Courseiva

NSE7 Enterprise Firewall and VDOMs Practice Question

An organization has multiple ADOMs in FortiManager. The admin wants to share a set of firewall objects across all ADOMs. What is the best approach?

⚠ Common exam trap

Candidates often confuse the Global ADOM with a regular ADOM or think that a simple system setting can enable object sharing, when in fact the Global ADOM is a distinct, purpose-built feature for cross-ADOM object sharing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use the Global ADOM to create global objects

The Global ADOM in FortiManager is specifically designed to create and manage global objects (such as address objects, services, and schedules) that can be shared across all regular ADOMs. When an object is created in the Global ADOM, it is automatically available in all ADOMs that are linked to it, eliminating the need for duplication. This is the only native, supported method for sharing objects across multiple ADOMs in FortiManager.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a meta field and assign objects

    Why it's wrong here

    Meta fields are custom attributes attached to objects for search and reporting; they do not replicate or reference objects between ADOMs. They are used to tag and filter policy objects, not to make one object definition available across administrative domains.

  • ✓

    Use the Global ADOM to create global objects

    Why this is correct

    Global ADOM objects are inherited by every ADOM, satisfying the cross-ADOM sharing requirement without duplication. Objects created there propagate automatically to all ADOMs, including newly created ones, and remain centrally managed. Per-ADOM objects cannot be referenced elsewhere, so only the Global ADOM provides the required scope.

  • ✗

    Manually recreate the objects in each ADOM

    Why it's wrong here

    Manually recreating objects in each ADOM duplicates configuration and creates drift, since edits in one ADOM never propagate to the others. It is tempting because per-ADOM objects are the default when ADOMs must stay isolated, such as separate tenants or regulatory boundaries where global sharing is prohibited.

  • ✗

    Enable object sharing in the system settings

    Why it's wrong here

    Enabling object sharing in system settings applies only within a single ADOM, letting its managed devices reference common objects — it does not span multiple ADOMs. It is tempting because it genuinely reduces duplication across devices sharing one ADOM, which is exactly the right choice when all firewalls sit in the same ADOM.

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.