NSE7 Enterprise Firewall and VDOMs Practice Question
An administrator is setting up a new FortiGate with multiple VDOMs. The administrator wants to ensure that each VDOM has its own set of administrators and that administrators of one VDOM cannot view or modify settings in another VDOM. Which feature should the administrator configure to achieve this?
⚠ Common exam trap
Watch out — candidates often confuse FortiManager ADOMs with FortiGate VDOM administrator restrictions; ADOMs manage devices, not VDOM-level admin access on a single FortiGate.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
VDOM-specific administrator accounts with restricted profiles.
To isolate administrators per VDOM, you create administrator accounts that are restricted to specific VDOMs. Each administrator account can be assigned a profile that limits their permissions to only the VDOM they are responsible for. This ensures that administrators cannot view or modify settings in other VDOMs. This is the standard method for achieving per-VDOM administrative separation on a FortiGate.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Role-based access control (RBAC) at the global level.
Why it's wrong here
FortiGate does not have a global RBAC feature that separates administrators by VDOM. The correct method is to create administrator accounts with VDOM restrictions. While administrator profiles exist, they are not called RBAC. The term RBAC is not used in FortiOS for this purpose. The administrator must use VDOM-specific admin accounts to achieve the desired isolation.
- ✓
VDOM-specific administrator accounts with restricted profiles.
Why this is correct
FortiGate allows you to create administrator accounts that are restricted to specific VDOMs. By assigning an administrator to a VDOM and using a profile with limited permissions, you can ensure that the administrator can only view and modify settings within that VDOM. This provides the required isolation. Each VDOM can have its own administrators, and they cannot access other VDOMs unless explicitly granted.
- ✗
Administrative domains (ADOMs) on FortiManager.
Why it's wrong here
ADOMs are a FortiManager feature used to group and manage multiple FortiGates, not to separate administrators within a single FortiGate. They do not provide per-VDOM administrative isolation on the FortiGate itself. While ADOMs can restrict which devices an administrator can manage, they do not control access to VDOMs on a single device. This scenario requires a FortiGate-local feature, not FortiManager.
- ✗
Virtual clustering with separate management IPs per VDOM.
Why it's wrong here
Virtual clustering is an HA feature that allows multiple VDOMs to be active on different cluster units. It does not provide administrative isolation between VDOMs. Separate management IPs can be assigned to VDOMs for management access, but they do not restrict administrator permissions. To isolate administrators, you must configure VDOM-specific administrator accounts, not virtual clustering.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.