NSE 8
NSE 8 Security Operations Practical Exam
Part of NSE 8
Independent study aid built from the public exam blueprint. Not affiliated with, authorized by, or endorsed by fortinet. Objectives are transcribed and mapped by hand, so this page may contain mistakes or may have fallen behind the vendor's current material: exam objectives, versions, numbering and availability all change without notice. Treat fortinet's own certification portal as the source of truth and verify against it before you book anything.
Note on this blueprint: Fortinet's own exam page publishes a Tasks column whose entries are truncated or blank, so the objectives below are transcribed from the Details column beside them, grouped under the published section headings and weightings. Verified against a fresh fetch.
Automation (23% of the exam)
1.01 FortiManager Jinja scripting
1.02 FortiManager provisioning templates
1.03 Fortinet APIs
1.04 Automated incident response
1.05 Automation connectors
1.06 FortiAnalyzer playbooks
1.07 Fortinet Security Fabric
1.08 Outbreak alerts
1.09 Security orchestration, automation, and response (SOAR) playbooks
1.10 Workflows and workspaces
1.11 FortiSIEM automation service
Analytics and reporting (26% of the exam)
2.01 Configuration management database (CMDB)
2.02 Compliance reports
2.03 Custom log parsers
2.04 Datasets
2.05 FortiAnalyzer custom reports
2.06 FortiSIEM analytics
2.07 FortiSOAR reports
2.08 Hcache
2.09 Incident reporting
2.10 Security information and event management (SIEM) parsers and monitors
2.11 SQL
2.12 Dashboards
2.13 Case management
2.14 Endpoint detection and response (EDR) security incidents
2.15 Indicators of compromise (IOC)
2.16 Investigation View
2.17 Searches and filters
2.18 SIEM analytics search
Threat handling (29% of the exam)
3.01 EDR threat hunting
3.02 extended Detection and response (XDR)
3.03 Device isolation and remediation
3.04 FortiEDR Connect
3.05 Incident response
3.06 War rooms
3.07 Simulation mode
3.08 Incident handling and response frameworks
3.09 Application communication control
3.10 Application control
3.11 Device control
3.12 Execution prevention
3.13 Exfiltration prevention
3.14 Prevention mode
3.15 Ransomware prevention
3.16 Suspicious indicator blocking
3.17 Vulnerability management
Infrastructure (22% of the exam)
4.01 Advanced health system
Article coming4.02 CMDB
4.03 FortiSIEM collectors
4.04 Device support advanced operations
4.05 HTTP generic poller
4.06 Multi-tenancy
4.07 Role-based access control (RBAC)
4.08 Security management
4.09 Segmented network support
4.10 FortiEDR HA
4.11 FortiAnalyzer HA
4.12 FortiManager HA
4.13 FortiSOAR HA
4.14 FortiSIEM HA
4.15 Application Editor
4.16 Content Hub
4.17 Modules
4.18 Policy Analyzer management extension application (MEA)
4.19 Queue, shift, and leave management
4.20 Rules, reports, and dashboards
4.21 Solution packs
4.22 Widgets
Public sources, used in good faith
These guides are independent study aids built from publicly available material: published exam blueprints, official product documentation, and vendor training catalogues. Product names, exam codes, and trademarks belong to their owners and are used only to identify the subject being taught. This site is not affiliated with or endorsed by any vendor named here. If you hold rights in material published on this page and believe it should be removed or corrected, please send the exact URL and a short note on the issue through the contact page; requests are reviewed promptly and in good faith. Read the full disclaimer →