NSE7 Enterprise Firewall and VDOMs Practice Question
What is the difference between a global ADOM and a regular ADOM in FortiManager?
⚠ Common exam trap
Many exam-takers confuse the Global ADOM with a 'super ADOM' that has unlimited resources or special device modes, when in fact its key differentiator is the ability to share objects and policies across ADOMs, not any hardware or licensing advantage.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Global ADOM allows sharing policy packages and objects across multiple ADOMs
In FortiManager, a Global ADOM is a special administrative domain that allows you to centrally manage and share policy packages, objects, and templates across multiple regular ADOMs. This enables consistent security policies and objects (like addresses, services, and schedules) to be pushed to all managed FortiGates, regardless of which ADOM they belong to. Regular ADOMs are isolated and cannot share objects or policies with other ADOMs, making the Global ADOM essential for large-scale, multi-tenant deployments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Global ADOM manages only FortiGates in transparent mode
Why it's wrong here
Global ADOMs hold shared policy packages and objects that all ADOMs inherit; they are not scoped by FortiGate operating mode, so transparent-mode management is irrelevant. It tempts because global ADOMs do centralise configuration, but the axis of difference is object and policy sharing, not device mode.
- ✗
Regular ADOM cannot use meta fields
Why it's wrong here
Meta fields are available in regular ADOMs; the actual difference concerns global ADOM scope and object sharing across managed devices. It is tempting because global ADOMs centralise policy objects, but the meta field restriction applies to neither ADOM type in the way described.
- ✓
Global ADOM allows sharing policy packages and objects across multiple ADOMs
Why this is correct
A global ADOM provides a shared container where policy packages and objects are defined once and assigned to multiple regular ADOMs, satisfying the requirement to reuse configuration across independently managed administrative domains. Regular ADOMs remain isolated, so each device group keeps its own objects without cross-domain visibility.
- ✗
Global ADOM has unlimited device capacity
Why it's wrong here
Device capacity is governed by the FortiManager licence and platform limits, not by ADOM type; global ADOMs exist to share policy packages and objects across ADOMs. It tempts because global ADOMs can hold many devices, but the defining difference is inheritance of shared configuration, not capacity.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.