Courseiva

NSE7 Enterprise Firewall and VDOMs Practice Question

A FortiGate administrator notices that after installing a new policy package from FortiManager, the firewall policies on the managed FortiGate do not match what was configured in FortiManager. What feature should the administrator use to review the exact changes before committing?

⚠ Common exam trap

Test-takers frequently confuse Revision history (which shows past snapshots) with the pre-commit review feature, but Revision history does not show the pending changes that will be applied in the next install operation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Install preview

Install preview, is correct because it allows the administrator to review the exact configuration changes that FortiManager will push to the managed FortiGate before the changes are committed. This feature compares the current running configuration on the FortiGate with the intended policy package in FortiManager and displays a detailed diff of additions, deletions, and modifications. It is specifically designed to prevent unexpected policy mismatches by providing a pre-commit review step.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Revision history

    Why it's wrong here

    Revision history records FortiManager-side configuration revisions, not the per-object delta applied to the managed device during installation. It is tempting because it is the natural place to inspect what changed in FortiManager, and it would be the correct choice when auditing or rolling back the manager's own configuration revisions.

  • ✗

    Device manager log

    Why it's wrong here

    The device manager log records FortiManager-to-FortiGate communication events such as retrieve and install operations, not the object-level differences between the policy package and the device. It is tempting because it confirms an install occurred, and it would be the right place to diagnose failed or rejected installation attempts.

  • ✓

    Install preview

    Why this is correct

    Install preview generates a per-policy diff between the FortiManager package and the FortiGate's running configuration, showing exactly which policies, objects and ordering will change before the install is committed. This satisfies the requirement to review precise changes beforehand.

  • ✗

    Policy consistency check

    Why it's wrong here

    Policy consistency check compares policy packages against each other or against target devices to flag mismatches, but it does not present the exact object-level changes an install would apply. It is tempting because its name suggests detecting the very mismatch described, and it would be correct for auditing drift across many managed devices.

About these practice questions

Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.