NSE7 Enterprise Firewall and VDOMs Practice Question
An administrator is deploying a FortiGate with multiple VDOMs in NAT mode. The administrator wants to ensure that traffic between VDOMs is inspected by security profiles and that inter-VDOM traffic does not bypass the firewall policy engine. Which configuration is required to achieve this?
⚠ Common exam trap
The trap here is assuming that enabling inter-VDOM links automatically inspects traffic; policies are still required on both VDOMs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable inter-VDOM routing and create a firewall policy between the VDOM links.
Inter-VDOM routing requires VDOM links, which are virtual interfaces that connect VDOMs. To inspect inter-VDOM traffic, firewall policies must be created on each VDOM to allow and apply security profiles to traffic traversing the VDOM link. This ensures that all inter-VDOM traffic is subject to the same security policies as external traffic, preventing bypass.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable VDOM partitioning and assign interfaces to each VDOM.
Why it's wrong here
VDOM partitioning is not a feature on FortiGate; it is a concept used in some other vendors. Assigning interfaces to VDOMs is necessary for traffic separation, but it does not by itself enable inter-VDOM routing or ensure inspection. Without inter-VDOM links and policies, traffic between VDOMs cannot be inspected.
- ✓
Enable inter-VDOM routing and create a firewall policy between the VDOM links.
Why this is correct
Inter-VDOM links create virtual interfaces that allow traffic to be routed between VDOMs. To inspect traffic, you must create firewall policies on each VDOM that permit and inspect traffic entering and leaving the VDOM link. This ensures that security profiles are applied and traffic does not bypass the policy engine.
- ✗
Enable ASIC offloading for inter-VDOM traffic to ensure inspection.
Why it's wrong here
ASIC offloading accelerates traffic but does not provide security inspection. In fact, offloading can bypass security profiles if not configured correctly. The requirement is to ensure traffic is inspected, which is achieved through firewall policies on VDOM links, not by enabling offloading.
- ✗
Configure a single firewall policy with all interfaces as source and destination.
Why it's wrong here
A single firewall policy cannot span multiple VDOMs because policies are VDOM-specific. Each VDOM maintains its own policy table. Inter-VDOM traffic must traverse policies in both the ingress and egress VDOMs. A policy with interfaces from different VDOMs is not valid and would not provide the required inspection.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.