Courseiva

NSE7 Enterprise Firewall and VDOMs Practice Question

An administrator has a FortiGate in multi-VDOM mode. VDOM-1 is assigned to the marketing team and VDOM-2 to the finance team. The administrator wants both VDOMs to be able to reach a shared DNS server at 10.10.10.53 that sits behind the root VDOM's wan1 interface, without giving either team access to the other's traffic. Which configuration accomplishes this?

⚠ Common exam trap

The trap here is assuming a single VDOM link or a shared physical interface can serve several VDOMs, when a VDOM link is only ever a two-VDOM point-to-point pair.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a VDOM link between root and VDOM-1 and another between root and VDOM-2, then add static routes in VDOM-1 and VDOM-2 pointing to the root side of their respective VDOM links, and configure firewall policies on root to allow DNS to 10.10.10.53.

Inter-VDOM links create a private point-to-point Layer 3 path between exactly two VDOMs. By giving each team VDOM its own link to the root VDOM and controlling traffic with root-side policies, the administrator provides selective shared-service access while preventing any direct path between the two teams. Sharing one physical interface or one VDOM link across three VDOMs is not supported and would compromise isolation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure a static route in VDOM-1 and VDOM-2 with the destination 10.10.10.53/32 and the outgoing interface set to wan1, then add a firewall policy in each VDOM allowing DNS outbound.

    Why it's wrong here

    wan1 belongs to the root VDOM, so VDOM-1 and VDOM-2 cannot reference it as an outgoing interface. Static routes in those VDOMs will not install because the interface is not visible in that VDOM's routing table, and there is no path from the team VDOMs toward the shared DNS server.

  • ✗

    Assign wan1 as a secondary IP on VDOM-1 and VDOM-2 so both VDOMs share the same physical interface, then add a policy route on root that forwards DNS traffic to 10.10.10.53.

    Why it's wrong here

    A physical interface can be assigned to only one VDOM in FortiGate multi-VDOM mode; it cannot be shared as a secondary IP across VDOM-1 and VDOM-2. Even if it could, this would not provide the isolated Layer 3 path the teams need and would expose wan1 configuration to both VDOMs, defeating segmentation.

  • ✓

    Create a VDOM link between root and VDOM-1 and another between root and VDOM-2, then add static routes in VDOM-1 and VDOM-2 pointing to the root side of their respective VDOM links, and configure firewall policies on root to allow DNS to 10.10.10.53.

    Why this is correct

    A VDOM link is a virtual point-to-point interface pair that provides Layer 3 connectivity between two VDOMs. Each team VDOM routes toward the root side of its own link, and the root VDOM applies policies permitting only DNS to the shared server. Because each VDOM has a distinct link, traffic between VDOM-1 and VDOM-2 cannot traverse directly, satisfying isolation.

  • ✗

    Enable inter-VDOM routing globally and create a single VDOM link shared by VDOM-1, VDOM-2, and root, then place all three VDOMs in the same OSPF area to exchange routes to 10.10.10.53.

    Why it's wrong here

    A VDOM link is strictly a point-to-point pair between exactly two VDOMs; it cannot be shared by three VDOMs. Placing them in one OSPF area would also leak routes between the marketing and finance VDOMs, breaking the required isolation. The shared DNS reachability goal is not achieved this way.

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.