Weekend Biggest Discount Flat 70% Offer - Ends in 0d 00h 00m 00s - Coupon code: 70diswrap

Fortinet NSE6_FSW-7.2 Dumps

NSE6_FSW-7.2 - Fortinet NSE 6 - FortiSwitch 7.2 Questions and Answers

Question 1

Which is a requirement to enable SNMP v2c on a managed FortiSwitch?

Options:

A.

Create an SNMP user to use for authentication and encryption.

B.

Specify an SNMP host to send traps to.

C.

Enable an SNMP v3 to handle traps messages with SNMP hosts.

D.

Configure SNMP agent and communities.

Question 2

How does FortiGate handle configuration of flow tracking sampling if you export the settings to a managed FortiSwitch stack with sampling mode set to perimeter is true?

Options:

A.

FortiGate configures FortiSwitch to perform ingress sampling on all switch interfaces.

B.

FortiGate configures FortiSwitch to perform ingress sampling on all switch interfaces, except ICL and ISL interfaces.

C.

FortiGate configures and enables flow sampling on FortiSwitch but does not change existing sampling settings of interfaces.

D.

FortiGate configures and enables egress sampling on all management interfaces.

Question 3

What can an administrator do to maintain the existing standalone FortlSwltch configuration while changing the management mode to FortLink?

Options:

A.

Use a migration tool based on python script to convert the configuration

B.

Enable the Forti-link setting on FortiSwitch before the authorization process

C.

FortiGate will automatically save the existing FortiSwitch configuration during the Forti-link management process.

D.

Register FortiSwitch to For1ISwitch Cloud to save a copy before managing by Forti-Gate.

Question 4

Exhibit.

as

port1 and port2 are the only ports configured with the same native VLAN 10.

What are two reasons that can trigger port1 to shut down? (Choose two.)

Options:

A.

port1 was shut down by loop guard protection.

B.

STP triggered a loop and applied loop guard protection on port1.

C.

An endpoint sent a BPDU on port1 that it received from another interface.

D.

Loop guard frame sourced from port1 was received on port1.

Question 5

Refer to the exhibits

as

as

Traffic arriving on port2 on FortiSwitch is tagged with VLAN ID 10 and destined for PC1 connected on port1. PC1 expects to receive traffic untagged from port1 on FortiSwitch.

Which two configurations can you perform on FortiSwitch to ensure PC1 receives untagged traffic on port1? (Choose two.)

Options:

A.

Add the MAC address of PCI as a member of VLAN 10.

B.

Add VLAN ID 10 as a member of the untagged VLANs on port1.

C.

Remove VLAN 10 from the allowed VLANs and add it to untagged VLANs on port1.

D.

Enable Private VLAN on VLAN 10 and add VLAN 20 as an isolated VLAN.

Question 6

Which QoS mechanism maps packets with specific CoS or DSCP markings to an egress queue?

Options:

A.

Queuing for egress traffic

B.

Classification for ingress traffic

C.

Rate limiting for egress traffic

D.

Marking for ingress traffic

Question 7

Refer to the configuration:

as

Which two conditions does FortiSwitch need to meet to successfully configure the options shown in the exhibit above? (Choose two.)

Options:

A.

The FortiSwitch model is equipped with a maximum of 54 interfaces

B.

FortiSwitch would need to be rebooted.

C.

The split port can be assigned to a native VLAN.

D.

The Dort full speed prior to the split was 100G QSFP+.

Question 8

Which drop policy mode, if assigned to a congested port, will drop incoming packets until there is no congestion on the egress port?

Options:

A.

Tail-drop mode

B.

Weighted round robin mode.

C.

Random early detection mode

D.

Strict mode

Question 9

Which statement about using MAC, IP, and protocol-based VLANs on FortiSwitch is true?

Options:

A.

lt is a scalable and secure solution in comparison to other Layer 2 security measures.

B.

FortiSwitch uses only the Ethernet type to assign traffic to VLANs.

C.

It provides benefits that can be obtained when using 802.1X authentication.

D.

Endpoints are required to use the same FortiSwitch port to remain members of the VLAN.

Question 10

Which statement about the configuration of VLANs on a managed FortiSwitch port is true?

Options:

A.

Untagged VLANs must be part of the allowed VLANs: ingress and egress.

B.

FortiSwitch VLAN interfaces are created only when FortiSwitch is managed by Forti-Gate.

C.

The native VLAN is implicitly part of the allowed VLAN on the port.

D.

Allowed VLANS expand the collision domain to the port.

Question 11

How does FortiSwitch perform actions on ingress and egress traffic using the access control list (ACL)?

Options:

A.

Only high-end FortiSwitch models support ACL.

B.

ACL can be used only at the prelookup stage in the traffic processing pipeline.

C.

Classifiers enable matching traffic based only on the VLAN ID.

D.

FortiSwitch checks ACL policies only from top to bottom.

Question 12

FortiGate is unable to establish a tunnel with the FortiSwitch device it is supposed to manage Based on the debug output shown in the exhibit, what is the reason for the failure?

Options:

A.

The handshake process timed out before FortiSwitch responded.

B.

DTLS client hello had the incorrect pre-shared key.

C.

The CAPWAP tunnel failed to come up due to a mismatch in time.

D.

FortiSwitch has disabled FortiLink and is only managed as a standalone.

Question 13

Refer to the exhibit.

as

The exhibit shows the current status of the ports on the managed FortiSwitch. Access-1.

Why would FortiGate display a serial number in the Native VLAN column associated with the port23 entry?

Options:

A.

port23 is configured as the dedicated management interface.

B.

Ports connected to adjacent FortiSwitch devices show their serial number as the native VLAN.

C.

port23 is a member of a trunk that uses the Access-1 FortiSwitch serial number as the name of the trunk.

D.

A standalone switch with the shown serial number is connected on port23.

Question 14

Refer to the exhibit.

as

What two conclusions can be made regarding DHCP snooping configuration? (Choose two.)

Options:

A.

Maximum value to accept clients DHCP request is configured as per DHCP server range.

B.

FortiSwitch is configured to trust DHCP replies coming on FortiLink interface.

C.

DHCP clients that are trusted by DHCP snooping configured is only one.

D.

Global configuration for DHCP snooping is set to forward DHCP client requests on all ports in the VLAN.

Question 15

Refer to the diagnostic output:

as

What makes the use of the sniffer command on the FortiSwitch CLI unreliable on__port__23?

Options:

A.

The types of packets captured is limited.

B.

Just the port egress payloads are printed on CLI.

C.

Only untagged VLAN traffic can be captured.

D.

The switch port might be used as a trunk member

Question 16

Exhibit.

as

LAG and MCLAG are used to increase the available network bandwidth and enable redundancy. How does spanning tree protocol see MCLAG and LAG if they are configured based on the physi-cal view shown in the exhibit? (Choose two)

Options:

A.

Switch 1. Switch 2, and Switch 3 are seen as one MCLAG peer group

B.

Switch 3 and Switch 4 uplinks are treated as single interfaces.

C.

Switch 3 and switch 4 are seen as one MCLAG switch client

D.

Switch 1 and Switch 2 both seen as one single switch.

Page: 1 / 6
Total 55 questions