Status:
Available
The Fortinet NSE 4 - FortiOS 7.6 Administrator exam evaluates your knowledge of, and expertise in, FortiGate devices.
This exam tests your applied knowledge of FortiGate configuration, operation, and day-to-day administration, and includes operational scenarios, configuration extracts, and troubleshooting captures.
Once you pass the exam, you will receive the following exam badge:

Audience
The Fortinet NSE 4 - FortiOS 7.6 Administrator exam is intended for network and security professionals who are responsible for the configuration and administration of firewall solutions in an enterprise network security infrastructure.
Exam Details
| Exam name |
Fortinet NSE 4 - FortiOS 7.6 Administrator |
| Exam time |
100 minutes |
| Exam questions |
50–55 questions |
| Scoring |
Pass or fail. A score report is available from your Pearson VUE account. |
| Language |
English and Japanese |
| Product version |
FortiOS 7.6.0 |
Exam Topics
Successful candidates have applied knowledge and skills in the following areas and tasks:
Deployment and system configuration (20–25%)
| Tasks |
Details |
| Perform initial configuration |
- FortiGate factory default settings
- FortiGuard licenses
- FortiGate administrative access
- FortiGate as a DHCP server
- System configuration file backup and restore
- FortiGate firmware upgrades
- Use cases
|
| Configure log settings and diagnose problems using the logs |
- Log workflow
- Log storage options
- Device registration on FortiAnalyzer
- Log message viewing and searching
|
| Configure FortiGate Clustering Protocol (FGCP) high-availability (HA) cluster |
- FortiGate HA
- HA setting modifications
- Session synchronization for seamless failover
- HA management interface
- Typical operation of an HA cluster
- HA cluster firmware upgrade
- Use cases
|
| Diagnose resource and connectivity problems |
- Abnormal behavior monitoring
- Physical and network layer problems
- Connectivity problems—sniffer and debug flow
- Resource problems—high CPU and memory usage
- Memory conserve mode
- Use cases—troubleshoot resource and connectivity problems
|
| Describe FortiGate Cloud-Native Firewall (CNF) and FortiGate VMs in the public cloud |
- Threats and challenges in the public cloud
- Fortinet public cloud solutions
- FortiGate VMs in the cloud
- FortiGate CNF
- Use cases—FortiGate CNF and FortiGate VMs in the cloud
|
| Explain FortiSASE administration and user onboarding methods |
- Challenges with remote work
- Secure access service edge (SASE) architecture
- FortiSASE components
- Security features
- Use cases—FortiSASE
|
Firewall policies and authentication (20–25%)
| Tasks |
Details |
| Configure firewall policies |
- Firewall policies
- Inspection modes for firewall policies
- Firewall policy traffic logs
- Use cases
|
| Configure source network address translation (SNAT) and destination network address translation (DNAT) options in firewall policies |
- SNAT configuration
- Firewall policy to perform DNAT using virtual IP (VIP) addresses
- Use cases
- DNAT settings using a VIP
|
| Configure different methods of firewall authentication |
- Remote LDAP authentication server on FortiGate
- Remote RADIUS authentication server on FortiGate
- Active and/or passive authentication
- Firewall user monitoring on the FortiGate GUI
- Use cases
|
| Explain how to deploy and configure Fortinet Single Sign-On (FSSO) |
- FSSO in domain controller (DC) agent mode
- Collector agent
- FSSO login issues
- Use cases—FortiGate FSSO authentication
|
Content inspection (25–30% )
| Tasks |
Details |
| Explain and inspect encrypted traffic using certificates |
- Full SSL/SSH inspection for outbound traffic
- Private certificate authority (CA) certificates on endpoints
- Certification issues
- Use cases
|
| Identify FortiGate inspection modes and configure web filtering |
- Inspection mode (flow or proxy) based on security needs
- Certificate inspection for web filtering
- Web filter profiles in flow-based and proxy-based inspection modes
- FortiGuard categories
- URL filters
- Web filtering issues
- Use cases
|
| Configure application control to monitor and control network applications |
- Application control in profile mode
- Application control event monitoring
- Traffic matching with application control profile issues
- Use cases—application traffic controlling
|
| Configure antivirus scanning modes to neutralize malware threats |
- Antivirus profiles in flow-based and proxy-based inspection modes
- Protocol options
- Antivirus events—log and monitor
- Common antivirus issues
|
| Configure an intrusion prevention system (IPS) to protect a network from threats and vulnerabilities |
- IPS sensors
- IPS high-CPU usage issues
- Use cases—Blocking known exploits
|
Routing (10–15%)
| Tasks |
Details |
| Configure and route packets using static routes |
- Static routing
- Routing table on FortiGate
- Route redundancy and load balancing
- Use cases
|
| Configure SD-WAN to load balance traffic between multiple WAN links effectively |
- SD-WAN concepts
- Main use cases for SD-WAN
- SD-WAN on FortiGate
- Routing behavior in an SD-WAN context
- SD-WAN behavior, link usage, and quality status
- Use cases
|
VPNs (10–15%)
| Tasks |
Details |
| Implement a meshed or partially redundant IPsec VPN |
- IPsec VPN concepts
- IPsec VPN using the IPsec wizard
- Redundant VPN between two FortiGate devices
- IPsec VPNs and review logs
- IPsec VPN issues
- Use cases
|
Training Resources
The following resources are recommended for attaining the knowledge and skills that are covered on the exam. The recommended training is available as a foundation for exam preparation. In addition to training, you are strongly encouraged to have hands-on experience with the exam topics and objectives.
Experience
- 1–2 years of experience with networking
- 0–1 year of experience with network security
- Minimum of 6 months of hands-on experience with FortiGate