Courseiva

NSE7 Enterprise Firewall and VDOMs Practice Question

An administrator is deploying a FortiGate in multi-VDOM mode for a managed services provider. Each customer must have an isolated logical firewall with its own interfaces, policies, and administrators, and the provider wants to limit each customer administrator to only their own VDOM. Which configuration accomplishes this?

⚠ Common exam trap

The trap here is assuming transparent mode or virtual clustering alone provides tenant isolation, when actual separation and delegated administration come from per-VDOM configuration plus scoped administrative profiles.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create one VDOM per customer, assign interfaces to each VDOM, and create an administrative profile that grants access only to that customer's VDOM

Multi-VDOM mode lets a single FortiGate host multiple logical firewalls, each with dedicated interfaces, policies, and routing. Pairing each customer VDOM with an administrative profile scoped to that VDOM gives the provider both traffic isolation and delegated, restricted management, which is the core MSSP deployment pattern on FortiGate.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use global firewall policies and global address objects shared across all customers

    Why it's wrong here

    Global objects are shared read-only resources visible in all VDOMs, which works against the goal of isolating customers. They do not create separate logical firewalls or limit administrator scope. A provider needing per-customer isolation should rely on per-VDOM configuration and scoped administrative profiles, not on global objects that intentionally span every VDOM.

  • ✗

    Enable virtual clustering and assign each customer to a different HA group within the cluster

    Why it's wrong here

    Virtual clustering divides an HA cluster into independent failover groups, one per VDOM group, to provide per-group redundancy. It does not by itself isolate customers or restrict administrator access to a single customer's configuration. While virtual clustering is often combined with VDOMs in MSSP designs, it is the VDOM and administrative profile that provide the logical separation described here.

  • ✗

    Configure transparent mode on the FortiGate so each customer subnet is bridged independently

    Why it's wrong here

    Transparent mode lets a FortiGate filter traffic without acting as a router, but it does not create isolated logical firewalls or restrict administrator visibility per customer. Multiple VDOMs can run in transparent mode, yet customer isolation and delegated administration still come from VDOM assignment and administrative profiles. Transparent mode changes forwarding behavior, not tenancy boundaries.

  • ✓

    Create one VDOM per customer, assign interfaces to each VDOM, and create an administrative profile that grants access only to that customer's VDOM

    Why this is correct

    Multi-VDOM mode plus per-VDOM administrative profiles is the standard way to give each customer an isolated logical firewall. Interfaces assigned to a VDOM cannot be used by other VDOMs, policies are per-VDOM, and an administrative profile scoped to a single VDOM restricts visibility and changes. This combination delivers the isolation and delegated administration the provider requires.

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.