NSE7 Enterprise Firewall and VDOMs Practice Question
A FortiGate admin configures a policy package with header and footer policies in FortiManager. What is the purpose of header policies?
⚠ Common exam trap
Watch out — candidates often confuse header policies with global policies or default settings, assuming they apply only to NAT or root VDOMs, when in fact they are simply policies that are evaluated first within a specific policy package.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
They are evaluated before other policies in the same policy package
Header policies in FortiManager are evaluated before any other policies in the same policy package. This allows administrators to enforce mandatory rules—such as blocking specific traffic or applying global inspection—that must be processed first, ensuring they are not bypassed by more specific policies later in the sequence.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
They are used for NAT policies only
Why it's wrong here
Header policies are not restricted to NAT; they are general rules positioned above all other policies to enforce global actions. NAT is configured within individual firewall policies, so tying headers to NAT confuses their scope with a policy feature.
- ✗
They provide default logging for all traffic
Why it's wrong here
Header policies sit at the top of the package to enforce global deny or accept rules before other policies are evaluated, not to log traffic. Default logging is configured per-policy or via global settings, so this misreads their placement role.
- ✗
They apply only to the root VDOM
Why it's wrong here
Header and footer policies exist to enforce global rules across every VDOM in a policy package, so restricting them to the root VDOM contradicts their design purpose. The tempting element is that root-VDOM scoping is genuine FortiManager behaviour for other objects, such as global system settings, but header policies are not VDOM-bound.
- ✓
They are evaluated before other policies in the same policy package
Why this is correct
Header policies sit at the top of a policy package and are evaluated before the package's other policies, letting administrators enforce global rules such as logging or blocking across all managed FortiGates without editing each individual policy.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.