Courseiva
Enterprise Firewall and VDOMshardMultiple SelectObjective-mapped

NSE7 Enterprise Firewall and VDOMs Practice Question

A company has a FortiGate with multiple VDOMs. The security team wants to use FortiManager to manage policies centrally. Which three steps are necessary to set up VDOM management via FortiManager? (Choose three.)

⚠ Common exam trap

Test-takers frequently assume FortiManager needs a static route to the FortiGate, but in reality the FortiGate must initiate the FGFM tunnel, so network connectivity must be from the FortiGate to FortiManager, not the other way around.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Enable VDOMs on the FortiGate and configure them for FortiManager management

VDOMs must be enabled on the FortiGate and each VDOM must be configured to allow FortiManager management. This is done by setting the 'set vdom mgmt' parameter within each VDOM or globally, which permits FortiManager to push policy and object changes to the specific VDOM context. Without this step, FortiManager cannot authenticate or communicate with the VDOMs, even if the device is added to the ADOM.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enable VDOMs on the FortiGate and configure them for FortiManager management

    Why this is correct

    VDOMs must be enabled and each VDOM's management must be set to FortiManager.

  • Configure a static route on FortiManager to reach the FortiGate's management IP

    Why it's wrong here

    FortiManager initiates the connection; it does not need a route to the FortiGate if the FortiGate can reach FortiManager.

  • Disable VDOM configuration locking on FortiManager

    Why it's wrong here

    Locking is optional, not required for setup.

  • Add the FortiGate to FortiManager and assign it an appropriate ADOM

    Why this is correct

    This is the first step for central management.

  • Ensure the FortiGate can reach the FortiManager server (network connectivity)

    Why this is correct

    The FortiGate must be able to connect to FortiManager.

About these practice questions

One of 940 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.