Pre-Winter Sale Special 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: ex2p65

Exact2Pass Menu

Question # 4

Which two statements about VLAN assignments on FortiSwitch ports are true? (Choose two.)

A.

Configure a native VLAN on the FortiLink

B.

Assign an IP address and subnet mask to FortiSwitch VLANs

C.

Only assign one native VLAN on a port

D.

Assign untagged VLANs using FortiGate CLI

Full Access
Question # 5

Exhibit.

port1 and port2 are the only ports configured with the same native VLAN 10.

What are two reasons that can trigger port1 to shut down? (Choose two.)

A.

Loop guard frame sourced from port 1 was received VLAN 10 ports.

B.

STP triggered a loop and applied loop guard protection on port1.

C.

Oport1 was shut down by loop guard protection.

D.

An endpoint sent BPDU on port1 it received from another interface.

Full Access
Question # 6

Which statement about the quarantine VLAN on FortiSwitch is true?

A.

Quarantine VLAN has no DHCP server

B.

Users who fail 802.1X authentication can be placed on the quarantine VLAN.

C.

It is only used for quarantined devices if global setting is set to quarantine by VLAN.

D.

FortiSwitch can block devices without configuring quarantine VLAN to be part of the allowed VLANs.

Full Access
Question # 7

What type of multimode transceiver can be used to split a 40G port?

A.

QSFP+ transceiver

B.

SFP transceiver

C.

QSFP transceiver

D.

SFP+ transceiver

Full Access
Question # 8

Which statement about 802.1X security profiles using MAC-based authentication mode is true?

A.

FortiSwitch allows connectivity to all hosts connected to a port, if one host is authenticated.

B.

FortiSwitch can grant each device a different access level based on the credentials provided

C.

FortiSwitch performs faster when using this security mode on the ports.

D.

FortiSwitch must communicate with the RADIUS server to authenticate devices

Full Access
Question # 9

Refer to the exhibit.

The profile shown in the exhibit is assigned to a group of managed FortiSwitch ports, and these ports are connected to endpoints which are powered by PoE.

Which configuration action can you perform on the LLDP profile to cause these endpoints to exchange PoE information and negotiate power with the managed FortiSwitch?

A.

Create new a LLDP-MED application type to define the PoE parameters.

B.

Assign a new LLDP profile to handle different LLDP-MED TLVs.

C.

Define an LLDP-MED location ID to use standard protocols for power.

D.

Add power management as part of LLDP-MED TLVs to advertise.

Full Access
Question # 10

What are two ways in which automatic MAC address quarantine works on FortiSwitch? (Choose two.)

A.

FortiSwitch supports only by VLAN quarantine mode.

B.

FortiGate applies the quarantine-related configuration only on FortiGate.

C.

FortiAnalyzer with a threat detection services license is required.

D.

MAC address quarantine can be enabled through the FortiGate CLI only.

Full Access
Question # 11

Which is a requirement to enable SNMP v2c on a managed FortiSwitch?

A.

Create an SNMP user to use for authentication and encryption.

B.

Specify an SNMP host to send traps to.

C.

Enable an SNMP v3 to handle traps messages with SNMP hosts.

D.

Configure SNMP agent and communities.

Full Access
Question # 12

Which QoS mechanism maps packets with specific CoS or DSCP markings to an egress queue?

A.

Queuing for egress traffic

B.

Classification for ingress traffic

C.

Rate limiting for egress traffic

D.

Marking for ingress traffic

Full Access
Question # 13

Refer to the exhibit.

Which two statements best describe what is displayed in the FortiLink debug output shown in the exhibit? (Choose two.)

A.

FortiSwitch is sending FortiLink heartbeats to FortiGate.

B.

FortiSwitch is discovered and authorized by FortiGate.

C.

FortiSwitch is in a waiting state to join the stack group on FortiGate.

D.

FortiSwitch is ready to push its new hostname to FortiGate.

Full Access
Question # 14

Which packet capture method allows FortiSwitch to capture traffic on trunks and management interfaces?

A.

SPAN

B.

Sniffer profile

C.

sFlow

D.

TCP dump

Full Access
Question # 15

How does FortiGate handle configuration of flow tracking sampling if you export the settings to a managed FortiSwitch stack with sampling mode set to perimeter is true?

A.

FortiGate configures FortiSwitch to perform ingress sampling on all switch interfaces.

B.

FortiGate configures FortiSwitch to perform ingress sampling on all switch interfaces, except ICL and ISL interfaces.

C.

FortiGate configures and enables flow sampling on FortiSwitch but does not change existing sampling settings of interfaces.

D.

FortiGate configures and enables egress sampling on all management interfaces.

Full Access
Question # 16

Which two statements about managing a FortiSwitch stack on FortiGate are true? (Choose two.)

A.

A FortiLink interface must be enabled on FortiGate.

B.

The switch controller feature must be enabled on FortiGate.

C.

Only a hardware-based FortiGate can manage a FortiSwitch stack.

D.

FortiSwitch must be operating in standalone mode before authorization.

Full Access