NSE_3 Sample Questions

NSE_3 Sample Questions & Answers

Inspecting SSL traffic, blocking malware, and web filtering carry the biggest share, built on FortiGate basics, interface and routing setup, firewall policies, user authentication, IPsec and SSL VPNs, system maintenance, the Security Fabric, and FortiLink HA.

Launch the full NSE_3 simulator →

Showing 6 of 12 free samples.

  1. Question 1Intermediate

    Security Profiles - Content Inspection · SSL/TLS Traffic Inspection

    An organization requires that all traffic to a specific set of financial websites bypasses SSL Deep Inspection due to privacy regulations. The administrator is configuring the SSL/SSH Inspection profile. Which action should be taken to achieve this?

    Show answer & explanation

    Correct answer: A

    SSL Inspection profiles include an exemption list. Adding reputable financial or healthcare sites to this list allows the FortiGate to bypass deep inspection for those destinations, preserving privacy and avoiding certificate pinning issues.

  2. Question 2Intermediate

    Virtual Private Networks (VPN) · IPsec VPN

    While troubleshooting a Site-to-Site IPsec VPN, the administrator notices that the Phase 1 negotiation is failing. The logs show a mismatch in the pre-shared key. Which status indicator in the IPsec Monitor would confirm that Phase 1 is down?

    Show answer & explanation

    Correct answer: B

    If Phase 1 fails (e.g., due to PSK mismatch), the tunnel cannot be established at all. The IPsec Monitor will show the tunnel as Down/Inactive. Phase 2 cannot negotiate if Phase 1 is not established.

  3. Question 3Advanced

    User Authentication · Authenticating Network Users

    A FortiGate administrator is setting up User Authentication for internet access. They want to ensure that users are transparently authenticated using their Windows Active Directory credentials without seeing a login prompt. Which component is required to facilitate this FSSO (Fortinet Single Sign-On) deployment?

    Show answer & explanation

    Correct answer: B

    For transparent FSSO, an FSSO Collector Agent is typically installed on a Windows server. It monitors AD domain controller logs for login events and forwards the username/IP mapping to the FortiGate.

  4. Question 4Beginner

    Firewall Policy Configuration · Firewall Policies and NAT

    What is the primary function of the 'Implicit Deny' policy found at the bottom of the Firewall Policy list?

    Show answer & explanation

    Correct answer: D

    The Implicit Deny policy is a default, immutable policy at the very bottom of the list. It ensures that if traffic does not match any user-defined allow rules, it is dropped by default, adhering to the security principle of 'deny all unless explicitly allowed'.

  5. Question 5Intermediate

    Network Configuration · Configuring Interfaces and Routing

    An administrator needs to configure a FortiGate interface to act as a DHCP relay agent for a specific VLAN. Where is this configuration setting typically found?

    Show answer & explanation

    Correct answer: C

    In the interface configuration, under the DHCP Server section, there is an option to switch the mode from 'Server' to 'Relay'. This allows the FortiGate to forward DHCP requests to an external DHCP server IP.

  6. Question 6Intermediate

    Virtual Private Networks (VPN) · SSL VPN

    Which of the following scenarios is the most appropriate use case for enabling 'Split Tunneling' on an SSL VPN portal?

    Show answer & explanation

    Correct answer: A

    Split tunneling allows only traffic destined for specific internal subnets to go through the VPN tunnel. All other traffic (like general internet browsing) goes directly out the user's local internet connection, reducing load on the corporate network.

Ready for the real thing?

The full NSE_3 simulator has every exam-style question, timed mode, and instant scoring.

Go to the NSE_3 simulator →