NSE8_880 Sample Questions

NSE8_880 Sample Questions & Answers

Hands-on work with SASE, routing, and setting up VPNs dominates the weighting, built on high availability paired with SD-WAN design, optimizing the system, certificate and authentication measures, plus Security Fabric automation with logging and analytics.

Launch the full NSE8_880 simulator →

Showing 6 of 12 free samples.

  1. Question 1Intermediate

    Infrastructure · High Availability

    In a FortiGate FGCP High Availability cluster, which command would you use to verify if the secondary unit is synchronized with the primary unit's configuration and is ready to take over?

    Show answer & explanation

    Correct answer: B

    This command displays the configuration checksums for all cluster members. If the checksums match for global, vdom, and all sub-contexts, the devices are synchronized.

  2. Question 2Advanced

    Infrastructure · System Optimization

    You are configuring a FortiGate in a multi-tenant environment using VDOMs. You need to ensure that a specific customer VDOM (VDOM-A) does not consume more than 20% of the total available sessions on the device. Which configuration context should you use to apply this limit?

    Show answer & explanation

    Correct answer: B

    The 'config system vdom-property' command in the global context allows you to set per-VDOM limits for resources like sessions, dial-up tunnels, and users.

  3. Question 3Advanced

    Networking · VPN

    An organization uses Auto Discovery VPN (ADVPN) to connect 50 branch offices. A shortcut tunnel has been successfully established between Branch A and Branch B. However, users in Branch A cannot access a specific UDP application in Branch B, although ICMP works fine.

    Reviewing the debug flow on Branch A shows:
    id=20085 trace_id=1 func=print_pkt_detail line=5824 msg="vd-root:0 received a packet(proto=17, 10.1.1.2:4500->10.2.2.2:4500) from local. type=1, code=0, ...

    What is the most likely cause of this issue?

    Show answer & explanation

    Correct answer: B

    Even if the IPsec shortcut is up, traffic must pass firewall policies. If ICMP works but UDP fails, and the shortcut exists, the most likely cause is a restrictive firewall policy on the FortiGate that allows PING but blocks the specific UDP port.

  4. Question 4Advanced

    Networking · Routing

    Which BGP attribute is automatically modified by the FortiGate SD-WAN engine when 'set neighbor-group' and 'set route-map-out' are configured to influence the Hub's path selection for overlay traffic?

    Show answer & explanation

    Correct answer: D

    In ADVPN and SD-WAN deployments, tags and communities are often used to signal link quality or path preference to the Hub. Specifically, BGP communities can be set via route-maps referenced in the neighbor-group to identify the spoke's uplink type.

  5. Question 5Intermediate

    Networking · VPN

    When implementing VXLAN over IPsec on a FortiGate, which critical interface setting must be adjusted to prevent IP fragmentation and ensure optimal performance, considering the additional overhead?

    Show answer & explanation

    Correct answer: C

    VXLAN adds 50 bytes of overhead, and IPsec adds additional overhead. To avoid fragmentation which kills performance, the inner MTU (VXLAN interface) must be lower than the physical interface MTU minus headers.

  6. Question 6Advanced

    Networking · Advanced Networking

    You are deploying a FortiGate in a network where asymmetric routing is expected due to multiple entry points. You configure set asymroute enable globally. What is a significant security implication of this command?

    Show answer & explanation

    Correct answer: B

    Enabling global asymmetric routing causes the FortiGate to bypass stateful inspection checks (like TCP flags) for asymmetric traffic, effectively treating it as stateless. This reduces security efficacy.

Ready for the real thing?

The full NSE8_880 simulator has every exam-style question, timed mode, and instant scoring.