NSE7 Enterprise Firewall and VDOMs Practice Question
A company uses FortiManager to manage multiple FortiGate firewalls. After making changes to a policy package, the administrator runs an install preview and sees a warning: 'Policy ID 10 will be deleted on device XYZ'. What is the most likely reason for this warning?
⚠ Common exam trap
It's easy for candidates to assume the warning indicates an error or conflict, when in fact it is a normal behavior of FortiManager's policy synchronization to remove policies that were manually added on the device outside of FortiManager management.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Policy ID 10 was manually added on the device but is not present in the policy package
The warning 'Policy ID 10 will be deleted on device XYZ' indicates that the policy package on FortiManager does not contain Policy ID 10, but the device currently has it. During an install, FortiManager synchronizes the device's policy set with the policy package, so any policy present on the device but absent from the package is flagged for deletion. This is a standard consistency check to prevent unintended policy loss.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Policy ID 10 was manually added on the device but is not present in the policy package
Why this is correct
Install preview compares the policy package against the device's running configuration. Policy ID 10 exists on the FortiGate but not in the package, so FortiManager flags it for removal during the next install, overwriting local changes.
- ✗
The policy package has been corrupted and needs to be re-imported
Why it's wrong here
Corruption would produce import or syntax errors, not a deterministic deletion notice for one policy ID. The warning arises because the policy exists on device XYZ but is absent from the installed package, so FortiManager removes it. Re-importing is the remedy when device configuration must be pulled back into FortiManager, not for reconciling a previewed install.
- ✗
The device is in a different ADOM and cannot use the same policy ID
Why it's wrong here
ADOM membership governs which devices and objects FortiManager manages, but policy IDs are scoped per device VDOM, so cross-ADOM coexistence is irrelevant. The warning reflects the package lacking policy ID 10 while the device still holds it. Separate ADOMs would be chosen to isolate administrative domains, not to explain deletion during install.
- ✗
A revision history conflict exists that prevents the install
Why it's wrong here
Revision history records package versions and supports rollback; it does not block or annotate installs with per-policy deletion warnings. The notice means policy ID 10 is present on device XYZ but absent from the package being installed, so FortiManager will remove it. Revision conflicts would surface as lock or version-mismatch errors instead.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.