NSE7 Enterprise Firewall and VDOMs Practice Question
An admin creates a VDOM named 'CustomerA' with inter-VDOM link to the management VDOM. The admin wants CustomerA administrators to manage only their own VDOM. Which configuration step is required?
⚠ Common exam trap
Many exam-takers confuse IP-based access control (trusthost) with VDOM-based administrative scoping, leading candidates to select Option A instead of understanding that VDOM assignment is the correct method to isolate admin privileges to a single VDOM.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a new administrator and set the 'VDOM' field to 'CustomerA' and assign a profile with appropriate permissions
To restrict a VDOM administrator to manage only their own VDOM, you must create a new administrator account and explicitly set the 'VDOM' field to that VDOM (e.g., 'CustomerA') and assign a profile with the necessary permissions. This ensures the admin's scope is limited to that VDOM, preventing access to the management VDOM or other VDOMs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use the 'config system admin' command and set trusthost to the admin's IP
Why it's wrong here
trusthost limits the source addresses an administrator may log in from, not which VDOMs they can manage. Restricting CustomerA admins to their VDOM needs a VDOM-scoped admin account or profile. trusthost is correct when locking an admin to specific management subnets.
- ✗
Place the management VDOM and CustomerA in different administrative domains (ADOMs) in FortiManager
Why it's wrong here
ADOMs are FortiManager containers for policy and device management, not FortiGate VDOM-level admin permissions. Placing VDOMs in separate ADOMs does not restrict a local administrator's CLI access on the FortiGate, which is what the scenario requires.
- ✓
Create a new administrator and set the 'VDOM' field to 'CustomerA' and assign a profile with appropriate permissions
Why this is correct
Assigning the administrator's VDOM field to CustomerA scopes their login session to that VDOM alone, so they cannot view or configure the management VDOM or any other. The accompanying profile then governs which actions are permitted within CustomerA, satisfying the requirement for isolated per-VDOM administration.
- ✗
Enable admin-role override in the VDOM settings
Why it's wrong here
Admin-role override governs which access profile an administrator may assume, not VDOM scope. Restricting CustomerA admins to their VDOM requires assigning a VDOM-scoped admin account or profile. Override suits delegated role switching within a permitted VDOM set.
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.