Courseiva

NSE7 Enterprise Firewall and VDOMs Practice Question

An administrator has a FortiGate with two VDOMs: 'root' and 'VDOM-A'. The administrator wants to assign a physical interface to VDOM-A, but the interface is currently assigned to the root VDOM and is in use by a firewall policy. What must the administrator do before changing the interface's VDOM assignment?

⚠ Common exam trap

The trap here is thinking that administrative disablement or zone membership can bypass the dependency check; the FortiGate strictly enforces removal of all references before a VDOM change.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Delete all firewall policies and routes that reference the interface.

On a FortiGate, a physical interface is bound to a VDOM. To reassign it, the interface must not be referenced by any configuration objects in its current VDOM, such as firewall policies, routes, or DHCP servers. The administrator must identify and delete those references. Only then can the interface's VDOM assignment be changed. This prevents configuration inconsistencies and potential security gaps.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Move the interface to a zone first, then change its VDOM.

    Why it's wrong here

    Zones are VDOM-specific; an interface in a zone cannot be moved to another VDOM without first removing it from the zone. Moreover, moving to a zone does not eliminate references from policies or routes. The fundamental requirement is to remove all references, not to create a zone.

  • ✗

    Shut down the interface administratively, then change its VDOM.

    Why it's wrong here

    Administratively disabling the interface does not remove its configuration dependencies. The FortiGate still sees the interface as part of the current VDOM and will reject the VDOM change if references exist. Disabling the interface is not sufficient; the administrator must remove all references first.

  • ✓

    Delete all firewall policies and routes that reference the interface.

    Why this is correct

    A physical interface cannot be moved to another VDOM while it is referenced by firewall policies, routes, or other configuration objects in its current VDOM. The administrator must first remove all references, such as policies and routes, to release the interface. Once no dependencies exist, the VDOM assignment can be changed.

  • ✗

    Enable 'set vdom-override' on the interface.

    Why it's wrong here

    There is no 'vdom-override' setting for physical interfaces on FortiGate. The VDOM assignment is changed by editing the interface and selecting a different VDOM, but only after dependencies are removed. This option is a fictitious command and would not resolve the issue.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.