Courseiva

NSE4 System and Network Administration Practice Question

A FortiGate is configured with two VDOMs: root and vdom1. The administrator wants to allow a server in vdom1 to be accessible from the internet via a virtual IP (VIP) configured in the root VDOM. Which configuration is required to achieve this?

⚠ Common exam trap

The trap here is thinking that a static route to a VIP or sharing interfaces can bridge VDOMs, when the correct method is inter-VDOM links with firewall policies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create inter-VDOM links between root and vdom1, and configure firewall policies to allow traffic.

To allow a server in one VDOM to be accessible via a VIP in another VDOM, inter-VDOM links must be configured to route traffic between them. Firewall policies on both VDOMs are also required to permit the traffic. This ensures that the VIP in the root VDOM can forward traffic to the server in vdom1, and return traffic can flow back.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable asymmetric routing on both VDOMs and disable session helpers.

    Why it's wrong here

    Asymmetric routing and session helpers do not enable inter-VDOM communication. Without inter-VDOM links, traffic cannot be routed between VDOMs. Disabling session helpers might affect protocols like SIP or FTP, but it does not solve the fundamental connectivity issue between VDOMs.

  • ✗

    Assign the same interface to both VDOMs and enable VDOM sharing.

    Why it's wrong here

    Interfaces cannot be assigned to multiple VDOMs simultaneously; each interface belongs to one VDOM. VDOM sharing is not a feature; VDOMs are isolated. To connect VDOMs, inter-VDOM links are used. This option reflects a misunderstanding of VDOM architecture and interface assignment.

  • ✗

    Configure a static route in vdom1 pointing to the root VDOM's VIP as the gateway.

    Why it's wrong here

    A static route pointing to a VIP is not valid because VIPs are not next-hop addresses. VIPs are used for destination NAT, not as gateways. The correct approach is to use inter-VDOM links, which provide a routable interface between VDOMs. This option misunderstands the role of VIPs in routing.

  • ✓

    Create inter-VDOM links between root and vdom1, and configure firewall policies to allow traffic.

    Why this is correct

    Inter-VDOM links are required to route traffic between VDOMs. The VIP in the root VDOM will translate the destination IP to the server's IP in vdom1. Firewall policies on both VDOMs must allow the traffic. This setup enables the server in vdom1 to be reachable from the internet through the root VDOM's VIP.

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.