NSE7 Enterprise Firewall and VDOMs Practice Question
An administrator is configuring a FortiGate with multiple VDOMs in NAT/route mode. The administrator wants to enable inter-VDOM routing between VDOM-A and VDOM-B using a VDOM link. Which TWO statements about VDOM links are correct? (Choose two.)
⚠ Common exam trap
The trap here is thinking that VDOM links are automatically created or that they bypass firewall policies, when in fact they are manual, point-to-point, and subject to policy enforcement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Each VDOM link interface must be assigned an IP address to enable routing.
VDOM links are virtual point-to-point interfaces that require manual creation and IP address assignment on each end. They connect exactly two VDOMs and traffic over them is subject to firewall policies in both VDOMs. These characteristics make them suitable for controlled inter-VDOM routing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Each VDOM link interface must be assigned an IP address to enable routing.
Why this is correct
To route traffic over a VDOM link, each end of the link must have an IP address assigned. This allows the VDOMs to treat the link as a routed interface and to exchange routing information or forward packets based on routing tables. Without IP addresses, the link cannot be used for Layer 3 routing.
- ✗
Traffic over a VDOM link is not subject to firewall policies.
Why it's wrong here
Traffic over a VDOM link is subject to firewall policies in both the source and destination VDOMs. Policies must be created to allow and inspect the traffic. Without policies, the traffic is dropped by the implicit deny rule. This is a common misconception.
- ✗
VDOM links are automatically created when a new VDOM is added.
Why it's wrong here
VDOM links are not automatically created. The administrator must manually create a VDOM link and assign it to two VDOMs. This gives control over which VDOMs are interconnected and how. Automatic creation would lead to unnecessary links and potential security risks.
- ✓
A VDOM link is a virtual point-to-point interface that connects two VDOMs.
Why this is correct
A VDOM link is indeed a virtual point-to-point interface that provides a direct Layer 3 connection between two VDOMs. It is created in pairs, with one end in each VDOM, and behaves like a physical interface for routing and policy purposes. This is the fundamental characteristic of VDOM links.
- ✗
A VDOM link can connect more than two VDOMs simultaneously.
Why it's wrong here
A VDOM link is strictly point-to-point and connects exactly two VDOMs. To connect multiple VDOMs, you would need multiple VDOM links or a shared interface with VLANs. This limitation ensures isolation and predictable routing between VDOM pairs.
Visual reference
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.