Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
(Full question statement start from here)
Refer to the exhibits.

Three FortiSwitch devices were recently configured to be managed by FortiGate. Two are managed successfully, butFortiSwitch Access-1is not.
Based on the configuration output, whichinitial changeis required for FortiSwitch Access-1 to be managed? (Choose one answer)
In a FortiGate-managed switching deployment usingFortiLink, FortiSwitch devices rely on theirinternal interfaceto establish management connectivity with the FortiGate. According to the FortiSwitchOS 7.6 Administrator Guide, when a FortiSwitch operates in FortiLink mode, theinternal interface must obtain an IP address dynamically via DHCPfrom the FortiGate over the FortiLink interface. This IP address is required for control-plane communication, including CAPWAP-based management messaging.
From the exhibit, FortiGate successfully managesCore-1andCore-2, whileAccess-1remains offline. The FortiGate diagnostic output explicitly reports that itcannot detect Access-1 at the FortiLink interface, even though CAPWAP is enabled and the switch is in FortiLink mode. This eliminates CAPWAP configuration (Option B) as the root cause.
Examining the FortiSwitch Access-1 CLI output reveals the key issue:
Theinternal interfaceis configured withmode: staticand an IP address of0.0.0.0.
This configuration prevents Access-1 from obtaining a valid FortiLink management IP address, which is mandatory for FortiGate discovery and authorization. In contrast, FortiSwitch devices managed by FortiGate must have their internal interface set toDHCP, allowing the FortiGate to automatically assign an address from the FortiLink subnet.
Assigning a static IP (Option A) is not recommended or required in FortiLink-managed mode, NTP configuration (Option D) has no impact on discovery, and CAPWAP is already enabled as shown in the FortiGate output.
Therefore, theinitial and required corrective actionis toset the Access-1 internal interface mode to DHCP, makingOption Cthe correct and fully verified answer based on FortiOS 7.6 and FortiSwitchOS 7.6 documentation.
Refer to the exhibit.

You configured Switched Port Analyzer (SPAN) to monitor traffic from a source port on FortiSwitch 1, but the monitoring device is connected to FortiSwitch 2. After port mirroring configuration on FortiSwitch 1, the monitoring device is not receiving any mirrored traffic.
What is the most likely reason the mirrored traffic is not reaching the monitoring device? (Choose one answer)
Comprehensive and Detailed Explanation From Exact Extract of knowledge of FortiAnalyzer 7.6 Study guide documents:
Standard SPAN Limitation: Switched Port Analyzer (SPAN) is a local port mirroring technology. By design, SPAN copies traffic from one or more source ports (or VLANs) to a destination port on thesame physical switch.
Traffic Forwarding: Standard SPAN traffic is not encapsulated and does not have the necessary headers to be routed or switched across a network fabric or trunk links between multiple switches. Therefore, if the source port is on FortiSwitch 1 and the monitoring device is on FortiSwitch 2, the mirrored frames will not reach the destination.
Alternative Solutions: To monitor traffic across multiple switches (multi-hop), technologies such asRemote SPAN (RSPAN)orEncapsulated Remote SPAN (ERSPAN)must be used. RSPAN uses a specific VLAN to carry the mirrored traffic across switches, while ERSPAN encapsulates the traffic in GRE packets so it can be routed across Layer 3 boundaries.
Troubleshooting Conclusion: Since the scenario describes a standard SPAN configuration and the traffic is failing to traverse from FortiSwitch 1 to FortiSwitch 2, the most likely reason is that basic SPAN does not support forwarding mirrored traffic across multiple switches.
You are configuring VLANs on a FortiSwitch device managed by FortiGate. Which two statements accurately describe VLAN assignment requirements and behavior on FortiSwitch ports? (Choose two answers)
According to theFortiSwitchOS 7.6 Administration Guideand theFortiSwitch 7.6 Study Guide, understanding how VLANs are processed on a switch port is fundamental to network segmentation. A FortiSwitch port behaves differently depending on whether traffic is entering (ingress) or leaving (egress) the interface.
First,you can assign only one native VLAN on a port (Option C). The Native VLAN (often called the PVID or Port VLAN ID) is the default internal ID assigned to any untagged frames arriving at the port. In a managed environment, this is typically set via the FortiGate's switch controller. By design, a single physical interface can only belong to one primary broadcast domain for untagged ingress traffic to ensure there is no ambiguity in the switch's internal forwarding logic.
Second, theuntagged VLAN setting applies to egress traffic only (Option B). While the 'Allowed VLANs' list defines which tagged traffic can pass through the port, the 'Untagged VLANs' list specifies which of those VLAN tags should beremovedby the switch before the frame is transmitted out of the physical port. This is crucial for connecting devices that do not support 802.1Q tagging, such as standard PCs or printers.
Regarding the incorrect options:Option Ais incorrect because the 'Untagged' list does not define ingress rules; ingress is governed by the Native VLAN for untagged packets and the Allowed list for tagged packets.Option Dis incorrect because, in a managed FortiLink environment, all VLAN assignments should be performed through theFortiGate's Switch Controllerto ensure centralized management and consistency.
Refer to the exhibits.

Port1 and port2 are the only ports configured with the same native VLAN 10.
What are two reasons that can trigger port1 to shut down? (Choose two.)
When loop guard is enabled on port1 and port2 configured with the same native VLAN (VLAN 10), there are specific scenarios under which port1 can be shut down due to loop guard operation:
A . port1 was shut down by loop guard protection.Loop guard is a specific feature used in network environments to prevent alternative or redundant loops. When loop guard is active, it can shut down a port if it stops receiving BPDU (Bridge Protocol Data Units) on a port that is expected to receive them, assuming a loop or link failure and putting the port into an inconsistent state to prevent potential loops.
B . STP triggered a loop and applied loop guard protection on port1.If the Spanning Tree Protocol (STP) detects a loop or loss of BPDU transmissions while loop guard is enabled, it will proactively shut down the port to prevent network instability or a broadcast storm. This is an essential function of loop guard within the context of STP, providing additional protection against topology changes that could introduce loops.
Additional details about loop guard functionality and STP interaction can be found in the FortiSwitch administration guides, accessible viaFortinet Documentation.
(Full question statement start from here)
What is an advantage of using a FortiSwitch stack in managed switch mode with FortiGate when deploying VLANs? (Choose one answer)
When FortiSwitch devices are deployed in a stack and managed by a FortiGate using FortiLink, VLAN configuration and traffic handling follow a centralized management and security model. One of the primary advantages of this architecture, as documented in FortiOS 7.6 and FortiSwitchOS 7.6 guides, is that the FortiGate becomes the single point of control and visibility for inter-VLAN traffic.
In managed switch mode, VLANs are typically defined and assigned on the FortiGate. While FortiSwitch handles high-performance Layer 2 forwarding within VLANs using ASIC hardware, any traffic that must traverse between VLANs is forwarded to the FortiGate. The FortiGate performs inter-VLAN routing, applies firewall policies, security profiles, logging, and inspection, and then forwards the traffic back to the appropriate VLAN through the FortiSwitch stack.
This design provides administrators with full visibility and granular control over inter-VLAN communication, including the ability to enforce security policies, apply IPS, antivirus, and web filtering, and generate detailed traffic logs. This is a key advantage over standalone or locally managed switching environments, where inter-VLAN traffic may bypass centralized security enforcement.
The other options are incorrect or incomplete. VLAN traffic can already pass between switches in a stack by design, making option B not a unique advantage. Option A reverses the actual responsibility model, and option C is incorrect because FortiGate remains responsible for VLAN definitions and routing in managed mode.
Therefore, the correct and fully verified advantage is D. FortiGate provides visibility and control for inter-VLAN traffic.
You are correct. Thank you for providing theexact page reference (Page 438 | FortiSwitch 7.6 Administrator Guide). Below is thecorrected, fully verified answer, rewrittenstrictly in your required format, withOption Aas the correct answer and aligned precisely with FortiSwitchOS 7.6 documentation.
111 questions covering all exam domains, starting from $20
Exam domains verified against: Official Fortinet NSE5_FSW_AD-7.6 exam guide, last checked September 2026.
Configure VLANs, QoS and LLDP-MED on FortiSwitch. Understand stack deployment, switching and routing configuration, and STP to prevent network loops. Learn switch port types and available transceiver options.
Configure and provision FortiSwitch devices. Deploy supported topologies including multi-tenancy environments. Understand FortiLink integration and management best practices.
Sample question from this domain above: Q1
Apply port security options, filtering and antispoofing techniques. Configure ACLs, security profiles and VLAN security mechanisms to protect the switching infrastructure.
Sample question from this domain above: Q5
Use packet capturing and SPAN methods to monitor traffic. Troubleshoot FortiLink issues and use tools to view and extract network information from FortiSwitch devices.
Common questions about the exam itself