NSE6-FSW-7-2 Sample Questions & Answers
Choosing the right topology and FortiSwitch model gets the heaviest weighting, built on managing switches over FortiLink or FortiCloud, VLANs, IGMP, and QoS basics, port security and filtering, and SNMP- or sFlow-based monitoring.
Launch the full NSE6-FSW-7-2 simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
FortiSwitch monitoring and troubleshooting · Use SNMP and sFlow to monitor FortiSwitch and ports
A network operations team is experiencing intermittent high CPU utilization on a core FortiSwitch. They suspect an application is generating excessive broadcast or unknown unicast traffic, but enabling storm control has not logged any dropped packets. To identify the source traffic without the performance impact of a full packet capture (SPAN), what is the most appropriate monitoring feature to configure?
Show answer & explanation
Correct answer: B
sFlow is designed for this exact purpose. It provides statistical sampling of network packets, which gives a clear view of traffic patterns, top talkers, and types of traffic (like broadcast or multicast) without the high overhead of mirroring every single packet. This allows the operations team to analyze traffic trends and identify the source of the excessive traffic on an external collector, making it the most efficient and appropriate tool for this troubleshooting scenario.
graph TD subgraph Core FortiSwitch A[Interface 1] --> S((sFlow Agent)) B[Interface 2] --> S end S -- Sampled Packets --> C[sFlow Collector/Analyzer] subgraph NOC C --> Admin[Admin Workstation] end Admin -->|Analyzes Traffic| C - Question 2Beginner
Layer 2 control and security · Use port security options on FortiSwitch
True or False: When configuring 802.1X port-based authentication on a FortiSwitch, a 'Guest VLAN' can be configured to automatically assign limited network access to endpoints that fail the RADIUS authentication process.
Show answer & explanation
Correct answer: A
This statement is true. A key feature of robust 802.1X implementations, including on FortiSwitch, is the ability to define a Guest VLAN. If a device connects to an 802.1X-enabled port and fails to authenticate correctly against the RADIUS server, the switch can be configured to place the device into this pre-defined Guest VLAN. This provides a fallback mechanism, allowing the device limited access (e.g., internet only) instead of no access at all.
- Question 3Intermediate
Network planning and design · Configure STP to prevent network loops
A network architect is implementing Multiple Spanning Tree Protocol (MSTP) on a multi-tier FortiSwitch campus network to optimize load balancing for different VLANs. What is the most critical configuration parameter that must be identical across all switches participating in the same MSTP region to ensure they can interoperate correctly?
Show answer & explanation
Correct answer: C
For switches to be considered part of the same MSTP region, they must share three identical attributes: the configuration name, the revision number, and the VLAN-to-instance mapping table. A hash of these values is included in the MSTP BPDUs. If a switch receives a BPDU with a different hash, it considers the sending switch to be in a different region. This consistency is absolutely critical for MSTP to function as intended.
- Question 4Intermediate
FortiSwitch monitoring and troubleshooting · Use available tools to view and extract network information from FortiSwitch
A network engineer is troubleshooting a FortiSwitch stack and needs to verify the health and statistics of the dedicated link between the two chassis in the MCLAG domain. Which CLI command will display this specific information?
diagnose switch mclag ______Show answer & explanation
Correct answer: D
The correct command is
diagnose switch mclag icl. This command provides detailed information specifically about the Inter-Chassis Link (ICL), which is the critical connection that carries synchronization and data traffic between the two switches in an MCLAG pair. The output includes status, member ports, and traffic statistics, which are essential for troubleshooting MCLAG health. - Question 5Advanced
Layer 2 control and security · Use ACLs, security profiles, and VLAN security mechanisms on FortiSwitch
A financial services company is using FortiSwitch Private VLANs (PVLANs) to enforce strict Layer 2 isolation for servers belonging to different clients, even though they are in the same IP subnet. A shared backup server must be able to initiate connections to all isolated client servers. The client servers must not be able to communicate with each other. What PVLAN port type must be configured for the port connected to the shared backup server?
Show answer & explanation
Correct answer: C
In a Private VLAN architecture, there are three port types. 'Isolated' ports can only communicate with promiscuous ports. 'Community' ports can communicate with each other and with promiscuous ports. 'Promiscuous' ports can communicate with all isolated and community ports within the PVLAN. Since the backup server needs to connect to all isolated client servers, its port must be configured as promiscuous.
- Question 6AdvancedSelect 2
Layer 2 control and security · Use available filtering and antispoofing techniques on FortiSwitch
A security consultant is implementing a defense-in-depth strategy on the access layer of a corporate network using FortiSwitches. The goal is to prevent common attacks such as IP spoofing, MAC spoofing, and ARP poisoning on ports connected to end-user devices. The consultant plans to use a combination of DHCP Snooping, Dynamic ARP Inspection (DAI), and IP Source Guard. Which TWO of the following statements accurately describe the configuration and dependencies of these features? (Select TWO)
Show answer & explanation
Correct answers: B, D
This is a correct statement. Both DAI and IP Source Guard rely on the binding database created and maintained by DHCP Snooping. This database maps legitimate IP addresses, MAC addresses, VLANs, and ports from valid DHCP transactions. Without this database, these features cannot dynamically validate traffic.
This statement accurately describes the function of DAI. It intercepts ARP requests and replies on untrusted ports and compares the information with the DHCP Snooping binding table to ensure that only devices with valid, DHCP-assigned IP addresses can have their ARP packets forwarded.
- Question 7Intermediate
Network planning and design · Deploy FortiSwitch supported deployment topologies
A network engineer is designing a highly available campus core using a FortiGate HA Active-Passive cluster and a pair of FortiSwitches configured in an MCLAG. The FortiGate cluster connects to each FortiSwitch in the MCLAG pair via a FortiLink interface. The primary design goal is to ensure seamless failover and load balancing of traffic from the access layer to the FortiGate cluster. Which configuration approach correctly establishes the FortiLink between the FortiGate HA cluster and the FortiSwitch MCLAG pair?
graph TD subgraph FortiGate HA Cluster FG1(FortiGate 1 - Active) FG2(FortiGate 2 - Passive) FG1 ---|HA Heartbeat| FG2 end subgraph FortiSwitch MCLAG Pair FSW1(FortiSwitch 1) FSW2(FortiSwitch 2) FSW1 |ICL| FSW2 end FG1 -- FortiLink Port A --> FSW1 FG1 -- FortiLink Port B --> FSW2 FG2 -- FortiLink Port C --> FSW1 FG2 -- FortiLink Port D --> FSW2 AccessLayer[Access Layer Switches] --> FSW1 AccessLayer --> FSW2Show answer & explanation
Correct answer: B
This is the correct and recommended method for connecting a FortiGate (standalone or HA) to a FortiSwitch MCLAG pair. Creating an 802.3ad LACP aggregate interface on the FortiGate and a matching multi-chassis LACP trunk on the FortiSwitches allows for active-active link utilization, load balancing, and seamless failover without relying on STP convergence times. This design provides both link and device redundancy.
- Question 8Intermediate
FortiSwitch monitoring and troubleshooting · Use SNMP and sFlow to monitor FortiSwitch and ports
A network operations center (NOC) is investigating reports of poor application performance for users connected to a specific FortiSwitch access switch. The team suspects microbursts of traffic are causing packet loss, but standard SNMP polling of interface counters is not granular enough to confirm this theory. They need to collect detailed traffic flow data, including source/destination IPs, ports, and protocols, without adding significant processing overhead to the switch's CPU. Which monitoring feature is most suitable for this requirement?
Show answer & explanation
Correct answer: C
sFlow is designed for this exact purpose. It uses statistical packet sampling, which is performed in hardware on FortiSwitch, to gather detailed flow information with very low CPU impact. It provides visibility into traffic patterns (source/destination IPs, ports, protocols) that SNMP cannot, and it is far less resource-intensive than a full packet capture, making it the ideal tool for identifying transient issues like microbursts.
- Question 9Beginner
Manage and Provision FortiSwitch · Differentiate available FortiSwitch management operation modes
True or False: A FortiSwitch operating in standalone mode can be fully integrated into the Fortinet Security Fabric, allowing it to share telemetry and participate in automated threat responses orchestrated by a FortiGate.
Show answer & explanation
Correct answer: B
This statement is false. Full integration into the Fortinet Security Fabric, including telemetry sharing and automated responses, requires the FortiSwitch to be managed by a FortiGate via a FortiLink connection. A FortiSwitch in standalone mode operates as an independent device and does not have the necessary control plane integration with the FortiGate to be part of the core Security Fabric.
- Question 10Advanced
Network planning and design · Deploy and configure FortiSwitch in a multi-tenancy environment
A Managed Service Provider (MSP) is deploying a multi-tenant network using a single FortiGate in VDOM mode. Each tenant requires a dedicated, managed FortiSwitch stack. The MSP's goal is to maintain strict administrative and traffic isolation between tenants while using a shared FortiLink connection from the FortiGate to a central distribution FortiSwitch.
Current Setup:
- A FortiGate 1800F is configured with two VDOMs: TenantA_VDOM and TenantB_VDOM.
- A central distribution FortiSwitch DS-1 connects to the FortiGate's FortiLink aggregate interface.
- Tenant A has a FortiSwitch stack (TS-A) connected to DS-1.
- Tenant B has a FortiSwitch stack (TS-B) connected to DS-1.
Requirements:
- The TenantA_VDOM must manage only the TS-A stack.
- The TenantB_VDOM must manage only the TS-B stack.
- Traffic from Tenant A must be completely isolated from Tenant B at Layer 2 on the distribution switch.
- The solution must be scalable for adding more tenants.
Which configuration approach meets all the MSP's requirements?
graph TD subgraph FortiGate VDOM_A[TenantA_VDOM] VDOM_B[TenantB_VDOM] end FortiGate -- FortiLink LACP --- DS1(Distribution Switch DS-1) DS1 -- Trunk --- TSA(Tenant A Stack) DS1 -- Trunk --- TSB(Tenant B Stack)Show answer & explanation
Correct answer: D
This is the correct and most scalable solution for FortiSwitch multi-tenancy. By creating a VLAN-based FortiLink interface on the FortiGate, you can create multiple logical FortiLink instances (split interfaces) over a single physical link or LACP bundle. Each split interface is assigned a unique VLAN and associated with a specific VDOM. This ensures that discovery and management traffic for each tenant is tagged and isolated, allowing the respective VDOM to manage only its assigned switches. The other options either lack proper administrative isolation, are not scalable, or use incorrect configuration constructs.
Ready for the real thing?
The full NSE6-FSW-7-2 simulator has every exam-style question, timed mode, and instant scoring.