11.11 Special Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: scxmas70

NSE6_FSW-7.2 Exam Dumps - NSE6_FSW-7.2 - Fortinet NSE 6 - FortiSwitch 7.2

Question # 4

Refer to the diagnostic output:

What makes the use of the sniffer command on the FortiSwitch CLI unreliable on__port__23?

A.

The types of packets captured is limited.

B.

Just the port egress payloads are printed on CLI.

C.

Only untagged VLAN traffic can be captured.

D.

The switch port might be used as a trunk member

Full Access
Question # 5

Which two statements about VLAN assignments on FortiSwitch ports are true? (Choose two.)

A.

Configure a native VLAN on the FortiLink

B.

Assign an IP address and subnet mask to FortiSwitch VLANs

C.

Only assign one native VLAN on a port

D.

Assign untagged VLANs using FortiGate CLI

Full Access
Question # 6

Which statement about using MAC, IP, and protocol-based VLANs on FortiSwitch is true?

A.

lt is a scalable and secure solution in comparison to other Layer 2 security measures.

B.

FortiSwitch uses only the Ethernet type to assign traffic to VLANs.

C.

It provides benefits that can be obtained when using 802.1X authentication.

D.

Endpoints are required to use the same FortiSwitch port to remain members of the VLAN.

Full Access
Question # 7

How does FortiGate handle configuration of flow tracking sampling if you export the settings to a managed FortiSwitch stack with sampling mode set to perimeter is true?

A.

FortiGate configures FortiSwitch to perform ingress sampling on all switch interfaces.

B.

FortiGate configures FortiSwitch to perform ingress sampling on all switch interfaces, except ICL and ISL interfaces.

C.

FortiGate configures and enables flow sampling on FortiSwitch but does not change existing sampling settings of interfaces.

D.

FortiGate configures and enables egress sampling on all management interfaces.

Full Access
Question # 8

Which two statements about the FortiLink authorization process are true? (Choose two.)

A.

The administrator must manually pre-authorize FortiGate on FortiSwitch by adding the FortiGate serial number.

B.

FortiSwitch requires a reboot to complete the authorization process.

C.

A FortiLink frame is sent by FortiGate to FortiSwitch to complete the authorization.

D.

FortiLink authorization sets the FortiSwitch management mode to FortiLink.

Full Access
Question # 9

Which QoS mechanism maps packets with specific CoS or DSCP markings to an egress queue?

A.

Queuing for egress traffic

B.

Classification for ingress traffic

C.

Rate limiting for egress traffic

D.

Marking for ingress traffic

Full Access
Question # 10

Refer to the exhibit.

Core-1 and Access-1 are managed and authorized by FortiGate-1. which uses port4 as the FortiLink interface. After FortiGate authorizes and manages Core-2. Port1 status becomes STP discarding.

Why is port1 in the discarding state?

A.

port1 on Core-2 is discarding only management traffic.

B.

Core-1 and Core-2 do not have MCLAG configuration.

C.

Access-1 is the root bridge and can only have one root port.

D.

Core-2 has the lowest bridge priority.

Full Access
Question # 11

Exhibit.

port1 and port2 are the only ports configured with the same native VLAN 10.

What are two reasons that can trigger port1 to shut down? (Choose two.)

A.

Loop guard frame sourced from port 1 was received VLAN 10 ports.

B.

STP triggered a loop and applied loop guard protection on port1.

C.

Oport1 was shut down by loop guard protection.

D.

An endpoint sent BPDU on port1 it received from another interface.

Full Access
Question # 12

How are the 'by VLAN redirect MAC address quarantine' mode and the 'by redirect MAC address quarantine' mode on FortiGate similar?

A.

Both modes move quarantined devices to the quarantine VLAN.

B.

Both modes require firewall policies to block inter-VLAN traffic.

C.

Both modes add quarantined device MAC addresses to the blocked firewall address group.

D.

Both modes block intra-VLAN traffic by FortiGate automatically.

Full Access
Question # 13

Which two statements about DHCP snooping enabled on a FortiSwitch VLAN are true? (Choose two.)

A.

Enabling DHCP snooping on a FortiSwitch VLAN ensures requests and replies are seen by all DHCP servers.

B.

switch-controller-dhcp-snooping-verify-mac verifies the destination MAC address to protect against DHCP exhaustion attacks.

C.

By default, all FortiSwitch ports are set to forward client DHCP requests to untrusted ports.

D.

Settings related to DHCP option 82 are only configurable through the CLI

Full Access
Question # 14

Which statement about the use of the switch port analyzer (SPAN) packet capture method is true?

A.

Mirrored traffic can be sent across multiple switches.

B.

SPAN can be configured only on a standalone FortiSwitch.

C.

Traffic on the management interface can be mirrored and captured by the monitoring device.

D.

The monitoring device must be connected to the same switch where the traffic is being mirrored

Full Access
Question # 15

What can an administrator do to maintain the existing standalone FortlSwltch configuration while changing the management mode to FortLink?

A.

Use a migration tool based on python script to convert the configuration

B.

Enable the Forti-link setting on FortiSwitch before the authorization process

C.

FortiGate will automatically save the existing FortiSwitch configuration during the Forti-link management process.

D.

Register FortiSwitch to For1ISwitch Cloud to save a copy before managing by Forti-Gate.

Full Access
Question # 16

Refer to the exhibit.

The profile shown in the exhibit is assigned to a group of managed FortiSwitch ports, and these ports are connected to endpoints which are powered by PoE.

Which configuration action can you perform on the LLDP profile to cause these endpoints to exchange PoE information and negotiate power with the managed FortiSwitch?

A.

Create new a LLDP-MED application type to define the PoE parameters.

B.

Assign a new LLDP profile to handle different LLDP-MED TLVs.

C.

Define an LLDP-MED location ID to use standard protocols for power.

D.

Add power management as part of LLDP-MED TLVs to advertise.

Full Access