NSE_3 Sample Questions & Answers
Inspecting SSL traffic, blocking malware, and web filtering carry the biggest share, built on FortiGate basics, interface and routing setup, firewall policies, user authentication, IPsec and SSL VPNs, system maintenance, the Security Fabric, and FortiLink HA.
Launch the full NSE_3 simulator →Showing 6 of 12 free samples.
- Question 1Intermediate
Security Profiles - Content Inspection · SSL/TLS Traffic Inspection
An organization requires that all traffic to a specific set of financial websites bypasses SSL Deep Inspection due to privacy regulations. The administrator is configuring the SSL/SSH Inspection profile. Which action should be taken to achieve this?
Show answer & explanation
Correct answer: A
SSL Inspection profiles include an exemption list. Adding reputable financial or healthcare sites to this list allows the FortiGate to bypass deep inspection for those destinations, preserving privacy and avoiding certificate pinning issues.
- Question 2Intermediate
Virtual Private Networks (VPN) · IPsec VPN
While troubleshooting a Site-to-Site IPsec VPN, the administrator notices that the Phase 1 negotiation is failing. The logs show a mismatch in the pre-shared key. Which status indicator in the IPsec Monitor would confirm that Phase 1 is down?
Show answer & explanation
Correct answer: B
If Phase 1 fails (e.g., due to PSK mismatch), the tunnel cannot be established at all. The IPsec Monitor will show the tunnel as Down/Inactive. Phase 2 cannot negotiate if Phase 1 is not established.
- Question 3Advanced
User Authentication · Authenticating Network Users
A FortiGate administrator is setting up User Authentication for internet access. They want to ensure that users are transparently authenticated using their Windows Active Directory credentials without seeing a login prompt. Which component is required to facilitate this FSSO (Fortinet Single Sign-On) deployment?
Show answer & explanation
Correct answer: B
For transparent FSSO, an FSSO Collector Agent is typically installed on a Windows server. It monitors AD domain controller logs for login events and forwards the username/IP mapping to the FortiGate.
- Question 4Beginner
Firewall Policy Configuration · Firewall Policies and NAT
What is the primary function of the 'Implicit Deny' policy found at the bottom of the Firewall Policy list?
Show answer & explanation
Correct answer: D
The Implicit Deny policy is a default, immutable policy at the very bottom of the list. It ensures that if traffic does not match any user-defined allow rules, it is dropped by default, adhering to the security principle of 'deny all unless explicitly allowed'.
- Question 5Intermediate
Network Configuration · Configuring Interfaces and Routing
An administrator needs to configure a FortiGate interface to act as a DHCP relay agent for a specific VLAN. Where is this configuration setting typically found?
Show answer & explanation
Correct answer: C
In the interface configuration, under the DHCP Server section, there is an option to switch the mode from 'Server' to 'Relay'. This allows the FortiGate to forward DHCP requests to an external DHCP server IP.
- Question 6Intermediate
Virtual Private Networks (VPN) · SSL VPN
Which of the following scenarios is the most appropriate use case for enabling 'Split Tunneling' on an SSL VPN portal?
Show answer & explanation
Correct answer: A
Split tunneling allows only traffic destined for specific internal subnets to go through the VPN tunnel. All other traffic (like general internet browsing) goes directly out the user's local internet connection, reducing load on the corporate network.
Ready for the real thing?
The full NSE_3 simulator has every exam-style question, timed mode, and instant scoring.