CertGrid
Security Study Guide

Fortinet NSE 4 - FortiOS Administrator Study Guide

The Fortinet NSE 4 - FortiOS Administrator certification (formerly FCP - FortiGate) validates the ability to deploy, configure, and operate FortiGate next-generation firewalls running FortiOS 7.6. It is aimed at network and security professionals who administer FortiGate day to day, across five domains: deployment and system configuration, firewall policies and authentication, content inspection, routing, and VPNs. The exam is 50-55 questions in 80-90 minutes and is graded pass/fail (no published numeric score).

Objective-mapped study guide, aligned to current exam objectives · Published Sep 2026 · Question bank reviewed Aug 2026 · Independent practice platform.

Real exam: 50-55 qs · 80-90 min

Domain 1: Deployment and system configuration

Key concepts you must know · 219 practice questions

Domain 2: Firewall policies and authentication

Key concepts you must know · 188 practice questions

Domain 3: Content inspection

Key concepts you must know · 240 practice questions

Domain 4: Routing

Key concepts you must know · 102 practice questions

Domain 5: VPNs

Key concepts you must know · 105 practice questions

Fortinet NSE 4 - FortiOS Administrator exam tips

Study guide FAQ

What is the difference between route-based and policy-based IPsec VPN on FortiGate?

Route-based (interface mode) IPsec creates a virtual tunnel interface that participates in the routing table, uses standard accept firewall policies, and supports dynamic routing and ADVPN. Policy-based IPsec has no tunnel interface and instead uses the special IPsec policy action to trigger encryption, so it cannot run dynamic routing over the tunnel.

How do FSSO DC Agent mode and polling mode differ?

DC Agent mode installs an agent on every monitored domain controller that pushes logon and logoff events to the Collector Agent in near real time. Polling mode installs no agent on the DC and instead periodically reads the domain controller's security event log, which is simpler to deploy but can lag behind actual logon activity.

In what order does FortiGate evaluate firewall policies?

FortiGate checks policies top-to-bottom and applies the first policy that matches the traffic. Traffic that matches no policy is dropped by the implicit deny rule at the bottom, whose logging is off by default. Because order determines the match, more specific policies should be placed above broader ones.

What is the relationship between administrative distance and priority in FortiGate routing?

Administrative distance chooses between different routing sources and the lower value wins. Priority is a FortiGate-specific tiebreaker used only among routes that already share the same administrative distance, where the numerically lower priority value is installed into the FIB while the other route stays in the RIB as a standby.

Official exam sources

The domain names and weightings on this page follow the published exam blueprint. Each source below records what it confirmed and when it was read, so the split can be checked rather than taken on trust.

Related Security resources

What CertGrid is (and is not)

CertGrid is an independent IT certification practice platform for Azure, AWS, Google, Cisco, Security, Linux, Kubernetes, Terraform, and other certification tracks. It provides objective-mapped practice questions, readiness scoring, weak-domain drills, and explanations to help learners understand what to study next.

Independent & original. CertGrid is an independent practice platform and is not affiliated with or endorsed by Security. Questions are original practice items designed to mirror certification concepts and exam style. CertGrid does not provide official exam questions or braindumps.