NSE7 Enterprise Firewall and VDOMs Practice Question
An administrator has a FortiGate 600E running FortiOS 7.2 with multiple VDOMs enabled. The administrator wants to create a new VDOM named 'DMZ' and assign it a specific physical interface (port3) that is currently unused. After creating the VDOM, the administrator navigates to Network > Interfaces in the DMZ VDOM but cannot see port3 in the list of available interfaces to assign. What is the most likely reason for this?
⚠ Common exam trap
The trap here is assuming that any unused physical interface is automatically available in all VDOMs, when in fact it must be explicitly assigned from the global configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The physical interface port3 must be assigned to a VDOM from the global configuration before it appears in the VDOM's interface list.
In a multi-VDOM FortiGate, physical interfaces belong to the global configuration by default. To use an interface within a VDOM, the administrator must explicitly assign it to that VDOM from the global VDOM settings. Until that assignment is made, the interface will not be listed in the VDOM's Network > Interfaces section, preventing configuration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The interface port3 is currently used by another VDOM, so it is hidden until it is removed from that VDOM.
Why it's wrong here
The scenario states port3 is unused, so it is not assigned to any VDOM. Even if it were assigned elsewhere, it would still appear in the global interface list but not in the new VDOM's list. The core issue is that the interface has not been assigned to the DMZ VDOM from the global configuration.
- ✗
The administrator needs to reboot the FortiGate after creating the VDOM for the interface to become visible.
Why it's wrong here
Creating a VDOM does not require a reboot for interfaces to appear. Interface visibility in a VDOM depends on assignment from the global configuration, not on a system restart. Rebooting would not resolve the missing interface because the assignment step was never performed.
- ✓
The physical interface port3 must be assigned to a VDOM from the global configuration before it appears in the VDOM's interface list.
Why this is correct
In FortiOS, physical interfaces are initially in the global configuration. To make an interface available within a VDOM, the administrator must first assign it to that VDOM from the global VDOM settings (System > VDOM > select VDOM > assign interfaces). Only after assignment does the interface appear in the VDOM's Network > Interfaces list for configuration.
- ✗
The administrator must enable 'VDOM mode' on the interface before it can be seen in the VDOM.
Why it's wrong here
There is no per-interface 'VDOM mode' setting in FortiOS. VDOM mode is a global system setting that enables multiple VDOMs. Interfaces are assigned to VDOMs via the global VDOM configuration, not by enabling a mode on the interface itself. This option misrepresents how VDOM interface assignment works.
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.