NSE7 Enterprise Firewall and VDOMs Practice Question
In a multi-VDOM deployment, what is the purpose of inter-VDOM routing?
⚠ Common exam trap
Watch out — candidates often assume inter-VDOM routing is automatic or purely a routing function, but Fortinet requires explicit firewall policies to permit traffic between VDOMs, making it a security-controlled feature rather than a simple routing path.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To allow traffic to pass between different VDOMs via firewall policies
Inter-VDOM routing allows traffic to be forwarded between different VDOMs on the same FortiGate unit. This is achieved by configuring inter-VDOM links (IVL) or using VDOM peering, and then applying firewall policies to control and secure the traffic flow between VDOMs. Option C correctly identifies that firewall policies are the mechanism used to permit or deny inter-VDOM traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To route traffic between the management VDOM and data VDOMs
Why it's wrong here
Management VDOMs carry administrative traffic only; inter-VDOM routing links data-plane VDOMs so traffic can traverse separate security domains. Routing to the management VDOM is neither its purpose nor supported as a data path. It is tempting because management access crosses VDOMs, but that uses dedicated management interfaces.
- ✗
To provide redundancy for VDOMs in an HA setup
Why it's wrong here
Inter-VDOM routing forwards packets between VDOMs by joining their interfaces through a shared link; it provides no HA failover or redundancy function, which is handled by FGCP and heartbeat interfaces. It would be chosen when separating tenants or functions, not for resilience.
- ✓
To allow traffic to pass between different VDOMs via firewall policies
Why this is correct
Inter-VDOM routing creates a dedicated link between VDOMs, enabling traffic to traverse them while still being inspected by firewall policies. This satisfies the multi-VDOM requirement that separate virtual domains remain isolated yet communicate securely, since each VDOM applies its own policy to the routed traffic.
- ✗
To connect VDOMs to external routers
Why it's wrong here
Inter-VDOM routing links VDOMs to each other through a shared VDOM link, not to external routers; egress to external devices uses physical interfaces or VDOM-specific uplinks. It is tempting because both involve traffic leaving a VDOM, but the correct use case is internal segmentation, such as a management VDOM reaching production VDOMs.
Visual reference
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.