Courseiva

NSE7 Enterprise Firewall and VDOMs Practice Question

In FortiManager, what is the purpose of header and footer policies in a policy package?

⚠ Common exam trap

It's easy for candidates to confuse header/footer policies with policy ordering or scheduling, assuming they are just a way to organize or time-limit policies, rather than understanding they enforce a fixed position in the policy list.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To ensure specific policies are always placed at the top (header) or bottom (footer) of the policy list

Header and footer policies in FortiManager are special policy types that enforce a fixed position within the policy list. Header policies are always placed at the top (before all other policies), and footer policies are always placed at the bottom (after all other policies). This ensures that critical security rules, such as default-deny or global allow rules, remain in their intended position regardless of policy package changes or reordering operations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To create policy groups for better organization

    Why it's wrong here

    Header and footer policies sit at the top and bottom of a policy package to enforce global rules across every installation target, not to group policies for tidiness. Grouping is achieved with policy sections or folders. Header/footer policies are correct when mandatory allow or deny rules must apply regardless of each device's own policy set.

  • ✗

    To apply policies only during specific times of the day

    Why it's wrong here

    Time-of-day enforcement is configured with schedules inside individual firewall policies, not via header or footer placement. Header and footer policies exist to guarantee global rules apply across all installation targets in a package. They would be the right mechanism when a mandatory rule must precede or follow every device's local policies.

  • ✓

    To ensure specific policies are always placed at the top (header) or bottom (footer) of the policy list

    Why this is correct

    Header and footer policies anchor specified rules at the very top or bottom of the package's policy list, regardless of subsequent insertions. This guarantees critical allow or deny rules retain precedence, satisfying the requirement to keep particular policies permanently positioned.

  • ✗

    To separate IPv4 and IPv6 policies

    Why it's wrong here

    IPv4 and IPv6 separation is handled by distinct policy packages or address families, not by header and footer positioning. Header and footer policies instead enforce rules globally across every installation target in the package. They are the correct choice when a mandatory allow or deny must bracket all local policies regardless of device.

About these practice questions

Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.