NSE7 Enterprise Firewall and VDOMs Practice Question
A FortiGate is configured with multiple VDOMs. The administrator needs to provide a network engineer with read-only access to all VDOMs, but the engineer should not be able to make any configuration changes. Which administrative profile configuration should the administrator use?
⚠ Common exam trap
The trap here is assuming that a built-in profile provides read-only access, but in FortiOS, read-only access requires a custom administrative profile with 'Read' permissions set for each category.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a new administrative profile with 'Read' access for all categories, and assign it to the engineer's administrator account with 'All VDOMs' scope.
To provide read-only access to all VDOMs, you must create a custom administrative profile with 'Read' permissions for all categories. Then assign this profile to the engineer's administrator account and set the VDOM scope to 'All VDOMs'. This allows the engineer to view configurations in any VDOM but prevents any changes. Built-in profiles do not offer this specific combination of read-only access across all VDOMs, so a custom profile is necessary.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Assign the engineer the built-in 'prof_admin' profile, which provides read-only access to all VDOMs by default.
Why it's wrong here
The 'prof_admin' profile is a built-in profile that typically provides full administrative access, not read-only. It is often equivalent to super_admin but without the ability to create other administrators. It does not restrict the engineer to read-only; the engineer would be able to make configuration changes. Therefore, using 'prof_admin' would not meet the requirement of read-only access. The administrator must create a custom profile with read-only permissions.
- ✗
Use the built-in 'prof_readonly' profile, which provides read-only access to all VDOMs by default.
Why it's wrong here
FortiOS does not have a built-in 'prof_readonly' profile. The built-in profiles are typically 'super_admin', 'prof_admin', and others that are not read-only. Administrators must create custom profiles to achieve read-only access. Assuming a built-in read-only profile exists is a common misconception. Therefore, this option is incorrect because the profile does not exist, and the administrator must create a custom one.
- ✗
Create a new administrative profile with 'None' access for all categories, and assign it to the engineer with 'All VDOMs' scope.
Why it's wrong here
Setting 'None' access for all categories would grant no permissions at all, meaning the engineer could log in but would not be able to view any configuration. This does not provide read-only access; it provides no access. The requirement is to allow viewing but not changing, so 'Read' access is needed, not 'None'. Therefore, this configuration is incorrect.
- ✓
Create a new administrative profile with 'Read' access for all categories, and assign it to the engineer's administrator account with 'All VDOMs' scope.
Why this is correct
An administrative profile defines the permissions for an administrator account. By creating a profile with 'Read' access for all categories (such as firewall, network, system, etc.), you ensure the engineer can view configurations but cannot modify them. Assigning the administrator account with 'All VDOMs' scope grants access to all VDOMs. This is the correct way to provide read-only access across all VDOMs. The profile can be customized to include read access to all relevant areas, and the scope ensures the engineer can switch between VDOMs and view their settings.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.