into DHCP requests
D. DHCP requests are dropped if sent from trusted ports
View answer
Correct Answer: AC
Question #6
Which statement about the use of the switch port analyzer (SPAN) packet capture method is true?
A. Mirrored traffic can be sent across multiple switches
B. SPAN can be configured only on a standalone FortiSwitch
C. Traffic on the management interface can be mirrored and captured by the monitoring device
D. The monitoring device must be connected to the same switch where the traffic is being mirrored
View answer
Correct Answer: A
Question #7
Which two statements about managing a FortiSwitch stack on FortiGate are true? (Choose two.)
A. A FortiLink interface must be enabled on FortiGate
B. The switch controller feature must be enabled on FortiGate
C. Only a hardware-based FortiGate can manage a FortiSwitch stack
D. FortiSwitch must be operating in standalone mode before authorization
View answer
Correct Answer: AB
Question #8
Which two are valid traffic processing actions that a FortiSwitch access control list (ACL) can apply to matching traffic? (Choose two.)
A. Redirect frames to another port
B. Assign traffic to a high-priority egress queue
C. Encrypt frames
D. Drop frames
View answer
Correct Answer: BD
Question #9
On supported FortiSwitch models, which access control list (ACL) stage is recommended for applying actions before the switch performs any layer 2 or layer 3 processing? (Choose one answer)
A. Ingress
B. Forwarding
C. Egress
D. Prelookup
View answer
Correct Answer: D
Question #10
Which statement about the use of the switch port analyzer (SPAN) packet capture method is true?
A. Mirrored traffic can be sent across multiple switches
B. SPAN can be configured only on a standalone FortiSwitch
C. Traffic on the management interface can be mirrored and captured by the monitoring device
D. The monitoring device must be connected to the same switch where the traffic is being mirrored
View answer
Correct Answer: A
Question #11
(Full question statement start from here)How does FortiSwitch determine the route for traffic traversing its interfaces? (Choose one answer)
A. Hardware-based routing on FortiSwitch is handled by the CPU
B. ASIC hardware routing can handle only dynamic routing, if supported
C. FortiSwitch looks up the hardware routing table and then the forwarding information base (FIB)
D. FortiSwitch forwards all traffic to FortiGate for routing decisions
View answer
Correct Answer: C
Question #12
Refer to the exhibit.Network TopologyYou configured Switched Port Analyzer (SPAN) to monitor traffic from a source port on FortiSwitch 1, but the monitoring device is connected to FortiSwitch 2. After port mirroring configuration on FortiSwitch 1, the monitoring device is not receiving any mirrored traffic.What is the most likely reason the mirrored traffic is not reaching the monitoring device?
A. SPAN does not support forwarding mirrored traffic across multiple switches
B. SPAN traffic must be filtered with an access control list (ACL)
C. The SPAN session must be restarted after configuration
D. The monitoring device must use a management IP in the same subnet
View answer
Correct Answer: A
Question #13
(Full question statement start from here)How does FortiSwitch determine the route for traffic traversing its interfaces? (Choose one answer)
A. Hardware-based routing on FortiSwitch is handled by the CPU
B. ASIC hardware routing can handle only dynamic routing, if supported
C. FortiSwitch looks up the hardware routing table and then the forwarding information base (FIB)
D. FortiSwitch forwards all traffic to FortiGate for routing decisions
View answer
Correct Answer: C
Question #14
Which statement about the use of the switch port analyzer (SPAN) packet capture method is true?
A. Mirrored traffic can be sent across multiple switches
B. SPAN can be configured only on a standalone FortiSwitch
C. Traffic on the management interface can be mirrored and captured by the monitoring device
D. The monitoring device must be connected to the same switch where the traffic is being mirrored
View answer
Correct Answer: A
Question #15
Which two statements about managing a FortiSwitch stack on FortiGate are true? (Choose two.)
A. A FortiLink interface must be enabled on FortiGate
B. The switch controller feature must be enabled on FortiGate
C. Only a hardware-based FortiGate can manage a FortiSwitch stack
D. FortiSwitch must be operating in standalone mode before authorization
View answer
Correct Answer: AB
Question #16
Which interfaces on FortiSwitch send out FortiLink discovery frames by default in order to detect a FortiGate with an enabled FortiLink interface?
A. All ports have auto-discovery enabled by default
B. No ports are enabled by default for auto-discovery
C. The ports with auto-discovery enabled by default are dependent upon the FortiSwitch model
D. The last four switch ports on FortiSwitch have auto-discovery enabled by default
View answer
Correct Answer: A
Question #17
Which statement about the use of the switch port analyzer (SPAN) packet capture method is true?
A. Mirrored traffic can be sent across multiple switches
B. SPAN can be configured only on a standalone FortiSwitch
C. Traffic on the management interface can be mirrored and captured by the monitoring device
D. The monitoring device must be connected to the same switch where the traffic is being mirrored
View answer
Correct Answer: A
Question #18
Which two statements about DHCP snooping enabled on a FortiSwitch VLAN are true? (Choose two.)
A. Enabling DHCP snooping on a FortiSwitch VLAN ensures requests and replies are seen by all DHCP servers
B. switch-controller-dhcp-snooping-verify-mac verifies the destination MAC address to protect against DHCP exhaustion attacks
C. By default, all FortiSwitch ports are set to forward client DHCP requests to untrusted ports
D. Settings related to DHCP option 82 are only configurable through the CLI
View answer
Correct Answer: BD
Question #19
Which drop policy mode, if assigned to a congested port, will drop incoming packets until there is no congestion on the egress port?
A. Tail-drop mode
B. Weighted round robin mode
C. Random early detection mode
D. Strict mode
View answer
Correct Answer: A
Question #20
On supported FortiSwitch models, which access control list (ACL) stage is recommended for applying actions before the switch performs any layer 2 or layer 3 processing? (Choose one answer)
A. Ingress
B. Forwarding
C. Egress
D. Prelookup
View answer
Correct Answer: D
Question #21
When Dynamic Host Configuration Protocol (DHCP) snooping is enabled on a FortiSwitch VLAN, which two statements are true? (Choose two answers)
A. DHCP replies are accepted only on trusted ports
B. DHCP snooping blocks all unicast traffic
C. Option 82 can be inserted into DHCP requests
D. DHCP requests are dropped if sent from trusted ports
View answer
Correct Answer: AC
Question #22
Which drop policy mode, if assigned to a congested port, will drop incoming packets until there is no congestion on the egress port?
A. Tail-drop mode
B. Weighted round robin mode
C. Random early detection mode
D. Strict mode
View answer
Correct Answer: A
Question #23
Which statement about the use of the switch port analyzer (SPAN) packet capture method is true?
A. Mirrored traffic can be sent across multiple switches
B. SPAN can be configured only on a standalone FortiSwitch
C. Traffic on the management interface can be mirrored and captured by the monitoring device
D. The monitoring device must be connected to the same switch where the traffic is being mirrored
View answer
Correct Answer: A
Question #24
On supported FortiSwitch models, which access control list (ACL) stage is recommended for applying actions before the switch performs any layer 2 or layer 3 processing? (Choose one answer)
A. Ingress
B. Forwarding
C. Egress
D. Prelookup
View answer
Correct Answer: D
Question #25
Which drop policy mode, if assigned to a congested port, will drop incoming packets until there is no congestion on the egress port?
A. Tail-drop mode
B. Weighted round robin mode
C. Random early detection mode
D. Strict mode
View answer
Correct Answer: A
Question #26
(Full question statement start from here)Refer to the exhibit.You run the command diagnose switch-controller switch-info loopguard access-1 and see that theMAC-Movecolumn displays a value of0forport1.What does this indicate? (Choose one answer)
A. Loop guard is disabled on port1
B. Port1 is not being monitored by loop guard
C. The MAC move feature is not enabled
D. Port1 will shut down if a loop occurs on any VLAN
View answer
Correct Answer: C
Question #27
(Full question statement start from here)How does FortiSwitch determine the route for traffic traversing its interfaces? (Choose one answer)
A. Hardware-based routing on FortiSwitch is handled by the CPU
B. ASIC hardware routing can handle only dynamic routing, if supported
C. FortiSwitch looks up the hardware routing table and then the forwarding information base (FIB)
D. FortiSwitch forwards all traffic to FortiGate for routing decisions
View answer
Correct Answer: C
Question #28
Refer to the exhibit.What two conclusions can be made regarding DHCP snooping configuration? (Choose two.)
A. Maximum value to accept clients DHCP request is configured as per DHCP server range
B. FortiSwitch is configured to trust DHCP replies coming on FortiLink interface
C. DHCP clients that are trusted by DHCP snooping configured is only one
D. Global configuration for DHCP snooping is set to forward DHCP client requests on all ports in the VLAN
View answer
Correct Answer: BD
Question #29
Which QoS mechanism maps packets with specific class of service (COS) or Differentiated Services Code Point (DSCP) markings to an egress queue?
A. Classification for ingress traffic
B. Queuing for egress traffic
C. Policing for ingress traffic
D. Shaping for egress traffic
View answer
Correct Answer: B
Question #30
(Full question statement start from here)How does FortiSwitch determine the route for traffic traversing its interfaces? (Choose one answer)
A. Hardware-based routing on FortiSwitch is handled by the CPU
B. ASIC hardware routing can handle only dynamic routing, if supported
C. FortiSwitch looks up the hardware routing table and then the forwarding information base (FIB)
D. FortiSwitch forwards all traffic to FortiGate for routing decisions
View answer
Correct Answer: C
Question #31
(Full question statement start from here)Refer to the exhibits.You enable Dynamic Host Configuration Protocol (DHCP) snooping on the VLAN,Student. The Linux- Client VM sends DHCP requests, and tcpdump confirms the broadcasts. However, the Linux-Server VM, acting as a DHCP server, receives no DHCP traffic.What is the most likely cause of this intra- VLAN traffic being blocked? (Choose one answer)
A. The DHCP requests are being sent on the wrong VLAN
B. Port1 is configured as an untrusted port
C. Port4 is not configured as a trusted port
D. The Student VLAN must be configured as an allowed VLAN on port1
View answer
Correct Answer: B
Question #32
What happens if FortiSwitch fails to discover either FortiEdge Cloud or a FortiGate with FortiLink?
A. It switches to FortiLink mode by default
B. It remains in local management mode
C. It requires manual reimaging
D. It disables auto-network
View answer
Correct Answer: B
Question #33
Refer to the exhibit.A periodic heartbeat message sent from a managed FortiSwitch and corresponding acknowledgments from FortiGate is shown. What does this behavior indicate? (Choose one answer)
A. The FortiLink connection between FortiGate and FortiSwitch is healthy and active
B. FortiGate is unable to establish a FortiLink session with FortiSwitch
C. FortiSwitch is expecting an authorization from FortiGate
D. FortiSwitch has not been authorized yet
View answer
Correct Answer: A
Question #34
Which drop policy mode, if assigned to a congested port, will drop incoming packets until there is no congestion on the egress port?
A. Tail-drop mode
B. Weighted round robin mode
C. Random early detection mode
D. Strict mode
View answer
Correct Answer: A
Question #35
Which two statements about 802.1X authentication on FortiSwitch ports are true? (Choose two.)
A. In port-based 802
B. A port policy is used to apply 802
C. 802
D. All devices connecting to FortiSwitch must support 802
View answer
Correct Answer: AB
Question #36
(Full question statement start from here)You enable Dynamic Host Configuration Protocol (DHCP) snooping on a VLAN and configure a FortiSwitch port astrustedfor DHCP snooping. What additional step is required to configure the port as trusted forDynamic ARP Inspection (DAI)? (Choose one answer)
A. Manually set the port as trusted for DAI through the CLI
B. DAI implicitly trusts the port
C. Enable IP Source Guard (IPSG) on the port
D. Enable static MAC learning on the port
View answer
Correct Answer: B
Question #37
(Full question statement start from here)How does FortiSwitch determine the route for traffic traversing its interfaces? (Choose one answer)
A. Hardware-based routing on FortiSwitch is handled by the CPU
B. ASIC hardware routing can handle only dynamic routing, if supported
C. FortiSwitch looks up the hardware routing table and then the forwarding information base (FIB)
D. FortiSwitch forwards all traffic to FortiGate for routing decisions
View answer
Correct Answer: C

View The Updated Fortinet Exam Questions

SPOTO Provides 100% Real Fortinet Exam Questions for You to Pass Your Fortinet Exam!

View Answers after Submission

Please submit your email and WhatsApp to get the answers of questions.

Note: Please make sure your email ID and Whatsapp are valid so that you can get the correct exam results.

Email:
Whatsapp/phone number:
Contact Us