Fortinet · NSE5_FSW_AD-7.6
Validates the ability to deploy, configure, and manage FortiSwitch devices using FortiLink integration with FortiGate, covering Layer 2/3 features, MCLAG topologies, standalone mode, and FortiLAN Cloud management. Part of the Fortinet Certified Professional (FCP) Secure Networking certification track.
Practice Questions
600
≈ 10 practice exams
Duration
70 minutes
Passing Score
Pass/Fail
Difficulty
ProfessionalLast Updated
Apr 2026
Use this NSE5_FSW_AD-7.6 practice exam to prepare for Fortinet NSE 5 - FortiSwitch 7.6 Administrator (NSE5_FSW_AD-7.6) with realistic questions, detailed explanations, and focused study modes. The practice bank includes 600 questions for Fortinet NSE5_FSW_AD-7.6, so you can review the exam steadily instead of relying on one long cram session.
As you practice, pay extra attention to recurring topics such as FortiSwitch Architecture and Concepts, FortiLink Deployment and Management, VLAN Configuration and Control, Layer 2 Features and Switching, and Layer 3 Features and Routing. Start with short sessions to identify weak areas, then move into timed quizzes once your accuracy is consistent.
The explanations are especially useful when you want to connect exam wording to the responsibilities and scenarios described in the official certification guidance. Use the free preview first, then unlock the full question bank when you are ready to build a complete study routine.
The Fortinet NSE 5 - FortiSwitch 7.6 Administrator (NSE5_FSW_AD-7.6) is a professional-level certification exam that validates the skills required to deploy, configure, and manage FortiSwitch devices running FortiSwitchOS 7.6 within networks integrated with FortiOS 7.6. It covers the full spectrum of FortiSwitch administration, including FortiLink-based managed deployments, standalone operation, FortiLAN Cloud management, VLAN configuration, Layer 2/3 switching and routing, and MCLAG redundancy topologies. The exam is part of the Fortinet Certified Professional (FCP) – Secure Networking certification track, one of four specialization paths available at the FCP tier alongside SASE, Cloud Security, and Security Operations.
As a component of the Fortinet Security Fabric ecosystem, FortiSwitch devices managed through FortiLink integration with FortiGate bring unified policy enforcement and visibility to campus access layers. This exam verifies that candidates can operate FortiSwitch infrastructure in production environments, troubleshoot operational issues, and implement Layer 2 security controls such as port security, anti-spoofing, and ACLs — skills directly aligned with enterprise and campus network administration responsibilities.
This certification is designed for network and security professionals who are responsible for the day-to-day deployment, configuration, and management of FortiSwitch devices. Typical candidates include network administrators managing campus switching infrastructure, engineers integrating FortiSwitch into Fortinet Security Fabric environments via FortiLink, and MSP engineers administering multi-tenant FortiSwitch deployments.
Candidates with at least six months of hands-on FortiSwitch experience are best positioned for success. The exam is also relevant for professionals progressing along the Fortinet certification path who have already earned NSE 4 (FortiOS Administrator) and are pursuing the FCP – Secure Networking designation by choosing a complementary NSE 5 specialization.
There are no formal mandatory prerequisites for attempting the NSE5_FSW_AD-7.6 exam, but Fortinet recommends a minimum of six months of hands-on experience administering FortiSwitch devices before sitting the exam. Candidates should be comfortable navigating FortiSwitchOS 7.6 and FortiOS 7.6, particularly with respect to FortiLink configuration and VLAN management.
Completion of Fortinet's official FortiSwitch Administrator training course is strongly recommended, as its content maps directly to the exam domains. Candidates already holding the NSE 4 – FortiOS Administrator certification will have a practical advantage, since FortiLink integration and Security Fabric concepts covered at NSE 4 underpin much of the FortiSwitch management content tested at this level.
The NSE5_FSW_AD-7.6 exam consists of 35–40 scored questions and must be completed within 70 minutes. Questions are delivered in a mix of formats, including multiple-choice items that test conceptual understanding of FortiSwitch features and terminology, as well as scenario-based items that present real-world topology diagrams and operational situations requiring candidates to identify correct configurations or diagnose issues.
The exam is administered through Pearson VUE and is available in English and Japanese. The result is reported as pass or fail; Fortinet does not publicly disclose the specific passing score threshold, but a detailed score report is accessible from the candidate's Pearson VUE account following the exam.
Earning the NSE5_FSW_AD-7.6 credential contributes toward the Fortinet Certified Professional (FCP) – Secure Networking designation when combined with the NSE 4 – FortiOS Administrator exam. FCP-certified professionals are recognized as competent in deploying and managing Fortinet-based secure networking infrastructure, which is directly valued in enterprise IT, managed service provider, and government network environments. Relevant job titles include Network Administrator, Campus Network Engineer, FortiGate/FortiSwitch Administrator, SOC Operations Engineer, and MSP Network Engineer.
Fortinet certifications at the FCP tier are associated with mid-level compensation in the $110,000–$135,000 annual salary range in the United States as of 2025, with certified professionals often citing a measurable salary increase upon achieving the FCP designation. As Fortinet maintains a leading position in the enterprise firewall and secure networking market, demand for professionals with validated FortiSwitch administration skills remains consistent across organizations that have standardized on the Fortinet Security Fabric platform.
5 sample questions with answers and explanations. The full bank has 600 questions, enough for 10 full-length practice exams.
Preview — answers shown1. Northwind is configuring STP security features on their FortiSwitch deployment. They need to prevent unauthorized switches from being connected to access ports, and also prevent rogue switches on downstream ports from becoming the root bridge. How should BPDU Guard and Root Guard be deployed? (Select two!)
Multiple correct answersExplanation
BPDU Guard should be enabled on access ports facing end devices—if a BPDU is received, the port is err-disabled to prevent rogue switches from being attached. Root Guard should be enabled on ports facing downstream switches—if a superior BPDU is received, the port enters root-inconsistent (blocking) state to prevent unauthorized root bridge election. These two features must NOT be enabled on the same port, as BPDU Guard on uplink trunk ports would cause disruption.
2. Litware's network team is configuring DHCP Option 138 on their DHCP server for zero-touch provisioning of FortiSwitch devices. The switches need to automatically contact the provisioning server at 10.50.100.200. What is the purpose of DHCP Option 138 in this context? (Select one!)
Explanation
DHCP Option 138 is used in FortiSwitch zero-touch provisioning to supply the IP address of the FortiManager or FortiGate controller. When a FortiSwitch boots without a pre-existing configuration, it sends a DHCP request and receives Option 138 in the response. The switch then uses this IP address to contact the management platform for automatic configuration download. This eliminates the need for manual console access on each switch during deployment. TFTP firmware downloads, DNS suffix assignment, and NTP configuration are all different DHCP options unrelated to Option 138.
3. Contoso is calculating STP convergence time for their legacy network running classic 802.1D STP (not RSTP). The network uses default STP timers. What is the worst-case convergence time when a link failure occurs? (Select one!)
Explanation
For classic 802.1D STP with default timers, worst-case convergence is 50 seconds: Max-Age (20 seconds) to detect topology change + Listening state (15 seconds, forward delay) + Learning state (15 seconds, forward delay) = 50 seconds total. RSTP significantly reduces this to typically under 2 seconds using rapid transition mechanisms. Default STP timers are: hello = 2s, max age = 20s, forward delay = 15s.
4. Fabrikam has FortiSwitch managed by FortiGate via FortiLink. VLAN 50 (192.168.50.0/24) and VLAN 60 (192.168.60.0/24) are configured as sub-interfaces under the FortiLink interface on FortiGate. Users in VLAN 50 cannot reach servers in VLAN 60. What is the most likely cause? (Select one!)
Explanation
In FortiLink managed mode, inter-VLAN routing is performed by the FortiGate, not the FortiSwitch. FortiGate requires explicit firewall policies to allow traffic between VLANs; without a policy, traffic is implicitly denied. The FortiSwitch Layer 3 configuration is not used in FortiLink managed mode. If allowed-vlans were missing, intra-VLAN traffic would also fail. The scenario confirms FortiLink managed mode, not standalone.
5. Adatum configured storm control on FortiSwitch access ports with a broadcast threshold of 500 packets per second to prevent DoS attacks. After deployment, DHCP discovery requests and ARP queries from workstations are being intermittently dropped during normal business hours. What is the most likely cause? (Select one!)
Explanation
A broadcast storm control threshold of 500 packets per second is too low for normal network operations with many workstations. Legitimate broadcast traffic including DHCP discovery messages and ARP requests can easily exceed this threshold during normal activity. Storm control thresholds must be set high enough to allow legitimate broadcasts while protecting against actual storm conditions.
Fortinet NSE 5 - FortiAnalyzer 7.4 Analyst (NSE5_FAZ-7.4)
NSE5_FAZ-7.4 · 597 questions
Fortinet NSE 5 - FortiNAC-F 7.6 Administrator
NSE 5 · 600 questions
Fortinet NSE 5 - FortiSASE and SD-WAN 7.6 Core Administrator (NSE5_SSE_AD-7.6)
NSE5_SSE_AD-7.6 · 600 questions
Fortinet NSE 5 - FortiWeb 8.0 Administrator
NSE5_FWB-8.0 · 596 questions
Fortinet NSE 6 - FortiAnalyzer 7.4 Administrator (FCP_FAZ_AD-7.4)
FCP_FAZ_AD-7.4 · 600 questions
Fortinet NSE 6 - FortiClient EMS 7.4 Administrator (FCP_FCT_AD-7.4)
FCP_FCT_AD-7.4 · 595 questions
$17.99
One-time access to this exam