NSE8_880 NSE 8 - Core Practical Exam Practice Questions
Prepare for NSE8_880 with more than an answer.
- Exam fee
- $800 USD
- Level
- Expert
- Valid for
- 3 years (recertification required)
Domains covered on the exam 4
- Infrastructure27%
- Networking40%
- Authentication14%
- Security Fabric19%
- 1
True or False: When using FortiGate VM in a cloud environment (AWS/Azure), the 'config system ha' unicast-hb setting is required because multicast is typically blocked in public cloud networks.
Show answer details
Correct answer: A
Public cloud providers generally block multicast traffic. Therefore, FortiGate HA in the cloud must use unicast heartbeats (unicast-hb) to establish the cluster.
- 2
A customer wants to use FortiAuthenticator (FAC) to provide Single Sign-On (SSO) for a legacy application that only supports RADIUS Accounting. Which FortiAuthenticator feature should be configured to parse the accounting packets and trigger SSO events on the FortiGate?
Show answer details
Correct answer: A
RADIUS SSO (RSSO) allows the FortiAuthenticator (or FortiGate directly) to create SSO sessions based on RADIUS Accounting Start/Stop messages sent by a NAS (like a wireless controller or VPN concentrator).
- 3
You are configuring a FortiGate to support ZTNA. You have configured the ZTNA Server (Access Proxy) and the necessary firewall policies. However, external users are receiving a '502 Bad Gateway' error when trying to access the internal web resource.
What is the most common cause of this specific error in a ZTNA deployment?
Show answer details
Correct answer: B
In ZTNA (Access Proxy mode), the FortiGate terminates the connection and establishes a new one to the real server. A 502 Bad Gateway indicates the proxy (FortiGate) cannot connect to the upstream server (internal resource), often due to DNS or routing issues.
- 4
You are designing a High Availability (HA) cluster for a financial institution that requires zero packet loss during failover. You decide to implement FortiGate Session Life Support Protocol (FGSP) across two geographically separated data centers. Which of the following requirements must be met to ensure successful Layer 3 session synchronization between the peers?
Show answer details
Correct answer: A, C
FGSP requires identical models and firmware versions to synchronize session tables correctly, as kernel structures for sessions must match.
For Layer 3 FGSP (where peers are in different subnets), you must explicitly define the peer-ip to establish the synchronization channel.
- 5
A network administrator is troubleshooting an SD-WAN deployment where traffic is not switching to the secondary link despite the primary link exceeding the latency threshold. The administrator reviews the SD-WAN rule configuration shown below:
config system sdwan
config service
edit 1
set mode sla
set protocol 6
set start-port 443
set end-port 443
set dst "all"
set src "all"
config sla
edit "latency_check"
set id 1
next
end
set priority-members 1 2
next
end
endWhat is the most likely cause of the issue?
Show answer details
Correct answer: C
In FortiOS, referencing an SLA ID in a rule is not enough; the Performance SLA itself (health-check) must have the 'set sla-fail-log-period' and specific threshold values configured and mapped to the ID referenced. If the threshold isn't breached according to the SLA definition, switching won't occur.
- 6
You are managing a FortiManager device with ADOMs enabled. You need to upgrade the firmware of a managed FortiGate cluster from v7.2.4 to v7.4.1. When you attempt to perform the upgrade via the FortiManager Device Manager, the option is grayed out. What is the primary reason for this restriction?
Show answer details
Correct answer: C
FortiManager ADOMs are version-specific. You cannot upgrade a managed device to a major firmware version higher than the ADOM version. You must first upgrade the ADOM to 7.4.
