NSE7 Enterprise Firewall and VDOMs Practice Question
An administrator configures a multi-VDOM FortiGate in transparent mode. The admin notices that the management IP is reachable from both interfaces, but traffic passing through the device is not being inspected. What is the likely issue?
⚠ Common exam trap
Watch out — candidates often assume transparent mode automatically inspects all traffic or that management IP reachability implies full functionality, but in reality, a firewall policy is mandatory for traffic inspection even in Layer 2 mode.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The VDOM is in transparent mode, but no firewall policy is applied to the traffic
In transparent mode, a FortiGate acts as a Layer 2 bridge, and traffic passing through the device is controlled by firewall policies, not by routing. Even though the management IP is reachable (because it is a separate IP on the bridge interface), no traffic inspection occurs unless an explicit firewall policy is configured to allow and inspect the traffic between the bridge interfaces. Option B correctly identifies that the missing firewall policy is the root cause.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Inter-VDOM routing is misconfigured
Why it's wrong here
There is only one VDOM in this scenario.
- ✓
The VDOM is in transparent mode, but no firewall policy is applied to the traffic
Why this is correct
In transparent mode, traffic is bridged by default; policies must be created to inspect traffic.
- ✗
The FortiGate needs a default route
Why it's wrong here
Transparent mode does not require routing for passing traffic.
- ✗
The management IP is assigned to the wrong VDOM
Why it's wrong here
If management IP is reachable, the VDOM is correct.
Go deeper
Related to this question
About these practice questions
One of 940 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.