NSE7 Enterprise Firewall and VDOMs Practice Question
An administrator has a FortiGate with multiple VDOMs in NAT mode. The administrator wants to configure a global policy that applies to all VDOMs to block traffic from a known malicious IP block. Which statement is correct about global policies?
⚠ Common exam trap
The trap here is assuming that global policies are evaluated after VDOM policies or that they can only deny traffic, when in fact they are processed first and can permit or block traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Global policies are configured in the global VDOM and are evaluated before VDOM-specific policies.
Global policies are configured at the global level and are evaluated before any VDOM-specific policies. This allows an administrator to enforce a uniform security rule, such as blocking a malicious IP block, across all VDOMs without duplicating the policy in each VDOM. They can be used in both NAT and transparent mode VDOMs and can allow or deny traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Global policies are only evaluated after VDOM-specific policies, and they can only deny traffic.
Why it's wrong here
Global policies are evaluated before VDOM-specific policies, not after. Also, global policies can allow or deny traffic, not only deny. This option incorrectly states the order of evaluation and the allowed actions, making it invalid for this scenario where the administrator needs to block malicious IPs early in the policy chain.
- ✗
Global policies require that all VDOMs are in transparent mode.
Why it's wrong here
Global policies work in both NAT and transparent mode VDOMs. There is no requirement for all VDOMs to be in transparent mode. In fact, global policies are commonly used in NAT mode deployments to apply consistent security rules. The mode of the VDOM does not affect the ability to use global policies.
- ✗
Global policies can only be applied to traffic entering the management VDOM.
Why it's wrong here
Global policies apply to all VDOMs, not just the management VDOM. They are designed to provide a unified policy across the entire FortiGate. Restricting them to the management VDOM would defeat their purpose of centralizing security enforcement for all VDOMs, including those handling user traffic.
- ✓
Global policies are configured in the global VDOM and are evaluated before VDOM-specific policies.
Why this is correct
Global policies are configured under the global settings, not within a specific VDOM, and they are evaluated before any VDOM-specific policies. This allows the administrator to enforce a consistent security rule across all VDOMs, such as blocking a malicious IP block, without having to replicate the policy in each VDOM.
Visual reference
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.