Courseiva

NSE7 Enterprise Firewall and VDOMs Practice Question

A FortiGate 600E is running in multi-VDOM mode and is managed by FortiManager. The administrator needs to assign CPU and memory resource limits to a specific VDOM so that it cannot consume more than 30% of the system's resources. Which FortiGate feature should the administrator configure?

⚠ Common exam trap

It's easy for candidates to confuse traffic shaping, which controls bandwidth, with resource limits, which control CPU and memory usage.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable VDOM resource limits under the global system settings and assign per-VDOM CPU and memory quotas.

The correct answer is to enable VDOM resource limits and assign per-VDOM quotas. This is the only method that directly enforces CPU and memory limits on a per-VDOM basis, ensuring fair resource distribution. Other options address bandwidth, administrative access, or hardware offloading, none of which satisfy the requirement to cap CPU and memory usage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a traffic shaping policy for all traffic entering and leaving the VDOM.

    Why it's wrong here

    Traffic shaping policies control bandwidth, not CPU or memory consumption. While they can limit throughput, they do not enforce resource quotas on the VDOM itself. The scenario specifically requires limiting CPU and memory, so shaping policies are irrelevant and would not prevent the VDOM from exhausting system resources.

  • ✗

    Assign the VDOM to a dedicated NP6 processor using NPU offload settings.

    Why it's wrong here

    NPU offload settings determine which traffic is accelerated by network processors, but they do not allocate CPU or memory quotas. While offloading can reduce CPU load, it does not enforce a hard limit on the VDOM's resource usage. The requirement is for explicit resource limits, which NPU settings do not provide.

  • ✓

    Enable VDOM resource limits under the global system settings and assign per-VDOM CPU and memory quotas.

    Why this is correct

    FortiOS supports per-VDOM resource limits through the 'config system vdom-resource-limits' or similar global settings. Once enabled, you can assign CPU and memory quotas to individual VDOMs. This directly addresses the requirement to cap a VDOM's resource usage, ensuring it does not starve other VDOMs on the same physical device.

  • ✗

    Configure a separate administrative profile that restricts the VDOM's access to system resources.

    Why it's wrong here

    Administrative profiles define what an administrator can view or modify, not the resources a VDOM can consume. They are used for role-based access control, not for resource allocation. Applying a restrictive profile would not impose CPU or memory limits on the VDOM's data plane operations.

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.