nerdexam
Fortinet

FCSS_LED_AR-7.6 · Question #26

Refer to the exhibits which show the FortiSwitch and FortiGate interface configurations. FortiSwitch VLAN configuration Port2 interface configuration Which two statements describe how port2 handles…

The correct answer is A. Port2 accepts ingress tagged traffic for VLAN IDs 4091 and 4093 only. B. Port2 assigns ingress untagged traffic to VLAN 100. Options A and B are correct because they accurately reflect how FortiSwitch handles trunk port behavior. The port's native VLAN (PVID) is 100, so all untagged ingress traffic is stamped with VLAN 100 internally - confirming B. The allowed VLANs configured as tagged are 4091 and…

FortiSwitch Deployment and Configuration

Question

Refer to the exhibits which show the FortiSwitch and FortiGate interface configurations. FortiSwitch VLAN configuration Port2 interface configuration Which two statements describe how port2 handles tagged and untagged traffic? (Choose two.)

Exhibits

FCSS_LED_AR-7.6 question #26 exhibit 1
FCSS_LED_AR-7.6 question #26 exhibit 2

Options

  • APort2 accepts ingress tagged traffic for VLAN IDs 4091 and 4093 only.
  • BPort2 assigns ingress untagged traffic to VLAN 100.
  • CPort2 accepts ingress untagged traffic for VLAN IDs 100, 4091, and 4093 only.
  • DPort2 tags egress traffic for VLAN 100.

How the community answered

(24 responses)
  • A
    75% (18)
  • C
    8% (2)
  • D
    17% (4)

Explanation

Options A and B are correct because they accurately reflect how FortiSwitch handles trunk port behavior. The port's native VLAN (PVID) is 100, so all untagged ingress traffic is stamped with VLAN 100 internally - confirming B. The allowed VLANs configured as tagged are 4091 and 4093, meaning port2 will only accept (and process) tagged ingress frames bearing those specific VLAN IDs - confirming A.

C is wrong because a port doesn't receive untagged traffic "for" multiple VLANs simultaneously. Untagged traffic has no VLAN tag by definition - it maps to exactly one VLAN (the native VLAN, 100). VLANs 4091 and 4093 are tagged-only VLANs on this port.

D is wrong because VLAN 100 is the native/untagged VLAN. Egress traffic for the native VLAN is sent without a tag - that's the whole point of a native VLAN. Only traffic for VLANs 4091 and 4093 gets tagged on egress.

Memory tip: Think "native = naked." The native VLAN travels untagged in both directions, while explicitly listed trunk VLANs always wear their tag. If a VLAN is the PVID, it never gets tagged on egress.

Topics

#VLAN tagging#FortiSwitch port#tagged traffic#untagged traffic

Community Discussion

No community discussion yet for this question.

Full FCSS_LED_AR-7.6 Practice