NSE7 Enterprise Firewall and VDOMs Practice Question
A FortiManager administrator wants to deploy a policy package that contains shared header and footer policies across multiple devices. How should these policies be configured in FortiManager?
⚠ Common exam trap
It's easy for candidates to confuse header/footer policies with global policy packages or assume that the default policy package can serve the same purpose, but FortiManager's architecture explicitly separates these concepts to enforce policy ordering and sharing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the policies as header/footer policies within the policy package
In FortiManager, header and footer policies are specifically designed to be shared across multiple devices within a policy package. By configuring them as header/footer policies, the administrator ensures that these common rules are applied consistently at the top and bottom of the device-specific policy tables, while the middle policies can vary per device. This is the correct method for deploying shared policies without duplicating them in each device's policy set.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Define the policies in the ADOM's default policy package
Why it's wrong here
Policies defined in the ADOM's default policy package belong to that package alone, so they cannot be shared as headers and footers across multiple separate device packages. The default package is the right place for policies intended only for devices assigned to it, not for common rules reused elsewhere.
- ✓
Configure the policies as header/footer policies within the policy package
Why this is correct
Header and footer policies sit inside the policy package and are automatically inherited by every device installing that package, so shared rules are maintained once. This satisfies the multi-device sharing constraint, unlike per-device policies, which would require duplication across each firewall.
- ✗
Create a global policy package and assign it to all devices
Why it's wrong here
A global policy package installs its policies to every device in every ADOM, so it cannot supply shared header and footer policies that wrap each device's own unique rules. Global packages suit organisation-wide baseline policies applied identically everywhere, not per-device policy sets requiring common headers and footers.
- ✗
Use the 'install preview' feature to merge policies
Why it's wrong here
Install preview only simulates and displays the configuration changes an installation would push; it performs no merging and creates no shared policies. It is tempting because it shows policy differences before committing, which is useful for validating an installation, but it cannot define header and footer policies across multiple devices.
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.