NSE8 Sample Questions & Answers
Ground spans Fortinet's security-architecture products and HA solutions, FortiGate's operation modes in the cloud, VPN technologies and advanced routing, SD-WAN design with cloud and ADVPN integration, email security, SOC management, and automation scripting.
Launch the full NSE8 simulator →Free NSE8 Sample Questions with Answers
Real questions from the Fortinet Certified Expert (FCX) - Cybersecurity practice test — answers and explanations included. Showing 10 of 20 free samples.
- Question 1Beginner
Security Operations · Fortinet endpoint solutions
An organization uses FortiClient EMS to manage endpoints and enforce compliance. The security team wants to implement a Zero Trust Network Access (ZTNA) policy where only endpoints with an active FortiClient, a specific software version installed, and a high security posture tag can access internal applications. Which component is responsible for collecting the endpoint posture information and assigning the relevant ZTNA tags?
Show answer & explanation
Correct answer: C
FortiClient EMS (Endpoint Management Server) is the central management component that communicates with FortiClient on the endpoints. It is responsible for defining compliance rules, collecting posture information (like software versions and security status), and dynamically assigning ZTNA tags to endpoints based on whether they meet the defined criteria. The FortiGate then uses these tags in its ZTNA policies.
- Question 2Advanced
Infrastructure · FortiGate hardware technology
A large enterprise has deployed FortiGate 7000 series chassis in their data centers. A network architect needs to explain the data path for traffic that can be fully offloaded by the NP7 processors. Which option correctly describes the 'fast path' for a TCP session through the chassis?
Show answer & explanation
Correct answer: B
In a FortiGate 7000 series chassis, fully offloaded traffic follows the 'fast path'. The packet enters through an ingress FortiGate Interface Module (FIM), travels across the high-speed fabric backplane directly to a FortiGate Processor Module (FPM) containing an NP7 processor. The NP7 handles all session processing, including firewall policy, NAT, and inspection, and then sends the packet back across the backplane to the egress FIM. The main FortiGate CPU is not involved in per-packet processing for these offloaded sessions.
- Question 3Intermediate
Automation · Fortinet API configuration and usage
An engineer is using the FortiGate REST API to automate the creation of firewall address objects. The following Python code snippet is used to send the request. Assuming the API key and FortiGate IP are correct, what must be added to the request headers for it to be accepted by the FortiGate?
import requests api_key = 'your_api_key' fg_ip = '10.0.1.1' headers = { 'Authorization': f'Bearer {api_key}', # Missing header here } url = f'https://{fg_ip}/api/v2/cmdb/firewall/address' response = requests.post(url, headers=headers, verify=False)Show answer & explanation
Correct answer: C
When sending data to the FortiGate REST API using methods like POST or PUT, the 'Content-Type' header is mandatory. It informs the API server about the format of the data in the request body. For FortiGate's API, this is typically 'application/json'. Without this header, the API will reject the request.
- Question 4Advanced
Networking · Advanced VPN design methodologies
A global enterprise has a complex hub-and-spoke ADVPN deployment. They are experiencing issues where spoke-to-spoke shortcut tunnels are not forming for VoIP traffic, causing calls to hairpin through the hub and increasing latency. The IPsec, BGP, and underlying network connectivity have been verified as correct. What is a common ADVPN-specific reason for this behavior?
Show answer & explanation
Correct answer: D
For ADVPN to trigger a shortcut, the initial packet from one spoke to another must pass through the hub. The firewall policy on the hub that matches this traffic must have
set auto-discovery-shortcut enableconfigured. This command instructs the FortiGate to send the IKE informational messages to the initiating and destination spokes, which allows them to build a direct shortcut tunnel. If this is missing, the traffic will simply be routed through the hub. - Question 5Intermediate
Secure SD-WAN · SD-WAN troubleshooting
A consultant is reviewing an SD-WAN deployment where application performance is poor despite having two high-quality internet links. The configuration uses a performance SLA with latency, jitter, and packet loss thresholds. The SD-WAN rule is set to 'Best Quality'. The consultant observes from the performance SLA logs that both links are consistently marked as 'dead' (red), even though manual ping tests show low latency and no loss. What is the most likely configuration error?
Show answer & explanation
Correct answer: B
The performance SLA relies on probes sent to a health-check server to measure link quality. If this server is unreachable (e.g., due to routing issues, upstream firewall blocks, or the server being down), all probes will fail. This will cause the FortiGate to mark the links as 'dead' because it cannot measure their quality, regardless of the actual link performance for other traffic.
- Question 6IntermediateSelect 2
Infrastructure · VDOM and VDOM links
A company is implementing a multi-VDOM architecture on a single FortiGate. The goal is to have a dedicated VDOM for managing internet-facing services (INET-VDOM) and another for internal corporate services (CORP-VDOM). An inter-VDOM link connects them. An administrator in CORP-VDOM needs to access a server in INET-VDOM. Which two components are essential for enabling this traffic flow? (Select TWO).
graph TD subgraph FortiGate subgraph CORP_VDOM AdminPC[Admin PC] VDOM_Link_C[port: vlink_corp] end subgraph INET_VDOM WebServer[Web Server] VDOM_Link_I[port: vlink_inet] end VDOM_Link_C -- Inter-VDOM Link -- VDOM_Link_I end AdminPC --> VDOM_Link_C VDOM_Link_I --> WebServerShow answer & explanation
Correct answers: A, C
- Question 7Advanced
Automation · Fortinet build-in scripting capabilities
During a security audit, it was discovered that an automated script is adding hundreds of temporary IP addresses to a dynamic firewall address group via the API. This is causing high CPU utilization on the FortiGate. The security architect decides to implement a solution using the FortiManager CLI to prevent this. Which FortiManager feature allows an administrator to define a script that runs automatically when configuration changes are imported from a device, which can be used to validate and reject the unwanted changes?
Show answer & explanation
Correct answer: B
FortiManager supports TCL (Tool Command Language) scripts for advanced automation. A TCL script can be assigned as a 'verification script' to an ADOM. This script automatically runs whenever a configuration is retrieved or imported from a managed device. The script can parse the configuration changes and, if they violate a defined policy (like adding too many addresses), it can be programmed to reject the changes, preventing them from being saved in the FortiManager database.
- Question 8Advanced
Security Architecture · Fortinet Security Fabric Solution deployments
A hospital needs to provide secure remote access for doctors to access patient records. The solution must use multi-factor authentication and ensure that only devices compliant with the hospital's security policy can connect. The current infrastructure includes FortiGate, FortiAuthenticator, and FortiClient EMS. Which of the following represents the most secure and integrated solution to meet all requirements?
Show answer & explanation
Correct answer: B
This solution provides the most comprehensive security by combining all elements. ZTNA provides granular, per-application access instead of full network access. Integrating with EMS ensures device posture and compliance are checked before access is granted. Using FortiAuthenticator as a SAML IdP allows for robust multi-factor authentication, fulfilling all stated requirements in a tightly integrated Security Fabric approach.
- Question 9Intermediate
Security Solutions · Fortinet application security solutions
An administrator is troubleshooting a FortiMail device operating in Transparent Mode. Email delivery is failing, and a packet capture shows that the FortiGate in front of the FortiMail is dropping the SMTP packets. What is the most likely reason for this behavior?
Show answer & explanation
Correct answer: D
When FortiMail is in Transparent Mode, it inspects traffic at Layer 2 and does not change IP headers. However, it can delay packets during inspection. If the FortiGate in front has the SMTP session helper enabled (which it is by default), it may time out and close the session if it doesn't see the expected SMTP command sequence within a certain timeframe. The standard practice is to remove the SMTP session helper on the FortiGate for the policy that handles traffic to the transparent-mode FortiMail, allowing the FortiMail to manage the session correctly.
- Question 10Advanced
Secure SD-WAN · SD-WAN troubleshooting
A FortiGate is configured with two SD-WAN members: Port1 (cost 10) and Port2 (cost 20). An SD-WAN rule is configured with the 'Lowest Cost (SLA)' strategy to prefer Port1. However, administrators notice traffic is still being sent out Port2. The performance SLA shows Port1 is alive and meeting all thresholds. Which of the following is the most plausible explanation for this behavior?
Show answer & explanation
Correct answer: B
FortiOS evaluates routing decisions in a specific order of precedence: Policy Routes, then SD-WAN rules, then Static/Dynamic routes. A policy route (also known as policy-based routing) will override any decision made by the SD-WAN engine. If a policy route exists that matches the traffic and specifies Port2 as the egress interface, the FortiGate will follow that instruction, ignoring the SD-WAN rule.
Ready for the real thing?
The full NSE8 simulator has every exam-style question, timed mode, and instant scoring.