最新のNSE6_FSW-7.2日本語実際の無料試験問題更新された57問あります [Q33-Q54]

Share

最新のNSE6_FSW-7.2日本語実際の無料試験問題更新された57問あります

無料で使えるNSE6_FSW-7.2日本語試験ブレーン問題集認定ガイドの問題と解答

質問 # 33
展示する。

この展示には、管理対象 FortiSwitch のポートの現在のステータスが表示されます。
アクセス-1.
FortiGate がポート 23 エントリに関連付けられたネイティブ VLAN 列にシリアル番号を表示するのはなぜですか?

  • A. ポート 23 は専用の管理インターフェイスとして構成されています。
  • B. showm シリアル番号を持つスタンドアロン スイッチが por123 に接続されています。
  • C. 隣接する FortiSwitch デバイスに接続するポートには、そのシリアル番号がネイティブ VLAN として表示されます。
  • D. Port23 は、Access-1 FortiSwitch の番号をトランク名として使用するトランクのメンバーです。

正解:B

解説:
The appearance of a serial number in the Native VLAN column for port23 suggests that the switch connected to this port is identified uniquely in the network. Given the options provided:
A standalone switch with the shown serial number is connected on port23 (Option C): This is the most plausible explanation. The FortiSwitch configuration interface is displaying the serial number of a standalone switch that is directly connected to port23. This kind of display helps in identifying and managing individual devices in a network setup, especially in environments with multiple switches.


質問 # 34
管理者は、デバイスをセグメント化するために複数の VLAN を使用する必要があるリモートの場所に管理対象 FortiSwitch デバイスを展開する必要があります。レイヤ 3 スイッチまたはルーターが存在しません。唯一の WAN 接続は、公共のインターネットに接続されている ISP が提供するルーターです。
管理者が使用する必要がある 2 つの項目はどれですか? (2つお選びください。)

  • A. IPsec インターフェイスで構成された FortiSwitch および FortiGate デバイス。
  • B. この構成に必要な内部ハードウェアを備えた FortiSwitch デバイス。
  • C. fortilink-13-mode が有効に設定された ISP ルーターに接続された FortiSwitch インターフェイス。
  • D. VXLAN インターフェイスで構成された FortiSwitch および FortiGate デバイス。
  • E. NAT が無効に設定された FortiSwitch デバイス。

正解:C、E

解説:
To deploy FortiSwitch in a remote location with multiple VLANs and no Layer 3 switch or router, you would need specific configurations:
VXLAN Interfaces (B):
Purpose: VXLAN (Virtual Extensible LAN) allows network segmentation without a Layer 3 device, extending VLAN capabilities across dispersed geographical locations over the WAN.
Implementation: Configuring VXLAN on both FortiSwitch and FortiGate can encapsulate Layer 2 traffic over a Layer 3 network, making it ideal for scenarios lacking dedicated routing hardware.
Appropriate Hardware (D):
Requirement: Not all FortiSwitch models might support advanced features like VXLAN; hence, ensuring that the hardware can support such configurations is crucial.
Reference:
For specific information on VXLAN configuration and hardware requirements, refer to the technical documentation provided by Fortinet: Fortinet Product Documentation


質問 # 35
展示する。

LAG と MCLAG は、利用可能なネットワーク帯域幅を増やし、冗長性を有効にするために使用されます。展示品に示されている物理ビューに基づいて設定されている場合、スパニング ツリー プロトコルは MCLAG と LAG をどのように認識しますか? (2つお選びください)

  • A. スイッチ 1。スイッチ 2 およびスイッチ 3 は 1 つの MCLAG ピア グループとして認識されます。
  • B. スイッチ 3 とスイッチ 4 のアップリンクは単一のインターフェイスとして扱われます。
  • C. スイッチ 3 とスイッチ 4 は 1 つの MCLAG スイッチ クライアントとして見なされます
  • D. スイッチ 1 とスイッチ 2 は両方とも 1 つの単一スイッチとして認識されます。

正解:C、D


質問 # 36
展示を参照してください。

Core-1 と Access-1 は FortiGate-1 によって管理および承認されます。これはポート4をFortiLinkインターフェイスとして使用します。 FortiGate が Core-2 を認証および管理した後。ポート1の状態はSTP廃棄状態になります。
port1 が廃棄状態になっているのはなぜですか?

  • A. Access-1 はルート ブリッジであり、ルート ポートを 1 つだけ持つことができます。
  • B. Core-2 のブリッジ優先度は最も低くなります。
  • C. Core-1 と Core-2 には MCLAG 構成がありません。
  • D. Core-2 のポート 1 は管理トラフィックのみを廃棄しています。

正解:C

解説:
The STP (Spanning Tree Protocol) discarding state on port1 of Core-2, after Core-1 and Access-1 are managed and authorized by FortiGate-1, is likely due to the lack of an MCLAG (Multi-Chassis Link Aggregation Group) configuration between Core-1 and Core-2. In typical network configurations involving STP and MCLAG, the absence of MCLAG can lead to STP blocking one of the redundant paths to prevent loops, which is a critical function of STP. Port1 on Core-2 being in a discarding state suggests that it has been identified as providing a redundant path that could potentially create a network loop, hence STP has placed this port in a blocking (discarding) state to maintain a loop-free topology.
Reference:
For a deeper understanding of STP operations and MCLAG configurations in FortiGate managed environments, consult the Fortinet knowledge base: Fortinet Knowledge Base.


質問 # 37
スイッチ ポート アナライザ(SPAN)パケット キャプチャ方式の使用に関する記述のうち、正しいものはどれですか?

  • A. モニタリング デバイスは、トラフィックがミラーリングされているのと同じスイッチに接続する必要があります
  • B. SPAN はスタンドアロン FortiSwitch でのみ設定できます。
  • C. ミラーリングされたトラフィックは複数のスイッチ間で送信できます。
  • D. 管理インターフェイス上のトラフィックは、監視デバイスによってミラーリングおよびキャプチャできます。

正解:C

解説:
The correct statement about using the Switch Port Analyzer (SPAN) packet capture method on FortiSwitch is that "Mirrored traffic can be sent across multiple switches (A)." This feature allows for extensive traffic analysis as it enables network administrators to configure SPAN sessions that span across different switches, thereby providing the capability to monitor traffic across a broad segment of the network infrastructure.


質問 # 38
境界が true に設定されたサンプリング モードを使用して、管理対象 FortiSwitch スタックに設定をエクスポートする場合、FortiGate はフロー追跡サンプリングの構成をどのように処理しますか?

  • A. FortiGate は、すべてのスイッチ インターフェイスで入力サンプリングを実行するように FortiSwitch を構成します。
  • B. FortiGate は FortiSwitch でフロー サンプリングを設定して有効にしますが、インターフェースの既存のサンプリング設定は変更しません。
  • C. FortiGate は、すべての管理インターフェースで出力サンプリングを設定し、有効にします。
  • D. FortiGate は、ICL および ISL インターフェースを除くすべてのスイッチ インターフェースで入力サンプリングを実行するように FortiSwitch を構成します。

正解:D

解説:
When FortiGate exports configuration settings to a managed FortiSwitch stack with sampling mode set to "perimeter is true," the behavior is:
B . FortiGate configures FortiSwitch to perform ingress sampling on all switch interfaces, except ICL and ISL interfaces. This setting ensures that all incoming traffic on normal operational ports is sampled for monitoring and analysis purposes, but it excludes the inter-chassis link (ICL) and inter-switch link (ISL) interfaces from sampling. These exclusions are typically made to prevent the duplication of sampled data and to reduce unnecessary load on the monitoring system, as these links often carry traffic already monitored at other points.
Options A and D are incorrect because they either generalize the sampling across all interfaces without exceptions or incorrectly specify egress sampling on management interfaces. Option C is also incorrect as FortiGate can modify existing sampling settings to fit the perimeter-based configuration requirement.


質問 # 39
展示する。

どの構成変更により、管理対象 FortiSwitch が任意のソースからの SNMP リクエストを受け入れることができるようになりますか?

  • A. SNMP 専用の新しいローカル アクセス プロファイルを作成します。
  • B. スイッチの内部インターフェイスで SNMP を有効にします。
  • C. スイッチの管理インターフェイスに SNMP サービスを追加します。
  • D. SNMP トラップを送信するように SNMP ホストを構成します。

正解:D


質問 # 40
FortiSwitch での MAC、IP、およびプロトコルベースの VLAN の使用に関する記述のうち、正しいのはどれですか?

  • A. エンドポイントは、VLAN のメンバーであり続けるために同じ FortiSwitch ポートを使用する必要があります。
  • B. 他のレイヤ 2 セキュリティ対策と比較して、スケーラブルで安全なソリューションです。
  • C. FortiSwitch は、トラフィックを VLAN に割り当てるためにイーサネット タイプのみを使用します。
  • D. 802.1X 認証を使用するときに得られる利点を提供します。

正解:D


質問 # 41
FortiSwitch は、アクセス コントロール リスト (ACL) を使用して、イングレス トラフィックおよびエグレス トラフィックに対してアクションをどのように実行しますか?

  • A. ハイエンド FortiSwitch モデルのみが ACL をサポートします。
  • B. FortiSwitch は ACL ポリシーを上から下までのみチェックします。
  • C. 分類子を使用すると、VLAN ID のみに基づいてトラフィックを照合できます。
  • D. ACL は、トラフィック処理パイプラインの事前検索段階でのみ使用できます。

正解:B


質問 # 42
IGMP クエリアによって処理される不要な IGMP レポートの数を減らすには、どの機能を有効にする必要がありますか?

  • A. すべてのマルチキャスト グループの静的ポートで IGMP フラッド設定を有効にします。
  • B. IGMP スヌーピング プロキシを有効にします。
  • C. グローバル設定で IGMP フラッド未知のマルチキャスト トラフィックを有効にします。
  • D. mRouter ポートで IGMP フラッド レポート設定を有効にします。

正解:B

解説:
Enable IGMP snooping proxy (C): To reduce the number of unwanted IGMP reports processed by the IGMP querier, enabling IGMP snooping proxy is effective. This feature acts as an intermediary between multicast routers and hosts, optimizing the management of IGMP messages by handling report messages locally and reducing unnecessary IGMP traffic across the network. This minimizes the processing load on the IGMP querier and improves overall network efficiency.


質問 # 43
階層ネットワーク モデルにおいてディストリビューションとコアの両方として同時に機能するデバイスの役割は何ですか?

  • A. FortiSwitch を管理する FortiGate
  • B. 高密度 FortiSwitch を備えた POE
  • C. FortiSwitch を管理する HA バックアップ FortiGate
  • D. FortiSwitch はスタンドアロンとして機能します

正解:A

解説:
In a hierarchical network model, the role of a device functioning simultaneously as both the distribution and core is most accurately described as "FortiGate managing FortiSwitch (B)." In this setup, FortiGate acts as the central unit managing multiple FortiSwitch units, thereby functioning both as a distribution layer-handling traffic between network segments-and as a core layer-managing traffic within the network on a broader scale. This setup is typical in medium-sized networks where a single device is capable enough to handle both roles effectively.


質問 # 44
展示を参照してください。

展示に示されている FortiLink デバッグ出力に表示される内容を最もよく説明している 2 つのステートメントはどれですか? (2つお選びください。)

  • A. FortiSwitch は FortiLink ハートビートを FortiGate に送信しています。
  • B. FortiSwitch は FortiGate によって検出され、承認されます。
  • C. FortiSwitch は、新しいホスト名を FortiGate にプッシュする準備ができています。
  • D. FortiSwitch は、FortiGate 上のスタック グループに参加するのを待機状態にあります。

正解:A、B


質問 # 45
展示品を参照


FortiSwitch のポート 2 に到着するトラフィックは、VLAN ID 10 でタグ付けされ、ポート 1 に接続されている PC1 を宛先としています。 PC1 は、FortiSwitch のポート 1 からタグなしのトラフィックを受信することを期待しています。
PC1 がポート 1 でタグなしトラフィックを受信できるようにするために、FortiSwitch で実行できる 2 つの構成はどれですか? (2つお選びください。)

  • A. PCI の MAC アドレスを VLAN 10 のメンバーとして追加します。
  • B. VLAN 10 を許可された VLAN から削除し、ポート 1 のタグなし VLAN に追加します。
  • C. VLAN ID 10 をポート 1 のタグなし VLAN のメンバーとして追加します。
  • D. VLAN 10 でプライベート VLAN を有効にし、VLAN 20 を分離 VLAN として追加します。

正解:A、C

解説:
The two reasons why port1 can be shut down are loop guard protection and Spanning Tree Protocol (STP).
Loop guard protection: This is a feature that helps to prevent switching loops in a network.expand_more A loop guard can be configured on a port to monitor for specific traffic patterns that indicate a loop. If loop guard protection detects a loop, it will shut down the port to prevent the loop from causing problems.
STP: STP is a protocol that helps to prevent switching loops.expand_more When multiple paths exist between two network devices, STP will block all but one of the paths, creating a loop-free topology.expand_more If STP detects a loop, it will shut down the ports that are involved in the loop.
In the exhibit, both ports 1 and 2 are configured with the same native VLAN 10. This configuration could create a switching loop if both ports are connected to devices on the same network segment. If a loop occurs, loop guard protection or STP could shut down port1 to prevent the loop from causing problems.
Reference:
Fortinet FortiSwitch 7.2 Administration Guide https://docs.fortinet.com/document/fortigate/7.4.3/administration-guide/954635/getting-started


質問 # 46
FortiSwitch での MAC、IP、およびプロトコルベースの VLAN の使用に関する記述のうち、正しいのはどれですか?

  • A. エンドポイントは、VLAN のメンバーであり続けるために同じ FortiSwitch ポートを使用する必要があります。
  • B. 他のレイヤ 2 セキュリティ対策と比較して、スケーラブルで安全なソリューションです。
  • C. FortiSwitch は、トラフィックを VLAN に割り当てるためにイーサネット タイプのみを使用します。
  • D. 802.1X 認証を使用するときに得られる利点を提供します。

正解:D

解説:
It provides benefits that can be obtained when using 802.1X authentication (C): MAC, IP, and protocol-based VLANs on FortiSwitch are beneficial in network environments where additional granularity is needed in traffic segmentation and security, similar to what can be achieved through 802.1X authentication. These VLAN types allow for dynamic assignment of ports to VLANs based on the characteristics of the incoming traffic, enhancing both security and network efficiency.


質問 # 47
VLAN 上で有効になっている場合の IGMP スヌーピング クエリアに関する記述はどれですか?

  • A. 間接的に接続されている他のすべてのスイッチは、IGMP マルチキャスト トラフィックを取得できなくなります。
  • B. アクティブなマルチキャスト レシーバー エントリは、VLAN 上で送信される各 IGMP クエリでエージングされます。
  • C. VLAN 上の IGMP レポートはすべてのスイッチ ポートに転送されます。
  • D. この設定は、FortiSwitch CLI を使用してのみ有効にできます。

正解:B

解説:
Active multicast receiver entries are aging on each IGMP query sent on the VLAN (A): When IGMP snooping querier is enabled on a VLAN, it functions to manage multicast traffic within the VLAN by keeping track of multicast group memberships. The IGMP querier sends queries to determine which ports require the multicast traffic. The multicast receiver entries, which are entries that indicate which devices have requested the multicast data, age or time out based on these IGMP queries. Each query refreshes active connections but ages out entries that no longer respond, helping to ensure that multicast traffic is only sent to ports with active receivers.


質問 # 48
FortiSwitch ではトラフィックはどのようにルーティングされますか?

  • A. レイヤー 3 ルーティングは FortiGate によって管理されながら、FortiSwitch 上で設定できます。
  • B. FortiSwitch はハードウェア ルーティング テーブルを検索し、次に転送情報ベース (FIB) を検索します。
  • C. FortiSwitch 上のハードウェアベースのルーティングは CPU によって処理されます。
  • D. ASIC ハードウェア ルーティングは、サポートされている場合、動的ルーティングのみを処理できます。

正解:A


質問 # 49
展示を参照してください。

DHCP スヌーピング設定に関して、次の 2 つの結論が得られますか? (2つお選びください。)

  • A. クライアントの DHCP 要求を受け入れる最大値は、DHCP サーバー範囲ごとに設定されます。
  • B. 設定されている DHCP スヌーピングによって信頼される DHCP クライアントは 1 つだけです。
  • C. FortiSwitch は、FortiLink インターフェイスからの DHCP 応答を信頼するように設定されています。
  • D. DHCP スヌーピングのグローバル設定は、VLAN 内のすべてのポートで DHCP クライアント要求を転送するように設定されています。

正解:B、C


質問 # 50
FortiGate の「VLAN リダイレクト MAC アドレス隔離」モードと「リダイレクト MAC アドレス隔離」モードはどのように似ていますか?

  • A. どちらのモードでも、VLAN 間のトラフィックをブロックするファイアウォール ポリシーが必要です。
  • B. どちらのモードも、FortiGate によって VLAN 内トラフィックを自動的にブロックします。
  • C. どちらのモードも、隔離されたデバイスの MAC アドレスをブロックされたファイアウォール アドレス グループに追加します。
  • D. どちらのモードも、隔離されたデバイスを隔離 VLAN に移動します。

正解:B


質問 # 51
FortiSwitch は、アクセス コントロール リスト (ACL) を使用して、イングレス トラフィックおよびエグレス トラフィックに対してアクションをどのように実行しますか?

  • A. ハイエンド FortiSwitch モデルのみが ACL をサポートします。
  • B. FortiSwitch は ACL ポリシーを上から下までのみチェックします。
  • C. 分類子を使用すると、VLAN ID のみに基づいてトラフィックを照合できます。
  • D. ACL は、トラフィック処理パイプラインの事前検索段階でのみ使用できます。

正解:B

解説:
In FortiSwitch, Access Control Lists (ACLs) are used to enforce security rules on both ingress and egress traffic:
ACL Evaluation Order (D):
Operational Function: FortiSwitch processes ACL entries from top to bottom, similar to how firewall rules are processed. The first match in the ACL determines the action taken on the packet, whether to allow or deny it, making the order of rules critical.
Configuration Advice: Careful planning of the order of ACL rules is necessary to ensure that more specific rules precede more general ones to avoid unintentional access or blocks.
Reference:
For a comprehensive guide on configuring ACLs in FortiSwitch, consult the FortiSwitch security settings documentation available on: Fortinet Product Documentation


質問 # 52
展示品をご参照ください。


同じネイティブ VLAN 10 で構成されているポートはポート 1 とポート 2 だけです。
ポート 1 のシャットダウンを引き起こす 2 つの理由は何ですか? (2つお選びください。)

  • A. STP がループをトリガーし、ポート 1 にループ ガード保護を適用しました。
  • B. エンドポイントは、別のインターフェイスから受信した BPDU をポート 1 に送信しました。
  • C. ポート 1 から送信されたループ ガード フレームがポート 1 で受信されました。
  • D. ポート 1 はループ ガード保護によってシャットダウンされました。

正解:A、B


質問 # 53
展示を参照してください。

この展示には、管理対象 FortiSwitch のポートの現在のステータスが表示されます。アクセス-1.
FortiGate がポート 23 エントリに関連付けられたネイティブ VLAN 列にシリアル番号を表示するのはなぜですか?

  • A. ポート 23 は専用の管理インターフェイスとして構成されます。
  • B. port23 は、トランクの名前として Access-1 FortiSwitch シリアル番号を使用するトランクのメンバーです。
  • C. 隣接する FortiSwitch デバイスに接続されているポートには、そのシリアル番号がネイティブ VLAN として表示されます。
  • D. 示されたシリアル番号を持つスタンドアロン スイッチがポート 23 に接続されています。

正解:D


質問 # 54
......

NSE6_FSW-7.2日本語認定概要最新のNSE6_FSW-7.2日本語のPDF問題集:https://www.passtest.jp/Fortinet/NSE6_FSW-7.2-JPN-shiken.html