NSE7 Enterprise Firewall and VDOMs Practice Question
An administrator is configuring a FortiGate in multi-VDOM mode. The administrator needs to ensure that a specific VDOM can use more system resources, such as sessions and CPU, than other VDOMs. Which FortiGate feature should the administrator use?
⚠ Common exam trap
Candidates often confuse performance optimization features like NPU offloading with resource allocation controls such as per-VDOM limits.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure per-VDOM resource limits in the VDOM settings.
To allocate more system resources to a specific VDOM, the administrator should configure per-VDOM resource limits. FortiGate allows setting maximum sessions, CPU usage, memory, and other resources on a per-VDOM basis. This ensures that the VDOM has sufficient resources while preventing it from monopolizing system resources. This is the correct feature for resource allocation in multi-VDOM deployments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure per-VDOM resource limits in the VDOM settings.
Why this is correct
FortiGate allows administrators to set resource limits per VDOM, such as maximum sessions, CPU usage, and memory. This ensures that a VDOM can be allocated more resources or restricted to prevent it from consuming all system resources. The administrator can adjust these limits for the specific VDOM that requires more resources.
- ✗
Enable NPU offloading for the VDOM to increase its throughput.
Why it's wrong here
NPU offloading can improve performance by accelerating traffic processing, but it does not directly allocate more system resources like sessions or CPU. The question asks for ensuring a VDOM can use more resources than others, which is achieved through resource limits, not offloading. Offloading is about efficiency, not allocation.
- ✗
Create a separate administrative profile for the VDOM with elevated privileges.
Why it's wrong here
Administrative profiles control access to management functions, not system resource allocation. They do not affect how many sessions or how much CPU a VDOM can use. The correct feature is per-VDOM resource limits, which are configured in the VDOM settings under system resource limits.
- ✗
Assign a higher priority to the VDOM in the global VDOM configuration.
Why it's wrong here
There is no global VDOM priority setting that directly allocates more CPU or sessions. Resource allocation is controlled via per-VDOM resource limits. Priority settings might exist for other purposes, but they do not govern resource quotas. The administrator must use the resource limits feature.
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.