NSE7 Enterprise Firewall and VDOMs Practice Question
An administrator is deploying a FortiGate with multiple VDOMs in NAT/route mode. The administrator needs to configure inter-VDOM routing between VDOM-A and VDOM-B. Which two actions are required to enable traffic to flow between the two VDOMs? (Choose two.)
⚠ Common exam trap
The trap here is thinking that a global setting can enable inter-VDOM routing, when in fact it requires per-VDOM VDOM links and policies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure firewall policies in each VDOM to allow traffic from the source to the destination through the VDOM link.
Inter-VDOM routing requires a VDOM link to provide the Layer 3 connection, and firewall policies in both VDOMs to permit the traffic. The VDOM link acts as a virtual cable between the two VDOMs, and each VDOM must have a policy allowing traffic from the source to the destination via that link. Without both, traffic is blocked by the implicit deny.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a static route in the global routing table pointing to both VDOMs.
Why it's wrong here
The global routing table is used for management traffic when a management VDOM is enabled, not for inter-VDOM data traffic. Static routes for inter-VDOM traffic must be configured within each VDOM's routing table. A global route would not direct traffic between VDOM-A and VDOM-B.
- ✓
Configure firewall policies in each VDOM to allow traffic from the source to the destination through the VDOM link.
Why this is correct
Even with a VDOM link, the implicit deny policy in each VDOM blocks traffic. You must create policies in VDOM-A and VDOM-B that permit the desired traffic, specifying the VDOM link as the incoming and outgoing interface. Both directions require policies to allow bidirectional communication.
- ✗
Enable inter-VDOM routing globally using the command 'config system global' and set 'inter-vdom-routing enable'.
Why it's wrong here
There is no global 'inter-vdom-routing' setting. Inter-VDOM routing is enabled by creating VDOM links and configuring policies. The command does not exist, so it would not enable anything. The misconception may arise from other vendors' global toggles, but FortiGate uses per-VDOM configuration.
- ✗
Assign the same VDOM ID to both VDOMs to allow routing between them.
Why it's wrong here
Each VDOM must have a unique VDOM ID. Assigning the same ID is not possible and would cause conflicts. VDOM IDs are used internally to identify VDOMs; they do not enable routing. Routing between VDOMs is achieved through VDOM links and policies, not by sharing IDs.
- ✓
Create a VDOM link and assign it to both VDOM-A and VDOM-B.
Why this is correct
A VDOM link is a virtual interface pair that connects two VDOMs. You must create the link and assign one end to each VDOM. This provides the Layer 3 path for inter-VDOM traffic. Without a VDOM link or similar interface, the VDOMs cannot communicate directly.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.