Fortinet NSE 5 - FortiSwitch 7.6 Administrator - NSE5_FSW_AD-7.6 模擬練習
(Full question statement start from here)
You enable Dynamic Host Configuration Protocol (DHCP) snooping on a VLAN and configure a FortiSwitch port astrustedfor DHCP snooping. What additional step is required to configure the port as trusted for Dynamic ARP Inspection (DAI)? (Choose one answer)
You enable Dynamic Host Configuration Protocol (DHCP) snooping on a VLAN and configure a FortiSwitch port astrustedfor DHCP snooping. What additional step is required to configure the port as trusted for Dynamic ARP Inspection (DAI)? (Choose one answer)
正解: B
解説: (PassTest メンバーにのみ表示されます)
Which statement about 802.1X security profiles using MAC-based authentication mode is true?
正解: C
解説: (PassTest メンバーにのみ表示されます)
(Full question statement start from here)
Refer to the exhibit.



Which information does FortiGate use to generate the port details in the FortiSwitch Faceplates view?
(Choose one answer)
Refer to the exhibit.



Which information does FortiGate use to generate the port details in the FortiSwitch Faceplates view?
(Choose one answer)
正解: A
解説: (PassTest メンバーにのみ表示されます)
Refer to the exhibits.

All three FortiSwitch-connected ports are configured in VLAN 10. FortiGate acts as the Dynamic Host Configuration Protocol (DHCP) server and is connected to a DHCP snooping trusted trunk port. PC1 and PC2 are connected to ports configured as untrusted for Dynamic ARP Inspection (DAI), and no static bindings are configured in the IP source guard (IPSG) database. PC2 is compromised and attempts to spoof the FortiGate IP address by sending forged Address Resolution Protocol (ARP) replies with its own MAC address. What will FortiSwitch do with the ARP packets from PC2? (Choose one answer)

All three FortiSwitch-connected ports are configured in VLAN 10. FortiGate acts as the Dynamic Host Configuration Protocol (DHCP) server and is connected to a DHCP snooping trusted trunk port. PC1 and PC2 are connected to ports configured as untrusted for Dynamic ARP Inspection (DAI), and no static bindings are configured in the IP source guard (IPSG) database. PC2 is compromised and attempts to spoof the FortiGate IP address by sending forged Address Resolution Protocol (ARP) replies with its own MAC address. What will FortiSwitch do with the ARP packets from PC2? (Choose one answer)
正解: D
解説: (PassTest メンバーにのみ表示されます)
You are deploying a multitier FortiSwitch topology with redundant links between access and aggregation switches. The team is considering Multiple Spanning Tree Protocol (MSTP) to manage spanning tree across multiple VLANs. Which two Rapid STP (RSTP) features would be useful in this deployment to ensure fast convergence and predictable port roles? (Choose two answers)
正解: B,C
解説: (PassTest メンバーにのみ表示されます)
On supported FortiSwitch models, which access control list (ACL) stage is recommended for applying actions before the switch performs any layer 2 or layer 3 processing? (Choose one answer)
正解: C
解説: (PassTest メンバーにのみ表示されます)