FortiGate 7.6, exam-shaped.
The NSE 4 / FCP FortiGate administrator exam, one domain at a time — the traps exhibits hide, the values you have to memorise, and the mode-vs-mode choices (flow vs proxy, central vs policy NAT, certificate vs deep inspection) the exam loves. Plus 120+ flashcards and a six-week plan weighted to the blueprint.
5 domains · 111 units · 10 concepts · 121 cards · 2 paths · what changed from the old Study Buddy →
The five domains
Domain 1 · 20–25%
Deployment & system configuration
Domain 2 · 20–25%
Firewall policies & authentication
Domain 3 · 15–20%
Content inspection
Domain 4 · 15–20%
Routing
Domain 5 · 15–20%
VPN
Study plans
Six weeks, weighted to the examA plan that spends time in proportion to the blueprint — the two 20–25% domains first, VPN last.
Where NOC work leaves gapsIf your day job is watching FortiGates but not building them, these are the topics you've never actually configured — spend extra time here.
Modes the exam tests
Inspection mode: flow vs proxyhow the FortiGate buffers and scans traffic for a security profile — packet-by-packet, or by reconstructing the whole object first
NGFW mode: profile vs policywhether application control and web-category matching happen inside a security profile, or as first-class firewall-policy match criteria
NAT: central vs policywhether NAT is configured on each firewall policy, or in separate central SNAT / DNAT tables evaluated independently
SSL inspection: certificate vs deephow much of an HTTPS session the FortiGate can actually see
FSSO: agent vs agentlesshow the FortiGate learns which user is behind an IP so identity-based policies work without a login prompt