Courseiva
Enterprise Firewall and VDOMsmediumMultiple ChoiceObjective-mapped

NSE7 Enterprise Firewall and VDOMs Practice Question

A FortiGate in NAT mode has multiple VDOMs. The administrator wants to centralize logging from all VDOMs to a single FortiAnalyzer. What configuration is required on the FortiGate to ensure logs from all VDOMs are sent?

⚠ Common exam trap

Many candidates assume a global setting or the management VDOM can centralize log forwarding, but FortiGate requires per-VDOM configuration because each VDOM is a logically separate firewall instance with its own logging subsystem.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Configure FortiAnalyzer logging in each VDOM individually

In a multi-VDOM FortiGate, each VDOM operates as an independent firewall with its own logging configuration. To send logs from all VDOMs to a single FortiAnalyzer, you must configure the FortiAnalyzer IP and logging settings within each VDOM individually. This ensures that each VDOM's logs are forwarded directly to the FortiAnalyzer, as there is no global or centralized log-forwarding mechanism that aggregates logs across VDOMs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Configure the FortiAnalyzer IP under system global settings

    Why it's wrong here

    System global settings apply to the management VDOM only, not all VDOMs.

  • Configure FortiAnalyzer logging in each VDOM individually

    Why this is correct

    Each VDOM has its own log settings. You must add the FortiAnalyzer server in each VDOM's log configuration.

  • Use the management VDOM as a log relay to FortiAnalyzer

    Why it's wrong here

    The management VDOM can forward logs from other VDOMs only if log forwarding is configured, but the default is per VDOM configuration.

  • Enable centralized logging under config log setting

    Why it's wrong here

    There is no centralized logging toggle; logging must be configured per VDOM.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

Courseiva writes every NSE7 question from scratch — 940 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.