NSE7 Advanced Networking and SD-WAN Practice Question
Which feature allows a FortiGate to participate in multiple routing tables simultaneously, enabling network segmentation and overlapping IP address spaces?
⚠ Common exam trap
Many candidates confuse VDOMs with VRFs, assuming VDOMs alone provide routing table separation, but VDOMs are a management and security context while VRFs are the actual mechanism for multiple routing tables and overlapping IP spaces.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
VRF
C is correct because VRF (Virtual Routing and Forwarding) allows a FortiGate to maintain multiple separate routing tables (RIB) on the same physical device. Each VRF instance operates as an independent routing domain, enabling network segmentation and the use of overlapping IP address spaces without conflict, which is essential for MPLS L3VPN and multi-tenant environments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
VDOM
Why it's wrong here
VDOMs virtualise the FortiGate into separate instances, each with its own interfaces and routing table, but the question asks for one instance participating in several routing tables simultaneously. It is tempting because VDOMs do deliver segmentation and overlapping address spaces, and would be correct if the requirement were isolated virtual firewalls rather than shared-table participation.
- ✗
Policy-based routing
Why it's wrong here
Policy-based routing selects a next hop per packet using policy criteria, but all decisions still reference one routing table, so overlapping subnets cannot coexist. It is tempting because PBR steers traffic by policy, and would be correct if the requirement were forwarding specific traffic out a chosen interface rather than maintaining multiple routing tables.
- ✓
VRF
Why this is correct
VRF (virtual routing and forwarding) creates separate routing table instances on one FortiGate, allowing simultaneous participation in multiple routing domains. This satisfies the segmentation and overlapping IP address requirement, since each VRF maintains independent routes.
- ✗
Route redistribution
Why it's wrong here
Route redistribution copies prefixes between routing protocols within a single routing table; it does not create additional tables or allow overlapping address spaces. It is tempting because redistribution is the usual answer for sharing routes across protocols, and would be correct if the requirement were exchanging routes between OSPF, BGP and static entries in one table.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.