NSE7 Enterprise Firewall and VDOMs Practice Question
A FortiGate with multiple VDOMs is experiencing inter-VDOM routing issues. The admin has created inter-VDOM links between VDOMs and configured firewall policies allowing traffic. However, traffic from VDOM_A to VDOM_B is not reaching the destination. What is the most likely cause?
⚠ Common exam trap
Watch out — candidates often assume inter-VDOM links and firewall policies alone are sufficient for traffic flow, overlooking the fundamental requirement of explicit routing entries in each VDOM's routing table, which is a common misstep in NSE7 scenarios.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The routing table in VDOM_A does not have a route to VDOM_B's subnet via the inter-VDOM link
Inter-VDOM routing requires explicit routes in each VDOM's routing table pointing to the destination subnet via the inter-VDOM link interface. Even with inter-VDOM links and firewall policies configured, if VDOM_A lacks a route to VDOM_B's subnet through that link, traffic will be dropped or forwarded incorrectly. The routing table must contain a static or dynamic route for the destination network with the next-hop set to the inter-VDOM link's IP address on the VDOM_A side.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The inter-VDOM link's administrative status is down
Why it's wrong here
Admin would likely have checked that.
- ✓
The routing table in VDOM_A does not have a route to VDOM_B's subnet via the inter-VDOM link
Why this is correct
Without a route, traffic cannot be forwarded to the inter-VDOM link.
- ✗
VDOM_B does not have an interface in the same subnet as the inter-VDOM link
Why it's wrong here
Inter-VDOM links are point-to-point with matching subnets.
- ✗
The traffic is blocked by an implicit deny policy in VDOM_B
Why it's wrong here
Implicit deny would block, but the scenario says policies were configured.
Visual reference
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 940-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.