NSE7 Enterprise Firewall and VDOMs Practice Question
An administrator is configuring a FortiGate in multi-VDOM mode. The administrator needs to ensure that the 'Management' VDOM can be accessed via HTTPS and SSH from the internal network, while other VDOMs should not have management access enabled on their interfaces. Which TWO actions must the administrator perform? (Choose two.)
⚠ Common exam trap
The trap here is assuming that enabling management access on a VDOM requires a special command or VDOM role, when it is simply a matter of per-interface administrative protocol settings.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disable administrative access on all interfaces in other VDOMs.
To allow management access to the Management VDOM, administrative protocols like HTTPS and SSH must be enabled on its interfaces. Simultaneously, to restrict management access to only that VDOM, administrative access must be disabled on interfaces in all other VDOMs. These two actions together meet the requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a management VDOM using the 'set manage-ip' command.
Why it's wrong here
The 'set manage-ip' command is used to assign a dedicated management IP address to a VDOM for out-of-band management, but it does not enable HTTPS or SSH access on interfaces. It is not required to achieve the stated goal of enabling management access via internal interfaces.
- ✓
Disable administrative access on all interfaces in other VDOMs.
Why this is correct
To prevent management access to other VDOMs, the administrator must disable administrative protocols on their interfaces. By default, some interfaces may have HTTP or SSH enabled. Disabling these ensures that only the Management VDOM is accessible for administrative purposes, aligning with the security requirement.
- ✗
Assign the Management VDOM as the primary VDOM for administrative access.
Why it's wrong here
There is no concept of a 'primary VDOM' for administrative access in FortiOS. Management access is controlled per interface and per VDOM. Assigning a primary VDOM does not exist and would not fulfill the requirement of enabling specific protocols on the Management VDOM's interfaces.
- ✗
Enable 'allowaccess' on the Management VDOM's inter-VDOM links.
Why it's wrong here
Inter-VDOM links are used for traffic between VDOMs, not for management access from the internal network. Enabling administrative access on inter-VDOM links would not provide management access from the internal network and could introduce security risks. The requirement is to access the Management VDOM via its physical or VLAN interfaces.
- ✓
Enable HTTPS and SSH administrative access on the Management VDOM's interfaces.
Why this is correct
To allow management access to the Management VDOM, the administrator must enable the desired administrative protocols (HTTPS and SSH) on the interfaces within that VDOM. This is done per interface under the VDOM's network settings. Without enabling these protocols, the Management VDOM would not be reachable via those methods.
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.