NSE8-812 Sample Questions & Answers
Advanced routing, VPN design, and Fortinet's own application and network security solutions tie for the biggest weighting, alongside Security Fabric deployments and HA, FortiGate and non-FortiGate hardware, SD-WAN architecture, SOC and endpoint tools, and automation.
Launch the full NSE8-812 simulator →Showing 10 of 20 free samples.
- Question 1Advanced
Networking · Fortinet access solutions advanced configurations and features
A large enterprise has deployed FortiSwitch units in a multi-chassis link aggregation (MCLAG) configuration for switch-level redundancy. An administrator needs to perform a firmware upgrade on the MCLAG peer switches with minimal disruption to network traffic. What is the recommended procedure to achieve this?
Show answer & explanation
Correct answer: C
The correct, non-disruptive procedure for upgrading an MCLAG pair is to upgrade one switch at a time. The recommended practice is to first set the secondary (passive) peer to standalone mode, which isolates it from the MCLAG domain. After upgrading and rebooting the secondary switch, you can fail over traffic to it (by shutting down links on the primary or rebooting it) and then proceed with upgrading the original primary switch. This rolling upgrade process ensures that at least one switch is always active and forwarding traffic.
- Question 2Advanced
Security Operations · Fortinet SOC solution
Case Study:
Global Logistics Inc. (GLI) is a multinational shipping company that is modernizing its security infrastructure. They have deployed a central FortiManager and FortiAnalyzer at their primary datacenter for managing hundreds of branch office FortiGates. To improve their security posture, GLI wants to implement a solution where if a threat is detected at any branch (e.g., a malware-infected host), the compromised host is automatically quarantined across the entire organization, preventing it from accessing any network resources at any branch or the datacenter.
The current setup involves Security Fabric enabled between the branch FortiGates and the central management devices. Each branch uses FortiSwitch and FortiAP for local access, managed by the local FortiGate. The security team wants to leverage their existing Fortinet investment to achieve this automated, global quarantine without significant new hardware purchases.
As the lead security architect, you are tasked with designing this solution. The solution must be scalable and react in near real-time. Which approach best meets GLI's requirements for automated, fabric-wide threat response?
Show answer & explanation
Correct answer: D
This solution leverages the existing central management infrastructure to create a scalable, automated, and fabric-wide response. FortiAnalyzer acts as the central detection point. The FortiAnalyzer-FortiManager webhook integration provides the trigger mechanism. FortiManager's automation stitch and scripting capabilities can then update a dynamic address group (like an IP list or threat feed) that is already part of a shared policy package. When this object is updated on FortiManager, the change is automatically pushed to all managed FortiGates, effectively quarantining the host across the entire organization in a synchronized and efficient manner.
- Question 3IntermediateSelect 2
Infrastructure · FortiGate hardware technology
A FortiGate is configured in transparent mode between an internal network and a core router. An administrator notices that traffic passing through the FortiGate is not being accelerated by the NP7 processor as expected. Which TWO of the following configurations could cause the traffic to bypass NP7 acceleration? (Select TWO).
Show answer & explanation
Correct answers: A, C
Traffic shaping is a feature that requires CPU processing to manage queues and enforce bandwidth limits. When a traffic shaper is applied to a firewall policy, sessions matching that policy are sent to the CPU and cannot be offloaded to NP7 processors.
Proxy-based inspection mode requires the FortiGate to terminate and re-initiate connections to perform in-depth analysis. This process is handled by the CPU and the content processors (CPs), not the network processors (NPs). Therefore, traffic subject to proxy-based inspection cannot be offloaded to NP7.
- Question 4Intermediate
Security Solutions · Authentication mechanisms
A systems administrator is configuring a FortiGate to act as a SAML Service Provider (SP) for SSL-VPN access, using a third-party Identity Provider (IdP). The IdP provides group membership information in a SAML attribute named
memberOf. The administrator needs to map users to different SSL-VPN realms based on this attribute. Which FortiGate CLI setting is used to specify the SAML attribute that contains the user's group information?Show answer & explanation
Correct answer: C
Within the
config user samlCLI context, theset group-claimparameter is used to define the name of the SAML attribute that the IdP will send to convey group membership. The FortiGate will parse the SAML assertion for this attribute (in this case,memberOf) to identify the user's groups and match them against FortiGate user groups for authorization. - Question 5Intermediate
Security Architecture · Fortinet Security Fabric Solution deployments
A consultant is tasked with designing a resilient email security solution using two FortiMail appliances in a high availability (HA) active-passive cluster. A key requirement is that in the event of a primary unit failure, the secondary unit must take over with minimal email service interruption and no loss of the mail queue. Which FortiMail HA mode must be configured to meet this requirement?
Show answer & explanation
Correct answer: D
FortiMail's Full HA mode provides the highest level of redundancy. In this mode, both configuration and mail data (including mail queues, user data, and archives) are continuously synchronized between the primary and secondary units. If the primary unit fails, the secondary unit has an identical, up-to-date copy of all data and can take over processing immediately, ensuring no emails are lost and service interruption is minimized.
- Question 6Advanced
Infrastructure · FortiGate hardware technology
A network engineer is configuring a new FortiGate 6000F chassis with multiple FIMs. The goal is to ensure that all traffic entering a specific 100G port is always processed by the same FIM to maintain session consistency for a stateful application. Which command should be used to achieve this?
Show answer & explanation
Correct answer: B
On a FortiGate chassis system, the
set port-mappingcommand underconfig load-balance settingis used to statically map an ingress port to a specific FIM (worker). This overrides the default hashing-based load balancing and ensures that all traffic from the specified port is directed to the designated FIM, providing deterministic traffic handling. - Question 7Beginner
Secure SD-WAN · SD-WAN advanced features
True or False: In a Fortinet Secure SD-WAN deployment, using the packet duplication feature will double the bandwidth consumption across the selected member interfaces for the duplicated traffic.
Show answer & explanation
Correct answer: A
The statement is true. The purpose of packet duplication is to send identical copies of each packet across multiple SD-WAN member links simultaneously to improve reliability for latency-sensitive applications like VoIP. This inherently doubles (or triples, etc., depending on the number of duplicated paths) the amount of bandwidth consumed for that specific traffic stream.
- Question 8IntermediateSelect 3
Security Operations · Fortinet endpoint solutions
A security analyst is investigating an alert from FortiEDR indicating a malicious file execution on a workstation. The analyst needs to create an EDR playbook that automatically isolates the affected endpoint from the network, retrieves the malicious file for analysis, and terminates the offending process. Which three actions should be included in the FortiEDR playbook to accomplish this? (Select THREE).
Show answer & explanation
Correct answers: A, B, D
The 'Isolate Device' action is the primary method in FortiEDR to contain a threat by blocking all network communication to and from the endpoint, except for communication with the FortiEDR management console.
The 'Collect File' action allows the playbook to automatically retrieve a copy of the specified malicious file from the endpoint and store it in the FortiEDR backend for further analysis by the security team.
The 'Kill Process' action is used to immediately terminate the running malicious process on the endpoint, stopping its activity and preventing further damage.
- Question 9Intermediate
Security Solutions · Fortinet application security solutions
An organization is deploying FortiWeb in reverse proxy mode to protect a web application. The security policy requires that all incoming HTTP traffic be inspected for SQL injection attacks, but encrypted HTTPS traffic should be passed through to the backend web servers without decryption for performance reasons. Which FortiWeb feature should be configured to meet this requirement?
Show answer & explanation
Correct answer: C
SSL/TLS Passthrough is a FortiWeb feature that allows the appliance to forward encrypted traffic directly to the backend server without decrypting and inspecting it. This is achieved by creating a server policy for HTTPS that does not have an SSL offloading or inspection profile applied. This configuration meets the requirement to let the backend servers handle the SSL/TLS termination while still allowing the FortiWeb to inspect unencrypted HTTP traffic through a separate policy.
- Question 10Intermediate
Automation · Fortinet build-in scripting capabilities
A large-scale FortiGate deployment is managed by FortiManager. The administrator needs to push a configuration change to a specific VDOM on 50 different FortiGates. Instead of creating a script for each device, the administrator wants to use a single template. How can the administrator use FortiManager's scripting capabilities to target a specific VDOM on each device using a single script?
Show answer & explanation
Correct answer: D
FortiManager provides a 'Dynamic VDOM' option when running a script. When this is enabled, FortiManager does not hardcode the VDOM context in the script itself. Instead, it runs the script on the specific VDOM that is assigned to the policy package for that device. This allows a single, generic script to be applied to many devices, with FortiManager dynamically selecting the correct target VDOM on each FortiGate based on the policy package assignment.
Ready for the real thing?
The full NSE8-812 simulator has every exam-style question, timed mode, and instant scoring.