NSE7 Enterprise Firewall and VDOMs Practice Question
An administrator is configuring FortiAnalyzer to receive logs from FortiGates in a multi-VDOM environment. The admin wants to ensure that logs from each VDOM are separated into their own datasets. What must be configured?
⚠ Common exam trap
Many candidates think disk partitions or separate FortiAnalyzers are required for log separation, but FortiAnalyzer ADOMs provide logical separation without additional hardware or complex partitioning.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable per-VDOM logging on the FortiGate and use ADOMs on FortiAnalyzer
Per-VDOM logging on the FortiGate must be enabled to tag logs with the VDOM identifier, and ADOMs on FortiAnalyzer must be configured to segregate those logs into separate datasets. Without both, logs from different VDOMs would be mixed in a single dataset, defeating the purpose of isolation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable per-VDOM logging on the FortiGate and use ADOMs on FortiAnalyzer
Why this is correct
Per-VDOM logging makes the FortiGate tag each log with its originating VDOM, while ADOMs partition FortiAnalyzer's database so each VDOM's logs land in a separate dataset. This satisfies the stem's requirement for VDOM-level log separation in a multi-VDOM environment.
- ✗
Use the same log settings for all VDOMs
Why it's wrong here
Identical log settings across VDOMs merge all traffic into one dataset, defeating the separation requirement; per-VDOM log settings or ADOMs are needed. Uniform settings suit single-VDOM appliances where consolidated reporting is intended, not multi-VDOM environments requiring isolated datasets.
- ✗
Configure a separate log disk partition for each VDOM
Why it's wrong here
Disk partitioning controls physical storage allocation, not logical dataset grouping; FortiAnalyzer separates VDOM logs through ADOMs, not partitions. Separate partitions would be chosen when isolating raw storage capacity or retention per tenant, which the scenario does not ask for.
- ✗
Configure each VDOM to send logs to a different FortiAnalyzer
Why it's wrong here
Directing each VDOM to a distinct FortiAnalyzer multiplies management overhead and abandons centralised collection; the requirement is dataset separation within one FortiAnalyzer via ADOMs. Multiple analysers suit geographically dispersed or regulatory-isolated sites, not a single multi-VDOM FortiGate.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.