Courseiva

NSE7 Enterprise Firewall and VDOMs Practice Question

An administrator has a FortiGate 600E running multiple VDOMs in NAT mode. The security team wants to inspect inter-VDOM traffic between VDOM-A and VDOM-B with a firewall policy that applies UTM profiles. The administrator has already created a VDOM link named vlink1 with interfaces vlink1-A in VDOM-A and vlink1-B in VDOM-B. What must the administrator do to ensure that inter-VDOM traffic is inspected by a security policy?

⚠ Common exam trap

The trap here is assuming that inter-VDOM traffic is automatically allowed or that a single policy can inspect traffic across both VDOMs, when in fact each VDOM requires its own policy to permit and inspect the traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a firewall policy in VDOM-A from the internal interface to vlink1-A and a matching policy in VDOM-B from vlink1-B to the internal interface, and apply UTM profiles to both policies.

Inter-VDOM traffic is routed through VDOM link interfaces and is subject to the firewall policies of each VDOM it enters. To inspect traffic from VDOM-A to VDOM-B, a policy in VDOM-A must allow traffic from the source interface to vlink1-A, and a policy in VDOM-B must allow traffic from vlink1-B to the destination interface. UTM profiles can be applied to either or both policies, depending on where inspection is desired. This ensures that inter-VDOM traffic is not implicitly allowed and can be inspected.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable UTM inspection on the VDOM link interface in VDOM-A only, because traffic is inspected once as it leaves the source VDOM.

    Why it's wrong here

    UTM inspection is not enabled on VDOM link interfaces; it is applied through firewall policies. Traffic must be allowed by a policy in each VDOM it traverses. Enabling UTM on an interface is not a supported configuration. The VDOM link is a virtual interface that carries traffic between VDOMs, but security profiles are enforced by policies, not by the link itself.

  • ✓

    Create a firewall policy in VDOM-A from the internal interface to vlink1-A and a matching policy in VDOM-B from vlink1-B to the internal interface, and apply UTM profiles to both policies.

    Why this is correct

    Inter-VDOM traffic traverses the VDOM link and is subject to the firewall policies of each VDOM. To inspect traffic from VDOM-A to VDOM-B, a policy in VDOM-A must allow traffic from the source interface to vlink1-A, and a policy in VDOM-B must allow traffic from vlink1-B to the destination interface. UTM profiles are applied per policy, so both policies can inspect the traffic as it passes through each VDOM.

  • ✗

    Assign the VDOM link interfaces to a zone in each VDOM, then create a single global firewall policy that applies to both VDOMs and includes UTM profiles.

    Why it's wrong here

    Firewall policies in FortiGate are VDOM-specific; there is no global firewall policy that spans multiple VDOMs in NAT mode. Zones are used within a VDOM to group interfaces, but they do not eliminate the need for separate policies in each VDOM. A global policy does not exist for inter-VDOM traffic. UTM profiles are applied per policy within each VDOM.

  • ✗

    Create a single firewall policy in VDOM-A from the internal interface to vlink1-A, and rely on the implicit inter-VDOM link policy to allow return traffic without inspection.

    Why it's wrong here

    There is no implicit inter-VDOM link policy that allows return traffic without inspection. Each VDOM must have its own policy to permit traffic from the VDOM link to the destination interface. Without a policy in VDOM-B, traffic arriving on vlink1-B will be dropped. Return traffic also requires policies in both VDOMs. UTM inspection would not be applied to return traffic if no policy exists.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.