Courseiva

NSE7 Enterprise Firewall and VDOMs Practice Question

An administrator is configuring a FortiGate with VDOMs. The administrator wants to ensure that each VDOM has its own independent routing table and that routes in one VDOM do not affect another. Which statement about VDOM routing is correct?

⚠ Common exam trap

The trap here is assuming that VDOMs share routing information or that routes are global; they are isolated per VDOM.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Each VDOM maintains its own separate routing table, and routes are isolated per VDOM.

VDOMs on a FortiGate are independent virtual instances, each with its own routing table. This means that routes configured in one VDOM are not shared with or visible to other VDOMs. This isolation is a key benefit of VDOMs, allowing separate routing domains for different departments or customers without interference.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    All VDOMs share a single global routing table, but route entries are tagged with VDOM IDs.

    Why it's wrong here

    FortiGate does not use a single global routing table with VDOM tags. Each VDOM has its own routing table. The shared table concept is incorrect and would not provide the required isolation. This option misrepresents how VDOM routing works.

  • ✓

    Each VDOM maintains its own separate routing table, and routes are isolated per VDOM.

    Why this is correct

    In a multi-VDOM FortiGate, each VDOM operates as an independent virtual device with its own routing table. Routes configured in one VDOM are not visible to or used by other VDOMs. This isolation is fundamental to VDOM functionality and ensures that routing changes in one VDOM do not impact others.

  • ✗

    Only the root VDOM can have a default route; other VDOMs must use inter-VDOM links for all traffic.

    Why it's wrong here

    Any VDOM can have its own default route. There is no restriction that only the root VDOM can have a default route. Non-root VDOMs can have default routes pointing to external interfaces or inter-VDOM links. This option incorrectly limits routing capabilities.

  • ✗

    Routes are automatically synchronized between VDOMs to ensure consistent routing.

    Why it's wrong here

    Routes are not automatically synchronized between VDOMs. Each VDOM's routing table is independent and must be managed separately. Automatic synchronization would defeat the purpose of VDOM isolation. Administrators must configure routes in each VDOM as needed.

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.