NSE7 Enterprise Firewall and VDOMs Practice Question
A FortiGate is configured with three VDOMs: root, Sales, and Engineering. The administrator wants to ensure that the Sales VDOM can access the internet through the root VDOM, but the Engineering VDOM must not have any internet access. All VDOMs are currently in NAT mode. Which configuration is required to achieve this?
⚠ Common exam trap
The trap here is assuming that a deny firewall policy alone can prevent internet access, when in fact routing must also be considered; without a route, traffic cannot reach the internet regardless of policies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an inter-VDOM link between Sales and root. Assign a default route in Sales pointing to the inter-VDOM link. Do not create any inter-VDOM link or default route for Engineering.
The correct configuration is to provide internet access only to the Sales VDOM by creating an inter-VDOM link to the root VDOM and assigning a default route in Sales pointing to that link. Engineering should not have any inter-VDOM link or default route, ensuring it has no path to the internet. This method is deterministic and avoids reliance on firewall policies that could be misconfigured.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create an inter-VDOM link between Sales and root. Assign a default route in Sales pointing to the inter-VDOM link. Do not create any inter-VDOM link or default route for Engineering.
Why this is correct
This configuration ensures that only Sales has a path to the internet via the inter-VDOM link to root. Engineering has no inter-VDOM link and no default route, so it cannot route traffic to the internet. Even if Engineering has a route to root via some other means, without a default route it cannot reach external destinations. This is the simplest and most secure way to meet the requirement.
- ✗
Create an inter-VDOM link between Sales and root, and another between Engineering and root. Assign default routes in both Sales and Engineering pointing to the inter-VDOM link. Apply a firewall policy in root that denies traffic from Engineering to the internet.
Why it's wrong here
This approach would allow Engineering to have a default route and potentially reach the internet if the policy is misconfigured or if there are multiple paths. The requirement is that Engineering must have no internet access at all, so creating a route and relying solely on a deny policy is not sufficient because it still allows the possibility of traffic if the policy is not correctly applied or if there are other interfaces. A more deterministic method is needed.
- ✗
Create an inter-VDOM link between Engineering and root. Assign a default route in Engineering pointing to the inter-VDOM link. Apply a firewall policy in root that denies traffic from Engineering to the internet. Do not configure anything for Sales.
Why it's wrong here
This would give Engineering a default route, which is contrary to the requirement that Engineering must have no internet access. The deny policy in root might block traffic, but it is not as robust as simply not providing a route. Sales would have no internet access in this scenario, which is also incorrect. The requirement is for Sales to have access and Engineering to not have access.
- ✗
Place all VDOMs in transparent mode. Create VLANs for each VDOM and assign them to the root VDOM. Configure firewall policies in root to allow Sales to the internet and deny Engineering.
Why it's wrong here
Transparent mode is not suitable for this scenario because it does not support NAT, which is typically required for internet access. Also, placing VDOMs in transparent mode would change their operation significantly. The requirement does not specify a need for transparent mode, and using it would complicate the configuration without benefit. The simplest solution is to use NAT mode with inter-VDOM links as needed.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.