NSE 8
NSE 8 Application Security Practical Exam
Part of NSE 8
Independent study aid built from the public exam blueprint. Not affiliated with, authorized by, or endorsed by fortinet. Objectives are transcribed and mapped by hand, so this page may contain mistakes or may have fallen behind the vendor's current material: exam objectives, versions, numbering and availability all change without notice. Treat fortinet's own certification portal as the source of truth and verify against it before you book anything.
Note on this blueprint: Fortinet's own exam page publishes a Tasks column whose entries are truncated or blank, so the objectives below are transcribed from the Details column beside them, grouped under the published section headings and weightings. Verified against a fresh fetch.
Email security (27% of the exam)
1.01 Archiving
Article coming1.02 DNS security
1.03 Domains
1.04 Email encryption
1.05 Identity-based encryption (IBE)
1.06 Monitoring
1.07 Quarantining
1.08 SMTP, IMAP, and POP3
1.09 User authentication
1.10 Webmail
1.11 Antispam profiles
1.12 Antivirus profiles
1.13 Bounce verification
1.14 Content disarm and reconstruction (CDR)
1.15 Content profiles
1.16 Data loss prevention (DLP)
1.17 Endpoint reputation
1.18 IP policies
1.19 Recipient-based policies
1.20 Sandbox integration
1.21 Sender-based policies
1.22 Session profiles
1.23 Threat feeds
1.24 URL filtering
Application delivery (44% of the exam)
2.01 Application Access Manager
Article coming2.02 Single sign-on (SSO)
2.03 Agentless Application Gateway
2.04 Users and authentication
2.05 Global load balancing (GLB)
2.06 Network security
2.07 Application load balancing
2.08 Scripting
2.09 Server load balancing (SLB)
2.10 Web Cache Communication Protocol (WCCP)
On this site: Carrier-Scale NAT, MAP-E, Domain Fronting, and WCCP2.11 Advanced Bot Protection
2.12 API protection
2.13 Bot mitigation
2.14 DoS protection
2.15 IP protection
2.16 Machine learning (ML)
2.17 Open Web Application Security Project (OWASP) Top 10 list
2.18 Secure connections
2.19 Tracking
2.20 WAF Adaptive Learning 2.0
2.21 Web protection
2.22 Web vulnerability scanning
Threat detection (12% of the exam)
3.01 Air-gapped sandboxing
3.02 Malware behavior analysis
3.03 On-demand scanning
3.04 Risk analysis
3.05 Scan jobs
3.06 Scan policies and objects
3.07 Website scanning
3.08 Network share protection
3.09 Operational technology (OT) protection
3.10 Dedicated internet setup
3.11 Inline sandboxes
Infrastructure (17% of the exam)
4.01 FortiADC clustering
4.02 FortiWeb clustering
4.03 FortiMail clustering
4.04 FortiSandbox clustering
4.05 VDOMs and ADOMs
4.06 Logging and reporting
4.07 Mail transfer agent (MTA) and blind carbon copy (BCC) adapter integration
4.08 Operation modes
4.09 Kubernetes Ingress Controller
4.10 Fortinet Security Fabric integration
Public sources, used in good faith
These guides are independent study aids built from publicly available material: published exam blueprints, official product documentation, and vendor training catalogues. Product names, exam codes, and trademarks belong to their owners and are used only to identify the subject being taught. This site is not affiliated with or endorsed by any vendor named here. If you hold rights in material published on this page and believe it should be removed or corrected, please send the exact URL and a short note on the issue through the contact page; requests are reviewed promptly and in good faith. Read the full disclaimer →