NSE8_880 Sample Questions & Answers
Hands-on work with SASE, routing, and setting up VPNs dominates the weighting, built on high availability paired with SD-WAN design, optimizing the system, certificate and authentication measures, plus Security Fabric automation with logging and analytics.
Launch the full NSE8_880 simulator →Showing 6 of 12 free samples.
- Question 1Intermediate
Infrastructure · High Availability
In a FortiGate FGCP High Availability cluster, which command would you use to verify if the secondary unit is synchronized with the primary unit's configuration and is ready to take over?
Show answer & explanation
Correct answer: B
This command displays the configuration checksums for all cluster members. If the checksums match for global, vdom, and all sub-contexts, the devices are synchronized.
- Question 2Advanced
Infrastructure · System Optimization
You are configuring a FortiGate in a multi-tenant environment using VDOMs. You need to ensure that a specific customer VDOM (VDOM-A) does not consume more than 20% of the total available sessions on the device. Which configuration context should you use to apply this limit?
Show answer & explanation
Correct answer: B
The 'config system vdom-property' command in the global context allows you to set per-VDOM limits for resources like sessions, dial-up tunnels, and users.
- Question 3Advanced
Networking · VPN
An organization uses Auto Discovery VPN (ADVPN) to connect 50 branch offices. A shortcut tunnel has been successfully established between Branch A and Branch B. However, users in Branch A cannot access a specific UDP application in Branch B, although ICMP works fine.
Reviewing the debug flow on Branch A shows:
id=20085 trace_id=1 func=print_pkt_detail line=5824 msg="vd-root:0 received a packet(proto=17, 10.1.1.2:4500->10.2.2.2:4500) from local. type=1, code=0, ...What is the most likely cause of this issue?
Show answer & explanation
Correct answer: B
Even if the IPsec shortcut is up, traffic must pass firewall policies. If ICMP works but UDP fails, and the shortcut exists, the most likely cause is a restrictive firewall policy on the FortiGate that allows PING but blocks the specific UDP port.
- Question 4Advanced
Networking · Routing
Which BGP attribute is automatically modified by the FortiGate SD-WAN engine when 'set neighbor-group' and 'set route-map-out' are configured to influence the Hub's path selection for overlay traffic?
Show answer & explanation
Correct answer: D
In ADVPN and SD-WAN deployments, tags and communities are often used to signal link quality or path preference to the Hub. Specifically, BGP communities can be set via route-maps referenced in the neighbor-group to identify the spoke's uplink type.
- Question 5Intermediate
Networking · VPN
When implementing VXLAN over IPsec on a FortiGate, which critical interface setting must be adjusted to prevent IP fragmentation and ensure optimal performance, considering the additional overhead?
Show answer & explanation
Correct answer: C
VXLAN adds 50 bytes of overhead, and IPsec adds additional overhead. To avoid fragmentation which kills performance, the inner MTU (VXLAN interface) must be lower than the physical interface MTU minus headers.
- Question 6Advanced
Networking · Advanced Networking
You are deploying a FortiGate in a network where asymmetric routing is expected due to multiple entry points. You configure
set asymroute enableglobally. What is a significant security implication of this command?Show answer & explanation
Correct answer: B
Enabling global asymmetric routing causes the FortiGate to bypass stateful inspection checks (like TCP flags) for asymmetric traffic, effectively treating it as stateless. This reduces security efficacy.
Ready for the real thing?
The full NSE8_880 simulator has every exam-style question, timed mode, and instant scoring.