Status:
Coming Soon (Expected: December, 2026)
The Fortinet NSE 8 - Secure Networking exam evaluates your comprehensive knowledge of network security design, configuration, and troubleshooting for complex networks in network security solutions. To attempt this exam, you must have industry experience.
Once you pass the exam, you will receive the following exam badge:

Audience
The Fortinet NSE 8 - Secure Networking exam is intended for networking and security experts who use Fortinet network security solutions. In addition to formal training, you should have experience with a variety of complex networks and be able to solve complicated security problems.
Exam Details
| Exam name |
Fortinet NSE 8 - Secure Networking |
| Format |
Onsite and online through the Fortinet Training Institute (proctored through ProctorU) |
| Cost |
US$800 per exam |
| Language |
English |
| Number of tasks |
To be communicated per exam |
| Appointment time |
To be communicated per exam |
| Task scoring method |
Partial credits are available for select tasks. There are no deductions for incorrect answers. |
| Task types |
Hands-on configuration, troubleshooting, drag and drop, and multiple choice |
| Time required between unsuccessful attempts |
30 days |
| Time for acknowledgment and training transcripts to be updated with exam grade |
30 days |
| Scoring |
Pass or fail |
| Products |
All products in the Core exam, FortiClient EMS 7.4, FortiSwitch 7.6, FortiNAC 7.6, and FortiSandbox 5.2 |
Exam Topics
The tasks listed in this table represent potential content areas covered in this exam. Your knowledge and skills in these areas will be assessed through design, configuration, and troubleshooting tasks.
Secure SD-WAN (25% of the exam)
| Tasks |
Details |
| Overlay VPN and advanced routing |
- 4G/5G last-option links
- Advanced auto-discovery VPN (ADVPN)
- Advanced IPsec troubleshooting
- ADVPN 2.0 versus legacy
- Application-based routing
- Bandwidth aggregation
- BGP multipath
- Software-defined branch (SD-Branch) deployment
- Dynamic BGP
- Dynamic QoS
- Forward error correction (FEC)
- Full mesh overlay networks
- Load balancing and redundancy
- Mean opinion score (MOS)
- Performance monitoring
- Performance SLAs and service rules
- Policy-based routing (PBR)
- Remote health signaling from spokes to hub
- Remote health signaling to third-party devices
- Route monitoring and triaging
- SD-WAN interfaces
- Self-healing with BGP
- Single hub and dual hub
- SLA probe Differentiated Services Code Point (DSCP) marking
- Virtual routing and forwarding (VRF)
|
| SD-WAN orchestration |
- Central VPN
- Jinja2 templates
- Overlay Orchestrator
- Variables
- FortiManager zero-touch provisioning (ZTP)
- Jinja scripting
- Templates
|
Endpoint security (20% of the exam)
| Tasks |
Details |
| Zero trust network access (ZTNA) |
- ZTNA profiles
- Agentless portal on FortiGate
- Zero-trust tags
- ZTNA access proxy—HTTP/HTTPS
- ZTNA TCP proxy
|
| Endpoint protection |
- Endpoint malware protection
- Anti-exploit
- Antiransomware
- FortiClient
- FortiClient EMS high availability (HA)
- FortiClient EMS integration
- Quarantine
- Sandbox integration
|
Threat mitigation (30% of the exam)
| Tasks |
Details |
| Advanced threat protection |
- Custom intrusion prevention system (IPS) signatures
- DDoS
- Deep traffic inspection
- FortiGuard
- Inline integration
- Sandbox detection
- FortiSandbox HA
- Sniffer integration
- Threat feed integration
- Vulnerability scan
|
| Next-generation firewall (NGFW) |
- Cloud access security broker (CASB)
- Carrier-grade network address translation (CGNAT)
- Domain fronting protection
- Fabric integrations
- Inspection modes
- IPv6
- Operational technology (OT) security
- Policy modes
- Proxy rules
- Security profiles
- Transparent mode
|
Enterprise networking (25% of the exam)
| Tasks |
Details |
| FortiSwitch technologies |
- Internet of Things (IoT)
- Switching concepts
- FortiLink
|
| Network access control |
- FortiNAC fabric integration
- FortiNAC HA
- Endpoint solutions
- Network services
- Policies and objects
|
| Advanced networking |
- Asymmetric routing
- Enhanced MAC Virtual Local Area Network (EMAC VLAN)
- Explicit proxy
- Inter-VDOM routing
- IPv6
- LAN extension
- Local-in policies
- Local-out routing
- Mapping of Address and Port with Encapsulation (MAP-E)
- Network address translation (NAT)
- QoS
- Route leaking
- Traffic shaping
- Interface-based shaping
- Transparent mode
- Transparent proxy
- VLANs
- VRF routing
- Virtual eXtensible LAN (VXLAN)
- VXLAN over IPsec
- VLAN inside VXLAN
- Zones
|
Training Resources
The following resources are recommended for attaining the knowledge and skills that are covered on the exam. The recommended training is available as a foundation for exam preparation. In addition to training, you are strongly encouraged to have hands-on experience with the exam topics and objectives.
Experience
You should have experience with a variety of complex networks and be able to solve complicated security problems.