FORTINET · NSE5_FSW_AD-7.6

Fortinet NSE5_FSW_AD-7.6 Exam Practice Questions

64 questionsPDF by emailUpdated September 2026

US$39

Try 10 questions free

Card, Apple Pay or Google Pay. Your PDF is sent by email as soon as you check out.

Pass or your money backFail the exam after using this pack and we refund it. How the guarantee works
Category:
TRY BEFORE YOU BUY

Three of the 64 questions in this pack

Question 1

Which two are valid traffic processing actions that a FortiSwitch access control list (ACL) can apply to matching traffic? (Choose two.)

  1. Redirect frames to another port.
  2. Assign traffic to a high-priority egress queue.
  3. Encrypt frames.
  4. Drop frames.
Show answer and explanation

Correct answer: B, D

B. Assign traffic to a high-priority egress queue. D. Drop frames. FortiSwitch ACLs can apply traffic processing actions including dropping frames and assigning traffic to egress queues for QoS purposes. These are standard Layer 2 switch capabilities. Redirecting frames to another port and encrypting frames are not valid ACL actions on FortiSwitch devices.

Why the other options are wrong

  • A. Frame redirection to another port is not a standard FortiSwitch ACL action.
  • C. Encryption of frames is not performed by ACLs; encryption would be handled at higher network layers.

Question 2

Which two statements about 802.1X authentication on FortiSwitch ports are true? (Choose two.)

  1. In port-based 802.1x, all hosts behind an authenticated port are allowed access after a successful authentication.
  2. A port policy is used to apply 802.1x authentication on a FortiSwitch interface.
  3. 802.1X authentication can be applied only to trunk ports and not access ports.
  4. All devices connecting to FortiSwitch must support 802.1X authentication.
Show answer and explanation

Correct answer: A, B

A. In port-based 802.1x, all hosts behind an authenticated port are allowed access after a successful authentication. B. A port policy is used to apply 802.1x authentication on a FortiSwitch interface. In port-based 802.1X, once a port is authenticated, all hosts connected behind that port are allowed access without individual authentication. Port policies are used to apply 802.1X authentication on FortiSwitch interfaces. 802.1X can be applied to both access and trunk ports, and not all devices are required to support 802.1X for network operation.

Why the other options are wrong

  • C. 802.1X can be applied to both access ports and trunk ports, not exclusively to trunk ports.
  • D. Not all devices need to support 802.1X; only devices needing authenticated access require this capability.

Question 3

Refer to the exhibits.

Topology view -Core-1 CLI output -Core-2 CLI output -An administrator has deployed two FortiSwitch devices, Core-1 and Core-2, as multichassis link aggregation group (MCLAG) peers. These switches are connected to FortiGate for FortiLink and to an access switch (Access-1) using an inter-switch link (ISL). After configuration, the administrator notices that both Core-1 and Core-2 are claiming to be the root bridge in the Multiple Spanning Tree Protocol (MSTP) topology.

What explains this behavior?

Exhibit for question 3

Exhibit for question 3

Exhibit for question 3

  1. FortiGate participates in MSTP and causes both switches to assume the root bridge role.
  2. The ISL was not configured correctly, leading to MSTP inconsistency.
  3. Both switches share the same bridge ID because MCLAG treats them as one logical switch.
  4. MCLAG automatically disables STP on all peer switches.
Show answer and explanation

Correct answer: C. Both switches share the same bridge ID because MCLAG treats them as one logical switch.

MCLAG treats them as one logical switch. In MCLAG (Multi-Chassis Link Aggregation Group), the two peer switches are logically treated as a single entity and share the same bridge MAC address and bridge ID. This is evident from the CLI output where both Core-1 and Core-2 display identical bridge MAC addresses (02090f000701) and identical priority values (20480), both claiming to be the root bridge. This shared bridge identity is the fundamental design of MCLAG, it presents a unified logical switch to the network, which includes presenting a single bridge ID in MSTP. Both switches legitimately claim the root role because they literally share the same identity, and this is correct behavior for an MCLAG deployment.

Why the other options are wrong

  • A. FortiGate does not participate in MSTP; it connects via FortiLink which is separate from the spanning tree topology managed by the switches.
  • B. The ISL is functioning correctly as evidenced by the MC-LAG ICL indicator in the topology diagram; MSTP inconsistency would manifest differently, not with both switches claiming root with identical bridge IDs.
  • D. MCLAG does not disable STP; rather, it requires STP/MSTP to function properly for loop prevention, and both switches continue to participate in MSTP as a unified logical entity.

See all 10 free questions Get the full pack, US$39

64 practice questions for Fortinet NSE 5, FortiSwitch 7.6 Administrator (NSE5_FSW_AD-7.6), with full explanations.

Every question comes with the correct answer, the reasoning behind it, and a short note on why each wrong option is wrong. Work through it once with the answers, then again with the questions-only copy under exam conditions.

  • 64 questions mapped to the NSE5_FSW_AD-7.6 exam description
  • Answers and explanations for every question, including the wrong options
  • A questions-only PDF for timed practice runs
  • Instant delivery by email the moment you check out
  • Free monthly updates for as long as the exam is live
  • Pass or your money back

A NSE5_FSW_AD-7.6 attempt costs US$400. This pack is US$39, paid once.

Try 10 questions free before you buy.

Last updated September 2026 · 64 questions

What makes the NSE 5 FortiSwitch exam hard

NSE5_FSW_AD-7.6 is the FortiSwitch exam under Fortinet’s July 2026 rebranding, where the product-level exams took NSE 4, 5 and 6 numbering and the FCP Secure Networking track kept the same structure underneath. It evaluates applied knowledge of FortiSwitch on FortiSwitchOS 7.6 integrated with FortiOS 7.6, through supported deployment topologies, operational scenarios, configuration extracts and troubleshooting captures, with standalone mode tested alongside FortiLink management.

The exam is built around four areas: FortiSwitch concepts and management modes, deployment and management over FortiLink including MCLAG and tiered topologies, Layer 2 control and security covering VLANs, spanning tree, link aggregation, port security and 802.1X, and monitoring and troubleshooting with packet capture and the diagnose switch command set.

Candidates consistently report that the tagging and native VLAN questions and the CLI-output questions are where marks are lost, so it is worth practising reading physical-ports summaries before sitting it.

About the exam

NSE5_FSW_AD-7.6 (Fortinet NSE 5, FortiSwitch 7.6 Administrator) is a product exam counting towards the Fortinet Certified Professional, Secure Networking certification. It covers FortiSwitch concepts and management modes, deployment and management over FortiLink, Layer 2 control and security, and monitoring and troubleshooting on FortiSwitchOS 7.6 with FortiOS 7.6. There are no prerequisites; Fortinet recommends the FortiSwitch course and hands-on experience.

Exam topics

  • FortiSwitch concepts and management modes
  • Deployment and management over FortiLink
  • Layer 2 control and security
  • Monitoring and troubleshooting

Fortinet does not publish weightings. About 30 multiple choice questions, 60 minutes, US$400 per attempt, Pearson VUE test centre (Fortinet is withdrawing OnVUE delivery for some exams from 21 September 2026), pass or fail reported without a published percentage, certification valid for two years.

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Questions before you buy

What do I get when I buy the Fortinet NSE5_FSW_AD-7.6 pack?

64 practice questions as a PDF, each with the correct answer, a full explanation and a note on why the other options are wrong, plus a separate questions-only PDF for timed practice.

How quickly do I receive it?

Your PDF is prepared and sent to your email address after checkout, and you get a confirmation as soon as it is on its way.

Is there a free sample?

Yes. Ten questions from this pack, with answers and explanations, are free on this page and as a PDF, so you can judge the quality before you pay.

Are updates included?

Yes. The pack is updated every month for as long as the exam is live, and updates are free for everyone who has bought it.

What if I fail the exam?

We refund the pack. Sit the exam 7 to 30 days after buying, then send your official score report within 7 days of the exam date, as set out in the refund policy.

Can I share it with colleagues?

Each purchase is licensed to one person. For a team, school or training organisation, email support@certstash.com for a licence that fits.