According to the FortiSwitch Administration Guide, “MAC-based 802.1X security mode allows you to
authenticate each device connected to a port using its MAC address as the username and password.”
Therefore, option B is true because it describes the MAC-based 802.1X security mode available on
FortiSwitch. Option D is also true because FortiSwitch can grant different access levels to each device
connected to the port based on the user group and security policy assigned to them. Option A is false
because FortiSwitch does not authenticate a single device and open the port to other devices
connected to the port, but rather authenticates each device individually. Option C is false because
MAC-based 802.1X security mode can be used in conjunction with MAC authentication bypass (MAB)
or EAP pass-through modes, which are fallback options for non-802.1X devices.