NSE7 Enterprise Firewall and VDOMs Practice Question
An administrator is troubleshooting a FortiGate in transparent mode. The FortiGate is not forwarding traffic between two segments connected to port1 and port2. The administrator checks the interface configuration. Which TWO configurations are REQUIRED for a transparent mode VDOM to forward traffic? (Choose two.)
⚠ Common exam trap
Many exam-takers think IP addressing or firewall policies are the primary requirements for forwarding, but in transparent mode, the critical Layer 2 bridging configuration is what enables traffic to pass between interfaces.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Both interfaces must be members of the same hardware switch (or software bridge)
In transparent mode, FortiGate acts as a Layer 2 bridge, so traffic must be switched between interfaces. Both interfaces must be members of the same hardware switch or software bridge to create a single broadcast domain, allowing frames to be forwarded based on MAC addresses. Without this, the interfaces are isolated and cannot forward traffic at Layer 2.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Spanning Tree Protocol (STP) must be enabled on both interfaces
Why it's wrong here
STP is optional and not required for basic bridging.
- ✗
Both interfaces must be assigned IP addresses in the same subnet
Why it's wrong here
Transparent mode interfaces do not require IP addresses for bridging; they are Layer 2 ports.
- ✓
Both interfaces must be members of the same hardware switch (or software bridge)
Why this is correct
Traffic is forwarded between interfaces that are part of the same bridge.
- ✗
A firewall policy must allow all traffic between the two interfaces
Why it's wrong here
While policies can be applied, traffic can be forwarded without policies if default action is allow; but typically policies are used. However, required configuration for forwarding is the bridge, not the policy.
- ✓
The VDOM must be configured in transparent mode
Why this is correct
Transparent mode must be enabled for the VDOM to operate as a bridge.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 940-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.