Skip to main content
Training Institute
  • Library
  • Schedule
  • Certifications
  • ATC
  • Academic Partner Program
  • Fast Track Workshops
  • More
Log in
Contents
Library Schedule Certifications ATC Academic Partner Program Fast Track Workshops

FortiDDoS Administrator

Blocks

Certification

This exam is part of the following certification track:

Visit the Cybersecurity Certification page for information about certification requirements.

Exams available at Pearson VUE are listed below. Select an exam to view the details.

Fortinet NSE 6 - FortiDDoS 7.2 Administrator

Status: Available



The Fortinet NSE 6 - FortiDDoS 7.2 Administrator exam evaluates your knowledge and expertise with deploying, configuring, and operating a FortiDDoS solution to detect and mitigate DDoS attacks and maintain service availability.

This exam tests your applied knowledge of FortiDDoS configuration and operation, and includes operational scenarios, incident analysis, attack detection and mitigation techniques, and troubleshooting scenarios related to traffic behavior, system performance, and service availability.

Once you pass the exam, you will receive the following exam badge:

Audience

The Fortinet NSE 6 - FortiDDoS 7.2 Administrator exam is intended for network and security professionals responsible for the deployment, configuration, monitoring, and troubleshooting of FortiDDoS, which is used to protect applications and networks from DDoS attacks while ensuring the availability of critical services.


Exam Details
Exam time 60 minutes
Exam questions 30–40 questions
Scoring Pass or fail. A score report is available from your Pearson VUE account.
Language English
Product version FortiDDoS 7.2

Exam Topics

Successful candidates have applied knowledge and skills in the following areas and tasks:

DDoS fundamentals (20–30%)
Tasks Details
Define DDoS attack concepts
  • DDoS concepts
  • DDoS attack types
Describe DDoS attack behavior and impacts
  • Types of attack vectors (volumetric, protocol, application layer)
  • Traffic behavior patterns (spikes, bursts, asymmetry)
  • Service degradation versus service outage scenarios
  • Legitimate traffic spikes and attack traffic
Explain DDoS prevention and mitigation methods
  • DDoS techniques
  • Rate limiting versus anomaly detection
  • Blocklisting versus allowlisting techniques
  • Inline versus out-of-path mitigation approaches
  • Signature-based detection
  • DDoS techniques
Deployment, configuration, and baselining (25–35%)
Tasks Details
Configure system settings
  • System settings
  • Administrator profiles
  • Use cases—initial setup and configuration
Implement DDoS protection in different network topologies
  • FortiDDoS deployment topologies
  • FortiDDoS high-availability (HA) configuration
  • Placement consideration
  • Inline versus out-of-path deployment modes
Establish network traffic baselines
  • Baseline learning modes
  • Normal traffic profiling
  • Peak versus average traffic patterns
  • Threshold tuning
Protection and mitigation controls (25–35%)
Tasks Details
Implement global protection settings
  • Deployment settings
  • Proxy IP addresses
  • Cloud signaling
  • Global threshold behavior
Configure service protection policies and traffic enforcement
  • Service protection policy feature settings
  • Service protection profiles
  • Use cases—FortiDDoS threshold values, attack log analysis
  • Use cases—service protection profiles, debug file evaluation
  • Handling false positives versus attack traffic
Configure and tune protection profiles for anomaly detection
  • Blocklisting IPv4 addresses and domains
  • IPsec tunnel endpoint addresses
  • GRE tunnel endpoint addresses
  • Access control lists
  • Use cases
Monitoring, logging, and analysis (10–20%)
Tasks Details
Configure logging and alert mechanisms
  • Use cases—address and service objects, ACLs, blocklists
  • Local and remote logging
  • Alert emails
  • Customizable reports
  • Debug logs
Analyze logs, reports, and traffic data
  • Dashboard familiarization
  • FortiView
  • Types of drops
  • Logs and statistics graphs to identify the characteristics of a DDoS attack
  • Use cases—SYN flood mitigation, statistics graphs and tables, DDoS attack logs
  • Use cases—characterizing the DDoS attacks, report generation
  • Correlation of logs, graphs, and events
  • Identification of attack phases (onset, peak, mitigation, and recovery)
  • Post attack analysis and reporting

Training Resources

The following resources are recommended for attaining the knowledge and skills that are covered on the exam. The recommended training is available as a foundation for exam preparation. In addition to training, you are strongly encouraged to have hands-on experience with the exam topics and objectives.

  • FortiDDoS 7.2 Administrator course and hands-on labs
  • FortiDDoS 7.2—Administration Guide
  • FortiDDoS 7.2—User Guide

Experience

A minimum of 6 months of hands-on experience with FortiDDoS and DDoS detection and mitigation concepts in an enterprise environment is recommended.

Exam Sample Questions

A set of sample questions is available from the Fortinet Training Institute. These questions represent the exam content in question type and content scope. However, the questions do not necessarily represent all the exam content, nor are they intended to assess your readiness to take the certification exam.

See the Fortinet Training Institute for the course that includes the sample questions

Examination Policies and Procedures

The Fortinet Training Institute recommends that you review the exam policies and procedures before you register for the exam. Access important information on the Fortinet Training Institute Policies page, and find answers to common questions on the FAQ page.

Questions?

If you have more questions about the NSE Certification Program, contact us through the Fortinet Training Institute Helpdesk page.

Data retention summary