Skip to content

NSE_3 NSE 3 - FortiGate Operator Practice Questions

Prepare for NSE_3 with more than an answer.

150 questions in the full set12 sample questionsUpdated Mar 12, 2026
Questions on the exam
40
Passing score
Not officially published; approximately 70-80% based on community reports
Level
Associate
Valid for
2 years
Domains covered on the exam 9
  1. FortiGate Fundamentals10%
  2. Network Configuration15%
  3. Firewall Policy Configuration15%
  4. User Authentication7%
  5. Security Profiles - Content Inspection20%
  6. Virtual Private Networks (VPN)13%
  7. System Administration and Monitoring10%
  8. Fortinet Security Fabric5%
  9. High Availability and Infrastructure5%
  1. 1

    A system administrator is reviewing the 'FortiView' dashboards. They notice a spike in traffic from a specific application category. Which action can they take directly from the FortiView source or application widget to mitigate this?

    Show answer details

    Correct answer: D

    FortiView allows administrators to drill down into traffic sources, destinations, or applications. From there, depending on configuration, they can often terminate sessions or quarantine a source IP directly from the context menu.

  2. 2

    When configuring an Antivirus Profile in 'Flow-based' mode, which of the following limitations should the administrator be aware of compared to 'Proxy-based' mode?

    Show answer details

    Correct answer: D

    Flow-based inspection is faster as it scans packets as they pass through without buffering the entire file first. However, it lacks some features available in proxy mode, such as client comforting (sending data to keep connection alive during scan) and some deeper archive inspection capabilities.

  3. 3

    An administrator wants to use the 'Internet Service Database' (ISDB) in a firewall policy. What is the primary advantage of using ISDB objects over traditional FQDN address objects?

    Show answer details

    Correct answer: B

    The ISDB is a database of IP addresses and ports used by well-known internet services. FortiGuard updates this database. Using ISDB allows policies to target 'Microsoft-Office365' or 'Google-Gmail' accurately without the admin manually tracking changing IP ranges.

  4. 4

    A junior administrator is configuring a new FortiGate device for a branch office. They need to ensure that the device's system time is accurate for log correlation with the central FortiAnalyzer. Which configuration setting should be prioritized to ensure time consistency across the Security Fabric?

    Show answer details

    Correct answer: B

    Accurate system time is critical for log correlation and certificate validation. Configuring a Network Time Protocol (NTP) server ensures the FortiGate synchronizes its clock with a reliable source. While manual setting works temporarily, it drifts over time.

  5. 5

    A network operator is reviewing the routing table on a FortiGate. They observe two static routes to the same destination subnet. Route A has a Distance of 10 and a Priority of 10. Route B has a Distance of 10 and a Priority of 20. Which route will be installed in the routing table and used for traffic forwarding?

    Show answer details

    Correct answer: A

    When Administrative Distance is equal, FortiGate uses Priority to break ties. A lower Priority value is preferred. However, unless ECMP (Equal Cost Multi-Path) is specifically intended and priorities are equal (or ignored depending on config), the lower priority route is preferred.

  6. 6

    When configuring a Firewall Policy, an administrator wants to ensure that a specific internal server is accessible from the internet using a public IP address. Which object must be created and referenced in the Destination field of the policy?

    Show answer details

    Correct answer: B

    A Virtual IP (VIP) is used for Destination NAT (DNAT). It maps a public IP address (and optionally a port) to an internal private IP address, allowing external access to internal resources.

Create an account to continue.