About the Exam

This proctored exam evaluates knowledge of FortiGate devices and applied skills in configuration, operation, day-to-day administration, and troubleshooting. It is intended for network and security professionals responsible for configuring and administering firewall solutions in an enterprise network security environment. Passing demonstrates practical competence with the FortiOS 7.6 platform and the core tasks covered by the NSE 4 FortiOS certification track.

Exam Topics

  • System and Network Settings0%
  • Logging and Monitoring0%
  • Firewall Policies and NAT0%
  • Routing0%
  • Firewall Authentication0%
  • Fortinet Single Sign-On (FSSO)0%
  • Certificate Operations0%
  • Antivirus0%
  • Web Filtering0%
  • Intrusion Prevention and Application Control0%
  • IPsec VPN0%
  • SD-WAN Configuration and Monitoring0%
  • High Availability0%
  • Diagnostics and Troubleshooting0%
  • FortiGate in the Cloud0%
  • FortiSASE0%

How to Use This Practice Exam

  1. Browse — Read each question, select your answer, and reveal the explanation.
  2. Exam Mode — Simulate real exam conditions with a timed session and score report.
  3. Learn Mode — Spaced repetition schedules questions you struggle with for long-term retention.

Download the Full Exam PDF

Get every question and answer in a clean, printable PDF built for offline study. Purchase once, keep permanent access, and re-download the latest version anytime.

Last updated June 22, 2026 at 4:44 PM

Topic filter
Retired questions
Question sort

QuestionQ1

Fortinet Single Sign-On (FSSO)

A new administrator is setting up FSSO authentication on FortiGate in DC Agent Mode.

Which step is not included in the expected process?

  • A The user logs into the windows domain.
  • B FortiGate determines user identity based on the IP address in the FSSO list.
  • C The DC agent sends login event data directly to FortiGate.
  • D The collector agent forwards login event data to FortiGate.
Explanation

In DC Agent Mode, DC agents monitor Windows domain logon events and pass them to the Collector Agent. The Collector Agent stores the information and sends it to FortiGate, which uses the associated IP-to-user information for identity-aware policy enforcement. The DC agent does not send login event data directly to FortiGate.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ2

Routing

Refer to the exhibit.

Question Image

Based on the routing table in the exhibit, which two statements are correct?

Choose two
  • A A packet with the source IP address 10.0.13.10 arriving on port2 is allowed if strict RPF is disabled.
  • B A packet with the source IP address 10.100.110.10 arriving on port3 is allowed if strict RPF is disabled.
  • C A packet with the source IP address 10.10.10.10 arriving on port2 is allowed if strict RPF is enabled.
  • D A packet with the source IP address 10.100.110.10 arriving on port2 is allowed if strict RPF is enabled.
Explanation

Feasible-path RPF accepts a packet when at least one active route to its source uses the receiving interface; the default route through port2 therefore permits source 10.0.13.10 received on port2. Strict RPF requires the best route back to the source to use the receiving interface; source 10.100.110.10 matches the default route through port2 and therefore passes when received on port2.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ3

Fortinet Single Sign-On (FSSO)

An administrator believes that the Collector Agent is not sending login events to FortiGate.

What is the most effective troubleshooting action?

  • A Verify if DC agent is enabled on the FortiGate.
  • B Restart the domain controller to refresh authentication services.
  • C Check if TCP port 8000 is open between the collector agent and FortiGate.
  • D Verify if FortiGate is set to use LDAP authentication instead of FSSO.
Explanation

The FSSO Collector Agent communicates login information to FortiGate through TCP port 8000. Confirming that this port is reachable between the Collector Agent and FortiGate directly tests the required forwarding path.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ4

SD-WAN Configuration and Monitoring

Refer to the exhibit showing an SD-WAN zone configuration in the FortiGate GUI.

Question Image

Based on the exhibit, which statement is correct?

  • A The Underlay zone contains no member.
  • B port2 and port3 are not assigned to a zone.
  • C The Underlay zone is the zone by default.
  • D The virtual-wan-link and overlay zones can be deleted.
Explanation

virtual-wan-link is the default SD-WAN zone, and the four displayed member interfaces are assigned within the SD-WAN configuration. The Underlay zone has no member interfaces listed beneath it, so it is an empty zone. Fortinet documents that the default SD-WAN zone is named virtual-wan-link.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ5

Web Filtering

Refer to the exhibits.

Question Image

Question Image

An administrator has configured the Web Filter Profile to block access to every social networking site except Facebook. However, when users attempt to reach Facebook.com, they are redirected to a FortiGuard web-filtering block page.

Based on the exhibits, which configuration change must the administrator make to permit Facebook while blocking every other social networking site?

  • A Set the Social Networking action as warning in the FortiGuard Category Based Filter.
  • B Change the Feature set of Web Filter Profile as Proxy-based.
  • C Set the Action as Exempt for www.facebook.com in the Static URL Filter.
  • D Change the type as Simple in the Static URL Filter section.
Explanation

A Static URL Filter action of Monitor behaves like Allow and continues processing through the remaining FortiGuard web filters, so Facebook is still blocked by the Social Networking category. Setting the matching www.facebook.com URL-filter entry to Exempt bypasses the remaining FortiGuard web filtering for that URL while the Social Networking category remains blocked for other sites.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!
Know a question that should be here? Contribute to this exam
Back home