Fortinet NSE8_811 Exam Overview:
| Certification Vendor: | Fortinet |
| Exam Name: | Fortinet NSE 8 - Network Security Expert 8 Written Exam |
| Exam Number: | NSE8_811 |
| Exam Format: | Multiple Choice, Multiple Select, Scenario-based questions |
| Certificate Validity Period: | 3 years |
| Exam Duration: | 120 minutes |
| Available Languages: | English |
| Real Exam Qty: | 55-60 |
| Related Certifications: | Fortinet NSE 4 Fortinet NSE 5 Fortinet NSE 6 Fortinet NSE 7 Fortinet NSE 8 Practical Exam |
| Recommended Training: | Fortinet Security Fabric Training Fortinet NSE Training Courses (NSE 4–7) |
| Exam Registration: | Pearson VUE Fortinet Exams Fortinet Training Institute NSE 8 Page |
| Sample Questions: | Fortinet NSE8_811 Sample Questions |
| Exam Way: | Available worldwide via Pearson VUE test centers and OnVUE online proctoring (depending on region and availability) |
| Pre Condition: | No mandatory prerequisites for the written exam; however, strong experience with Fortinet products and lower NSE levels (NSE 4–7) is strongly recommended. |
| Official Syllabus URL: | https://training.fortinet.com/local/staticpage/view.php?page=nse_8 |
Fortinet NSE8_811 Exam Syllabus Topics:
| Section | Objectives |
|---|---|
| Configuration and Implementation | - FortiGate configuration in complex environments
|
| Secure Network Design | - Enterprise architecture design using Fortinet Security Fabric
|
| Troubleshooting and Analysis | - Network and security issue diagnosis
|
| Security Operations and Integration | - Fortinet Security Fabric integration
|
Fortinet NSE 8 Written Exam (NSE8_811) Sample Questions:
1. Exhibit
You created a custom health-check for your FortiWeb deployment.
Referring to the output shown in the exhibit, which statement is true?
A) The FortiWeb must receive an RST packet from the server.
B) The FortiWeb must receive an HTTP 200 response code from the server.
C) The FortiWeb must receive an ICMP Echo Request from the server.
D) The FortiWeb must match the hash value of the page index html.
2. An organization has one central site and three remote sites. A FortiSIEM has been installed on the central site and now all devices across the remote sites must be centrally monitored by the FortiSIEM at the central site.
Which action will reduce the WAN usage by the monitoring system?
A) Install local Collectors on each remote site.
B) Install both Supervisor and Collector on each remote site.
C) Disable real-time log upload on the remote sites.
D) Enable SD-WAN FEC (Forward Error Correction) on the FortiGate at the remote site.
3. Exhibit
Click the Exhibit button.
You are trying to configure Link-Aggregation Group (LAG), but ports A and B do not appear on the list of member options. Referring to the exhibit, which statement is correct in this situation?
A) The FortiGate model being used does not support LAG.
B) The FortiGate interfaces are defective and require replacement.
C) The FortiGate SFP+ slot does not have the correct module.
D) The FortiGate model does not have an Integrated Switch Fabric (ISF).
4. Click the Exhibit button.
Your customer is using dynamic routing to exchange the default route between two FortiGates using OSPFv2. The output of the get router info ospf neighbor command shows that the neighbor is up, but the default route does not appear in the routing neighbor shown below:
According to the exhibit, what is causing the problem?
A) FG2 is within the wrong OSPF area.
B) There is an OSPF interface network-type mismatch.
C) A prefix for the detail route is missing
D) OSPF requires the redistribution of connected networks.
5. Click the Exhibit button.
Central NAT was configured on a FortiGate firewall. A sniffer shows ICMP packets out to a host on the Internet egresses with the port1 IP address instead of the virtual IP(VIP) that was configured.
Referring to the exhibit, which configuration will ensure that ICMP traffic is also translated?
A) config firewall ippool edit "secondry_ip" set arp-intf 'port1' next end
B) config firewall central-snat-map edit 1 set orig-addr "all" next end
C) config firewall central-snat-map edit 1 set protocol 1 next end
D) config firewall central-snat-map edit 1 unset protocol next end
Solutions:
| Question # 1 Answer: B | Question # 2 Answer: A | Question # 3 Answer: D | Question # 4 Answer: B | Question # 5 Answer: D |

We're so confident of our products that we provide no hassle product exchange.


By Penelope


