NSE8_813 Fortinet NSE 8 - Recertification Written Exam Practice Questions
Prepare for NSE8_813 with more than an answer.
- Exam fee
- $400 USD
- Time limit
- 120 minutes
- Questions on the exam
- 55-60
- Passing score
- Pass/Fail (no numeric score disclosed)
- Level
- Expert (NSE 8 / FCX)
- Valid for
- 3 years (extends from original expiration date, not from exam date)
Domains covered on the exam 7
- Security Architecture15%
- Infrastructure15%
- Networking20%
- Secure SD-WAN12%
- Security Solutions18%
- Security Operations10%
- Automation10%
- 1
A FortiGate is configured with Dual-Stack (IPv4 and IPv6). You need to allow internal IPv6-only clients to access IPv4-only servers on the Internet. DNS resolution for these clients is handled by the FortiGate.
Which two technologies must be combined to achieve this? (Select TWO)
Show answer details
Correct answer: A, C
NAT64 translates the IPv6 source packets to IPv4 so they can traverse the IPv4 internet to the server.
DNS64 is required to synthesize an AAAA record from the IPv4-only server's A record. The IPv6 client asks for an AAAA record; DNS64 fakes it using a specific prefix, pointing the client to the NAT64 gateway.
- 2
You are implementing Traffic Shaping on a FortiGate with NP7 processors. You have created a 'Per-IP Shaper' to limit each user to 5 Mbps. You apply this shaper to a firewall policy.
What is the impact on hardware acceleration for traffic matching this policy?
Show answer details
Correct answer: B
FortiOS 7.4 Hardware Acceleration: NP7 and NP7Lite (SOC5) processors support offloading for all FortiOS traffic shaping functions, including policy shaping, per-IP shaping, port shaping and interface shaping profiles. By default, shaping is applied to offloaded traffic with no special configuration, and the CPU applies shaping only if you disable offloading. NP6-offloaded sessions also support most types of traffic shaping.
- 3
You are troubleshooting a VXLAN over IPsec deployment between two data centers. The tunnel comes up, but users report that large file transfers fail, while ping works fine. You suspect an MTU issue.
Considering the overhead of VXLAN (50 bytes) and IPsec (ESP+IP header ~50-80 bytes), what is the correct action to resolve this without enabling fragmentation on the WAN?
Show answer details
Correct answer: A
The inner packet (User Data) + VXLAN Header + UDP Header + IP Header (Outer) + ESP Header + IP Header (Tunnel) must fit within the physical WAN MTU (usually 1500). VXLAN adds ~50 bytes. IPsec adds another ~70-80 bytes. The virtual interface inside the tunnel must have a lower MTU (e.g., 1350 or 1360) to prevent the final packet from exceeding 1500. Additionally, TCP MSS clamping helps negotiate the correct segment size for TCP traffic.
- 4
A large enterprise is deploying a standalone FortiGate 7000 series chassis in a high-traffic data center, using Session-Aware Load Balancing (SLBC).
During a failure test, one of the processing modules (FPM) fails. The administrator notices that while new sessions are distributed to the remaining FPMs, a subset of long-lived TCP sessions was dropped and had to be re-established by the clients.
Based on the architecture of the 7000 series, what is the most likely cause of this behavior?
Show answer details
Correct answer: C
SLBC sends each session to one FPM, and that FPM holds the session state. FPMs in the same chassis do not synchronize sessions with each other, so when an FPM fails, the sessions it was processing are lost and the clients must reconnect. Only an FGCP HA cluster of two FortiGate 7000 chassis with session-pickup enabled keeps such sessions: the primary syncs its sessions to the secondary chassis, and an FPM failure makes the chassis with more working FPMs the primary.
- 5
An organization requires a high-availability architecture spanning two geographically separated data centers (DC A and DC B) connected by a Layer 2 metro link. The requirement is to utilize all available bandwidth on both sites simultaneously for outbound internet traffic while maintaining session continuity if one site fails completely.
Which Fortinet HA solution best fits this requirement, and what is a critical configuration constraint?
Show answer details
Correct answer: C
FGSP (Standalone Session Sync) allows two independent FortiGates to synchronize sessions without clustering them into a single logical entity (like FGCP). This allows active-active forwarding at Layer 3 across sites. However, because they are independent, asymmetric routing is a major issue; auxiliary sessions or strict symmetry must be managed.
- 6
You are designing a multi-tenant deployment on a single high-end FortiGate with one VDOM per tenant. All VDOMs send logs to the provider's central FortiAnalyzer using the global FortiAnalyzer settings. One tenant requires that its VDOM's logs be sent only to the tenant's own FortiAnalyzer.
Which configuration achieves this?
Show answer details
Correct answer: A
By default, every VDOM uses the global FortiAnalyzer settings. To send one VDOM's logs to a different FortiAnalyzer, go into that VDOM and enable config log setting / set faz-override enable. Then configure config log fortianalyzer override-setting with set status enable and set server . The other VDOMs keep using the global FortiAnalyzer.
