Official Bank 0/105

Fortinet NSE 8 – Written (NSE8_812) - Fortinet Exam Questions

Last updated on June 20, 2026

97% Exam Compliance
105 Total Questions
1
Question
A customer is planning on moving their secondary data center to a cloud-based laaS. They want to place all the Oracle-based systems Oracle Cloud, while the other systems will be on Microsoft Azure with ExpressRoute service to their main data center. They have about 200 branches with two internet services as their only WAN connections. As a security consultant you are asked to design an architecture using Fortinet products with security, redundancy and performance as a priority.

Which two design options are true based on these requirements? (Choose two.)
Select 2
Options
A Use FortiGate VM for IPSEC over ExpressRoute, as traffic is not encrypted by Azure.
B Systems running on Azure will need to go through the main data center to access the services on Oracle Cloud.
C Branch FortiGate devices must be configured as VPN clients for the branches' internal network to be able to access Oracle services without using public IPs.
D Two ExpressRoute services to the main data center are required to implement SD-WAN between a FortiGate VM in Azure and a FortiGate device at the data center edge
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question
Refer to the exhibit.

Exhibit

The exhibit shows the forensics analysis of an event detected by the FortiEDR core In this scenario, which statement is correct regarding the threat?
Options
A This is an exfiltration attack and has not been stopped by FortiEDR
B This is an exfiltration attack and has been stopped by FortiEDR.
C This is a ransomware attack and has not been stopped by FortiEDR.
D This is a ransomware attack and has been stopped by FortiEDR
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question
Refer to the exhibit.

Exhibit

A customer reports that they are not able to reach subnet 10.10.10.0/24 from their FortiGate device. Based on the exhibit, what should you do to correct the situation?
Options
A Enable recursive resolution for BGP routes
B Enable iBGP multipath
C Enable next-hop-self feature
D Enable additional-path feature
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question
Refer to the exhibit, which shows a multi-region SD-WAN architecture.

Exhibit

Given this scenario, which two statements are true? (Choose two.)
Select 2
Options
A If eBGP is used, ADVPN can be established for branch-to-branch traffic across regions.
B If iBGP is used, cross-regional spoke-to-hub shortcuts can be established.
C If eBGP is used, ADVPN can be established only for branch-to-branch traffic within each region.
D If iBGP is used, cross-regional spoke-to-hub shortcuts cannot be used.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question
An automation stitch was configured using an incoming webhook as the trigger named 'my_incoming_webhook'. The action is configured to execute the CLI Script shown:

Exhibit
Options
A data: ‘{ “hostname”: “bad_host_1”, “ip”: [“1.1.1.1”]}’
url: http://192.168.226.129/api/v2/monitor/system/automation- stitch/webhook/my_incoming_webhook
B data: ‘{ “hostname”: “bad_host_1”, “ip”: “1.1.1.1”}’
url: http://192.168.226.129/api/v2/monitor/system/automation- stitch/webhook/my_incoming_webhook
C data: ‘{ “hostname”: “bad_host_1”, “ip”: [“1.1.1.1”]}’
url: http://192.168.226.129/api/v2/cmdb/system/automation- stitch/webhook/my_incoming_webhook
D data: ‘{ “hostname”: “bad_host_1”, “ip”: “1.1.1.1”}’
url: http://192.168.226.129/api/v2/cmdb/system/automation- stitch/webhook/my_incoming_webhook
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.