Status:
Available
The Fortinet NSE 6 - FortiCNAPP 26 Analyst exam evaluates your ability to configure, administer, analyze, and troubleshoot the Fortinet cloud-native application protection platform (CNAPP), FortiCNAPP.
This exam tests your applied knowledge of analysis in cloud posture management, workload protection, static application security testing (SAST) and dynamic application security testing (DAST) scanning, continuous integration/continuous delivery (CI/CD) integration, threat detection, incident response, and Software-as-a-Service (SaaS) security posture.
Once you pass the exam, you will receive the following exam badge:

Audience
The Fortinet NSE 6 - FortiCNAPP 26 Analyst exam is intended for network and security professionals responsible for configuring, administering, analyzing, and troubleshooting FortiCNAPP.
Exam Details
| Time allowed |
65–75 minutes |
| Exam questions |
30–40 questions |
| Scoring |
Pass or fail. A score report is available from your Pearson VUE account. |
| Language |
English |
| Product version |
FortiCNAPP 26 |
Exam Topics
Successful candidates have applied knowledge and skills in the following areas and tasks:
FortiCNAPP fundamentals (25–35% of the exam)
| Tasks |
Details |
| FortiCNAPP Fundamentals |
- FortiCNAPP architecture and core components
- FortiCNAPP CLI installation
|
| Configure FortiCNAPP integration with cloud accounts |
- FortiCNAPP in different cloud platforms (AWS, Azure, GC)
- FortiCNAPP with Kubernetes clusters
- Use cases—FortiCNAPP integration with AWS, Google Cloud, Azure, and K8s
|
| Explain the different deployment models |
- Agent-based and agentless deployment models
|
| Generate compliance reports |
- Automated compliance monitoring and alerting
- Audit trails for security events
- Compliance frameworks
- Document security procedures and playbooks
- Compliance reports for stakeholders or regulatory audits
|
End-to-end risk management (35–45% of the exam)
| Tasks |
Details |
| Detect risks with FortiCNAPP |
- Cloud infrastructure entitlement management (CIEM), cloud security posture management/Kubernetes security posture management (CSPM/KSPM) concepts and use cases
- Detect, prioritize, remediate, and fine-tune risks
- Cloud workload protection platform (CWPP) concepts and use cases
- Real-time behavioral analytics to detect threats
|
| Identify non-compliant assets |
- Over-privileged users, roles, and permissions
- Misconfiguration in cloud and Kubernetes environments
- Contextualize detected risks using FortiCNAPP Explorer
|
| Explain shift-left security |
- Identity risk scores based on risk factors
- Visualize risk using attack paths
- Steps to right-size permissions across cloud platforms
|
| Remediate risks with FortiCNAPP |
- Security posture issues and automated guidance
- Least privilege principles using FortiCNAPP
|
Threat detection and response (25–35%of exam)
| Tasks |
Details |
| Investigate threats with FortiCNAPP |
- CWPP concepts and use cases
- Real-time behavioral analytics to detect threats
- Correlate security events and composite alerts using the FortiCNAPP threat engine
- Identify anomalies based on user and entity behavior
- Code repository integration, security composition analysis (SCA) and SAST to analyze code and repositories for vulnerabilities
- Integration types (integrated development environment (IDE) vs. code repository vs. pipeline)
- Hard-coded secrets and insecure configurations
|
| Respond to and remediate threats |
- FortiCNAPP integration with the Fortinet Security Fabric (FortiGate, FortiSIEM, and FortiSOAR)
- Code repository integration, SCA and SAST to analyze code and repositories for vulnerabilities
- Integration types (IDE vs. code repository vs. pipeline)
- Review code security findings
- Remediation guidance through pull requests on code repository integration
- SmartFix capabilities
|
| Fine-tune threat detection |
- Fine-tune threat detection possible ways
- Policy and alert configuration
- FortiCNAPP risk-based approach to prioritize threats
|
Training Resources
The following resources are recommended for attaining the knowledge and skills that are covered on the exam. The recommended training is available as a foundation for exam preparation. In addition to training, you are strongly encouraged to have hands-on experience with the exam topics and objectives.
Experience
- Minimum of 6 months of hands-on experience with FortiCNAPP
- Working knowledge of Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP) security services
- Familiarity with CI/CD workflows, containerization, and cloud APIs