1. FortiSwitchâ„¢ Managed by FortiOS 7.6 Administration Guide, Page 111, "Configuring 802.1X port-based authentication".
Reference for B: The guide states, "You can configure 802.1X port-based authentication by creating a security policy and then applying the policy to one or more FortiSwitch ports." This directly supports option B.
Reference for A: The same section describes the behavior: "You can configure port-based network access control to block traffic from a client on a specific port until the client is authenticated. After one client is authenticated, any traffic from other clients on the same port is allowed." This confirms option A.
Reference for C: On page 112, Step 4 of the configuration process instructs to "Select one or more RADIUS servers from the User Groups list," demonstrating that external RADIUS servers are used, invalidating the claim that a local database must be used.
Reference for D: On page 112, a configuration option is "MAC authentication bypass (MAB)," which is explicitly for devices that do not support 802.1X, proving option D is false.