Courseiva

NSE7 Enterprise Firewall and VDOMs Practice Question

A FortiGate 600F is running in multi-VDOM mode with VDOMs named 'root', 'finance', and 'guest'. The administrator notices that a firewall policy created in the 'finance' VDOM does not appear when logging into the 'guest' VDOM and wants to confirm that policies, address objects, and routing tables are kept completely separate per VDOM. Which FortiGate feature provides this separation by default?

⚠ Common exam trap

The trap here is assuming that global configuration objects synchronize firewall policies between VDOMs, when in fact global settings cover only a limited set of system and firewall objects, not per-VDOM policies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Per-VDOM configuration databases that store firewall policies, objects, and routing tables independently

Each VDOM on a FortiGate keeps its own configuration database, so firewall policies, address objects, and routing tables are isolated by design. That is exactly why a policy built in the finance VDOM cannot be seen from the guest VDOM. Global configuration and administrative profiles affect management and shared objects but do not merge or split VDOM policy tables.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Per-VDOM configuration databases that store firewall policies, objects, and routing tables independently

    Why this is correct

    In multi-VDOM mode, each VDOM maintains its own independent configuration database, including firewall policies, address objects, services, and the routing table. This is why a policy created in the finance VDOM is invisible in the guest VDOM. The isolation is inherent to VDOM operation and requires no extra configuration, which matches what the administrator observed on the FortiGate 600F.

  • ✗

    Global VDOM configuration that synchronizes policies across all VDOMs

    Why it's wrong here

    Global configuration in FortiGate applies only to settings explicitly marked as global, such as some system-level objects and global firewall addresses, not to per-VDOM firewall policies. It does not synchronize policies between VDOMs, so it would not create the isolation the administrator is seeing. The separation of finance and guest policies comes from the VDOM architecture itself, not from global configuration objects.

  • ✗

    Virtual clustering that partitions the cluster into separate configuration domains

    Why it's wrong here

    Virtual clustering splits a FortiGate HA cluster into multiple HA groups, each with its own primary, to provide redundancy per VDOM group. It does not create the per-VDOM configuration separation seen here; that exists regardless of HA. Virtual clustering is relevant to failover design, not to why finance policies are absent from the guest VDOM.

  • ✗

    Administrative profiles that restrict which VDOMs an administrator can view

    Why it's wrong here

    Administrative profiles control what an administrator is permitted to do and which VDOMs they can access, but they do not create the underlying separation of policies and routes. Even an administrator with full access to both VDOMs would still see distinct policy lists. The observed separation is a property of the VDOM configuration databases, not of administrative profile permissions.

About these practice questions

Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.