Weekend Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Fortinet NSE6_FSW-7.2 Dumps

NSE6_FSW-7.2 - Fortinet NSE 6 - FortiSwitch 7.2 Questions and Answers

Question 1

Which two statements about 802.1X authentication on FortiSwitch ports are true? (Choose two.)

Options:

A.

All hosts behind an authenticated port are allowed access after a successful authentica-tion.

B.

A security policy is used to apply 802.1 authentication on a port.

C.

A local user database must be used to authenticate devices using the 802.1X authentica-tion protocol.

D.

All devices connecting to FortiSwitch must support 802.1X authentication.

Question 2

Refer to the exhibit.

Which two statements best describe what is displayed in the FortiLink debug output shown in the exhibit? (Choose two.)

Options:

A.

FortiSwitch is sending FortiLink heartbeats to FortiGate.

B.

FortiSwitch is discovered and authorized by FortiGate.

C.

FortiSwitch is in a waiting state to join the stack group on FortiGate.

D.

FortiSwitch is ready to push its new hostname to FortiGate.

Question 3

How does FortiSwitch perform actions on ingress and egress traffic using the access control list (ACL)?

Options:

A.

Only high-end FortiSwitch models support ACL.

B.

ACL can be used only at the prelookup stage in the traffic processing pipeline.

C.

Classifiers enable matching traffic based only on the VLAN ID.

D.

FortiSwitch checks ACL policies only from top to bottom.

Question 4

Exhibit.

LAG and MCLAG are used to increase the available network bandwidth and enable redundancy. How does spanning tree protocol see MCLAG and LAG if they are configured based on the physi-cal view shown in the exhibit? (Choose two)

Options:

A.

Switch 1. Switch 2, and Switch 3 are seen as one MCLAG peer group

B.

Switch 3 and Switch 4 uplinks are treated as single interfaces.

C.

Switch 3 and switch 4 are seen as one MCLAG switch client

D.

Switch 1 and Switch 2 both seen as one single switch.

Question 5

What is the role of a device that is simultaneously functioning as both the distribution and core in the hierarchy network model?

Options:

A.

POE with high density FortiSwitch

B.

FortiGate managing FortiSwitch

C.

FortiSwitch functioning as standalone

D.

HA backup FortiGate managing FortiSwitch

Question 6

Which QoS mechanism maps packets with specific CoS or DSCP markings to an egress queue?

Options:

A.

Queuing for egress traffic

B.

Classification for ingress traffic

C.

Rate limiting for egress traffic

D.

Marking for ingress traffic

Question 7

An administrator needs to deploy managed FortiSwitch devices in a remote location where multiple VLANs must be utilized to segment devices. No Layer 3 switch or router is present. The the only WAN connectivity is the router provided by the ISP connected to the public internet.

Which two items will the administrator need to use? (Choose two.)

Options:

A.

A FortiSwitch interface connected to the ISP router configured with fortilink-13-mode enabled.

B.

FortiSwitch and FortiGate devices configured with VXLAN interfaces.

C.

FortiSwitch devices configured with NAT disabled.

D.

FortiSwitch devices that have the required internal hardware for this configuration.

E.

FortiSwitch and FortiGate devices configured with IPsec interfaces.

Question 8

Refer to the diagnostic output:

Two entries in the exhibit show that the same MAC address has been used in two different VLANs. Which MAC address is shown in the above output?

Options:

A.

It is a MAC address of FortiLink interface on FortiGate.

B.

It is a MAC address of a switch that accepts multiple VLANs.

C.

It is a MAC address of an upstream FortiSwitch.

D.

It is a MAC address of FortiGate in HA configuration.

Question 9

What type of multimode transceiver can be used to split a 40G port?

Options:

A.

QSFP+ transceiver

B.

SFP transceiver

C.

QSFP transceiver

D.

SFP+ transceiver

Question 10

Refer to the exhibits.

Port1 and port2 are the only ports configured with the same native VLAN 10.

What are two reasons that can trigger port1 to shut down? (Choose two.)

Options:

A.

port1 was shut down by loop guard protection.

B.

STP triggered a loop and applied loop guard protection on port1.

C.

An endpoint sent a BPDU on port1 that it received from another interface.

D.

Loop guard frame sourced from port 1 was received on port 1.

Question 11

Exhibit.

Two routes are not installed in the forwarding information base (FIB) as shown in the exnibit. Which two statements about these two route entries are true? (Choose two.)

Options:

A.

These two routes have a higher administrative distance value available to the destina-tion networks.

B.

These two routes will become primary, if the best routes are removed.

C.

These two routes will be used as load-balancing routes.

D.

These two routes are available in the hardware routing table.

Question 12

Which two statements about VLAN assignments on FortiSwitch ports are true? (Choose two.)

Options:

A.

Configure a native VLAN on the FortiLink

B.

Assign an IP address and subnet mask to FortiSwitch VLANs

C.

Only assign one native VLAN on a port

D.

Assign untagged VLANs using FortiGate CLI

Question 13

Refer to the configuration:

Which two conditions does FortiSwitch need to meet to successfully configure the options shown in the exhibit above? (Choose two.)

Options:

A.

The FortiSwitch model is equipped with a maximum of 54 interfaces

B.

FortiSwitch would need to be rebooted.

C.

The split port can be assigned to a native VLAN.

D.

The Dort full speed prior to the split was 100G QSFP+.

Question 14

Which two statements about DHCP snooping enabled on a FortiSwitch VLAN are true? (Choose two.)

Options:

A.

Enabling DHCP snooping on a FortiSwitch VLAN ensures requests and replies are seen by all DHCP servers.

B.

switch-controller-dhcp-snooping-verify-mac verifies the destination MAC address to protect against DHCP exhaustion attacks.

C.

By default, all FortiSwitch ports are set to forward client DHCP requests to untrusted ports.

D.

Settings related to DHCP option 82 are only configurable through the CLI

Question 15

What can an administrator do to maintain a FortiGate-compatible FortiSwitch configuration when changing the management mode from standalone to FortiLinK?

Options:

A.

Use a migration tool based on Python script to convert the configuration.

B.

Enable the FortiLink setting on FortiSwitch before the authorization process.

C.

FortiGate automatically saves the existing FortiSwitch configuration during the FortiLink management process.

D.

Register FortiSwitch to FortiSwitch Cloud to save a copy before managing with FortiGate.

Question 16

Refer to the exhibit.

The exhibit shows the current status of the ports on the managed FortiSwitch. Access-1.

Why would FortiGate display a serial number in the Native VLAN column associated with the port23 entry?

Options:

A.

port23 is configured as the dedicated management interface.

B.

Ports connected to adjacent FortiSwitch devices show their serial number as the native VLAN.

C.

port23 is a member of a trunk that uses the Access-1 FortiSwitch serial number as the name of the trunk.

D.

A standalone switch with the shown serial number is connected on port23.