Courseiva
Enterprise Firewall and VDOMsmediumMultiple SelectObjective-mapped

NSE7 Enterprise Firewall and VDOMs Practice Question

A FortiGate in HA mode has two VDOMs: VDOM1 and VDOM2. The administrator needs to ensure that if the active unit fails, the standby unit takes over with minimal disruption. Which TWO steps should be taken?

⚠ Common exam trap

A common mix-up: candidates think enabling HA on each VDOM individually is required (Option C), but FortiGate HA is a global feature that automatically synchronizes all VDOM configurations across cluster members, and per-VDOM HA configuration does not exist.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Enable session synchronization

Session synchronization ensures that stateful firewall sessions (e.g., TCP/UDP connections) are replicated from the active FortiGate to the standby unit. In HA active-passive mode, this allows the standby to seamlessly take over active sessions upon failover, minimizing disruption. Without session synchronization, all existing connections would be dropped and must be re-established.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enable session synchronization

    Why this is correct

    Session sync ensures active sessions are preserved on failover.

  • Set the HA mode to active-active

    Why it's wrong here

    Active-active is possible but not required for minimal disruption; active-passive also works.

  • Enable HA on each VDOM individually

    Why it's wrong here

    HA is configured globally, not per VDOM.

  • Configure the same VDOMs on both units

    Why this is correct

    Both HA units must have identical VDOM configurations.

  • Use VDOM link for inter-VDOM traffic

    Why it's wrong here

    Not required for HA failover.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every NSE7 question from scratch — 940 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.