Courseiva
Enterprise Firewall and VDOMsmediumMultiple ChoiceObjective-mapped

NSE7 Enterprise Firewall and VDOMs Practice Question

A multi-tenant FortiGate uses VDOMs. The administrator notices that logins via SSH to the management VDOM succeed, but attempts to SSH to a traffic VDOM's management IP fail. The traffic VDOM has an administrative user configured. What is the most likely cause?

⚠ Common exam trap

Many candidates assume a configured admin user and a valid management IP are sufficient for SSH access, overlooking the per-interface administrative access control that must be explicitly enabled.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

SSH access is not enabled on the traffic VDOM's management interface

SSH access to a VDOM's management IP requires that the management interface explicitly permits SSH administrative access. In a multi-tenant FortiGate with VDOMs, each VDOM's management interface has its own independent administrative access settings. Even if the admin user exists and the VDOM is licensed, SSH will be rejected if the management interface does not have SSH access enabled under config system interface or via the GUI. The fact that SSH to the management VDOM succeeds but fails to the traffic VDOM's management IP points directly to this per-interface access control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The traffic VDOM does not have a license

    Why it's wrong here

    VDOMs do not require separate licenses.

  • The traffic VDOM is in transparent mode

    Why it's wrong here

    Transparent mode still supports SSH management.

  • The admin user is not in the correct trust group

    Why it's wrong here

    Not a FortiGate concept.

  • SSH access is not enabled on the traffic VDOM's management interface

    Why this is correct

    Administrative access protocols must be enabled per interface per VDOM.

About these practice questions

This NSE7 question is part of Courseiva's 940-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.