NSE7 Enterprise Firewall and VDOMs Practice Question
A network administrator wants to logically separate two departments on a single FortiGate. Each department must have its own firewall policies, routing table, and administrators. Which feature should be used?
⚠ Common exam trap
Candidates often confuse VLANs with VDOMs: VLANs segment Layer 2 traffic but do not provide independent routing tables or administrative domains, so candidates often pick VLANs when the question explicitly requires separate routing and administrators.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Virtual Domains (VDOMs)
Virtual Domains (VDOMs) allow a single FortiGate to be partitioned into multiple independent virtual firewalls, each with its own firewall policies, routing table, and administrative access. This meets the requirement for logical separation of departments with isolated policy and routing domains.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Virtual Domains (VDOMs)
Why this is correct
VDOMs partition a single FortiGate into independent virtual firewalls, each with its own firewall policies, routing table and administrator accounts. This satisfies the requirement to separate the two departments logically while sharing the same physical appliance.
- ✗
Policy Packages
Why it's wrong here
Policy packages group firewall policies for centralised management or provisioning across devices; they cannot create per-department routing tables or separate administrator accounts. The requirement is multi-VDOM, where each VDOM holds its own policies, routing table and admin logins. Policy packages are tempting when bundling many policies for installation onto managed FortiGates.
- ✗
Administrative Domains (ADOMs)
Why it's wrong here
ADOMs partition FortiManager management of many devices, not a single FortiGate's data plane. They tempt because they also separate administrators, but the stem requires per-department firewall policies and routing tables on one appliance, which VDOMs provide.
- ✗
VLANs
Why it's wrong here
VLANs segment Layer 2 broadcast domains within one VDOM; they cannot give each department its own routing table, firewall policies, and administrators. They tempt because they logically separate traffic, but the stem's requirement for independent policy and admin scope needs VDOMs.
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.