Courseiva

NSE7 Advanced Networking and SD-WAN Practice Question

What is the function of a VRF (Virtual Routing and Forwarding) on a FortiGate?

⚠ Common exam trap

It's easy for candidates to confuse VRF with VDOM (Virtual Domain), but VRF is a Layer 3 routing isolation mechanism within a single VDOM, whereas VDOM provides full administrative and security separation at the device level.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To create multiple independent routing tables

VRF (Virtual Routing and Forwarding) on a FortiGate allows the creation of multiple independent routing tables within a single physical device. This enables network segmentation and traffic isolation at Layer 3, where each VRF maintains its own routing table, forwarding decisions, and interface associations, preventing routes from leaking between VRFs unless explicitly configured with route leaking.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To provide redundancy for routing protocols

    Why it's wrong here

    VRF separates routing and forwarding tables into isolated virtual domains; it does not provide routing-protocol redundancy, which is achieved through HA, graceful restart or protocol timers. It is tempting because VRF instances can each run independent routing processes, but the correct answer describes traffic separation between tenants or interfaces.

  • ✗

    To aggregate multiple physical interfaces into one logical interface

    Why it's wrong here

    Interface aggregation into one logical link is performed by LAG or 802.3ad, not VRF. VRF instead maintains separate routing and forwarding tables so overlapping address space stays isolated. It is tempting because both features involve grouping network elements, but the correct answer concerns logical routing separation, not link bundling.

  • ✓

    To create multiple independent routing tables

    Why this is correct

    A VRF maintains a separate routing table and forwarding instance, allowing overlapping IP subnets to coexist on one FortiGate. Traffic within each VRF is isolated from others, enabling multi-tenant or segmented routing without additional hardware.

  • ✗

    To encrypt traffic between different virtual domains

    Why it's wrong here

    VRF provides routing and forwarding isolation between virtual domains; it performs no encryption, which requires IPsec or TLS. It is tempting because VRF segments traffic so domains cannot reach each other, but the correct answer describes separating routing tables, not cryptographically protecting traffic between them.

About these practice questions

Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.