Courseiva

NSE7 Enterprise Firewall and VDOMs Practice Question

Which of the following is a required step when enabling VDOMs on a FortiGate for the first time?

⚠ Common exam trap

Many candidates assume VDOMs can be enabled and used immediately without a reboot, similar to other features like interface configuration, but FortiGate specifically requires a reboot to activate the multi-VDOM architecture.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Reboot the FortiGate after enabling VDOMs

When enabling VDOMs on a FortiGate for the first time, the device must be rebooted to restructure the internal data plane and control plane to support multiple virtual domains. This reboot is mandatory because the firmware transitions from a single-VDOM mode to a multi-VDOM mode, which requires reinitializing kernel structures and memory allocation for VDOM-specific resources.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create at least two VDOMs before enabling the VDOM feature

    Why it's wrong here

    The FortiGate creates a default VDOM (root) automatically when the feature is enabled, so pre-creating two VDOMs is impossible and unnecessary. It is tempting because multi-VDOM deployments do eventually require several VDOMs, but that configuration happens after enabling, not as a prerequisite.

  • ✗

    Disable all firewall policies

    Why it's wrong here

    Enabling VDOMs restarts the FortiGate and places all interfaces in the root VDOM; existing firewall policies are not deleted, so disabling them is unnecessary. It is tempting because policies must reference specific VDOMs afterwards, but that reconfiguration happens after enabling, not as a prerequisite step.

  • ✓

    Reboot the FortiGate after enabling VDOMs

    Why this is correct

    Enabling VDOM mode restructures the FortiGate's configuration and interface-to-VDOM mapping, so the device must reboot before the new mode takes effect. This satisfies the stem's requirement for a mandatory first-time step: without the reboot, VDOMs remain inactive and the configuration cannot be used.

  • ✗

    Configure inter-VDOM routing

    Why it's wrong here

    Inter-VDOM routing is configured only after VDOMs exist and traffic must cross between them; it is not part of the initial enablement. It is tempting because inter-VDOM links are central to multi-VDOM designs, but a single-VDOM or isolated-VDOM setup needs no such routing.

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.