Fortinet NSE8 Actual Free Exam Questions & Community Discussion

  • Exam Code/Number: NSE8
  • Exam Name/Title: Fortinet Network Security Expert 8 Written Exam (NSE8 801 - FortiOS 5.2)
  • Certification Provider: Fortinet
  • Corresponding Certification: Network Security
  • Exam Questions: 65
  • Updated On: May 31, 2026
Your marketing department uncompressed and executed a file that the whole department received using
Skype.
Reviewing the exhibit, which two details do you determine frim your initial analysis if the payload?
Correct Answer: D Vote an answer
You are hosting Web applications that must be PCI DSS compliant. The Web applications are protected
by a FortiWeb. Compliance will be tested during the quarterly security review.
In this scenario, which three FortiWeb features should you use? (Choose three.)
Correct Answer: A,B,C Vote an answer
Referring to the exhibit, users are reporting that their FortiFones ring but when they pick up, the cannot
hear each other. The FortiFones use SIP to communicate with the SIP Proxy Server and RTP between
the phones.
Which configuration change will resolve the problem?

A:

B:

C:

D:
Correct Answer: C Vote an answer
Referring to the exhibit, you want to know if aggregating port7 and port22 will work.
Which statement is correct?
Correct Answer: C Vote an answer
A customer is authenticating users using a FortiGate and an external LDAP server. The LDAP user, John
Smith, cannot authenticate. The administrator runs the debug command diagnose debug application fnbamd 255 while John Smith attempts the authentication:
Based on the output shown in the exhibit, what is causing the problem?
Correct Answer: A Vote an answer
A company wants to protect against Denial of Service attacks and has launched a new project.
They want to block the attacks that go above a certain threshold and for some others they are just trying to get a
baseline of activity for those types of attacks so they are letting the traffic pass through without action.
Given the following:
-The interface to the Internet is on WAN1.
-There is no requirement to specify which addresses are being protected or protected from.
-The protection is to extend to all services.
-The tcp_syn_flood attacks are to be recorded and blocked.
-The udp_flood attacks are to be recorded but not blocked.
-The tcp_syn_flood attack's threshold is to be changed from the default to 1000.
The exhibit shows the current DoS-policy.
Which policy will implement the project requirements?

A:

B:

C:

D:
Correct Answer: A,B Vote an answer
Which VPN protocol is supported by FortiGate units?
Correct Answer: B,D Vote an answer
0
0
0
10