Status:
Available
The Fortinet NSE 7 - FortiSASE 26 Architect exam evaluates your knowledge of designing, deploying, and operating advanced Fortinet FortiSASE and SD-WAN solutions.
This exam evaluates your advanced knowledge of FortiSASE and Fortinet SD-WAN configuration and operation, including real-world deployment scenarios, integration of secure access services with SD-WAN, support for distributed users and edge locations, and troubleshooting complex SD-WAN and FortiSASE deployments.
Once you pass the exam, you will receive the following exam badge:

Audience
The Fortinet NSE 7 - FortiSASE 26 Architect exam is intended for network and security professionals responsible for designing, deploying, administering, monitoring, and troubleshooting Fortinet FortiSASE and SD‑WAN solutions, including complex deployment scenarios, troubleshooting advanced environments, and analyzing operational and security data across distributed users and edge locations.
Exam Details
| Exam name |
Fortinet NSE 7 - FortiSASE 26 Architect |
| Time allowed |
70–80 minutes |
| Exam questions |
40–50 questions |
| Scoring |
Pass or fail. A score report is available from your Pearson VUE account. |
| Language |
English |
| Product version |
FortiSASE 26, FortiOS 7.4 and 7.6 |
Exam Topics
Successful candidates have applied knowledge and skills in the following areas and tasks:
SD-WAN architecture and deployment (10–20% of the exam)
| Tasks |
Details |
| Design enterprise SD-WAN architectures |
- Architecture components
- Use case identification
- Zero-touch provisioning (ZTP) of SD-WAN branches
- Device deployment with ZTP
- Device blueprints and device imports using CSV files
- Steps for ZTP of SD-WAN branches
- Multiregion topologies and large deployments
- Use cases—SD-WAN multiregion topologies
- Multiregion topology routing
- Common managed security service provider (MSSP) deployments with SD-WAN
- Virtual routing and forwarding (VRF)-aware overlays
|
| Deploy SD-WAN infrastructure |
- Direct internet access (DIA) topologies
- DIA best practices and recommended settings
- Basic SD-WAN DIA setup
- SD-WAN traffic distribution and member health
- SD-WAN traffic logs and events
- SD-WAN member and zone configuration
- Underlay and overlay links
- Dual-hub topologies
- Use cases for SD-WAN with dual-hub topologies
- Dual-hub options in the SD-WAN overlay template
- Configuration specifics for large topologies
|
| Implement SD-WAN performance controls |
- SLA targets
- Active and passive monitoring
- SLA configuration
- SLA monitoring
- Member status and performance
- Advanced settings
- Member state change actions
- ICMP probe passing of SLA information
- Advanced performance SLA settings
- SD-WAN monitoring tools that FortiManager provides
- SD-WAN logs on FortiAnalyzer
- SD-WAN analytics and reports available on FortiAnalyzer
|
SD-WAN traffic control and IPsec (20–30% of the exam)
| Tasks |
Details |
| Design SD-WAN rules |
- User-defined SD-WAN rules
- SD-WAN rule lookup process
- SD-WAN for local-out traffic
- Implicit SD-WAN rule
- SD-WAN rule strategies
- SD-WAN rule traffic matching criteria
- Application steering and application learning phases
- Internet services as destination criteria
- Preferred member election based on strategy
- Advantage given to higher priority members
- SD-WAN rule status monitoring
- Use cases—rule configuration and monitoring
|
| Configure SD-WAN routing |
- Key routing principles in SD-WAN
- Policy routes
- Route lookup process
- Member static routes
- Static routes for zones
- Member probe routes
- Session tables
- Different protocol states
- Common session flags
- Session reevaluation and triggers
- Routing changes in SNAT sessions
- BGP routing and self-healing
- BGP advanced option for SD-WAN
- Routing options for dual-hub topologies
|
| Deploy advanced IPsec for SD-WAN |
- SD-WAN overlay design
- SD-WAN overlay configuration with BGP
- Scalable SD-WAN hub-and-spoke topology
- IPsec and SD-WAN required settings
- IPsec and BGP for BGP per overlay deployments
- IPsec and BGP for BGP on loopback deployments
- BGP configuration to exchange additional paths
- Overlay stickiness
- Use cases—SD-WAN overlay-as-a-service
- Auto-discovery VPN (ADVPN)
|
FortiSASE architecture and integration (15–25% of the exam)
| Tasks |
Details |
| Evaluate FortiSASE components in advanced deployment scenarios |
- FortiSASE provisioning
- MSSP workflow
- FortiSASE licence types
- FortiFlex offering
- Secure internet access (SIA) use cases
- SIA for FortiClient agent-based remote users
- SIA for agentless remote users
- SIA for edge devices
- FortiExtender/FortiBranch SASE
- FortiAP as an edge device
- Branch on-ramp
- Private proxy
- Secure Private Access (SPA) use cases—SD-WAN, next-generation firewall (NGFW), secure SaaS access (SSA)
- Fortinet SASE solution
- Dedicated public IP address functionality
- RESTful API support
- SASE infrastructure and points of presence (POP)
- Data residency
- Data sovereignty
|
| Integrate FortiSASE into hybrid networks |
- Advanced deployment implementations for branch and remote users
- SIA for edge devices
- FortiExtender/FortiBranch SASE
- FortiAP as an edge device
- SD-WAN on-ramp
- FortiSASE as a spoke
- SIA deployment for remote users
- Use cases—log forwarding to FortiAnalyzer through SPA, performing traffic analytics
|
| Integrate SD-WAN and FortiSASE workflows |
- FortiSASE architecture
- Site-based remote users using FortiGate SD-WAN as a secure edge
- Site-based remote users using SD-WAN on-ramp
- SPA using SD-WAN
- SPA with SD-WAN deployment using FortiSASE
- SD-WAN review
- SPA with SD-WAN deployment use cases (single hub, dual hub)
- FortiSASE as a spoke
|
FortiSASE deployment and secure access (20–30% of the exam)
| Tasks |
Details |
| Deploy FortiSASE access and onboarding |
- SIA for FortiClient agent-based remote users
- SIA for agentless remote users
- SIA for edge devices
- Secure SPA deployments
- SPA use cases—SD-WAN, NGFW, SSA
- FortiSASE SAML authentication for administrators
- User authentication source
- FortiClient installers
- FortiSASE dashboads and GUI tool management
|
| Configure endpoint posture and access control |
- Endpoint profiles
- Security posture tags
- Endpoint upgrade
- Endpoint management
- FortiClient agent
- Digital experience monitoring (DEM) workflow
- Advanced endpoint profile settings
- On-net and off-net use cases
- Network lockdown
- Steering bypass destinations
- FortiSASE security posture tagging rules for endpoint compliance
- Basic HTTPS access proxy with SSL certificate-based authentication
- FortiSASE security posture tags
|
| Deploy cloud-delivered secure services |
- SPA FortiGate configuration
- FortiSASE to the Fortinet Security Fabric
- SaaS and SPA application monitoring
- SPA use cases—NGFW
- Security policy enforcement
- Agentless ZTNA
- Service availability and POP monitoring
|
Centralized management, visibility and troubleshooting (10–20% of the exam)
| Tasks |
Details |
| Centrally manage FortiSASE and SD-WAN deployments |
- FortiManager features for SD-WAN
- SD-WAN management on FortiManager
- FortiManager integration and configuration with FortiSASE
- Use cases—log forwarding to FortiAnalyzer through SPA, performing traffic analytics
- SOC-as-a-Service (SOCaaS)
- FortiGuard forensic analysis
|
| Analyze traffic and security logs |
- FortiClient diagnostic logs
- SD-WAN log identification
- Analytics and reports
|
| Troubleshoot connectivity and policy behavior |
- General troubleshooting commands useful in an SD-WAN context
- CLI commands to observe SD-WAN parameters and behavior
- Tunnel connectivity issues
- Tunnel performance issues
- SPA connectivity issues
- FortiClient diagnostic logs
- Packet captures for connected endpoints
- Use cases—packet capture on FortiSASE, FortiClient diagnostic tools
|
Training Resources
The following resources are recommended for attaining the knowledge and skills that are covered on the exam. The recommended training is available as a foundation for exam preparation. In addition to training, you are strongly encouraged to have hands-on experience with the exam topics and objectives.
Experience
- 3 years of experience with networking
- 3 years of experience with network security
- 2 years of experience with FortiGate and FortiManager
- 1 year of experience with FortiSASE