Courseiva
Enterprise Firewall and VDOMsmediumMultiple SelectObjective-mapped

NSE7 Enterprise Firewall and VDOMs Practice Question

A FortiGate administrator is planning a multi-VDOM deployment for a service provider. Which TWO statements are true about VDOM limitations and best practices?

⚠ Common exam trap

A common mix-up: candidates assume VDOMs share a routing table or that transparent mode is unsupported, but FortiGate allows full routing isolation and both Layer 2 and Layer 3 operation per VDOM.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

It is recommended to use a dedicated management VDOM

Using a dedicated management VDOM is a best practice in multi-VDOM deployments. It isolates administrative traffic (e.g., HTTPS, SSH, SNMP) from data-plane VDOMs, ensuring that management access remains available even if a data VDOM fails or is misconfigured. This also simplifies auditing and RBAC by centralizing admin access without exposing production traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • There is no limit to the number of VDOMs supported

    Why it's wrong here

    VDOM count is limited by model and license.

  • All VDOMs must share the same routing table

    Why it's wrong here

    Each VDOM has its own routing table.

  • It is recommended to use a dedicated management VDOM

    Why this is correct

    Best practice to separate management traffic.

  • Each VDOM can have its own independent administrator accounts

    Why this is correct

    VDOMs support separate admin accounts.

  • VDOMs cannot operate in transparent mode

    Why it's wrong here

    VDOMs can operate in transparent mode.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 940 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.