Black Friday Special Sale - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: mxmas70

Home > Fortinet > Fortinet Certification > NSE6_FSW-7.2

NSE6_FSW-7.2 NSE6_FSW-7.2 - Fortinet NSE 6 - FortiSwitch 7.2 Question and Answers

Question # 4

Refer to the exhibit.

The profile shown in the exhibit is assigned to a group of managed FortiSwitch ports, and these ports are connected to endpoints which are powered by PoE.

Which configuration action can you perform on the LLDP profile to cause these endpoints to exchange PoE information and negotiate power with the managed FortiSwitch?

A.

Create new a LLDP-MED application type to define the PoE parameters.

B.

Assign a new LLDP profile to handle different LLDP-MED TLVs.

C.

Define an LLDP-MED location ID to use standard protocols for power.

D.

Add power management as part of LLDP-MED TLVs to advertise.

Full Access
Question # 5

How is traffic routed on FortiSwitch?

A.

Hardware-based routing on FortiSwitch is handled by the CPU.

B.

FortiSwitch looks up the hardware routing table and then the forwarding information base (FIB).

C.

ASIC hardware routing can only handle dynamic routing, if supported.

D.

Layer 3 routing can be configured on FortiSwitch, while managed by FortiGate.

Full Access
Question # 6

Exhibit.

What conditions does a FortiSwitch need to have to successfully configure the options shown in the exhibit above? (Choose two.)

A.

The FortiSwitch model is equipped with a maximum of 54 interfaces.

B.

The CLI commands are enabling a splitpo rt into four 10Gbps interfaces.

C.

The port full speed prior the split was 100G SFP+

D.

The split port can be assigned to native VLAN

Full Access
Question # 7

FortiGate is unable to establish a tunnel with the FortiSwitch device it is supposed to manage Based on the debug output shown in the exhibit, what is the reason for the failure?

A.

The handshake process timed out before FortiSwitch responded.

B.

DTLS client hello had the incorrect pre-shared key.

C.

The CAPWAP tunnel failed to come up due to a mismatch in time.

D.

FortiSwitch has disabled FortiLink and is only managed as a standalone.

Full Access
Question # 8

Which drop policy mode, if assigned to a congested port, will drop incoming packets until there is no congestion on the egress port?

A.

Tail-drop mode

B.

Weighted round robin mode.

C.

Random early detection mode

D.

Strict mode

Full Access
Question # 9

Which statement about the use of the switch port analyzer (SPAN) packet capture method is true?

A.

Mirrored traffic can be sent across multiple switches.

B.

SPAN can be configured only on a standalone FortiSwitch.

C.

Traffic on the management interface can be mirrored and captured by the monitoring device.

D.

The monitoring device must be connected to the same switch where the traffic is being mirrored

Full Access
Question # 10

Exhibit.

The exhibit shows the current status of the ports on the managed FortiSwitch.

Access-1.

Why would FortiGate display a serial number in the Native VLAN column associated with the port23 entry?

A.

Port23 is a member of a trunk that uses the Access-1 FortiSwitch senal number as the name of the trunk.

B.

Port23 is configured as the dedicated management interface.

C.

A standalone switch with the showm serial number is connected on por123.

D.

Ports connect to adjacent FortiSwitch devices will show their.serial number as the na-tive VLAN

Full Access
Question # 11

What type of multimode transceiver can be used to split a 40G port?

A.

QSFP+ transceiver

B.

SFP transceiver

C.

QSFP transceiver

D.

SFP+ transceiver

Full Access
Question # 12

Refer to the diagnostic output:

What makes the use of the sniffer command on the FortiSwitch CLI unreliable on__port__23?

A.

The types of packets captured is limited.

B.

Just the port egress payloads are printed on CLI.

C.

Only untagged VLAN traffic can be captured.

D.

The switch port might be used as a trunk member

Full Access
Question # 13

Which two statements about the FortiLink authorization process are true? (Choose two.)

A.

The administrator must manually pre-authorize FortiGate on FortiSwitch by adding the FortiGate serial number.

B.

FortiSwitch requires a reboot to complete the authorization process.

C.

A FortiLink frame is sent by FortiGate to FortiSwitch to complete the authorization.

D.

FortiLink authorization sets the FortiSwitch management mode to FortiLink.

Full Access
Question # 14

Which interfaces on FortiSwitch send out FortiLink discovery frames by default in order to detect a FortiGate with an enabled FortiLink interface?

A.

All ports have auto-discovery enabled by default.

B.

No ports are enabled by default for auto-discovery. This must be configured under config switch interface.

C.

The ports with auto-discovery enabled by default are dependent upon the FortiSwitch model.

D.

The last four switch ports on FortiSwitch have auto-discovery enabled by default.

Full Access
Question # 15

Which two statements about 802.1X authentication on FortiSwitch ports are true? (Choose two.)

A.

All hosts behind an authenticated port are allowed access after a successful authentica-tion.

B.

A security policy is used to apply 802.1 authentication on a port.

C.

A local user database must be used to authenticate devices using the 802.1X authentica-tion protocol.

D.

All devices connecting to FortiSwitch must support 802.1X authentication.

Full Access
Question # 16

Which feature should you enable to reduce the number or unwanted IGMP reports processed by the IGMP querier?

A.

Enable the IGMP flood setting on the static port for all multicast groups.

B.

Enable the IGMP flood reports setting on the mRouter port.

C.

Enable IGMP snooping proxy.

D.

Enable IGMP flood unknown multicast traffic on the global setting.

Full Access