Status:
Available
The Fortinet NSE 6 - FortiDDoS 7.2 Administrator exam evaluates your knowledge and expertise with deploying, configuring, and operating a FortiDDoS solution to detect and mitigate DDoS attacks and maintain service availability.
This exam tests your applied knowledge of FortiDDoS configuration and operation, and includes operational scenarios, incident analysis, attack detection and mitigation techniques, and troubleshooting scenarios related to traffic behavior, system performance, and service availability.
Once you pass the exam, you will receive the following exam badge:

Audience
The Fortinet NSE 6 - FortiDDoS 7.2 Administrator exam is intended for network and security professionals responsible for the deployment, configuration, monitoring, and troubleshooting of FortiDDoS, which is used to protect applications and networks from DDoS attacks while ensuring the availability of critical services.
Exam Details
| Exam time |
60 minutes |
| Exam questions |
30–40 questions |
| Scoring |
Pass or fail. A score report is available from your Pearson VUE account. |
| Language |
English |
| Product version |
FortiDDoS 7.2 |
Exam Topics
Successful candidates have applied knowledge and skills in the following areas and tasks:
DDoS fundamentals (20–30%)
| Tasks |
Details |
| Define DDoS attack concepts |
- DDoS concepts
- DDoS attack types
|
| Describe DDoS attack behavior and impacts |
- Types of attack vectors (volumetric, protocol, application layer)
- Traffic behavior patterns (spikes, bursts, asymmetry)
- Service degradation versus service outage scenarios
- Legitimate traffic spikes and attack traffic
|
| Explain DDoS prevention and mitigation methods |
- DDoS techniques
- Rate limiting versus anomaly detection
- Blocklisting versus allowlisting techniques
- Inline versus out-of-path mitigation approaches
- Signature-based detection
- DDoS techniques
|
Deployment, configuration, and baselining (25–35%)
| Tasks |
Details |
| Configure system settings |
- System settings
- Administrator profiles
- Use cases—initial setup and configuration
|
| Implement DDoS protection in different network topologies |
- FortiDDoS deployment topologies
- FortiDDoS high-availability (HA) configuration
- Placement consideration
- Inline versus out-of-path deployment modes
|
| Establish network traffic baselines |
- Baseline learning modes
- Normal traffic profiling
- Peak versus average traffic patterns
- Threshold tuning
|
Protection and mitigation controls (25–35%)
| Tasks |
Details |
| Implement global protection settings |
- Deployment settings
- Proxy IP addresses
- Cloud signaling
- Global threshold behavior
|
| Configure service protection policies and traffic enforcement |
- Service protection policy feature settings
- Service protection profiles
- Use cases—FortiDDoS threshold values, attack log analysis
- Use cases—service protection profiles, debug file evaluation
- Handling false positives versus attack traffic
|
| Configure and tune protection profiles for anomaly detection |
- Blocklisting IPv4 addresses and domains
- IPsec tunnel endpoint addresses
- GRE tunnel endpoint addresses
- Access control lists
- Use cases
|
Monitoring, logging, and analysis (10–20%)
| Tasks |
Details |
| Configure logging and alert mechanisms |
- Use cases—address and service objects, ACLs, blocklists
- Local and remote logging
- Alert emails
- Customizable reports
- Debug logs
|
| Analyze logs, reports, and traffic data |
- Dashboard familiarization
- FortiView
- Types of drops
- Logs and statistics graphs to identify the characteristics of a DDoS attack
- Use cases—SYN flood mitigation, statistics graphs and tables, DDoS attack logs
- Use cases—characterizing the DDoS attacks, report generation
- Correlation of logs, graphs, and events
- Identification of attack phases (onset, peak, mitigation, and recovery)
- Post attack analysis and reporting
|
Training Resources
The following resources are recommended for attaining the knowledge and skills that are covered on the exam. The recommended training is available as a foundation for exam preparation. In addition to training, you are strongly encouraged to have hands-on experience with the exam topics and objectives.
Experience
A minimum of 6 months of hands-on experience with FortiDDoS and DDoS detection and mitigation concepts in an enterprise environment is recommended.