NSE7 Enterprise Firewall and VDOMs Practice Question
An administrator is configuring a FortiGate with VDOMs. The administrator wants to ensure that each VDOM has its own independent routing table and that routes in one VDOM do not affect another. Which statement about VDOM routing is correct?
⚠ Common exam trap
The trap here is assuming that VDOMs share routing information or that routes are global; they are isolated per VDOM.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Each VDOM maintains its own separate routing table, and routes are isolated per VDOM.
VDOMs on a FortiGate are independent virtual instances, each with its own routing table. This means that routes configured in one VDOM are not shared with or visible to other VDOMs. This isolation is a key benefit of VDOMs, allowing separate routing domains for different departments or customers without interference.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
All VDOMs share a single global routing table, but route entries are tagged with VDOM IDs.
Why it's wrong here
FortiGate does not use a single global routing table with VDOM tags. Each VDOM has its own routing table. The shared table concept is incorrect and would not provide the required isolation. This option misrepresents how VDOM routing works.
- ✓
Each VDOM maintains its own separate routing table, and routes are isolated per VDOM.
Why this is correct
In a multi-VDOM FortiGate, each VDOM operates as an independent virtual device with its own routing table. Routes configured in one VDOM are not visible to or used by other VDOMs. This isolation is fundamental to VDOM functionality and ensures that routing changes in one VDOM do not impact others.
- ✗
Only the root VDOM can have a default route; other VDOMs must use inter-VDOM links for all traffic.
Why it's wrong here
Any VDOM can have its own default route. There is no restriction that only the root VDOM can have a default route. Non-root VDOMs can have default routes pointing to external interfaces or inter-VDOM links. This option incorrectly limits routing capabilities.
- ✗
Routes are automatically synchronized between VDOMs to ensure consistent routing.
Why it's wrong here
Routes are not automatically synchronized between VDOMs. Each VDOM's routing table is independent and must be managed separately. Automatic synchronization would defeat the purpose of VDOM isolation. Administrators must configure routes in each VDOM as needed.
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.