Courseiva

NSE7 Enterprise Firewall and VDOMs Practice Question

A FortiGate administrator is configuring a multi-VDOM deployment. The administrator wants to use a single physical interface for multiple VDOMs. Which TWO methods allow this?

⚠ Common exam trap

Candidates often assume a physical interface can be directly shared among VDOMs (Option A), not realizing that FortiGate requires either VLAN subinterfaces or NP6 virtual interfaces to achieve this separation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use NP6 virtual interfaces (e.g., virtual wire) on supported models

Option C is correct because a physical interface can be partitioned into VLAN subinterfaces (e.g., port1.10, port1.20), and each subinterface can be assigned to a different VDOM, allowing one physical port to serve multiple VDOMs. Option B is correct because on NP6-accelerated FortiGate models, NP6 virtual interfaces such as virtual wire pairs (and NP6 vlinks) can be created and mapped into different VDOMs, letting a single physical NP6 interface be shared across VDOMs. Option A is incorrect because a physical interface can belong to only one VDOM at a time; it cannot be directly assigned to multiple VDOMs. Option D is incorrect because a software switch is a single interface object that resides in one VDOM and cannot be assigned to multiple VDOMs simultaneously. Option E is incorrect because inter-VDOM routing is used to pass traffic between VDOMs and does not allow sharing the same physical interface or the same IP subnet across VDOMs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use the same physical interface in multiple VDOMs directly

    Why it's wrong here

    A physical interface can belong to only one VDOM; assigning it directly to several is rejected by the FortiGate configuration. It tempts administrators because interfaces are the natural building block of VDOM segmentation, and a single interface does serve one VDOM entirely — the limitation is that sharing requires a VLAN subinterface or virtual switch layer above it.

  • ✓

    Use NP6 virtual interfaces (e.g., virtual wire) on supported models

    Why this is correct

    NP6 virtual interfaces, such as virtual wire pairs, let a single physical interface's acceleration hardware present multiple logical interfaces, each assignable to a different VDOM. This satisfies the requirement to share one physical port across multiple VDOMs.

  • ✓

    Configure VLAN subinterfaces and assign each to a different VDOM

    Why this is correct

    VLAN subinterfaces partition one physical interface into multiple logical interfaces, each tagged with a distinct VLAN ID and assigned to a separate VDOM. This satisfies the requirement to reuse a single physical port across multiple VDOMs.

  • ✗

    Create a software switch interface and assign it to multiple VDOMs

    Why it's wrong here

    A software switch binds its member interfaces to one VDOM, so it cannot be placed in multiple VDOMs simultaneously. It tempts because software switches do let several physical ports share one broadcast domain, which is the correct tool when the goal is aggregating ports inside a single VDOM rather than spanning VDOMs.

  • ✗

    Configure inter-VDOM routing to share the same IP subnet

    Why it's wrong here

    Inter-VDOM routing forwards traffic between VDOMs and cannot place one interface in several VDOMs or share a subnet across them. It tempts because inter-VDOM links are the standard mechanism for connecting VDOMs, and they are correct when separate VDOMs must exchange traffic while each retains its own distinct interfaces.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.