Fortinet
NSE5_FSW_AD-7.6
Fortinet NSE 5 - FortiSwitch 7.6 Administrator
Exam Version: 8.0
Questions & Answers PDF
(Demo Version - Limited Content)
For More Information - Visit link below:
https://p2pexam.com/nse5_fsw_ad-7.6
, Question 1. (Multi Select)
Which two statements about DHCP snooping enabled on a FortiSwitch VLAN are true? (Choose two.)
A: Enabling DHCP snooping on a FortiSwitch VLAN ensures requests and replies are seen by all DHCP
servers.
B: switch-controller-dhcp-snooping-verify-mac verifies the destination MAC address to protect against
DHCP exhaustion attacks.
C: By default, all FortiSwitch ports are set to forward client DHCP requests to untrusted ports.
D: Settings related to DHCP option 82 are only configurable through the CLI
Answer: B, D
Explanation:
Switch-controller-dhcp-snooping-verify-mac verifies the destination MAC address to protect against DHCP
exhaustion attacks (B): This feature of DHCP snooping helps prevent DHCP exhaustion attacks by
ensuring that the destination MAC addresses in DHCP packets match the MAC addresses learned by the
switch. This check helps prevent attackers from overwhelming the DHCP server with requests from
spoofed MAC addresses.
Settings related to DHCP option 82 are only configurable through the CLI (D): DHCP Option 82 is used for
"agent information," and it's typically used in network environments where additional information between
DHCP clients and servers is necessary for policy and billing purposes. Configuration of these settings in
FortiSwitch is only available through the Command Line Interface (CLI), not the Graphical User Interface
(GUI).
Question 2. (Single Select)
Which statement about the quarantine VLAN on FortiSwitch is true?
A: Quarantine VLAN has no DHCP server
B: Users who fail 802.1X authentication can be placed on the quarantine VLAN.
C: It is only used for quarantined devices if global setting is set to quarantine by VLAN.
D: FortiSwitch can block devices without configuring quarantine VLAN to be part of the allowed VLANs.
Answer: B
https://p2pexam.com/nse5_fsw_ad-7.6 Page 2 of 8
NSE5_FSW_AD-7.6
Fortinet NSE 5 - FortiSwitch 7.6 Administrator
Exam Version: 8.0
Questions & Answers PDF
(Demo Version - Limited Content)
For More Information - Visit link below:
https://p2pexam.com/nse5_fsw_ad-7.6
, Question 1. (Multi Select)
Which two statements about DHCP snooping enabled on a FortiSwitch VLAN are true? (Choose two.)
A: Enabling DHCP snooping on a FortiSwitch VLAN ensures requests and replies are seen by all DHCP
servers.
B: switch-controller-dhcp-snooping-verify-mac verifies the destination MAC address to protect against
DHCP exhaustion attacks.
C: By default, all FortiSwitch ports are set to forward client DHCP requests to untrusted ports.
D: Settings related to DHCP option 82 are only configurable through the CLI
Answer: B, D
Explanation:
Switch-controller-dhcp-snooping-verify-mac verifies the destination MAC address to protect against DHCP
exhaustion attacks (B): This feature of DHCP snooping helps prevent DHCP exhaustion attacks by
ensuring that the destination MAC addresses in DHCP packets match the MAC addresses learned by the
switch. This check helps prevent attackers from overwhelming the DHCP server with requests from
spoofed MAC addresses.
Settings related to DHCP option 82 are only configurable through the CLI (D): DHCP Option 82 is used for
"agent information," and it's typically used in network environments where additional information between
DHCP clients and servers is necessary for policy and billing purposes. Configuration of these settings in
FortiSwitch is only available through the Command Line Interface (CLI), not the Graphical User Interface
(GUI).
Question 2. (Single Select)
Which statement about the quarantine VLAN on FortiSwitch is true?
A: Quarantine VLAN has no DHCP server
B: Users who fail 802.1X authentication can be placed on the quarantine VLAN.
C: It is only used for quarantined devices if global setting is set to quarantine by VLAN.
D: FortiSwitch can block devices without configuring quarantine VLAN to be part of the allowed VLANs.
Answer: B
https://p2pexam.com/nse5_fsw_ad-7.6 Page 2 of 8