Courseiva

NSE7 Enterprise Firewall and VDOMs Practice Question

An administrator sees the following error when trying to commit changes from FortiManager to a FortiGate: 'Policy check failed: Policy ID 5 uses a zone that does not exist on the device.' What is the most likely cause?

⚠ Common exam trap

Many exam-takers confuse a missing object error with a firmware version mismatch or permission issue, but the error message explicitly names the missing zone, making the root cause straightforward if read carefully.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The zone referenced in the policy is not yet created on the FortiGate

The error 'Policy check failed: Policy ID 5 uses a zone that does not exist on the device' indicates that the FortiGate does not have the zone object referenced in the policy. When FortiManager pushes a policy that references a zone, the zone must already exist on the managed FortiGate; otherwise, the commit fails. Option B correctly identifies that the zone is missing on the FortiGate.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The policy package is locked by another administrator

    Why it's wrong here

    A locked policy package prevents the administrator from editing or committing at all, producing a lock or workspace error rather than a policy check referencing a missing zone. The message names Policy ID 5 and a zone absent on the device, indicating an object mismatch. Locking is tempting because it blocks commits, but not with this wording.

  • ✓

    The zone referenced in the policy is not yet created on the FortiGate

    Why this is correct

    FortiManager validates policy objects against the target FortiGate's configuration before committing. Because the referenced zone does not exist on the device, the policy check fails. Creating the zone on the FortiGate, or removing the zone reference, resolves the commit error.

  • ✗

    The FortiGate is not running the same firmware version as FortiManager

    Why it's wrong here

    Firmware version mismatch typically causes unsupported object or syntax errors, not a specific 'zone does not exist' policy check. The error names Policy ID 5 referencing a zone absent from the FortiGate's configuration. Version parity is tempting because it causes commit failures, but the message points to a missing zone object.

  • ✗

    The administrator has insufficient permissions

    Why it's wrong here

    Insufficient permissions would block the commit entirely with an authorisation error, not a policy check naming a specific zone mismatch. The error text explicitly states Policy ID 5 references a zone absent from the target device. Permissions are tempting because commit failures often stem from RBAC, but here the message identifies a configuration object mismatch.

About these practice questions

Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.