Official Bank 0/65

Fortinet NSE 8 Written Exam (NSE8_811) - Fortinet Exam Questions

Last updated on June 20, 2026

97% Exam Compliance
65 Total Questions
1
Question
Exhibit

Exhibit

The exhibit shows a topology where a FortiGate is two VDOMS, root and vd-vlasn. The root VDCM provides SSL-VPN access, where the users authenticated by a FortiAuthenticatator. The vd-lan VDOM provids internal access to a Web server. For the remote users to access the internal web server, there are a few requirements, which are shown below.

--At traffic must come from the SSI-VPN

--The vd-lan VDOM only allows authenticated traffic to the Web server.

-- Users must only authenticate once, using the SSL-VPN portal.

-- SSL-VPN uses RADIUS-based authentication.
referring to the exhibit, and the requirement describe above, which two statements are true? (Choose two.)
Select 2
Options
A root is configured for FSSO while vd-lan is configuration for RSSO.
B vd-lan authentication messages from root using FSSO.
C root sends “RADIUS Accounting Messages" to FortiAuthenticator.
D vd-lan connects to Fort authenticator as a regular FSSO client.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question
An organization has one central site and three remote sites. A FortiSIEM has been installed on the central site and now all devices across the remote sites must be centrally monitored by the FortiSIEM at the central site.

Which action will reduce the WAN usage by the monitoring system?
Options
A Enable SD-WAN FEC (Forward Error Correction) on the FortiGate at the remote site.
B Install local Collectors on each remote site.
C Disable real-time log upload on the remote sites.
D Install both Supervisor and Collector on each remote site.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question
A customer has a SCADA environmental control device that is triggering a false-positive IPS alert whenever the Web GUI of the device is accessed. You cannot create a functional custom IPS filter to exempt this behavior, and it appears that the device is so old that it does not have HTTPS support. You need to prevent the false positive IPS alerts from occurring. In this scenario, which two actions will accomplish this task? (Choose two.)
Select 2
Options
A Create a very specific firewall policy for that device IP address which does not perform IPS scanning.
B Create a URL filter with the Exempt action for that device IP address.
C Reconfigure the FortiGate to operate in proxy-based inspection mode instead of flow-based.
D Change the relevant firewall policies to use SSL certificate-inspection instead of SSL deep- inspection.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question
Exhibit

Exhibit

An organization has a FortiGate cluster that is connected to two independent ISPs. You must configure the FortiGate failover for a single ISP failure to occur without disruption. Referring to the exhibit, which two FortiGate BGP features are enabled to accomplish this task? (Choose two.)
Select 2
Options
A Synchronization
B EBGP multipath
C BFD
D Graceful restart
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question
A FortOS devices is used for termination of VPNs for number of remote spoke VPN units (designated group A spokes) using a phase 1 main mode dial-up tunnel using pre-shared. Your company recently acquired another organization. You are asked establish VPN correctively for the newly acquired organization's sites which new devices will be provisioned (designated Group B spokes). Both exiting (Group A) and new (Group
Options
A Implement a new phase 1 dial-up main mode tunnel with a different pre-shared key than the Group A spokes.
B Implement a new phase 1 dial-up main mode tunnel with pre-shared keys and XAuth.
C Implement separate phase 1 dial-up aggressive mode tunnels with a distinct peer ID.
D Implement a new phase 1 dial-up main mode tunnel with certificate authentication.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.