Back to blog
Study Tips12 min read

How to Pass the Fortinet NSE 4 (NSE4_FGT_AD-7.6) Exam in 2026: An 8-Week FortiOS 7.6 Study Plan

Fortinet's NSE programme changed on 15 July 2026, and NSE 4 is now the gateway to every higher level. Here is the exact exam you book, the five domain weights, and an 8-week FortiOS 7.6 study plan.

Tom Ashford

Tom Ashford · Security Certifications Lead

30 July 2026

If you are trying to work out how to pass the Fortinet NSE 4 exam in 2026, you have almost certainly hit the same wall everyone else has: the certification programme changed on 15 July 2026, half the search results still talk about FCP, and you are no longer sure which exam code to put in your Pearson VUE basket.

Here is the short answer. The exam you book is NSE4_FGT_AD-7.6, officially titled Fortinet NSE 4 - FortiOS 7.6 Administrator. It is 50 to 55 questions in 80 to 90 minutes, costs 200 US dollars, and is scored Pass or Fail. The content did not get harder in July. What changed is the structure around it, and NSE 4 is now the single most important exam in the entire Fortinet ladder, because without it none of the higher certifications will be awarded to you at all.

This guide covers what actually changed, the five domains and their real weights, an eight-week study plan built around the free official course, and the four topics that trip up the most candidates.

What Changed on 15 July 2026 (And Which Exam You Actually Book)

On 15 July 2026, Fortinet retired the FCF, FCA, FCP, FCSS and FCX branding and replaced it with a numbered ladder running from NSE 1 to NSE 8. The programme expanded from five levels to eight. Four training tracks were kept: Secure Networking, Security Operations, Cloud Security and SASE.

Three consequences matter to you as an NSE 4 candidate.

The old core-plus-elective model is gone. Under FCP you needed one core exam and one elective to earn the certification. That is finished. Under the new programme a single qualifying exam earns its matching NSE certification, and the exams that used to be electives (FortiSwitch, FortiAnalyzer and similar) now map to their own NSE 5 certifications by track.

NSE 4 became a hard prerequisite. This is the part people miss. Fortinet's own worked examples make it explicit: if you pass an NSE 5 or NSE 7 exam but do not hold an active NSE 4, no certification is awarded. Fortinet's example shows a candidate passing the NSE 5 SASE exam on 1 October 2026 and receiving nothing until the NSE 4 exam was completed afterwards. Pass NSE 4 later and the higher certification is awarded retroactively, and the prerequisites renew to the new expiry date.

Everything now runs on a two-year cycle. Certifications are valid for two years from the date you pass the exam. Pass NSE 4 on 1 October 2026 and it expires on 1 October 2028. Fortinet sends recertification reminders at 90, 45 and 5 days before expiry and does not grant extensions.

Exam Tip: If you already passed the FortiGate Administrator exam before 15 July 2026, you do not need to retest. The FortiGate Administrator exam (now renamed FortiOS Administrator) maps directly across to NSE 4, and the FortiOS 7.6 content and difficulty were unchanged by the transition. Check your Fortinet Training Institute transcript before you pay for anything.

If you want the full picture of how the eight levels and four tracks fit together, we broke the whole transition down in Fortinet Is Retiring FCP, FCSS and FCX on 15 July 2026: The New NSE 1-8 Path Explained.

Fortinet NSE 4 Exam Facts at a Glance

These are the current official details for the exam as listed by the Fortinet Training Institute.

DetailNSE4_FGT_AD-7.6
Official exam nameFortinet NSE 4 - FortiOS 7.6 Administrator
Exam codeNSE4_FGT_AD-7.6
Questions50 to 55
Time limit80 to 90 minutes
Cost200 USD per attempt
ScoringPass or Fail (no numeric pass mark published)
Product versionFortiOS 7.6.0
LanguagesEnglish and Japanese
DeliveryPearson VUE test centre or OnVUE online proctored
Validity2 years from the pass date
Retake after a fail15 consecutive days

Two of those deserve a comment.

Fortinet does not publish a numeric pass mark for NSE 4. You receive a Pass or Fail result, with a score report available through Pearson VUE. Anyone quoting you an exact percentage is guessing, so plan to be comfortably competent rather than aiming at a threshold.

The retake rule is stricter than most vendors. Fail and you wait 15 consecutive days before you can sit it again. Pass and Pearson VUE blocks you from ever retaking that exam, so you cannot use a second NSE 4 attempt to renew the certification later.

If you are sitting it from home, read the room scan and check-in rules first. Fortinet delivers through OnVUE, and the reasons candidates get turned away are almost never technical. Our guide to OnVUE online proctored exam rules in 2026 covers what actually gets you banned.

The Five NSE 4 Domains and What They Really Test

The exam is organised into five domains with published weights. Note where the marks actually sit, because most candidates over-study firewall policies and under-study content inspection.

DomainWeightCore content
Content inspection25 to 30%SSL and SSH inspection, web filtering, application control, antivirus, IPS
Deployment and system configuration20 to 25%Initial config, logging, HA clustering, troubleshooting, cloud, FortiSASE
Firewall policies and authentication20 to 25%Policy configuration, NAT options, LDAP and RADIUS, FSSO deployment
Routing10 to 15%Static routes and SD-WAN
VPNs10 to 15%IPsec VPN implementation and redundancy

Content inspection is the biggest domain

At 25 to 30 per cent, content inspection carries more marks than any other domain. It is also the one candidates report as hardest, because the questions are rarely about whether a feature exists. They are about ordering and mode.

You need to be fluent in the difference between flow-based and proxy-based inspection, what each mode can and cannot do, certificate inspection versus full deep inspection, and how a request is evaluated when web filtering, application control and an explicit proxy are all in play at once. Matching order decides the answer.

Deployment and system configuration is broader than it sounds

This domain now reaches well beyond initial setup. It includes high availability clustering, logging and monitoring, diagnostic CLI work, FortiGate in cloud deployments and FortiSASE. Reflecting the FortiOS 7.6 objectives, the cloud and SASE content is genuinely examinable rather than a footnote.

Firewall policies and authentication punishes vague understanding

Policy creation is the easy half. The marks are in NAT (source and destination, and knowing which one a scenario needs), user authentication methods, and FSSO. Understand FSSO as a push model where the collector agent pushes logon events, versus LDAP as a query model where FortiGate asks. Scenario questions hinge on that distinction.

Routing and VPNs are smaller but not optional

Together they are 20 to 30 per cent, so they are worth roughly the same as content inspection. Routing focuses on static routes and SD-WAN, including virtual interfaces, performance SLAs and traffic steering rules. VPNs centre on IPsec Phase 1 and Phase 2 configuration and redundancy design.

The 8-Week Fortinet NSE 4 Study Plan

This plan assumes eight to ten hours a week and no prior FortiGate experience beyond basic networking. If you already administer FortiGate daily, compress it to five weeks by halving weeks 1 to 4.

The backbone is the free official FortiOS Administrator course in the Fortinet Training Institute library, which is designed to take around 28 hours and includes interactive labs. It maps directly to the exam objectives, so it is the syllabus, not a supplement. Book the exam now for the end of week 8 to give yourself a deadline.

Weeks 1 and 2: Deployment, system configuration and logging

Work through the deployment modules of the official course. Build a lab: a FortiGate VM evaluation licence plus two client VMs is enough for most of the syllabus.

  • Do a full initial configuration from factory reset, twice, without notes the second time.
  • Configure interfaces, DNS, administrative access and firmware upgrade paths.
  • Set up logging to memory and to disk, then find a specific session in the logs.
  • Configure an HA active-passive cluster and force a failover.
  • Learn the diagnostic order: get system status, diagnose debug flow, diagnose sniffer packet. Practise reading the output rather than just running the commands.

Weeks 3 and 4: Firewall policies, NAT and authentication

  • Build policies that satisfy a written business requirement, then break one deliberately and diagnose why traffic fails.
  • Configure source NAT (IP pools and overload) and destination NAT (VIPs). Be able to explain in one sentence which a given scenario needs.
  • Integrate LDAP against an Active Directory VM, then RADIUS.
  • Deploy FSSO with the collector agent and watch the logon events arrive. Then compare it directly with the LDAP query flow.
  • Write out FortiGate's policy matching order from memory at the end of week 4.

Weeks 5 and 6: Content inspection, the highest-weight domain

Give this domain more time than any other. It is 25 to 30 per cent of the exam and the most common reason for a fail.

  • Configure antivirus, web filtering, application control and IPS profiles, and apply them to a policy.
  • Enable certificate inspection, then full SSL deep inspection. Install the CA certificate on a client and observe the difference in what FortiGate can see.
  • Switch a profile between flow-based and proxy-based inspection and note precisely which features become unavailable.
  • Build a scenario where web filtering, application control and an explicit proxy interact, then trace which rule wins and why.
  • Interpret detection logs and tune a false positive rather than just disabling the signature.

Week 7: Routing and VPNs

  • Configure static routes, then policy-based routing, and verify with the routing table.
  • Build an SD-WAN zone with two WAN links, define a performance SLA, and create a rule that steers traffic by latency. Then pull a cable and watch the failover.
  • Configure a site-to-site IPsec VPN between two FortiGates, covering Phase 1 and Phase 2 settings.
  • Add VPN redundancy and confirm which tunnel carries traffic after a failure.

Week 8: Practice exams, weak-spot repair and exam day

Do not learn anything new this week. Test, review and consolidate.

  • Sit timed practice exams under real conditions: 55 questions, 80 minutes, no notes.
  • Log every question you get wrong by domain, and repair only those areas.
  • Rebuild the two labs you found hardest, from scratch, without notes.
  • Re-read the OnVUE check-in rules and test your equipment 48 hours before, not on the day.

Exam Tip: 50 to 55 questions in 80 to 90 minutes gives you roughly 95 seconds per question. That is comfortable for recall questions and tight for multi-step scenario questions. Flag anything that needs more than two minutes, move on, and return to it. Running out of time on the last five questions is an avoidable fail.

The Four Topics That Fail Most Candidates

Across candidate reports, four areas cause the most damage. Plan extra time for them.

1. SSL and SSH deep inspection. Knowing how to enable it is not enough. You need to know what breaks when you do, why certificate warnings appear, and what full inspection can see that certificate inspection cannot.

2. Flow versus proxy inspection mode. Questions frequently hinge on a feature being unavailable in the mode described in the scenario. Memorise the differences.

3. Diagnostic and troubleshooting order. Scenario questions ask what you check first. Practise the sequence in a lab until it is instinct, because the answer options are usually all valid commands, just in the wrong order.

4. SD-WAN performance SLAs. SD-WAN is only part of a 10 to 15 per cent domain, so it is easy to skim. It is also configuration-heavy and reliably examined. Build one properly and watch it fail over.

What NSE 4 Is Worth, and What Comes Next

NSE 4 sits at the associate-to-professional boundary and is the credential most Fortinet-facing job adverts ask for by name. FortiGate is one of the most widely deployed firewall platforms in enterprise networking, so the skills transfer directly into day-one work rather than sitting on a shelf.

More importantly, under the post-July 2026 programme it is the gate. Every NSE 5, NSE 6 and NSE 7 certification requires an active NSE 4 before it will be awarded, in any of the four tracks. If your longer-term aim is NSE 7 in Secure Networking or Security Operations, NSE 4 is not optional and it is not a detour.

After you pass, pick a track and take the matching NSE 5. Set a calendar reminder at the 21-month mark, because the two-year clock starts on your pass date and an exam already counted towards a certification cannot be reused to renew that same certification.

If you are weighing Fortinet against a vendor-neutral or multi-vendor route first, it is worth reading Is the CompTIA Trifecta Still Worth It in 2026? and our Cisco CCNA 200-301 12-week study plan, since CCNA and NSE 4 solve different problems for a network security CV.

Ready to Start Practising?

Reading the FortiOS Administrator course once will teach you the features. It will not teach you to answer a 95-second scenario question about policy matching order under exam pressure. That only comes from repetition against exam-style questions with explanations that tell you why the other three options were wrong.

CertCrush is built for exactly that. Work through targeted question banks by domain, sit timed mock exams that mirror the real question count and clock, and track which of the five NSE 4 domains is actually holding you back so week 8 fixes the right thing.

Browse the full course catalogue or create a free account and start practising today. Your exam date is eight weeks away, and week 1 starts now.

FortinetNSE 4FortiGateFortiOS 7.6study plannetwork securityexam guide
Tom Ashford

Written by

Tom Ashford · Security Certifications Lead

Tom spent over a decade in security operations and consulting before turning to full-time exam-prep writing. He covers the big security certifications — CISSP, CISM, CISA, Security+ and the rest of the alphabet — with a soft spot for the questions everyone gets wrong. His rule for every article: if it doesn’t help you score marks, it doesn’t go in.

All articles by Tom

Want a Fortinet practice course?

We don’t cover this exam yet — we build the most-requested courses first. One click tells us you want it.

Practising for something nearby?

Try real exam-style questions free — no account needed, full explanations included.