Skip to content

NSE8_880 NSE 8 - Core Practical Exam Practice Questions

Prepare for NSE8_880 with more than an answer.

120 questions in the full set12 sample questionsUpdated Mar 12, 2026
Exam fee
$800 USD
Level
Expert
Valid for
3 years (recertification required)
Domains covered on the exam 4
  1. Infrastructure27%
  2. Networking40%
  3. Authentication14%
  4. Security Fabric19%
  1. 1

    True or False: When using FortiGate VM in a cloud environment (AWS/Azure), the 'config system ha' unicast-hb setting is required because multicast is typically blocked in public cloud networks.

    Show answer details

    Correct answer: A

    Public cloud providers generally block multicast traffic. Therefore, FortiGate HA in the cloud must use unicast heartbeats (unicast-hb) to establish the cluster.

  2. 2

    A customer wants to use FortiAuthenticator (FAC) to provide Single Sign-On (SSO) for a legacy application that only supports RADIUS Accounting. Which FortiAuthenticator feature should be configured to parse the accounting packets and trigger SSO events on the FortiGate?

    Show answer details

    Correct answer: A

    RADIUS SSO (RSSO) allows the FortiAuthenticator (or FortiGate directly) to create SSO sessions based on RADIUS Accounting Start/Stop messages sent by a NAS (like a wireless controller or VPN concentrator).

  3. 3

    You are configuring a FortiGate to support ZTNA. You have configured the ZTNA Server (Access Proxy) and the necessary firewall policies. However, external users are receiving a '502 Bad Gateway' error when trying to access the internal web resource.

    What is the most common cause of this specific error in a ZTNA deployment?

    Show answer details

    Correct answer: B

    In ZTNA (Access Proxy mode), the FortiGate terminates the connection and establishes a new one to the real server. A 502 Bad Gateway indicates the proxy (FortiGate) cannot connect to the upstream server (internal resource), often due to DNS or routing issues.

  4. 4

    You are designing a High Availability (HA) cluster for a financial institution that requires zero packet loss during failover. You decide to implement FortiGate Session Life Support Protocol (FGSP) across two geographically separated data centers. Which of the following requirements must be met to ensure successful Layer 3 session synchronization between the peers?

    Show answer details

    Correct answer: A, C

    FGSP requires identical models and firmware versions to synchronize session tables correctly, as kernel structures for sessions must match.

    For Layer 3 FGSP (where peers are in different subnets), you must explicitly define the peer-ip to establish the synchronization channel.

  5. 5

    A network administrator is troubleshooting an SD-WAN deployment where traffic is not switching to the secondary link despite the primary link exceeding the latency threshold. The administrator reviews the SD-WAN rule configuration shown below:

    config system sdwan
    config service
    edit 1
    set mode sla
    set protocol 6
    set start-port 443
    set end-port 443
    set dst "all"
    set src "all"
    config sla
    edit "latency_check"
    set id 1
    next
    end
    set priority-members 1 2
    next
    end
    end

    What is the most likely cause of the issue?

    Show answer details

    Correct answer: C

    In FortiOS, referencing an SLA ID in a rule is not enough; the Performance SLA itself (health-check) must have the 'set sla-fail-log-period' and specific threshold values configured and mapped to the ID referenced. If the threshold isn't breached according to the SLA definition, switching won't occur.

  6. 6

    You are managing a FortiManager device with ADOMs enabled. You need to upgrade the firmware of a managed FortiGate cluster from v7.2.4 to v7.4.1. When you attempt to perform the upgrade via the FortiManager Device Manager, the option is grayed out. What is the primary reason for this restriction?

    Show answer details

    Correct answer: C

    FortiManager ADOMs are version-specific. You cannot upgrade a managed device to a major firmware version higher than the ADOM version. You must first upgrade the ADOM to 7.4.

Create an account to continue.