NSE7 Enterprise Firewall and VDOMs Practice Question
An administrator is troubleshooting why a new firewall policy on a managed FortiGate is not taking effect. The policy was created in FortiManager and installed successfully. Which TWO steps should the administrator verify to identify the issue? (Select TWO.)
⚠ Common exam trap
A common mix-up: candidates assume a successful installation guarantees the policy is active, overlooking the disabled state or the impact of policy order on traffic matching.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Check if the policy is disabled
Option C is correct because a policy that exists in FortiManager and installs successfully can still be administratively disabled on the managed FortiGate, in which case it will never match traffic; the administrator should confirm the policy's status is enabled. Option D is correct because firewall policies are evaluated top-down and the first matching policy wins, so if a broader or conflicting policy appears above the new policy in the policy list, the new policy will never be hit; verifying its position in the order is essential. Option A is not appropriate because rebooting the FortiGate does not resolve a policy configuration or ordering problem and would only cause unnecessary downtime. Option B is not the right focus because routing determines whether traffic reaches the FortiGate and which interface/next-hop is used, but the scenario states the policy itself is not taking effect, not that traffic is failing to route. Option E is not relevant because HA status affects failover and session synchronization, not whether a specific installed policy matches traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reboot the FortiGate
Why it's wrong here
Rebooting does not reconcile a policy that FortiManager reports as installed but the FortiGate has not applied; the discrepancy lies in installation target, revision, or policy package assignment. It is tempting because reboots clear transient daemon faults, which is the right step when a FortiGate is unresponsive rather than when a specific policy is missing.
- ✗
Review the FortiGate's routing table
Why it's wrong here
Routing determines whether traffic reaches the FortiGate, not whether an installed policy matches it; a policy that never sees matching traffic is a policy-lookup or installation-scope problem. It is tempting because routing is the first check for traffic that never arrives, which is the correct scenario when sessions fail before policy evaluation.
- ✓
Check if the policy is disabled
Why this is correct
A policy installed successfully can still be inactive if its status is disabled. Verifying the enabled/disabled state on the managed FortiGate confirms whether the policy is actually evaluated, directly explaining why it produces no effect.
- ✓
Check the policy order in the policy list
Why this is correct
FortiGate evaluates policies top-down and stops at the first match, so an earlier policy can shadow the new one. Checking policy order confirms whether a preceding rule intercepts the traffic before the new policy is reached.
- ✗
Verify the FortiGate's HA status
Why it's wrong here
HA status affects which unit holds the primary role and synchronises configuration, but a policy installed to the managed FortiGate is present regardless of HA state; the failure is in policy installation scope or matching. It is tempting because HA failover can revert configuration, which is the right check when a policy disappears after a cluster event.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.