NSE7 Part 1: Exam Blueprint and Study Roadmap

I said back in NSE6 Part 1 that this site would eventually cover NSE7. That was over two months ago. This is that post, and the twelve that follow it.

NSE 4 proves you can configure a single FortiGate. NSE 5 proves you can manage a fleet of them from FortiManager. NSE 6 Secure Networking proves you understand the access layer feeding traffic into that fleet. NSE 7 is where all three threads get pulled together into one exam: design, administer, and support a secure SD-WAN and enterprise security infrastructure built from multiple FortiGate devices, managed centrally, and routed correctly at scale.

Which NSE 7 Exam This Is

Fortinet restructured the NSE 7 track a while back. Where it used to be a handful of separate product-specific exams (Enterprise Firewall, SD-WAN, and so on), NSE 7 in Secure Networking is now a single certification built around one exam: Fortinet NSE 7 - Secure Networking Architect, exam code NSE7_FSN_AR-7.6 against FortiOS 7.6, FortiManager 7.6, and FortiAnalyzer 7.6.

The exam is 40 to 50 questions, 60 to 70 minutes, multiple choice and drag-and-drop, pass or fail with no partial credit. That’s a shorter exam than the 10 to 14-part study series I’ve run for NSE4 through NSE6 might suggest is proportionate, but the questions are dense. Fortinet’s own framing is “applied knowledge and skills,” which in practice means scenario questions: given this topology and this symptom, what’s actually wrong, and which of four plausible-sounding fixes is correct.

Prerequisites

To sit the exam and have it count toward certification, you need:

  • NSE 4 FortiOS certification, active
  • Either NSE 5 Secure Networking or NSE 6 Secure Networking certification, active

If you’ve worked through the NSE4 and NSE6 series on this site, you already have both boxes ticked (NSE5’s FortiManager track also satisfies the second requirement, and that series is on this site too). The certification stays active for two years from whichever prerequisite or the NSE 7 exam itself was passed most recently, and passing NSE 7 recertifies everything below it: NSE 1 through 4, and whichever of NSE 5 or NSE 6 Secure Networking you used to qualify.

Fortinet also lists recommended experience alongside the prerequisites, not as a hard gate but worth taking seriously: three years with networking generally, three years with network security, and two years of hands-on time each with FortiGate, FortiManager, and FortiAnalyzer. NSE 7 is not a first FortiOS exam.

The Five Domains

Fortinet publishes topic weightings as ranges rather than fixed percentages, and the ranges overlap enough that they don’t sum cleanly to 100, which tells you the exam draws unevenly across scenarios rather than allocating a fixed question count per domain. Here’s the breakdown as published:

DomainWeightWhat it covers
System configuration and SD-WAN setup20-30%Security Fabric, HA (FGCP/FGSP), VLANs and VDOMs, enterprise SD-WAN fundamentals
Central management15-25%Zero-touch provisioning, SD-WAN Manager and overlay orchestration on FortiManager
Security profiles5-15%SSL/SSH inspection, web filtering, application control, IPS, ISDB
Rules and routing25-35%OSPF, BGP, SD-WAN rule design, SD-WAN routing internals
Advanced IPsec25-35%IKEv2 VPN design, multihub/multiregion deployments, ADVPN

Two things jump out immediately. First, routing and advanced IPsec are each weighted as heavily as the other three domains combined, which is a direct statement about what this exam actually is: an SD-WAN and VPN architecture exam wearing a general “secure networking” title. Second, security profiles is the lightest domain by a wide margin. If you’re coming from NSE4 and expecting IPS sensor tuning and web filter profile options to dominate the way they did there, recalibrate. NSE 7 assumes you already know how to build a security profile. It tests whether you know when full SSL inspection breaks something and why, not how to click through the GUI to enable it.

Study Approach

The pattern that’s worked for every study series on this site applies here too: lab first, then map the lab against the objective, then read the admin guide for the corners the lab didn’t cover. NSE 7 rewards this more than NSE4 or NSE5 did, because a meaningful share of the exam is scenario-based troubleshooting, and there’s no substitute for having actually watched an SD-WAN rule fail to steer traffic the way you expected, or an ADVPN shortcut refuse to negotiate.

If you don’t have physical FortiGates to spare, this site has already built most of the lab infrastructure the later parts of this series lean on. The FortiManager lab on Proxmox series walks through standing up FortiManager and a lab-edge FortiGate VM from scratch, and SD-WAN Resilience builds a two-hub, dual-DC topology with BGP on loopback interfaces that Part 12 of this series (ADVPN) will reuse directly.

What This Series Assumes You Already Know

This series does not re-teach FortiGate fundamentals, FortiManager basics, OSPF and BGP theory, or IPsec’s IKE phase 1/phase 2 mechanics from scratch. Those are NSE4, NSE5, and prerequisite-networking-knowledge territory, and re-deriving them here would either bloat every part past the point of usefulness or thin out the NSE 7-specific content to make room. Where a part depends on foundational material this site has already covered in depth, I link to it rather than repeat it:

  • OSPF fundamentals: the OSPF Deep Dive series, twelve parts on the protocol itself, plus a dedicated FortiOS implementation part.
  • BGP fundamentals: the BGP Deep Dive series, twelve parts covering the session, the attribute catalog, best-path selection, route reflection, communities, policy, and convergence.
  • IPsec fundamentals: the IPsec Deep Dive series on ESP/AH, IKE phase 1 and phase 2, and NAT-T.
  • HA basics: NSE4 Part 10 covers FGCP fundamentals; this series picks up from there into active-active load balancing, virtual clustering, and FGSP.
  • VDOM basics: One Box, Many Firewalls covers VDOM types and VRF-vs-VDOM framing; this series extends into enterprise-scale segmentation patterns.
  • FortiManager fundamentals: the NSE5 series covers ADOMs, device provisioning, templates, and policy packages; this series picks up at ZTP and SD-WAN-specific FortiManager tooling.

The Roadmap

Thirteen parts, ordered to build rather than jump around, and weighted roughly toward how the exam itself is weighted:

  1. This post: blueprint, prerequisites, roadmap.
  2. Security Fabric at enterprise scale: Fabric Connectors, Automation Stitches, and the SSO/IoC/FortiNAC/FortiNDR integration use cases the exam names explicitly.
  3. High availability: FGCP active-active and virtual clustering, FGSP session sync, and where VRRP still earns a place in a Fortinet design.
  4. VLANs and VDOMs at enterprise scale: the virtual LAN switch, VDOM types, and segmentation/inter-VDOM-routing use cases.
  5. Enterprise SD-WAN fundamentals: DIA topology and best practices, SD-WAN monitoring, widgets, and traffic logs.
  6. Central management: ZTP branch provisioning and SD-WAN Manager/overlay orchestration on FortiManager.
  7. Security profiles at scale: SSL/SSH inspection strategy, the SNI check, and the real performance cost of stacking UTM.
  8. OSPF for enterprise routing: the FortiOS-specific pieces, covering access lists, prefix lists, route maps, redistribution, OSPF over IPsec, and ECMP.
  9. BGP for enterprise routing: the same, plus loopback sourcing, neighbor-group, route reflectors, BFD, and graceful restart.
  10. Designing SD-WAN rules and routing: the rule lookup process, implicit rules, local-out traffic, application steering, and the session table mechanics underneath it all.
  11. Advanced IPsec: IKEv2 design at scale, hardware offload, dual-hub and multiregion topologies, MSSP deployments, and VRF-aware overlays.
  12. ADVPN: on-demand shortcut tunnels, IBGP and EBGP hub-and-spoke designs, and ADVPN 2.0.
  13. A full design walkthrough and exam day: a multiregion topology tying every domain together, plus the logistics of the exam itself.

Part 2 starts with the Security Fabric.