Status:
Available
The Fortinet NSE 5 - FortiAppSec Cloud 26 Administrator exam evaluates your knowledge of, and expertise with, FortiAppSec Cloud deployment, configuration, management, and operation for securing web applications and APIs in hybrid-cloud environments.
This exam tests your applied knowledge of FortiAppSec Cloud configuration and operation, and includes operational scenarios, threat analysis, integration with the Fortinet Security Fabric, and management of web application firewall (WAF) protection, API security, bot mitigation, global server load balancing (GSLB), and application availability.
Once you pass the exam, you will receive the following exam badge:

Audience
The Fortinet NSE 5 - FortiAppSec Cloud 26 Administrator exam is intended for network and security professionals responsible for the deployment, configuration, administration, management, and monitoring of FortiAppSec Cloud, including web application firewall (WAF) protection, API security, bot mitigation, global server load balancing (GSLB), threat analytics, and application availability.
Exam Details
| Exam name |
Fortinet NSE 5 - FortiAppSec Cloud 26 Administrator |
| Time allowed |
60–70 minutes |
| Exam questions |
30–40 questions |
| Scoring |
Pass or fail. A score report is available from your Pearson VUE account. |
| Language |
English |
| Product version |
FortiAppSec Cloud 26.2 |
Exam Topics
Successful candidates have applied knowledge and skills in the following areas and tasks:
Platform architecture and deployment (10–20%)
| Tasks |
Details |
| Describe platform architecture and licensing |
- SaaS shared responsibility model
- Comprehensive application protection (cloud web application and API protection (WAAP))
- FortiAppSec cloud deployment and traffic flow
- Licensing options (sales, FortiFlex, public marketplace)
|
| Onboard and configure applications |
- Web application integration
- DNS configuration (A or CNAME record)
|
| Configure initial deployment settings |
- Restrict direct-to-IP traffic
|
Web application and API protection (30–40%)
| Tasks |
Details |
| Configure web application firewall (WAF) protection |
- Implement DDoS protection and WAF security rules
- Known attacks, anomaly detection, file protection
|
| Implement API security |
- Secure API interfaces using OpenAPI, JSON API, XML
- Parse API call content against schema files
- Machine learning (ML)-based API protection
|
| Optimize protection policies |
- Configure client-side protection against browser-based threats
- Use a Content Security Policy (CSP) to inject a JavaScript collector into HTTP responses
|
Bot protection and traffic management (30–40%)
| Tasks |
Details |
| Configure bot protection |
- Differentiate between good, bad, and sophisticated bots
- Describe behavior-based detection and biometric attributes
- Explain AI-based threat detection
|
| Implement advanced bot controls |
- Detect and mitigate sophisticated bots
- Deep learning bot detection, data correlation and interpretability
- Multivariate data over time
- Use auto-discovery to onboard WAF applications
- Implement Advanced Bot Protection (ABP) with the Fortinet Security Fabric
|
| Configure global server load balancing (GSLB) |
- Understand the physical and logical components of GSLB
- Define health checks and synthetic testing
- Support for Extension Mechanisms for DNS (EDNS), EDNS Client Subnet (ECS), and anycast
- Implement GSLB with the Security Fabric
|
Monitoring and analytics (10–20%)
| Tasks |
Details |
| Analyze threat analytics |
- Accelerate security alerts and investigation
- Four-step threat analytics process
- Describe FortiAI Assistant capabilities and limitations
|
| Configure logging and integration with the Security Fabric |
- Implement threat analytics with FortiADC and FortiWeb
- Use FortiAnalyzer or FortiSIEM to collect attack logs
|
| Perform incident analysis |
- Gain threat insights using widgets
- Correlate security events with incidents
- Analyze threats using FortiAI
|
Training Resources
The following resources are recommended for attaining the knowledge and skills that are covered on the exam. The recommended training is available as a foundation for exam preparation. In addition to training, you are strongly encouraged to have hands-on experience with the exam topics and objectives.
Experience
- 1–2 years of experience with networking
- 0–1 year of experience with network security
- Minimum of 6 months of hands-on experience with FortiGate