FCNAPP-ANA-26: Fortinet NSE 6 - FortiCNAPP 26 Analyst
Browse certifications
Exam Resources
Official learning paths, exam details, skills measured, and community resources to supplement your study.
About the NSE 6 - FortiCNAPP 26 Analyst Exam
Operate FortiCNAPP to secure cloud-native environments end to end — onboard AWS, Azure and GCP accounts, find and prioritise cloud, workload, code and identity risk, and investigate and respond to runtime threats with the Polygraph Data Platform and LQL
The FCNAPP-ANA-26 (Fortinet NSE 6 - FortiCNAPP 26 Analyst) is a professional-level Fortinet Cloud Security exam that validates the applied skills of a cloud security analyst, DevSecOps engineer or SOC analyst working in FortiCNAPP — Fortinet’s cloud-native application protection platform (the rebranded Lacework FortiCNAPP) that unifies cloud security posture management (CSPM), workload protection (CWPP), identity and entitlement analysis (CIEM), infrastructure-as-code and code security, and runtime threat detection across AWS, Azure, GCP and OCI. It covers FortiCNAPP fundamentals (CNAPP concepts and the Polygraph Data Platform, agentless and agent-based deployment models, cloud-account integration, and compliance-report generation); end-to-end risk management (detecting cloud misconfigurations and non-compliant assets with CSPM, assessing host, container, image and library vulnerabilities and secrets with CWPP, shift-left security with IaC, SAST, DAST and CI/CD guardrails, attack-path analysis and CIEM risk prioritisation, and remediation with continuous compliance monitoring); and threat detection and response (investigating Polygraph anomaly detections and composite alerts, querying platform data and authoring detections with LQL, and responding to, remediating and fine-tuning threats through alert channels, rules and policies). Original practice questions. Not affiliated with, endorsed by, or sourced from Fortinet certification exams.
Who Should Take This Exam?
The NSE 6 - FortiCNAPP 26 Analyst is designed for cloud security analysts, DevSecOps and platform engineers, and SOC analysts responsible for finding, prioritising and responding to risk in cloud-native environments using FortiCNAPP. Fortinet recommends familiarity with cloud platforms (AWS, Azure and GCP), containers and Kubernetes, and core cloud-security concepts such as CSPM, CWPP and vulnerability management. It is a strong step for practitioners who want to prove applied CNAPP skills — onboarding cloud accounts, reading posture and vulnerability findings, analysing attack paths, and triaging and responding to Polygraph threat detections. It is one of the qualifying exams for the NSE 6 in Cloud Security certification (which also requires the NSE 4 FortiOS certification), and it complements the Public Cloud Security and FortiDLP exams in the Fortinet cloud-security track.
Typical study time: 4-8 weeks of focused study
Exam Quick Facts
| Detail | Value |
|---|---|
| Exam Series | FCNAPP-ANA-26 |
| Title | Fortinet NSE 6 - FortiCNAPP 26 Analyst |
| Product Version | FortiCNAPP 26 (Lacework FortiCNAPP) |
| Duration | 70 minutes |
| Questions | 30-40 |
| Pass Score | Pass / fail (a score report is available from your Pearson VUE account; Fortinet does not publish a numeric cut score) |
| Cost | $200 USD |
| Provider | Pearson VUE |
| Validity | 2 years |
| Question Types | Multiple choice, Drag and drop |
Exam Domains & Weights
The NSE 6 - FortiCNAPP 26 Analyst exam covers 3 objective areas. Fortinet does not publish percentage weights for this exam; the weights below are planning estimates based on the breadth of each area and are used to plan study time and practice-question depth.
| Domain | Weight | Practice Qs |
|---|---|---|
| FortiCNAPP Fundamentals | 20% | 50 |
| End-to-end Risk Management | 50% | 125 |
| Threat Detection and Response | 30% | 75 |
| Total | 100% | 250 |
💡 Study tip: This is an analyst exam — the focus is finding, prioritising, investigating and responding to cloud risk in FortiCNAPP, not designing a network. First, get the rebrand and the platform straight: FortiCNAPP is the former Lacework platform, so names like Lacework Query Language (LQL), the Polygraph Data Platform and the Lacework FortiCNAPP API deliberately keep the Lacework name. Understand the Polygraph Data Platform as a zero-touch behavioural detection engine that baselines normal activity and correlates resources, users and network behaviour into contextual alerts — it is not micro-segmentation and not a firewall/packet engine. Keep the CNAPP pillars distinct: CSPM (posture and misconfigurations), CWPP (host, container and workload vulnerabilities and runtime protection), CIEM (identity and entitlement risk) and code security / shift-left (IaC, SAST, DAST, SCA and secrets — do not treat those five as synonyms). Know that FortiCNAPP collects data agentlessly or with agents — agentless scanning finds vulnerabilities and secrets with no agent, while the agent adds runtime fidelity. Remember that attack paths chain vulnerabilities, internet reachability, secrets and IAM entitlements (not a single CVSS score), that LQL is not IQL (IQL is FortiNDR Cloud’s), that report rules are now report configurations and reports go only to email channels, and that closing an alert as a false positive does not suppress future alerts — you use a policy exception for that.
Practice Exam — 250 Questions
Prepare for the NSE 6 - FortiCNAPP 26 Analyst with our 250-question practice exam covering all 3 objective areas. Every question is an original analyst-level scenario built around FortiCNAPP 26 with detailed explanations and maps to the official exam objectives.
What you get:
- ✅ 250 exam-style questions across all 3 domains
- ✅ Detailed explanations for every question — learn why each answer is right
- ✅ Timed exam mode and untimed practice mode
- ✅ Progress tracking and per-domain scoring
- ✅ Works on desktop and mobile — study anywhere
- ✅ 20 free questions — no account needed
Fortinet Certification Path
Fortinet certifications run from Associate through Professional and Solution Specialist up to Expert. The NSE 6 - FortiCNAPP 26 Analyst is a professional-tier Cloud Security exam focused on cloud-native application protection, and it is one of the qualifying exams for the NSE 6 in Cloud Security certification (which also requires the NSE 4 FortiOS certification). Fortinet recommends the FortiCNAPP 26 Analyst training plus hands-on experience with FortiCNAPP.
Related Fortinet Certifications
If you’re studying for the NSE 6 - FortiCNAPP 26 Analyst, you might also be interested in these Fortinet certifications:
- NSE7-CDS: Fortinet NSE 7 - Public Cloud Security 7.6.4 Architect — the architect exam on deploying and protecting FortiGate-based workloads in AWS and Azure — practice exam
- FortiDLP: Fortinet NSE 6 - FortiDLP 26 Administrator — the cloud-native endpoint data-loss-prevention and insider-risk exam in the same NSE 6 tier — practice exam
- FortiWeb: Fortinet NSE 5 - FortiWeb 8.0 Administrator — the web application and API security (WAF) exam that protects the workloads FortiCNAPP monitors — practice exam
Study Tips
- Think like an analyst — for every task, ask “how do I find, prioritise, investigate or respond to this risk in FortiCNAPP?” (posture, vulnerabilities, attack paths, Polygraph detections and LQL), not “how do I design the network?”
- Use our practice exam — try the 20 free questions first to gauge your readiness
- Master the rebrand and the platform — FortiCNAPP is the former Lacework platform; the Polygraph Data Platform is a zero-touch behavioural detection engine (not micro-segmentation, not a firewall), and LQL (Lacework Query Language) is FortiCNAPP’s query language — not FortiNDR Cloud’s IQL
- Keep the CNAPP pillars separate — CSPM (posture/misconfiguration), CWPP (host/container/workload vulnerabilities and runtime), CIEM (identity/entitlement risk), and code security / shift-left (IaC, SAST, DAST, SCA and secrets scanning are distinct techniques, not synonyms)
- Know how risk is collected and chained — agentless scanning finds vulnerabilities and secrets with no agent while the agent adds runtime fidelity; attack paths chain vulnerabilities, internet reachability, secrets and IAM entitlements (identity attack paths are AWS-only), so prioritise by the full path, not a single CVE score
- Separate detection from response — Polygraph anomaly detections and composite alerts surface threats; investigation uses the alert graph, context and LQL; and response uses alert channels, policy exceptions/suppression and custom LQL-backed policies (closing an alert as a false positive does not stop future alerts)
- Simulate exam conditions — use the timed exam mode to practise reasoning about pillar boundaries, deployment choices, risk prioritisation, investigation and response under pressure