When a device’sMAC address is quarantinedon a FortiSwitch (via FortiLink NAC, fabric automation, or manual quarantine), FortiSwitch enforces quarantine using thequarantine VLAN, also called theaccess VLANinside FortiSwitch NAC operations.
FortiSwitch behavior is defined in LAN Edge documentation:
Quarantined devices are moved into an"access VLAN" reserved for isolation.
This VLAN isstatically defined on the FortiGate NAC policy, and switch ports dynamically reassign the quarantined MAC into that VLAN.
All egress traffic from the quarantined MAC is forced into this VLAN, preventing access to the production network.
Thus, the correct description is:
✔Traffic is sent to an access VLAN.
Options B, C, and D are incorrect because:
Quarantine doesnotreassign to native VLAN.
It doesnotsend untagged traffic arbitrarily.
It doesnotforward traffic to allowed VLANs