Courseiva

NSE7 Enterprise Firewall and VDOMs Practice Question

A FortiGate administrator is planning a multi-VDOM deployment for a service provider. Which TWO statements are true about VDOM limitations and best practices?

⚠ Common exam trap

A common mix-up: candidates assume VDOMs share a routing table or that transparent mode is unsupported, but FortiGate allows full routing isolation and both Layer 2 and Layer 3 operation per VDOM.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It is recommended to use a dedicated management VDOM

Option C is correct because Fortinet best practice for multi-VDOM deployments is to create a dedicated management VDOM so that administrative access, management interfaces, and management traffic are isolated from production VDOMs, improving security and operational clarity. Option D is correct because each VDOM maintains its own independent configuration, including its own administrator accounts, authentication, and access profiles, allowing delegated administration per VDOM. Option A is incorrect because FortiGate models have platform-specific maximum VDOM limits (for example, entry-level units support fewer VDOMs than high-end chassis), so VDOMs are not unlimited. Option B is incorrect because each VDOM has its own independent routing table and can run its own routing protocols. Option E is incorrect because VDOMs can operate in NAT/route mode or transparent mode, so transparent mode is supported per VDOM.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    There is no limit to the number of VDOMs supported

    Why it's wrong here

    FortiGate models cap the number of VDOMs by platform and licence, so no unlimited figure exists. It is tempting because virtualisation suggests elastic scaling, and would be correct only on a platform whose documented maximum genuinely imposed no ceiling, which FortiOS does not.

  • ✗

    All VDOMs must share the same routing table

    Why it's wrong here

    Each VDOM maintains its own independent routing table, so this claim is false. It is tempting because shared routing resembles the global routing table used before VDOMs are enabled, which is the correct model only for a single-VDOM FortiGate.

  • ✓

    It is recommended to use a dedicated management VDOM

    Why this is correct

    A dedicated management VDOM isolates administrative traffic from customer data-plane VDOMs, satisfying the service provider's need for separation between management and tenant traffic. It also prevents management-plane resource contention, since each VDOM maintains independent routing and administrative domains, keeping out-of-band access stable even when customer VDOMs generate heavy load.

  • ✓

    Each VDOM can have its own independent administrator accounts

    Why this is correct

    Each VDOM supports its own independent administrator accounts, enabling the service provider to delegate management per tenant without granting cross-VDOM access. This satisfies the multi-tenancy isolation constraint in the stem, since administrators scoped to one VDOM cannot view or configure others, unlike a single global admin account spanning the whole FortiGate.

  • ✗

    VDOMs cannot operate in transparent mode

    Why it's wrong here

    VDOMs can each be set to NAT or transparent mode independently, so this restriction does not exist. It is tempting because transparent mode is configured per-VDOM rather than globally, which is the correct approach when a VDOM must bridge traffic without IP changes.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.