NSE 8
NSE 8 Core Practical Exam
Part of NSE 8
Independent study aid built from the public exam blueprint. Not affiliated with, authorized by, or endorsed by fortinet. Objectives are transcribed and mapped by hand, so this page may contain mistakes or may have fallen behind the vendor's current material: exam objectives, versions, numbering and availability all change without notice. Treat fortinet's own certification portal as the source of truth and verify against it before you book anything.
Note on this blueprint: Fortinet's own exam page publishes a Tasks column whose entries are truncated or blank, so the objectives below are transcribed from the Details column beside them, grouped under the published section headings and weightings. Verified against a fresh fetch.
Infrastructure (27% of the exam)
1.01 Aggregation (Link Aggregation Control Protocol (LACP))
1.02 FortiGate Clustering Protocol (FGCP)
1.03 FortiGate Session Life Support Protocol (FGSP)
1.04 FortiAnalyzer HA
1.05 FortiAuthenticator HA
1.06 FortiManager HA
1.07 Virtual clustering
1.08 Virtual Router Redundancy Protocol (VRRP)
1.09 Application performance
1.10 Multi-data-center deployments
1.11 Redundant connectivity
1.12 Work from anywhere
1.13 Hardening
1.14 Performance tuning
1.15 FortiGate-VM bootstrapping
1.16 Firmware management
1.17 FortiAnalyzer integration
1.18 FortiGuard
1.19 FortiManager policy packages
1.20 Log management
1.21 Multi-tenancy
1.22 Virtual domains (VDOM)
1.23 Operation modes
1.24 VM deployments
1.25 Workspace mode
Networking (40% of the exam)
2.01 Secure Private Access (SPA) preparation
2.02 SD-WAN on-ramp
2.03 SPA
2.04 Asymmetric routing
2.05 BFD
2.06 Dynamic routing
2.07 Equal-cost multi-path (ECMP)
2.08 Multicast
2.09 Policy routing
2.10 Policy-based routing (PBR)
2.11 SD-WAN routing
2.12 Static routing
2.13 Virtual routing and forwarding (VRF)
2.14 Auto-discovery VPN (ADVPN)
2.15 Dial-up VPN
2.16 IPsec VPN
2.17 Overlay VPN
2.18 Post-quantum cryptography (PQC) for IPsec key exchange
2.19 SD-WAN
2.20 SSL VPN
2.21 Virtual eXtensible LAN (VXLAN) over IPsec
2.22 Zero trust network access (ZTNA)
2.23 Fabric integrations
2.24 Inspection modes
2.25 IPv6
2.26 Policy modes
2.27 Proxy rules
2.28 Security profiles
2.29 Data loss prevention (DLP)
2.30 Web filtering
2.31 SSL inspection
2.32 Intrusion prevention system (IPS)
2.33 Transparent mode
2.34 Explicit proxy
2.35 Inter-VDOM routing
2.36 Local-in policies
2.37 Local-out routing
2.38 Network address translation (NAT)
2.39 Traffic shaping
2.40 Transparent proxy
2.41 VLANs
2.42 Zones
Authentication (14% of the exam)
3.01 802.1X
3.02 ADOM-scoped administrators
3.03 Advanced authentication
3.04 API authentication
3.05 Captive portal
3.06 Device and user authentication
3.07 Fabric single sign-on (SSO)
3.08 Fortinet Single Sign-On (FSSO)
3.09 Identity and access management (IAM)
3.10 LDAP
3.11 Open authorization (OAuth)
3.12 RADIUS
3.13 RADIUS single sign-on (RSSO)
3.14 SAML
3.15 SNMPv3
3.16 Single sign-on mobility agent (SSOMA)
3.17 Syslog SSO
3.18 Terminal Access Controller Access-Control System Plus (TACACs+)
3.19 Certificate authority
3.20 Certificate-based authentication
3.21 Certificate Management Protocol (CMP)
3.22 Online Certificate Status Protocol (OCSP)
3.23 Public key infrastructure (PKI)
3.24 Simple Certificate Enrollment Protocol (SCEP)
Fortinet Security Fabric (19% of the exam)
4.01 Automation parameters
Article coming4.02 Automation stitches
4.03 Automated scripts
4.04 Fortinet device APIs
4.05 Meta fields
4.06 Fabric integration
4.07 Fabric objects
4.08 Threat feeds
4.09 Custom FortiAnalyzer views
4.10 Device logging
4.11 Event handlers
4.12 FortiView
4.13 Incidents and events
4.14 Log management
4.15 Network triaging
4.16 Operation modes
4.17 Reporting
Public sources, used in good faith
These guides are independent study aids built from publicly available material: published exam blueprints, official product documentation, and vendor training catalogues. Product names, exam codes, and trademarks belong to their owners and are used only to identify the subject being taught. This site is not affiliated with or endorsed by any vendor named here. If you hold rights in material published on this page and believe it should be removed or corrected, please send the exact URL and a short note on the issue through the contact page; requests are reviewed promptly and in good faith. Read the full disclaimer →