Courseiva

NSE7 Enterprise Firewall and VDOMs Practice Question

An administrator has a FortiGate with multiple VDOMs in NAT mode. The administrator wants to configure a global policy that applies to all VDOMs to block traffic from a known malicious IP block. Which statement is correct about global policies?

⚠ Common exam trap

The trap here is assuming that global policies are evaluated after VDOM policies or that they can only deny traffic, when in fact they are processed first and can permit or block traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Global policies are configured in the global VDOM and are evaluated before VDOM-specific policies.

Global policies are configured at the global level and are evaluated before any VDOM-specific policies. This allows an administrator to enforce a uniform security rule, such as blocking a malicious IP block, across all VDOMs without duplicating the policy in each VDOM. They can be used in both NAT and transparent mode VDOMs and can allow or deny traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Global policies are only evaluated after VDOM-specific policies, and they can only deny traffic.

    Why it's wrong here

    Global policies are evaluated before VDOM-specific policies, not after. Also, global policies can allow or deny traffic, not only deny. This option incorrectly states the order of evaluation and the allowed actions, making it invalid for this scenario where the administrator needs to block malicious IPs early in the policy chain.

  • ✗

    Global policies require that all VDOMs are in transparent mode.

    Why it's wrong here

    Global policies work in both NAT and transparent mode VDOMs. There is no requirement for all VDOMs to be in transparent mode. In fact, global policies are commonly used in NAT mode deployments to apply consistent security rules. The mode of the VDOM does not affect the ability to use global policies.

  • ✗

    Global policies can only be applied to traffic entering the management VDOM.

    Why it's wrong here

    Global policies apply to all VDOMs, not just the management VDOM. They are designed to provide a unified policy across the entire FortiGate. Restricting them to the management VDOM would defeat their purpose of centralizing security enforcement for all VDOMs, including those handling user traffic.

  • ✓

    Global policies are configured in the global VDOM and are evaluated before VDOM-specific policies.

    Why this is correct

    Global policies are configured under the global settings, not within a specific VDOM, and they are evaluated before any VDOM-specific policies. This allows the administrator to enforce a consistent security rule across all VDOMs, such as blocking a malicious IP block, without having to replicate the policy in each VDOM.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.