About the Exam

Prepare for the NSE7-FSN-AR-7-6 certification from Fortinet with 55 practice questions, community-verified answers, and detailed explanations.

Exam Topics

  • System configuration and SD-WAN setup20–30%
  • Central management15–25%
  • Security profiles5–15%
  • Rules and routing25–35%
  • Advanced IPsec25–35%

How to Use This Practice Exam

  1. Browse — Read each question, select your answer, and reveal the explanation.
  2. Exam Mode — Simulate real exam conditions with a timed session and score report.
  3. Learn Mode — Spaced repetition schedules questions you struggle with for long-term retention.

Download the Full Exam PDF

Get every question and answer in a clean, printable PDF built for offline study. Purchase once, keep permanent access, and re-download the latest version anytime.

Last updated August 27, 2026 at 12:40 AM

Topic filter
Retired questions
Question sort

QuestionQ1

Central management

Which three traits apply to the provisioning templates available in FortiManager?

Choose three
  • A CLI template group can contain CLI templates of different types.
  • B CLI templates are applied in order, from top to bottom.
  • C CLI template can be of type CLI script or Perl script.
  • D A template group can include a system template and an SD-WAN template.
  • E Each template group can contain up to three IPsec tunnel templates.
Explanation

FortiManager CLI template groups can combine CLI and Jinja templates and apply them sequentially from top to bottom. A provisioning template group can include one template of each supported type, including a system template and an SD-WAN template. CLI templates use CLI Script or Jinja Script—not Perl Script—and a template group allows one IPsec tunnel template.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ2

System configuration and SD-WAN setup

In a transparent VDOM interface, what is the effect of the command set forward-domain <domain_ID>?

  • A It allows the interface to access the configured admin domain.
  • B It assigns a unique domain ID to the interface, allowing it to operate across multiple VLANs within the same VDOM.
  • C It restricts the interface to managing traffic from only the specified VLAN, effectively segregating network traffic.
  • D It isolates traffic within a specific VLAN by assigning a broadcast domain to an interface based on the VLAN ID.
Explanation

A forwarding domain assigns an interface to a Layer 2 broadcast/forwarding group in transparent mode. Broadcast traffic is confined to interfaces in that group, providing traffic isolation between separate domains.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ3

Central management

In a Security Fabric environment, which three actions are required to ensure successful communication between the nodes?

Choose three
  • A You must enable FortiTelemetry on the receiving interface of the upstream FortiGate.
  • B You must authorize the downstream FortiGate on the root FortiGate.
  • C You must ensure that TCP port 8013 is not blocked along the way.
  • D You must ensure that the port for Neighbor Discovery has been changed.
  • E You must configure FortiGate in transparent mode.
Explanation

Security Fabric connections require Security Fabric Connection (FortiTelemetry) to be enabled on the upstream FortiGate interface receiving the downstream connection. A downstream FortiGate must be authorized on the root FortiGate before it can join the fabric, and TCP port 8013 must be permitted for Security Fabric communication.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ4

System configuration and SD-WAN setup

Refer to the exhibit.

Question Image

A FortiGate device segmented into VDOMs is illustrated. You must provide effective, accelerated Internet access for every VDOM in this enterprise network. How can this be accomplished?

  • A Configure network processing unit (NPU) vlinks.
  • B Create VLANs over network processing unit (NPU) vlinks.
  • C Connect a physical interface from each VDOM to the root VDOM.
  • D Create VDOM links.
Explanation

NPU VDOM links provide hardware-accelerated traffic forwarding between VDOMs. Assigning NPU-link interfaces to the root VDOM and to each non-root VDOM lets their traffic reach the Internet connection in root while offloading the inter-VDOM portion to the network processor. Standard VDOM links and physical-interface connections do not provide this inherent NPU acceleration.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ5

Rules and routing

Refer to the exhibit.

Partial output from an OSPF command is displayed.

Question Image

While checking FortiGate’s OSPF status, you receive the output shown in the exhibit. Based on this output, which two statements about FortiGate are correct?

Choose two
  • A FortiGate has OSPF ECMP enabled.
  • B FortiGate is connected to multiple areas.
  • C FortiGate is a backup designated router.
  • D FortiGate injects external routing information.
Explanation

The This router is an ABR status identifies an OSPF area border router, which connects multiple OSPF areas. FortiGate permits ECMP by default; ECMP is disabled only when ecmp-max-paths is set to 1. External routing information is injected by an ASBR, not merely by an ABR, and backup-designated-router status is determined per broadcast network and is not shown here.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

That's the end of the preview

It's free

100% of the questions are free for all users.
No strings attached.

Topics covered
System configuration and SD-WAN setupCentral managementSecurity profilesRules and routingAdvanced IPsec
Know a question that should be here? Contribute to this exam
Back home