Courseiva

NSE7 · domain

Enterprise Firewall and VDOMs

This domain covers FortiGate VDOM architecture, inter-VDOM links, and FortiManager policy packages. Questions test how policies flow from FortiManager to managed FortiGates, how header and footer policies apply across VDOMs, and how traffic moves between VDOMs through VDOM links with correct routing and firewall policies.

186 questions47 easy94 medium45 hard

Focused practice

Practice Enterprise Firewall and VDOMs questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Enterprise Firewall and VDOMs

Be able to configure VDOM links with correct IPs, routing, and firewall policies, and explain how FortiManager header and footer policies apply across VDOMs in a policy package. The key is knowing which policies take precedence and where they are enforced.

VDOM link interface IP assignment and inter-VDOM routing between VDOMs A and B

FortiManager policy package header and footer policies and their scope across VDOMs

FortiGate registration and policy update synchronization with FortiManager and Security Fabric

Global versus VDOM-specific policy behavior when pushing a policy package

Watch out for

Common Enterprise Firewall and VDOMs exam traps

  • ▸Assuming a VDOM link passes traffic once IPs are assigned, without a firewall policy allowing the inter-VDOM traffic.
  • ▸Confusing header/footer policies with per-VDOM policies and expecting them to be overridden by VDOM-specific rules.
  • ▸Believing a FortiGate registered with FortiManager automatically receives policy updates without correct provisioning or policy package assignment.

Question index

All Enterprise Firewall and VDOMs questions (186)

Click any question to see the full explanation, or start a practice session above.

1

A FortiGate is configured with multiple VDOMs. The administrator wants to assign a specific physical interface to a non-management VDOM and ensure that the interface is not visible or configurable from other VDOMs. The interface is currently assigned to the root VDOM. What is the correct procedure to reassign the interface to VDOM-1?

Hard
2

An administrator needs to monitor traffic flows across multiple FortiGate devices in a Security Fabric. The administrator wants to see a unified view of all traffic, including inter-device traffic, from a single pane. Which Fortinet tool provides this capability?

Easy
3

A FortiGate in HA active-passive mode has two VDOMs. VDOM-1 is configured for management (management VDOM). The administrator connects to the management VDOM IP to manage the device. What is a characteristic of the management VDOM?

Medium
4

An admin creates a VDOM named 'CustomerA' with inter-VDOM link to the management VDOM. The admin wants CustomerA administrators to manage only their own VDOM. Which configuration step is required?

Hard
5

What is the primary function of FortiAnalyzer's FortiView feature?

Easy
6

An organization uses FortiAnalyzer for centralized logging. The security team wants to use playbooks to automate responses to detected incidents. Which THREE components are essential for a playbook to function?

Hard
7

An administrator configures a new ADOM in FortiManager for a set of FortiGates. The administrator wants to assign meta fields to devices in this ADOM. Where should the meta fields be defined?

Medium
8

A FortiGate admin configures inter-VDOM routing between VDOM-A and VDOM-B using a VDOM link. The admin wants traffic from VDOM-A to reach a server in VDOM-B. Which three configuration steps are required? (Choose three.)

Hard
9

A network administrator wants to delegate management of a specific VDOM to a junior administrator. The junior should be able to modify firewall policies and objects within that VDOM but not change system settings or other VDOMs. Which administrative access configuration meets this requirement?

Easy
10

What is the purpose of FortiAnalyzer in a Fortinet security fabric?

Easy
11

An administrator configures a FortiGate with VDOMs and notices that the 'config vdom' command lists multiple VDOMs, but only one VDOM is shown in the 'show full-configuration' output. What is the most likely reason?

Medium
12

An administrator wants to group firewall objects by department (e.g., Sales, Engineering) and easily filter them in FortiManager policy packages. Which feature should be used?

Medium
13

Which FortiManager feature allows an administrator to view the exact CLI commands that will be pushed to a managed FortiGate before installation?

Easy
14

In a FortiManager deployment with global ADOM enabled, an administrator creates a firewall policy in the global ADOM. What is the effect of this policy on the per-ADOM devices?

Hard
15

An administrator is troubleshooting why a new firewall policy on a managed FortiGate is not taking effect. The policy was created in FortiManager and installed successfully. Which TWO steps should the administrator verify to identify the issue? (Select TWO.)

Medium
16

An administrator has a FortiGate with multiple VDOMs in NAT/route mode. VDOM-1 and VDOM-2 are connected via an inter-VDOM link. The administrator wants to apply security profiles to traffic passing between the VDOMs. However, when checking the policy list in VDOM-1, no policy is shown for traffic destined to VDOM-2. What is the most likely reason?

Hard
17

A FortiGate is configured with multiple VDOMs. The administrator wants to assign a physical interface to a specific VDOM so that it can be used for that VDOM's traffic. Which configuration step is required?

Medium
18

An administrator is deploying a FortiGate in multi-VDOM mode for a managed services provider. Each customer must have an isolated logical firewall with its own interfaces, policies, and administrators, and the provider wants to limit each customer administrator to only their own VDOM. Which configuration accomplishes this?

Easy
19

An administrator has a FortiGate in multi-VDOM mode. VDOM-1 is assigned to the marketing team and VDOM-2 to the finance team. The administrator wants both VDOMs to be able to reach a shared DNS server at 10.10.10.53 that sits behind the root VDOM's wan1 interface, without giving either team access to the other's traffic. Which configuration accomplishes this?

Medium
20

In FortiAnalyzer, which tool provides real-time traffic monitoring and allows drilling down into details such as top talkers, applications, and threats?

Easy
21

A FortiGate is configured with multiple VDOMs in NAT/route mode. The administrator wants to allow a server in VDOM-A to be accessed from the internet through VDOM-B, which has the public IP address. The administrator has already created a VDOM link between VDOM-A and VDOM-B. Which additional configuration is required to make the server accessible?

Hard
22

An administrator needs to isolate customer traffic in a FortiGate deployed at a service provider. Each customer should have independent administrators and security policies. Which feature should be used?

Easy
23

An administrator manages a FortiGate 500E with multiple VDOMs. The administrator needs to configure a new VDOM named 'Partner' and ensure that the Partner VDOM can use a dedicated physical interface for WAN connectivity. The FortiGate has an unused interface 'port5'. The administrator wants to assign port5 to the Partner VDOM and configure it with an IP address. Which sequence of steps is correct?

Hard
24

Drag and drop the steps to configure a FortiGate to send logs to a FortiAnalyzer into the correct order.

Medium
25

Match each Fortinet component to its description.

Medium
26

A company has deployed two FortiGate-600Es in an active-passive HA cluster. The cluster is configured with three VDOMs: VDOM-A (corporate LAN), VDOM-B (guest Wi-Fi), and VDOM-C (DMZ). Each VDOM has its own set of interfaces and policies. The cluster is also configured to use FGCP with session pickup enabled. Recently, the network team noticed that after a failover event, some user sessions in VDOM-B are not being picked up, causing disruption for guest users. The session pickup feature is enabled globally. The administrator checks the configuration and finds the following settings on the primary FortiGate: - config system ha set session-pickup enable set session-pickup-connectionless enable end - config vdom edit VDOM-A config system ha set session-pickup enable end next edit VDOM-B config system ha set session-pickup disable end next edit VDOM-C config system ha set session-pickup enable end next Based on this configuration, what is the most likely reason that sessions in VDOM-B are not being picked up?

Hard
27

An administrator is reviewing the HA configuration shown in the exhibit. The primary unit has failed, and the secondary unit (with priority 100) has taken over. However, the administrator notices that the secondary unit has an IP address of 10.10.10.2 on port3, but cannot ping the management gateway 10.10.10.1. What is the most likely cause?

Easy
28

An administrator is configuring a FortiGate with multiple VDOMs. The administrator wants to assign a physical interface to a specific VDOM and ensure that the interface is dedicated to that VDOM only. Which action should the administrator take?

Easy
29

A FortiGate running FortiOS 7.2 has multiple VDOMs. The administrator notices that inter-VDOM routing between two VDOMs is not working. Configuration shows a firewall policy allowing the traffic, and the route table shows routes to the destination VDOM. What additional configuration is required?

Hard
30

A FortiGate administrator configures a VDOM with a limit on the number of firewall policies. The VDOM has 200 policies, and the limit is set to 250. The administrator attempts to add a new policy but receives an error indicating the limit has been reached. What is the MOST likely reason?

Hard
31

A FortiGate HA cluster is configured with two units in active-passive mode. The administrator needs to perform a firmware upgrade on the cluster with minimal downtime. The current firmware version is 7.2.5 and the target is 7.2.7. The cluster uses FGCP with session synchronization enabled. Which procedure should the administrator follow?

Hard
32

A network administrator wants to logically separate two departments on a single FortiGate. Each department must have its own firewall policies, routing table, and administrators. Which feature should be used?

Easy
33

An administrator is deploying a FortiGate with multiple VDOMs in NAT mode. The administrator wants to ensure that traffic between VDOMs is inspected by security profiles and that inter-VDOM traffic does not bypass the firewall policy engine. Which configuration is required to achieve this?

Medium
34

An administrator configures a multi-VDOM FortiGate in transparent mode. The admin notices that the management IP is reachable from both interfaces, but traffic passing through the device is not being inspected. What is the likely issue?

Hard
35

An administrator configures inter-VDOM routing between VDOM-A and VDOM-B using a VDOM link. The default route in VDOM-A points to a next-hop router, and VDOM-B has a static route to a subnet behind VDOM-A. Users in VDOM-B cannot reach that subnet. The administrator runs 'diagnose ip route list' in both VDOMs and sees the routes are present. What is the most likely cause?

Hard
36

An administrator configures automation stitches on FortiManager to trigger a script when a specific event log is received. The script should block the source IP on the firewall. However, the script does not run when the event occurs. What is a likely cause?

Hard
37

What is the purpose of header and footer policies in a FortiManager policy package?

Easy
38

What is the primary purpose of an administrative VDOM on a FortiGate?

Easy
39

An administrator is configuring a FortiGate in multi-VDOM mode. The administrator needs to ensure that a specific VDOM can use more system resources, such as sessions and CPU, than other VDOMs. Which FortiGate feature should the administrator use?

Easy
40

Which FortiAnalyzer feature allows administrators to create automated response actions triggered by specific log events, such as blocking an IP address when an intrusion is detected?

Easy
41

An administrator runs 'diagnose sys session filter dport 443' and sees the following output: proto=6 proto_state=01 duration=3600 expire=3599 What does this indicate?

Medium
42

A FortiGate 600E is running in multi-VDOM mode with VDOM-1 and VDOM-2. The administrator assigns physical port3 to VDOM-1 as a dedicated interface, then creates a VLAN subinterface (VLAN 100) on port3 for VDOM-2. After configuration, VLAN 100 traffic is dropped even though the VLAN interface is up. Which action resolves the issue?

Medium
43

An enterprise FortiGate has multiple VDOMs. The administrator wants to allow traffic from VDOM A to reach servers in VDOM B without traversing an external router. Which configuration is required?

Medium
44

A FortiGate running FortiOS 7.4.1 has two VDOMs: CustomerA and CustomerB. The administrator wants CustomerA to access an HTTP server in CustomerB. Both VDOMs have appropriate policies. What additional configuration is required?

Medium
45

An organization has multiple ADOMs in FortiManager. The admin wants to share a set of firewall objects across all ADOMs. What is the best approach?

Hard
46

A FortiGate administrator wants to use FortiAnalyzer to view traffic logs from multiple VDOMs. Which TWO steps must the administrator perform on FortiAnalyzer?

Easy
47

An enterprise FortiGate has multiple VDOMs. The security policy requires that all traffic between VDOMs must be inspected by a next-generation firewall profile. Which three steps are necessary to achieve this? (Choose three.)

Medium
48

An administrator has configured two VDOMs on a FortiGate. One VDOM is in NAT mode and the other in transparent mode. The administrator wants traffic from the transparent mode VDOM to be routed through the NAT mode VDOM. What must be configured to allow inter-VDOM routing?

Hard
49

A FortiGate in transparent mode is deployed between a router and a switch. The administrator needs to apply a deep inspection profile to HTTP traffic. What is the correct configuration for the interfaces?

Hard
50

A FortiGate has multiple VDOMs. The administrator notices that traffic from VDOM-1 to VDOM-2 is allowed by inter-VDOM policies but is not being inspected by the security profiles. What is the most likely cause?

Medium
51

An administrator wants to use FortiAnalyzer to generate weekly compliance reports for all managed FortiGates. Which FortiAnalyzer feature should be used?

Easy
52

An admin needs to configure a FortiGate to send logs to FortiAnalyzer for a specific VDOM only. How can this be achieved?

Medium
53

A company is implementing a Security Fabric with multiple FortiGate devices. They want to use FortiAnalyzer for centralized logging and FortiManager for centralized management. Which of the following is a prerequisite for adding a FortiGate to the Security Fabric?

Easy
54

A FortiGate administrator runs the following command and sees the output: diagnose sys session filter dport 443 diagnose sys session list Output shows sessions with proto=6 and expire time decreasing. What does this indicate?

Medium
55

A FortiGate administrator wants to use FortiManager automation stitches to automatically block IP addresses that trigger multiple intrusion prevention events. Which two components are required to configure an automation stitch? (Choose two.)

Medium
56

A FortiGate has two VDOMs: 'root' and 'customer'. The admin wants to route traffic from 'customer' to the internet via 'root', which has a BGP connection to an ISP. What is the required configuration?

Medium
57

A FortiGate is deployed with multiple VDOMs in NAT/route mode. The administrator wants VDOM-A and VDOM-B to exchange routing information dynamically without using static routes. The administrator has already created a VDOM link named 'vlink' between the two VDOMs and assigned IP addresses 10.0.0.1/30 and 10.0.0.2/30 to the respective interfaces. Which additional configuration is required on each VDOM to enable OSPF adjacency over the VDOM link?

Medium
58

Which THREE actions can an administrator perform using FortiManager in a Security Fabric environment? (Choose three.)

Hard
59

A network engineer needs to collect logs from multiple FortiGates and generate compliance reports. Which TWO FortiAnalyzer features should be used?

Medium
60

An administrator is configuring a FortiGate with multiple VDOMs. The administrator wants to ensure that each VDOM has its own separate routing table. Which statement is correct?

Easy
61

Drag and drop the steps to configure a site-to-site IPsec VPN on a FortiGate firewall into the correct order.

Medium
62

An administrator is deploying a FortiGate with multiple VDOMs in NAT/route mode. The administrator needs to configure inter-VDOM routing between VDOM-A and VDOM-B. Which two actions are required to enable traffic to flow between the two VDOMs? (Choose two.)

Medium
63

Match each FortiGate routing concept to its description.

Medium
64

A FortiGate is configured with multiple VDOMs. The administrator wants to assign a physical interface to multiple VDOMs to save physical ports. Which feature should they use?

Hard
65

A FortiGate administrator needs to configure a policy that allows traffic from VDOM A to VDOM B using inter-VDOM routing. Which configuration is required?

Medium
66

A FortiGate admin configures a policy package with header and footer policies in FortiManager. What is the purpose of header policies?

Medium
67

What is the purpose of a management VDOM in a multi-VDOM FortiGate?

Easy
68

An administrator has a FortiGate with multiple VDOMs and a management VDOM enabled. The management VDOM is used for out-of-band management and logging. The administrator wants to ensure that the management VDOM can reach a syslog server on the Internet while all other VDOMs use a separate data VDOM for their Internet traffic. Which configuration is required to allow the management VDOM to use a different default route than the other VDOMs?

Hard
69

An administrator has a FortiGate 600E running FortiOS 7.2 with multiple VDOMs enabled. The administrator wants to create a new VDOM named 'DMZ' and assign it a specific physical interface (port3) that is currently unused. After creating the VDOM, the administrator navigates to Network > Interfaces in the DMZ VDOM but cannot see port3 in the list of available interfaces to assign. What is the most likely reason for this?

Medium
70

In FortiManager, an administrator wants to apply a set of firewall policies to multiple FortiGates in different ADOMs. The policies must be centrally managed. What is the best approach?

Medium
71

An administrator wants to ensure that traffic between two VDOMs on the same FortiGate is properly inspected. Which THREE configurations must be in place?

Hard
72

An administrator configures FortiAnalyzer to receive logs from multiple FortiGates. They want to create a report that shows only incidents involving 'critical' severity and specific attack types. Which FortiAnalyzer feature allows the administrator to define such a custom report?

Hard
73

An administrator is troubleshooting a scenario where FortiAnalyzer is not receiving logs from a FortiGate. The FortiGate shows 'log-fortianalyzer setting status: disconnected'. Which step should be taken first to resolve this?

Medium
74

An administrator is configuring a new FortiGate with multiple VDOMs. The administrator wants to ensure that each VDOM has its own independent routing table and that traffic between VDOMs is inspected by firewall policies. Which TWO statements about inter-VDOM routing are correct? (Choose two.)

Medium
75

A company has a FortiGate with multiple VDOMs. The security team wants to use FortiManager to manage policies centrally. Which three steps are necessary to set up VDOM management via FortiManager? (Choose three.)

Hard
76

A network admin is deploying a FortiGate in transparent mode to inspect traffic between two Layer 2 switches. Which of the following statements about transparent mode is correct?

Medium
77

A FortiGate administrator is troubleshooting a scenario where users in VDOM-1 cannot reach a server in VDOM-2. Inter-VDOM routing is configured using a VDOM link. The administrator checks the session table and sees that packets are arriving on the VDOM link interface but are not being forwarded. What is the MOST likely cause?

Hard
78

A FortiGate administrator notices that after installing a new policy package from FortiManager, the firewall policies on the managed FortiGate do not match what was configured in FortiManager. What feature should the administrator use to review the exact changes before committing?

Easy
79

A FortiGate is configured with multiple VDOMs in NAT/route mode. The administrator wants to enable communication between VDOM-A and VDOM-B using an inter-VDOM link. The administrator creates the link and assigns IP addresses 10.0.0.1/30 and 10.0.0.2/30 to the respective interfaces. The administrator then adds a static route in VDOM-A to VDOM-B's network (192.168.2.0/24) via 10.0.0.2, and a static route in VDOM-B to VDOM-A's network (192.168.1.0/24) via 10.0.0.1. However, traffic still fails. What is the most likely missing configuration?

Hard
80

A FortiGate administrator needs to use FortiManager to deploy a new security policy to all firewalls in a specific ADOM. Which two steps are part of the installation process? (Choose two.)

Easy
81

A network administrator is deploying a FortiGate in multi-VDOM mode. The administrator wants to restrict a specific VDOM so that it can only use a maximum of 2 GB of system memory and 10% of the total CPU resources. Which FortiGate feature should the administrator use?

Easy
82

An administrator has a FortiGate with two VDOMs: 'root' and 'VDOM-A'. The administrator wants to assign a physical interface to VDOM-A, but the interface is currently assigned to the root VDOM and is in use by a firewall policy. What must the administrator do before changing the interface's VDOM assignment?

Hard
83

A FortiGate administrator is planning a multi-VDOM deployment for a service provider. Which TWO statements are true about VDOM limitations and best practices?

Medium
84

An enterprise deploys a FortiGate in transparent mode to bridge two broadcast domains. The administrator needs to apply a web filter to HTTP traffic between these domains. Which configuration is required?

Medium
85

A FortiManager administrator wants to deploy a policy package that contains shared header and footer policies across multiple devices. How should these policies be configured in FortiManager?

Medium
86

In FortiManager, what is the difference between a Global ADOM and a regular ADOM?

Easy
87

A FortiManager administrator wants to push policy package changes to a managed FortiGate, but wants to see what changes will be applied before committing. Which FortiManager feature should the administrator use?

Medium
88

In FortiManager, what is an automation stitch?

Easy
89

A multi-tenant FortiGate uses VDOMs. The administrator notices that logins via SSH to the management VDOM succeed, but attempts to SSH to a traffic VDOM's management IP fail. The traffic VDOM has an administrative user configured. What is the most likely cause?

Medium
90

Refer to the exhibit. A FortiGate is connected to the Security Fabric and registered with FortiManager. However, the administrator notices that the FortiGate is not receiving policy updates from FortiManager. What is the most likely cause?

Hard
91

An administrator deploys a FortiGate in transparent mode within a Layer 2 network. They apply a firewall policy with an antivirus profile to inspect traffic between two VLANs. What is a key characteristic of transparent mode that affects policy application?

Medium
92

An administrator configures two FortiGate units in an active-passive HA cluster. During a failover test, the administrator notices that the secondary unit becomes primary but the session table is empty, causing all existing connections to drop. Which configuration change should be made to preserve session information during failover?

Medium
93

A FortiGate 600E is running multiple VDOMs in NAT/route mode. VDOM-1 and VDOM-2 each have an inter-VDOM link interface named 'ivl-1' and 'ivl-2' respectively, and both are assigned IP addresses in the 10.10.10.0/30 subnet. VDOM-1 has a static route to 192.168.2.0/24 via 10.10.10.2, and VDOM-2 has a static route to 192.168.1.0/24 via 10.10.10.1. A user in VDOM-1 (192.168.1.10) cannot ping a server in VDOM-2 (192.168.2.10). What is the most likely cause?

Medium
94

An organization uses FortiManager to manage multiple FortiGates. A junior admin accidentally deleted a critical firewall policy on one device and the change was auto-installed. How can the senior admin revert the device to the previous configuration?

Medium
95

An administrator configures inter-VDOM routing between VDOM-A and VDOM-B using a VDOM link. After configuration, traffic from VDOM-A cannot reach VDOM-B. Which configuration step is MOST likely missing?

Medium
96

A FortiGate 600E is configured with multiple VDOMs in NAT mode. The administrator wants to route traffic between VDOM-1 and VDOM-2 without using physical interfaces. They create a VDOM link named 'vlink' with interfaces vlink0 and vlink1, assign vlink0 to VDOM-1 (IP 10.0.1.1/30) and vlink1 to VDOM-2 (IP 10.0.1.2/30). However, traffic from a host in VDOM-1 (192.168.1.0/24) to a server in VDOM-2 (192.168.2.0/24) fails. The administrator has added static routes in both VDOMs pointing to the respective VDOM link IPs. What is the most likely cause of the failure?

Medium
97

An administrator has configured a FortiGate HA cluster with two units. The cluster uses a virtual cluster for load balancing in active-active mode. The administrator notices that traffic from one VDOM is not being load-balanced and is only handled by one unit. What is the most likely cause?

Medium
98

An administrator is configuring a FortiGate with VDOMs. The administrator wants to ensure that each VDOM has its own independent routing table and that routes in one VDOM do not affect another. Which statement about VDOM routing is correct?

Easy
99

Which FortiManager feature allows an administrator to roll back a policy package to a previous version?

Easy
100

A company uses FortiManager to manage multiple FortiGates. The admin wants to use a global ADOM to manage certain policies across all devices while allowing local customization. Which two statements about global ADOM are true? (Choose two.)

Medium
101

A FortiGate administrator wants to use FortiManager to manage multiple FortiGates in different geographic regions. To isolate configuration changes, the administrator creates separate ADOMs for each region. Which type of ADOM should be used to allow some common objects (like address groups) to be shared across all regions?

Medium
102

An administrator has a FortiGate 600E running multiple VDOMs in NAT mode. The security team wants to inspect inter-VDOM traffic between VDOM-A and VDOM-B with a firewall policy that applies UTM profiles. The administrator has already created a VDOM link named vlink1 with interfaces vlink1-A in VDOM-A and vlink1-B in VDOM-B. What must the administrator do to ensure that inter-VDOM traffic is inspected by a security policy?

Medium
103

An administrator configures an automation stitch in FortiManager to execute a CLI script on a FortiGate when a specific event is triggered. The automation stitch is enabled but does not run when the event occurs. What is the most likely cause?

Hard
104

A FortiGate administrator is configuring a multi-VDOM deployment. The administrator wants to use a single physical interface for multiple VDOMs. Which TWO methods allow this?

Medium
105

An administrator is configuring a FortiGate with multiple VDOMs in NAT/route mode. The administrator wants to enable inter-VDOM routing between VDOM-A and VDOM-B using a VDOM link. Which TWO statements about VDOM links are correct? (Choose two.)

Medium
106

An administrator manages a FortiGate with VDOMs 'prod' and 'dev' on a single HA pair. The administrator wants 'prod' to fail over independently from 'dev' so that maintenance on the dev environment does not trigger a failover of prod. Which FortiGate feature should be configured?

Hard
107

A FortiGate is deployed in multi-VDOM mode with VDOM-1 and VDOM-2. The administrator creates an inter-VDOM link named IVL1 with interface ivl-1-0 in VDOM-1 and ivl-1-1 in VDOM-2. Static routes are configured in both VDOMs to route traffic across the link. However, traffic from VDOM-1 to VDOM-2 is dropped. What is the most likely reason?

Hard
108

An administrator configures inter-VDOM routing between VDOMs A and B using a VDOM link. The administrator can ping from VDOM A to an interface in VDOM B, but traffic from VDOM B to VDOM A times out. What is the most likely cause?

Medium
109

A network administrator is configuring VDOMs on a FortiGate and wants to separate management traffic from production data traffic. What is the best practice when using a management VDOM?

Easy
110

A FortiGate administrator wants to use FortiManager automation stitches to automatically block an IP address when a specific threat is detected. Which components must be configured within the automation stitch?

Medium
111

What is the purpose of a header policy in a FortiManager policy package?

Easy
112

An administrator wants to isolate tenant traffic in a single FortiGate by creating separate virtual firewalls with independent routing tables, administrators, and policies. Which feature should the administrator use?

Easy
113

A FortiGate 600E is running multiple VDOMs in NAT mode. The administrator wants to assign a VLAN subinterface to VDOM-A while the parent physical interface remains in the root VDOM. Which configuration step is required to accomplish this?

Medium
114

What is the difference between a global ADOM and a regular ADOM in FortiManager?

Easy
115

A FortiGate has two VDOMs: Root and CustomerA. The administrator wants to manage the CustomerA VDOM from FortiManager. What must be configured on FortiManager to allow management of the CustomerA VDOM?

Medium
116

During a failover test in an HA cluster, the administrator observes that the secondary unit becomes primary but does not have the latest configuration. What is the most likely cause?

Medium
117

Which of the following is a required step when enabling VDOMs on a FortiGate for the first time?

Easy
118

A FortiGate is configured with three VDOMs: root, Sales, and Engineering. The administrator wants to ensure that the Sales VDOM can access the internet through the root VDOM, but the Engineering VDOM must not have any internet access. All VDOMs are currently in NAT mode. Which configuration is required to achieve this?

Medium
119

An administrator configures a firewall policy with an application control profile to block social media. The administrator observes that some social media traffic is still passing through. The traffic is HTTPS. What additional configuration is REQUIRED for application control to effectively block HTTPS-based social media?

Hard
120

An enterprise uses multiple VDOMs on a FortiGate. The administrator needs to route traffic between VDOM-A and VDOM-B using a firewall policy. What is the correct configuration step?

Medium
121

A network admin needs to apply a common set of firewall rules at the beginning of every policy package for all VDOMs managed by FortiManager. The rules should be automatically inserted and not editable within each VDOM. What should be configured?

Medium
122

Which FortiAnalyzer feature allows an administrator to create a sequence of automated response actions triggered by a specific log event?

Easy
123

An administrator configures two VDOMs as shown in the exhibit. They create an inter-VDOM link between VDOM1 and VDOM2. They then add a firewall policy in VDOM1 allowing traffic from port1 to the inter-VDOM link, and a policy in VDOM2 allowing traffic from the inter-VDOM link to port2. However, traffic from 192.168.1.10 to 10.10.10.50 fails. What is the most likely cause?

Medium
124

An admin runs 'diagnose sys session filter dport 443' and sees the following output: proto=6 proto_state=01 duration=3600 expire=3599 What does this indicate?

Hard
125

An administrator needs to ensure that all firewall policies in a FortiGate VDOM have a common set of inspection profiles added at the end of the policy list. Which FortiManager feature best achieves this?

Medium
126

A FortiGate is managed by FortiManager. The administrator creates a new policy package for VDOM 'Sales' and installs it. Later, they find that the previous configuration has been overwritten. What should the administrator do to avoid this in the future?

Medium
127

A FortiGate is configured with multiple VDOMs. The administrator wants to enable inter-VDOM routing between VDOM-A and VDOM-B. The administrator creates an inter-VDOM link and assigns IP addresses to both ends. Which additional configuration is required to allow traffic to pass between the VDOMs?

Medium
128

A network administrator is troubleshooting a scenario where FortiView in FortiAnalyzer shows no traffic data for a specific FortiGate, but logs are being received. Which two possible causes should the administrator investigate? (Choose two.)

Hard
129

A FortiGate administrator is troubleshooting an issue where IPsec VPN traffic is not being forwarded correctly in a multi-VDOM environment. Which TWO factors should the administrator verify?

Medium
130

A FortiGate is configured with multiple VDOMs. The administrator needs to provide a network engineer with read-only access to all VDOMs, but the engineer should not be able to make any configuration changes. Which administrative profile configuration should the administrator use?

Medium
131

An administrator needs to back up the configuration of a FortiGate managed by FortiManager before making major changes. Which feature in FortiManager should the administrator use?

Easy
132

An administrator runs 'diagnose sys session list' and sees sessions with 'proto=6 proto_state=02' and a long duration. The administrator is troubleshooting why sessions are not being terminated after a policy change that should block the traffic. What does 'proto_state=02' indicate?

Hard
133

A FortiGate 600E is running in multi-VDOM mode and is managed by FortiManager. The administrator needs to assign CPU and memory resource limits to a specific VDOM so that it cannot consume more than 30% of the system's resources. Which FortiGate feature should the administrator configure?

Medium
134

A FortiGate admin configures a firewall policy with an antivirus profile in flow-based inspection mode. The admin notices that some large files are being scanned but others are allowed without scanning. What is the most likely cause?

Hard
135

An administrator is configuring a FortiGate in multi-VDOM mode. The administrator wants to assign a physical interface to a non-management VDOM. The interface currently belongs to the root VDOM and has an IP address. What must the administrator do first?

Medium
136

An administrator needs to view real-time traffic logs and top applications for a specific VDOM on FortiAnalyzer. Which tool should be used?

Easy
137

A FortiGate 600E is deployed with multiple VDOMs in NAT/route mode. The administrator assigns VLAN 100 to VDOM-A on port1 and VLAN 200 to VDOM-B on port1, then configures the VLAN interfaces as management interfaces for each VDOM. Users in VDOM-A report intermittent connectivity to servers in VDOM-B, while pings between the VLAN interface IPs fail. What is the most likely cause?

Medium
138

An organization wants to use FortiManager to manage multiple FortiGate devices. The administrator needs to ensure that each device group has separate policy and object configurations. Which FortiManager feature should be configured?

Medium
139

What is the purpose of a management VDOM on a FortiGate?

Easy
140

An administrator sees the following error when trying to commit changes from FortiManager to a FortiGate: 'Policy check failed: Policy ID 5 uses a zone that does not exist on the device.' What is the most likely cause?

Medium
141

An administrator is configuring FortiAnalyzer to receive logs from FortiGates in a multi-VDOM environment. The admin wants to ensure that logs from each VDOM are separated into their own datasets. What must be configured?

Hard
142

Which FortiManager feature allows administrators to view the exact configuration changes that would be applied to a managed FortiGate before committing them?

Easy
143

An administrator needs to generate a report showing top applications by bandwidth usage across all VDOMs for the last 30 days. Which FortiAnalyzer feature should be used?

Medium
144

A security administrator wants to generate a weekly report in FortiAnalyzer that shows the top threats detected by the FortiGate. Which feature should the administrator use to create this report?

Medium
145

What is the purpose of a management VDOM in a multi-VDOM FortiGate deployment?

Easy
146

In a multi-VDOM deployment, an administrator needs to route traffic between VDOM-A and VDOM-B. The administrator creates a VDOM link between the two VDOMs. What additional configuration is required on each VDOM to enable inter-VDOM traffic?

Medium
147

What is the purpose of a global ADOM in FortiManager?

Easy
148

A FortiGate is deployed in multi-VDOM mode. The administrator has created VDOM-A and VDOM-B, and configured an inter-VDOM link between them. Users in VDOM-A need to access a web server in VDOM-B. The administrator has added a static route in VDOM-A for the server's subnet pointing to the VDOM link interface, and a return route in VDOM-B. Which TWO additional configurations are required to allow the traffic? (Choose two.)

Hard
149

In a multi-VDOM deployment, inter-VDOM routing is configured using VDOM links. After configuring the VDOM links and adding static routes, traffic between VDOMs is not working. The administrator verifies that the VDOM link interfaces are up and have correct IP addresses. What is the most likely missing configuration?

Hard
150

An administrator is configuring a FortiGate in multi-VDOM mode. The administrator needs to ensure that the 'Management' VDOM can be accessed via HTTPS and SSH from the internal network, while other VDOMs should not have management access enabled on their interfaces. Which TWO actions must the administrator perform? (Choose two.)

Medium
151

A FortiGate administrator is planning to deploy VDOMs to separate customer traffic. The administrator wants to use FortiManager for centralized management. Which TWO prerequisites must be met before the VDOMs can be managed from FortiManager?

Easy
152

What is the function of FortiAnalyzer in a Fortinet Security Fabric?

Easy
153

A company uses FortiManager to manage multiple FortiGate firewalls. After making changes to a policy package, the administrator runs an install preview and sees a warning: 'Policy ID 10 will be deleted on device XYZ'. What is the most likely reason for this warning?

Medium
154

A FortiGate administrator configures inter-VDOM routing. Traffic from VDOM-A to VDOM-B is blocked. The administrator checks the policy in VDOM-A allowing traffic to the VDOM link interface. What else must be verified?

Medium
155

In a multi-VDOM deployment, what is the purpose of inter-VDOM routing?

Easy
156

An administrator configures FortiManager automation stitches to respond to high CPU usage on a FortiGate. The stitch should trigger a script to run diagnostics. Which THREE components are required in an automation stitch?

Hard
157

A network engineer is deploying a FortiGate in transparent mode at a branch office. The goal is to insert the firewall without changing the existing IP subnet scheme. Which statement about transparent mode is TRUE?

Easy
158

An administrator is configuring a FortiGate in transparent mode for a data center segment. Which of the following is true about transparent mode operation in an enterprise environment?

Medium
159

A FortiGate 600F is running in multi-VDOM mode with VDOMs named 'root', 'finance', and 'guest'. The administrator notices that a firewall policy created in the 'finance' VDOM does not appear when logging into the 'guest' VDOM and wants to confirm that policies, address objects, and routing tables are kept completely separate per VDOM. Which FortiGate feature provides this separation by default?

Medium
160

Drag and drop the steps to configure a FortiGate as a DNS server (DNS proxy) into the correct order.

Medium
161

An administrator wants to use FortiManager to manage multiple FortiGates, each in a separate customer environment. The administrator needs to isolate configuration changes per customer and ensure each customer's admin can only see their own devices. What FortiManager feature should be used?

Medium
162

A FortiGate administrator is troubleshooting a scenario where traffic between two VDOMs is not working. The admin has configured inter-VDOM routing. Which TWO steps should the administrator verify? (Choose two.)

Medium
163

An administrator is deploying a FortiGate in transparent mode to seamlessly integrate into an existing network. The administrator needs to manage the FortiGate remotely over the network. Which configuration is required?

Medium
164

An administrator is setting up a new FortiGate with multiple VDOMs. The administrator wants to ensure that each VDOM has its own set of administrators and that administrators of one VDOM cannot view or modify settings in another VDOM. Which feature should the administrator configure to achieve this?

Easy
165

In FortiManager, what is the purpose of an automation stitch?

Hard
166

An administrator wants to use FortiManager to push a new firewall policy to a managed FortiGate. Before installing, the administrator wants to review what changes will be applied. Which FortiManager feature should be used?

Easy
167

An administrator has a FortiGate 600E running multiple VDOMs. The administrator wants to ensure that when a VDOM is deleted, all associated firewall policies, addresses, and routes are also removed to avoid orphaned objects. Which action should the administrator take?

Medium
168

An administrator has a FortiGate with multiple VDOMs in NAT mode. The administrator wants to configure a global policy that applies to all VDOMs to block traffic from a known malicious IP block. Which statement is correct about global policies?

Medium
169

A FortiGate administrator is deploying a multi-VDOM setup for a service provider. The provider wants each customer VDOM to have its own administrative access, yet the overall device management (including firmware upgrades) should be centralized from the management VDOM. Which TWO statements are true regarding administrative VDOMs?

Medium
170

A FortiGate is deployed in multi-VDOM mode with two VDOMs: VDOM-1 and VDOM-2. The administrator needs to enable communication between these VDOMs using a VDOM link. Which TWO statements about VDOM link configuration are correct? (Choose two.)

Hard
171

An admin configures a FortiManager ADOM for a customer with multiple FortiGates. The admin wants to use meta fields to group firewalls by location. After defining a meta field 'Location' and assigning values to devices, where can the admin use the meta field for policy targeting?

Hard
172

An administrator wants to create a separate virtual firewall instance on a FortiGate to isolate a DMZ environment. The DMZ must have its own routing table, firewall policies, and administrators. Which FortiGate feature should be used?

Easy
173

An administrator is planning a multi-VDOM deployment with a management VDOM. Which TWO statements about management VDOMs are correct? (Choose two.)

Medium
174

An administrator configures a FortiGate in transparent mode for a VDOM. After switching to transparent mode, the administrator notices that the default route disappears and traffic fails. What must be configured to restore routing?

Medium
175

A FortiGate is deployed with multiple VDOMs in NAT/route mode. The administrator has created a VDOM link between VDOM-1 and VDOM-2 and assigned IP addresses to both ends. A server in VDOM-1 (10.1.1.10/24) needs to reach a server in VDOM-2 (10.2.2.10/24). The administrator has added a static route in VDOM-1 for 10.2.2.0/24 pointing to the VDOM-2 link interface IP, and a static route in VDOM-2 for 10.1.1.0/24 pointing to the VDOM-1 link interface IP. However, traffic is not passing. Which additional configuration is required on the FortiGate to allow the traffic to flow?

Medium
176

A FortiGate in an HA cluster with VDOMs enabled experiences a failover. After the failover, traffic that was passing before is now being dropped. The configuration is synchronized between the primary and secondary units. What is the most likely reason?

Hard
177

An administrator configures a VDOM link between VDOMs A and B. In VDOM A, the VDOM link interface is assigned IP 10.10.10.1/24, and in VDOM B, it is assigned 10.10.10.2/24. A firewall policy on VDOM A allows traffic from a subnet in VDOM A to a subnet in VDOM B. However, traffic fails. The admin checks the routing table in VDOM A and sees a route to the destination subnet via 10.10.10.2. What is the most likely cause?

Medium
178

An administrator configures a VDOM on a FortiGate and assigns two interfaces (port1, port2) to it. The administrator wants to route traffic between two different subnets within the same VDOM. Which configuration is required?

Medium
179

An administrator is configuring a FortiGate with multiple VDOMs. The administrator needs to allow a VDOM to use a shared physical interface with another VDOM. Which feature should be used?

Medium
180

An administrator is configuring a FortiGate with multiple VDOMs. The administrator wants to ensure that the VDOMs can use overlapping IP addresses on their respective interfaces. Which setting must be enabled to allow this?

Medium
181

A network administrator is configuring inter-VDOM routing between two VDOMs: VDOM-A and VDOM-B. The administrator creates a inter-VDOM link and adds routes pointing to the link. However, traffic from VDOM-A to VDOM-B fails. What is the most likely missing configuration?

Medium
182

In FortiManager, what is the purpose of header and footer policies in a policy package?

Medium
183

An administrator has a FortiGate with VDOMs 'VDOM-A' and 'VDOM-B' connected by an inter-VDOM link. Users in VDOM-A can reach a web server in VDOM-B, but return traffic from the server to clients is being dropped. The administrator has already created policies in both directions. Which action should the administrator take to resolve the dropped return traffic?

Hard
184

A network administrator is deploying a FortiGate in transparent mode to replace an existing layer 2 switch. Which statement about transparent mode is true?

Easy
185

A FortiManager administrator wants to push a policy package that includes both global header/footer policies and VDOM-specific policies. Which statement about header/footer policies is correct?

Medium
186

An administrator wants to add custom fields to device objects in FortiManager to track location and contact info. Which feature should be used?

Medium

Frequently asked questions

What does the Enterprise Firewall and VDOMs domain cover on the NSE7 exam?
Be able to configure VDOM links with correct IPs, routing, and firewall policies, and explain how FortiManager header and footer policies apply across VDOMs in a policy package. The key is knowing which policies take precedence and where they are enforced.
How many questions are in this domain?
This page lists all 186 Enterprise Firewall and VDOMs questions in the NSE7 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Enterprise Firewall and VDOMs questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
fortinet-nse7 FORTINET-NSE7 nse7 enterprise vdom Practice Questions