Courseiva

NSE7 · topic practice

Enterprise Firewall and VDOMs practice questions

This domain covers FortiGate VDOM architecture, inter-VDOM links, and FortiManager policy packages. Questions test how policies flow from FortiManager to managed FortiGates, how header and footer policies apply across VDOMs, and how traffic moves between VDOMs through VDOM links with correct routing and firewall policies.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Enterprise Firewall and VDOMs

What the exam tests

What to know about Enterprise Firewall and VDOMs

Be able to configure VDOM links with correct IPs, routing, and firewall policies, and explain how FortiManager header and footer policies apply across VDOMs in a policy package. The key is knowing which policies take precedence and where they are enforced.

VDOM link interface IP assignment and inter-VDOM routing between VDOMs A and B

FortiManager policy package header and footer policies and their scope across VDOMs

FortiGate registration and policy update synchronization with FortiManager and Security Fabric

Global versus VDOM-specific policy behavior when pushing a policy package

Watch out for

Common Enterprise Firewall and VDOMs exam traps

  • ▸Assuming a VDOM link passes traffic once IPs are assigned, without a firewall policy allowing the inter-VDOM traffic.
  • ▸Confusing header/footer policies with per-VDOM policies and expecting them to be overridden by VDOM-specific rules.
  • ▸Believing a FortiGate registered with FortiManager automatically receives policy updates without correct provisioning or policy package assignment.

Practice set

Enterprise Firewall and VDOMs questions

20 questions · select your answer, then reveal the explanation

Question 1mediummulti select
Review the full routing breakdown →

A network engineer wants to deploy a FortiGate in transparent mode and have it managed by FortiManager. The FortiGate should not participate in routing, but must be able to send logs to FortiAnalyzer. Which two settings must be configured on the FortiGate to achieve this?

An organization is deploying multiple FortiGate devices across different geographic locations. The central IT team manages all devices from a single FortiManager. The remote FortiGates connect to FortiManager over a WAN link. Which feature should be enabled on FortiManager to ensure that configuration changes are applied consistently and without interruption to the remote FortiGates?

A network administrator is troubleshooting a FortiGate that is not appearing in the Security Fabric topology on FortiManager. The FortiGate is reachable from FortiManager via ping. What is the most likely cause?

An organization uses FortiManager to manage multiple FortiGate devices in a Security Fabric. The administrator wants to push a new firewall policy that includes an FQDN address object. Which statement is true regarding FQDN objects in FortiManager policies?

Which TWO statements about the Security Fabric and FortiManager are correct? (Choose two.)

Refer to the exhibit. A FortiGate is configured with the above settings. The FortiManager at 192.168.1.100 cannot establish a management connection to the FortiGate. What is the most likely cause?

Exhibit

config system interface
edit "port1"
set vdom "root"
set ip 10.0.1.1 255.255.255.0
set allowaccess ping https ssh snmp
set type physical
set role wan
next
end
config system admin
edit "admin"
set trusthost1 192.168.1.0 255.255.255.0
next
end

A network engineer is troubleshooting a Security Fabric where a downstream FortiGate (model 60F) is not appearing in the Fabric topology of the root FortiGate (model 600E). Both devices are running FortiOS 7.4. The root FortiGate shows the downstream device as 'Unreachable' in the Security Fabric widget. The engineer has verified that the downstream FortiGate can ping the root FortiGate's management IP. What is the most likely cause of this issue?

A company is deploying a Security Fabric with multiple FortiGate devices managed by FortiManager. The administrator wants to apply a policy package to multiple FortiGate devices in the Fabric. However, after assigning the policy package to the devices in FortiManager and installing the configuration, the policies are not applied consistently across all devices. The administrator notices that some devices have local policies that override the policy package. What is the best practice to ensure that the policy package is enforced on all devices?

Which TWO statements about Security Fabric deployment are correct? (Choose two.)

Question 10mediummultiple choice
Review the full subnetting walkthrough →

A company has deployed a Security Fabric with a root FortiGate 600E and two downstream FortiGate 200E devices. The network also includes a FortiAnalyzer and a FortiManager. The administrator notices that the Security Fabric topology in FortiGate is not showing the downstream devices. The root FortiGate can ping the management IPs of the downstream devices. Additionally, the administrator has configured the downstream devices with the correct root IP and authorization mode is set to 'none'. However, when running 'diagnose sys fabric list' on the root, it shows the downstream devices with status 'Pending'. The root FortiGate's firewall policy allows all traffic from the downstream subnets. What is the most likely cause of the issue?

A network engineer is configuring an HA pair of FortiGate firewalls. They want to ensure that session failover occurs for UDP-based voice traffic with minimal interruption. Which HA configuration setting is most important for achieving this goal?

An organization has two FortiGate firewalls in an HA active-passive cluster. They notice that after a failover event, some users cannot access external resources. The administrator checks the HA configuration and finds that failover occurred correctly. What is the most likely cause of the connectivity issue?

Question 13easymultiple choice
Review the full routing breakdown →

A FortiGate administrator is designing a VDOM configuration for a multi-tenant environment. Each tenant requires its own routing table and firewall policies. Which VDOM type should be used for each tenant?

An HA cluster is configured with two FortiGates in active-passive mode. The administrator wants to ensure that the secondary unit automatically takes over if the primary unit fails. Which TWO settings must be configured?

A FortiGate with multiple VDOMs is experiencing high CPU usage. The administrator suspects that one VDOM is consuming excessive resources. Which THREE methods can be used to limit resource usage per VDOM?

A network engineer is designing a FortiGate HA cluster with two units operating in active-active mode. The cluster will be placed in a VDOM-enabled environment. The engineer wants to ensure that traffic from a specific VDOM is load-balanced across both units based on source IP address. Which setting must be configured on the cluster to achieve this?

An administrator is configuring a FortiGate HA cluster and wants to ensure that the cluster can tolerate a failure of one unit without administrative intervention. The cluster must also support upgrading firmware with minimal downtime. Which HA mode should the administrator select?

An administrator is troubleshooting an HA cluster issue. The cluster consists of two FortiGate units in active-passive mode. The passive unit is showing a 'heartbeat lost' error in the logs. Which TWO configuration checks should the administrator perform to resolve this issue?

A FortiGate HA cluster is configured in active-passive mode with VDOMs. The administrator wants to ensure that a specific VDOM (VDOM1) always runs on the primary unit unless that unit fails. Additionally, the administrator wants to minimize disruption during a failover. Which THREE configuration steps should be taken?

Refer to the exhibit. An administrator has configured an active-passive HA cluster. After reviewing the configuration and status, the administrator wants to ensure that the management interface (port2) is accessible on both units using the same IP address. What additional configuration is required?

Exhibit

config system ha
    set mode a-p
    set group-name "HA_Cluster"
    set password ENC abcd1234
    set hbdev "port1" 100
    set session-pickup enable
    set session-pickup-connectionless enable
    set ha-mgmt-status enable
    config ha-mgmt-interfaces
        edit 1
            set interface "port2"
            set gateway 10.0.0.1
        next
    end
end

HA cluster status:

HA Health Status: OK
Model: FortiGate-100F
Mode: Active-Passive
Group: HA_Cluster
Debug: 0
npu-1: primary
npu-2: standby

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Enterprise Firewall and VDOMs sessions

Start a Enterprise Firewall and VDOMs only practice session

Every question in these sessions is drawn from the Enterprise Firewall and VDOMs domain — nothing else.

Related practice questions

Related NSE7 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the NSE7 exam test about Enterprise Firewall and VDOMs?
Be able to configure VDOM links with correct IPs, routing, and firewall policies, and explain how FortiManager header and footer policies apply across VDOMs in a policy package. The key is knowing which policies take precedence and where they are enforced.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Enterprise Firewall and VDOMs questions in a focused session?
Yes — the session launcher on this page draws every question from the Enterprise Firewall and VDOMs domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other NSE7 topics?
Use the topic links above to move to related areas, or go back to the NSE7 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the NSE7 exam covers. They are not copied from any real exam or dump site.