Courseiva

NSE7 Enterprise Firewall and VDOMs Practice Question

A FortiGate admin configures a policy package with header and footer policies in FortiManager. What is the purpose of header policies?

⚠ Common exam trap

Watch out — candidates often confuse header policies with global policies or default settings, assuming they apply only to NAT or root VDOMs, when in fact they are simply policies that are evaluated first within a specific policy package.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

They are evaluated before other policies in the same policy package

Header policies in FortiManager are evaluated before any other policies in the same policy package. This allows administrators to enforce mandatory rules—such as blocking specific traffic or applying global inspection—that must be processed first, ensuring they are not bypassed by more specific policies later in the sequence.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    They are used for NAT policies only

    Why it's wrong here

    Header policies are not restricted to NAT; they are general rules positioned above all other policies to enforce global actions. NAT is configured within individual firewall policies, so tying headers to NAT confuses their scope with a policy feature.

  • ✗

    They provide default logging for all traffic

    Why it's wrong here

    Header policies sit at the top of the package to enforce global deny or accept rules before other policies are evaluated, not to log traffic. Default logging is configured per-policy or via global settings, so this misreads their placement role.

  • ✗

    They apply only to the root VDOM

    Why it's wrong here

    Header and footer policies exist to enforce global rules across every VDOM in a policy package, so restricting them to the root VDOM contradicts their design purpose. The tempting element is that root-VDOM scoping is genuine FortiManager behaviour for other objects, such as global system settings, but header policies are not VDOM-bound.

  • ✓

    They are evaluated before other policies in the same policy package

    Why this is correct

    Header policies sit at the top of a policy package and are evaluated before the package's other policies, letting administrators enforce global rules such as logging or blocking across all managed FortiGates without editing each individual policy.

About these practice questions

Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.