NSE8_813 Sample Questions

NSE8_813 Sample Questions & Answers

Networking technologies, VPN design methodologies, and advanced routing take the largest slice, next to Fortinet's security-architecture and HA solutions, FortiGate versus non-FortiGate hardware, SD-WAN architecture, application security, SOC tools, and automation.

Launch the full NSE8_813 simulator →

Showing 6 of 12 free samples.

  1. Question 1Intermediate

    Security Architecture · Fortinet solutions for cloud security

    A customer requires a secure SD-WAN architecture where the hub FortiGate is located in AWS. They need to support 5000 spokes connecting via IPsec with ADVPN enabled. The Hub must reflect BGP routes between spokes.

    What is the primary constraint to consider regarding the AWS instance size and type for this architecture?

    Show answer & explanation

    Correct answer: B

    In a cloud environment, encryption (IPsec) and control plane functions (BGP route reflection for 5000 peers) are heavily CPU dependent. Selecting an instance type with SR-IOV/ENA support and high CPU core count is critical. Unlike physical FortiGates with ASICs, VMs rely on the general-purpose CPU.

  2. Question 2Advanced

    Infrastructure · Demonstrate knowledge of FortiGate hardware technology

    You are analyzing a performance issue on a FortiGate 3600E. The 'diagnose sys top' command shows the IPS engine consuming 99% CPU, but the NP6 processors show low utilization. The traffic consists primarily of large file transfers over HTTP.

    Which configuration factor would prevent this traffic from being offloaded to the NP6 processor?

    Show answer & explanation

    Correct answer: D

    Firewall sessions that include proxy-based security profiles are never offloaded to network processors and are always processed by the FortiGate CPU. Flow-based sessions (IPS, application control) can still be offloaded through NTurbo. Traffic shaping is not the blocker: NP6-offloaded sessions support offloading most types of traffic shaping.

  3. Question 3Intermediate

    Infrastructure · Demonstrate knowledge of FortiGate operation modes

    A service provider is deploying a FortiGate in a multi-tenant environment using VDOMs. They need to ensure that a DDoS attack targeting one tenant (VDOM-A) cannot exhaust the session table capacity available to another tenant (VDOM-B).

    Which configuration achieves this isolation?

    Show answer & explanation

    Correct answer: D

    Per-VDOM resource limits isolate tenants. In the Global VDOM go to System > VDOM > Edit and set Override Maximum (and optionally Guaranteed) for Sessions. In the CLI this is config system vdom-property / edit / set session . Capping VDOM-A's maximum sessions stops a flood against VDOM-A from consuming the shared session table, and a guaranteed value reserves capacity for VDOM-B. System > Global Resources sets device-wide limits, not per-VDOM limits.

  4. Question 4Intermediate

    Infrastructure · Demonstrate knowledge of FortiGate operation modes

    You are deploying a FortiGate in Transparent Mode between a core switch and an edge router. The core switch runs MSTP (Multiple Spanning Tree Protocol). You notice that Spanning Tree BPDUs are being dropped by the FortiGate, causing a loop in the network.

    Which command allows BPDUs to pass through the FortiGate?

    Show answer & explanation

    Correct answer: D

    In Transparent Mode, the FortiGate does not participate in Spanning Tree by default and may block BPDUs. To allow BPDUs to pass through so upstream/downstream switches can converge, 'set stpforward enable' must be configured on the interfaces.

  5. Question 5Advanced

    Infrastructure · Demonstrate knowledge of FortiGate hardware technology

    A network architect is designing a hyperscale firewall solution using FortiGate NP7 hardware. The requirement is to support 5 million concurrent connections with Carrier Grade NAT (CGNAT) using PBA (Port Block Allocation).

    Which limitation must be considered when enabling hyperscale firewall features?

    Show answer & explanation

    Correct answer: C

    Hyperscale firewall policies on NP7 hardware are designed for maximum throughput and session setup rates (e.g., for CGNAT). To achieve this, the traffic is offloaded to the hardware session setup engine. This bypasses the CPU-intensive UTM engines. Therefore, standard UTM profiles like AV and IPS cannot be applied to hyperscale policies.

  6. Question 6Advanced

    Networking · Demonstrate knowledge of advanced VPN design methodologies

    You are configuring an ADVPN solution using iBGP (all FortiGates in the same AS). The Hub learns each Spoke's LAN subnet, but the Spokes do not learn each other's LAN subnets from the Hub.

    Which configuration on the Hub is most likely missing?

    Show answer & explanation

    Correct answer: D

    Under iBGP rules, a router does not advertise routes learned from one iBGP peer to other iBGP peers. On an ADVPN hub peering with all spokes in the same AS, the spokes' neighbor-group must be configured as route-reflector clients (config router bgp / config neighbor-group / set route-reflector-client enable), as in the FortiOS 7.4 hub example. Otherwise each spoke never learns the other spokes' subnets and cannot trigger shortcuts to them.

Ready for the real thing?

The full NSE8_813 simulator has every exam-style question, timed mode, and instant scoring.