NSE7 Enterprise Firewall and VDOMs Practice Question
An organization uses FortiManager to manage multiple FortiGates. A junior admin accidentally deleted a critical firewall policy on one device and the change was auto-installed. How can the senior admin revert the device to the previous configuration?
⚠ Common exam trap
Many exam-takers think the only way to revert a change is to manually recreate the policy (Option D) or use a generic command (Option C), overlooking FortiManager's built-in revision history feature which is specifically designed for this purpose.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Go to Device Manager -> Revision History and restore the previous revision
FortiManager automatically stores configuration revisions for managed FortiGates. By navigating to Device Manager -> Revision History, the admin can select the previous revision and restore it, which reverts the device to its state before the accidental deletion. This process ensures the change is undone without manual intervention or affecting other devices.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Delete the ADOM and recreate it
Why it's wrong here
Deleting the ADOM destroys every managed device's policy package, objects and revision history, so the deleted policy cannot be recovered from it. ADOM deletion is for decommissioning or rebuilding a management container, not rollback. FortiManager's configuration revision history restores the prior policy package instead.
- ✓
Go to Device Manager -> Revision History and restore the previous revision
Why this is correct
Device Manager's Revision History stores per-device configuration revisions, so restoring the prior revision pushes the pre-deletion policy back to that FortiGate. This satisfies the scenario's requirement to revert a single device after an auto-installed change, without affecting other managed FortiGates or relying on full-system backups.
- ✗
Use the 'restore' command on FortiManager
Why it's wrong here
FortiManager has no 'restore' command; recovery uses the per-device configuration revision history, where the admin selects the earlier revision and installs it. 'Restore' belongs to FortiGate backup files or FortiManager system backup, which would overwrite the whole management database rather than revert one policy package.
- ✗
Manually recreate the policy on the FortiGate
Why it's wrong here
Recreating the policy by hand on the FortiGate leaves FortiManager's policy package unchanged, so the next auto-install pushes the broken package again and removes it. Manual rebuilds suit unmanaged devices; managed devices require the revision history rollback, which realigns both FortiManager and the FortiGate.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.