NSE7 Enterprise Firewall and VDOMs Practice Question
An administrator has a FortiGate with two VDOMs: 'root' and 'VDOM-A'. The administrator wants to assign a physical interface to VDOM-A, but the interface is currently assigned to the root VDOM and is in use by a firewall policy. What must the administrator do before changing the interface's VDOM assignment?
⚠ Common exam trap
The trap here is thinking that administrative disablement or zone membership can bypass the dependency check; the FortiGate strictly enforces removal of all references before a VDOM change.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Delete all firewall policies and routes that reference the interface.
On a FortiGate, a physical interface is bound to a VDOM. To reassign it, the interface must not be referenced by any configuration objects in its current VDOM, such as firewall policies, routes, or DHCP servers. The administrator must identify and delete those references. Only then can the interface's VDOM assignment be changed. This prevents configuration inconsistencies and potential security gaps.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Move the interface to a zone first, then change its VDOM.
Why it's wrong here
Zones are VDOM-specific; an interface in a zone cannot be moved to another VDOM without first removing it from the zone. Moreover, moving to a zone does not eliminate references from policies or routes. The fundamental requirement is to remove all references, not to create a zone.
- ✗
Shut down the interface administratively, then change its VDOM.
Why it's wrong here
Administratively disabling the interface does not remove its configuration dependencies. The FortiGate still sees the interface as part of the current VDOM and will reject the VDOM change if references exist. Disabling the interface is not sufficient; the administrator must remove all references first.
- ✓
Delete all firewall policies and routes that reference the interface.
Why this is correct
A physical interface cannot be moved to another VDOM while it is referenced by firewall policies, routes, or other configuration objects in its current VDOM. The administrator must first remove all references, such as policies and routes, to release the interface. Once no dependencies exist, the VDOM assignment can be changed.
- ✗
Enable 'set vdom-override' on the interface.
Why it's wrong here
There is no 'vdom-override' setting for physical interfaces on FortiGate. The VDOM assignment is changed by editing the interface and selecting a different VDOM, but only after dependencies are removed. This option is a fictitious command and would not resolve the issue.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.