NSE7 Sample Questions

NSE7 Sample Questions & Answers

Free Fortinet NSE 7 Network Security Architect practice questions with worked answers and explanations. See how the ExamJungle simulator prepares you — then jump into the full test.

Launch the full NSE7 simulator →

Showing 10 of 20 free samples.

  1. Question 1Beginner

    Central Management · FortiManager Integration

    True or False: When using FortiManager in a workspace mode configuration, an administrator must lock an ADOM before making any configuration changes to policy packages or objects within that ADOM.

    Show answer & explanation

    Correct answer: A

    Workspace mode is designed to prevent multiple administrators from making conflicting changes simultaneously. Before any modifications can be made within an ADOM (such as editing policies, objects, or device settings), the administrator must explicitly lock that ADOM. This ensures a safe and controlled change management process.

  2. Question 2Intermediate

    System Configuration · High Availability (HA) Clusters

    An organization uses two FortiGate devices in different data centers, managed by a third-party load balancer for active/active processing. They need to ensure that if one FortiGate fails, user sessions are seamlessly transferred to the other without requiring re-authentication. A traditional FGCP cluster is not feasible due to the network architecture. Which Fortinet technology is designed for this specific scenario?

    Show answer & explanation

    Correct answer: C

    FortiGate Session Life Support Protocol (FGSP) is the correct technology. It is specifically designed to synchronize sessions between two or more standalone FortiGate devices. This allows a load balancer to distribute traffic, and if one device fails, the other can take over the sessions without interruption because it has a copy of the session table.

  3. Question 3Intermediate

    Routing · BGP Implementation

    A consultant is reviewing a BGP configuration on a FortiGate that is multihomed to two different ISPs. The company wants to ensure that all outbound traffic prefers the primary ISP link, but can automatically fail over to the secondary ISP. The primary ISP connection has higher bandwidth and lower latency. Which BGP attribute should be manipulated on the inbound route maps from the ISPs to achieve this routing policy?

    Show answer & explanation

    Correct answer: D

    Local Preference is the standard attribute used to influence outbound traffic path selection within a single Autonomous System (AS). By setting a higher Local Preference value (default is 100) on routes received from the primary ISP, the FortiGate will prefer that path for all outbound traffic. This attribute is propagated to all iBGP peers within the AS, ensuring consistent exit point selection.

  4. Question 4Advanced

    Security Profiles · SSL Inspection

    Case Study:

    A large enterprise, FinCorp, operates a primary data center and a disaster recovery (DR) site, each with a FortiGate cluster. They have a requirement for deep SSL inspection for all outbound web traffic for compliance reasons. To reduce the load on the individual FortiGates and centralize certificate management, they want to offload the SSL inspection to a dedicated appliance.

    All outbound traffic from the user network is routed to the primary FortiGate cluster. The dedicated SSL inspection appliance is located in a separate security zone. The FortiGates are responsible for applying web filtering, IPS, and application control after the traffic has been decrypted.

    The security architect has proposed a solution where the FortiGate forwards traffic to the SSL inspection appliance, receives the decrypted traffic back, applies security profiles, and then forwards it to the internet. The following diagram illustrates the intended logical traffic flow:

    graph TD User --> FGT[FortiGate Cluster] FGT -->|Encrypted Traffic| SSL_App[SSL Inspection Appliance] SSL_App -->|Decrypted Traffic| FGT FGT -->|Apply Profiles| FGT_NAT[NAT & Egress] FGT_NAT --> Internet((Internet))

    Which FortiOS feature must be configured on the FortiGate to support this design?

    Show answer & explanation

    Correct answer: D

    This scenario describes a classic SSL offloading use case. The FortiGate can be configured as a transparent web proxy. Within the web proxy profile, you can enable SSL offloading, which directs HTTPS traffic to an external appliance for decryption. The FortiGate then receives the decrypted HTTP traffic, applies the necessary security profiles (Web Filter, IPS, etc.), and routes it out. This feature is designed specifically for integrating with third-party SSL inspection solutions.

  5. Question 5Intermediate

    VPN · IPsec VPN with IKE version 2

    An administrator is attempting to establish a certificate-based IKEv2 IPsec tunnel between two FortiGates. Phase 1 fails to come up. The debug output on the initiator shows the message "received peer certificate but it is not trusted". The administrator has confirmed that both FortiGates have their own signed local certificates and the CA certificate for the peer. What is a common cause for this error?

    Show answer & explanation

    Correct answer: A

    When using certificate authentication, the FortiGate must both trust the CA that signed the peer's certificate AND verify the peer's identity. A common mistake is a mismatch between the configured peer ID (e.g., a specific FQDN or IP address) and the identity contained within the peer's certificate (e.g., the Subject or Subject Alternative Name field). If these do not match based on the peerid setting, the FortiGate will not trust the certificate for authentication, even if the issuing CA is trusted.

  6. Question 6Intermediate

    System Configuration · VDOMs

    A FortiGate is configured with two VDOMs: 'root' and 'Internal'. A VDOM link has been created between them. A static route exists in the 'root' VDOM to direct traffic for 10.100.0.0/16 to the VDOM link interface. In the 'Internal' VDOM, there is a policy allowing traffic from the VDOM link to an internal server. However, traffic from the root VDOM is not reaching the server. What essential configuration is missing?

    Show answer & explanation

    Correct answer: A

    Traffic flow between VDOMs over a VDOM link requires a complete set of policies and routes, just like physical interfaces. A route in the source VDOM ('root') directs traffic to the link, but a firewall policy is also required in the 'root' VDOM to permit that traffic to egress through its side of the VDOM link interface. Without this policy, the traffic will be implicitly denied before it can cross into the 'Internal' VDOM.

  7. Question 7Beginner

    VPN · ADVPN

    What is the primary function of the auto-discovery-sender command when configuring ADVPN on a spoke FortiGate?

    Show answer & explanation

    Correct answer: B

    The set auto-discovery-sender enable command on a spoke's Phase 1 interface configuration allows that spoke to actively initiate the creation of a shortcut tunnel when it needs to send traffic to another spoke. It sends an IKE message to the hub, which then forwards the information to the destination spoke, triggering the shortcut negotiation.

  8. Question 8Intermediate

    Security Profiles · FortiGuard Services

    A FortiGate is configured to use FortiManager as its local FortiGuard server for web filtering services. During a network outage, the FortiGate loses connectivity to the FortiManager. How will the FortiGate handle new web requests if it cannot reach its local FortiGuard server?

    Show answer & explanation

    Correct answer: C

    FortiGate devices maintain a local cache of the FortiGuard database. If the primary FortiGuard server (in this case, the FortiManager) becomes unreachable, the FortiGate will continue to use its cached ratings to categorize websites. The behavior for unrated sites depends on the 'Rate URLs by domain and IP Address' setting. This caching mechanism provides resilience against temporary connectivity loss.

  9. Question 9Intermediate

    VPN · ADVPN

    True or False: Using the set net-device disable command on the hub's IPsec Phase 1 configuration for ADVPN is a best practice because it prevents the hub from creating a kernel route for the tunnel, forcing all spoke-to-spoke traffic to be routed dynamically via BGP or OSPF.

    Show answer & explanation

    Correct answer: A

    This statement is true. The set net-device disable command is a crucial and recommended setting on the ADVPN hub. It prevents the FortiGate from automatically adding a kernel route for each spoke that connects. This forces the routing of traffic between spokes to rely exclusively on the dynamic routing protocol (like BGP) running over the overlay, which is the correct design for ADVPN to function and scale properly.

  10. Question 10AdvancedSelect 3

    System Configuration · Hardware Acceleration

    A system administrator is analyzing traffic on a FortiGate with NP7 processors and notices that certain sessions, which should be offloaded, are being processed by the CPU. The administrator has verified that no proxy-based inspection is applied. Which of the following are valid reasons for traffic to be sent to the CPU (slow path) instead of being offloaded? (Select THREE)

    Show answer & explanation

    Correct answers: A, C, D

Ready for the real thing?

The full NSE7 simulator has every exam-style question, timed mode, and instant scoring.

Go to the NSE7 simulator →