NSE7 Enterprise Firewall and VDOMs Practice Question
A FortiGate administrator notices that after installing a new policy package from FortiManager, the firewall policies on the managed FortiGate do not match what was configured in FortiManager. What feature should the administrator use to review the exact changes before committing?
⚠ Common exam trap
Test-takers frequently confuse Revision history (which shows past snapshots) with the pre-commit review feature, but Revision history does not show the pending changes that will be applied in the next install operation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Install preview
Install preview, is correct because it allows the administrator to review the exact configuration changes that FortiManager will push to the managed FortiGate before the changes are committed. This feature compares the current running configuration on the FortiGate with the intended policy package in FortiManager and displays a detailed diff of additions, deletions, and modifications. It is specifically designed to prevent unexpected policy mismatches by providing a pre-commit review step.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Revision history
Why it's wrong here
Revision history records FortiManager-side configuration revisions, not the per-object delta applied to the managed device during installation. It is tempting because it is the natural place to inspect what changed in FortiManager, and it would be the correct choice when auditing or rolling back the manager's own configuration revisions.
- ✗
Device manager log
Why it's wrong here
The device manager log records FortiManager-to-FortiGate communication events such as retrieve and install operations, not the object-level differences between the policy package and the device. It is tempting because it confirms an install occurred, and it would be the right place to diagnose failed or rejected installation attempts.
- ✓
Install preview
Why this is correct
Install preview generates a per-policy diff between the FortiManager package and the FortiGate's running configuration, showing exactly which policies, objects and ordering will change before the install is committed. This satisfies the requirement to review precise changes beforehand.
- ✗
Policy consistency check
Why it's wrong here
Policy consistency check compares policy packages against each other or against target devices to flag mismatches, but it does not present the exact object-level changes an install would apply. It is tempting because its name suggests detecting the very mismatch described, and it would be correct for auditing drift across many managed devices.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.