Courseiva
Enterprise Firewall and VDOMsmediumMultiple SelectObjective-mapped

NSE7 Enterprise Firewall and VDOMs Practice Question

An administrator needs to restrict inter-VDOM traffic between two VDOMs on a FortiGate. Which TWO configurations are required?

⚠ Common exam trap

Watch out — candidates often assume inter-VDOM routing requires a global enablement or IP addressing on the VDOM link, but FortiGate handles this automatically, and the key requirement is the firewall policies to enforce restrictions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create firewall policies in each VDOM to allow/deny traffic

Inter-VDOM traffic on a FortiGate is controlled by firewall policies within each VDOM. By creating policies in each VDOM that specify the VDOM link as the interface, the administrator can explicitly allow or deny traffic between the VDOMs, enforcing security boundaries. Without these policies, traffic would be implicitly denied by the default firewall behavior.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Create firewall policies in each VDOM to allow/deny traffic

    Why this is correct

    Policies are necessary to control traffic flow.

  • Enable inter-VDOM routing globally

    Why it's wrong here

    Inter-VDOM routing is enabled by default; no global setting required.

  • Assign an IP address to the VDOM link in each VDOM

    Why it's wrong here

    IP addressing is required for routing but not the minimal two items for restriction; policies are the key.

  • Configure a VDOM link between the two VDOMs

    Why this is correct

    The VDOM link is the interface connecting the VDOMs.

  • Configure static routes on each VDOM

    Why it's wrong here

    Static routes are needed for routing to remote networks, but not strictly for inter-VDOM traffic if directly connected.

About these practice questions

Courseiva writes every NSE7 question from scratch — 940 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.