NSE7 Enterprise Firewall and VDOMs Practice Question
An administrator configures a VDOM link between VDOMs A and B. In VDOM A, the VDOM link interface is assigned IP 10.10.10.1/24, and in VDOM B, it is assigned 10.10.10.2/24. A firewall policy on VDOM A allows traffic from a subnet in VDOM A to a subnet in VDOM B. However, traffic fails. The admin checks the routing table in VDOM A and sees a route to the destination subnet via 10.10.10.2. What is the most likely cause?
⚠ Common exam trap
It's easy for candidates to assume a single policy on the source VDOM is sufficient, overlooking that the destination VDOM also requires a policy to permit the traffic, which is a common misconfiguration in multi-VDOM setups.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
No firewall policy in VDOM B to allow traffic from the VDOM link
In a VDOM link configuration, traffic must be permitted by firewall policies on both VDOMs. Even though VDOM A has a policy allowing traffic to the destination subnet and a valid route via 10.10.10.2, VDOM B must have a policy that allows traffic from the VDOM link interface to reach the destination subnet. Without this policy, VDOM B will drop the packets, causing the traffic failure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
No firewall policy in VDOM B to allow traffic from the VDOM link
Why this is correct
Routing in VDOM-A correctly points to 10.10.10.2, so forwarding succeeds across the link. The drop occurs because VDOM-B has no firewall policy permitting traffic entering its VDOM link interface, so its implicit deny blocks the packets.
- ✗
The VDOM link is not administratively up in VDOM B
Why it's wrong here
A route via 10.10.10.2 requires the VDOM link interface in VDOM B to be up; if it is down, the link cannot forward and traffic is dropped. It is tempting because link state is a common cause, though here the route already resolves correctly.
- ✗
Inter-VDOM routing is disabled globally
Why it's wrong here
Inter-VDOM routing is enabled by default and has no global toggle; the missing piece is a firewall policy in VDOM B permitting return traffic, since VDOM A's policy alone cannot authorise the reverse direction. It is tempting because inter-VDOM links do require policies on both sides, but that is per-VDOM policy configuration, not a global setting.
- ✗
The subnet in VDOM B is not defined as an address object in VDOM A's policy
Why it's wrong here
Address objects are optional in FortiGate policies; the policy can reference the destination subnet directly, and the routing table already shows a valid route via 10.10.10.2. It is tempting because object mismatches do cause policy failures, but that applies when the policy references an object that does not match the actual subnet, not when the subnet is simply absent from the policy.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.