Courseiva

NSE7 Enterprise Firewall and VDOMs Practice Question

A FortiGate administrator configures a VDOM with a limit on the number of firewall policies. The VDOM has 200 policies, and the limit is set to 250. The administrator attempts to add a new policy but receives an error indicating the limit has been reached. What is the MOST likely reason?

⚠ Common exam trap

It's easy for candidates to assume the limit applies only to IPv4 firewall policies, ignoring that FortiGate counts all policy types (IPv4, IPv6, local-in, etc.) against the same limit, leading them to choose an incorrect answer like C or D.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The limit includes IPv4, IPv6, and other policy types

The FortiGate VDOM policy limit includes all policy types—IPv4, IPv6, and others (e.g., local-in policies, authentication policies). Even if the administrator has only 200 IPv4 policies, the total count of all policy types combined may already reach the 250 limit, preventing the addition of a new policy. This is why the error occurs despite the VDOM appearing to have room under the configured limit.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The administrator must reboot the FortiGate for the limit to take effect

    Why it's wrong here

    Policy limits apply immediately on commit; no reboot is involved. Rebooting is tempting because many FortiGate configuration changes, such as interface or VDOM additions, can require a restart, but a policy-count limit is enforced dynamically at commit time.

  • ✓

    The limit includes IPv4, IPv6, and other policy types

    Why this is correct

    FortiGate's VDOM policy limit is a combined counter covering IPv4, IPv6, multicast and other policy types, not IPv4 alone. With 200 policies already configured across those categories, the effective total has reached 250, so the next addition is rejected despite the apparent headroom.

  • ✗

    The VDOM has reached the maximum number of objects, not policies

    Why it's wrong here

    The error names the policy limit, and object counts are tracked separately from firewall policies. Confusing the two is tempting because VDOMs also cap addresses and services, but reaching an object ceiling would produce a different message and would not block policy creation at 200 of 250.

  • ✗

    The limit is per VDOM and cannot be changed

    Why it's wrong here

    The limit is configurable per VDOM and can be raised or removed by the administrator. Treating it as fixed is tempting because default VDOM policy ceilings exist, but those defaults are editable, so the error stems from the configured value, not immutability.

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.