Fortinet Enterprise Firewall 7.6 FCSS_EFW_AD-7.6 VLANs VDOMs And Enterprise Segmentation Practice Test
This practice test focuses on vlans vdoms and enterprise segmentation through original applied scenarios aligned to the final published Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator 7.6 blueprint. It is intended for study and does not reproduce live exam content. For broader exam preparation, review the Fortinet FCSS_EFW_AD-7.6 Exam Dumps page.
Question 1
A change ticket for Coho Winery states that administrators must carry several isolated layer-3 segments over a shared physical trunk. Which choice is correct? The change is taking place in a controlled maintenance window. Only one site is affected; peer sites are healthy.
- Create VLAN subinterfaces with the correct 802.1Q tags and assign addressing and policy per segment
- Match the FortiGate VLAN ID and trunk configuration to the upstream switch design and verify tags on the wire
- Place the business units in separate VDOMs and delegate administration according to the required boundary
- Create the tenant VDOM, migrate its interfaces and objects deliberately, then manage it through the intended central-management ADOM model
- Use an inter-VDOM link and explicit routing and firewall policies for the approved flows
Correct answer: A
Explanation
- VLAN subinterfaces provide logical layer-3 interfaces over a tagged physical link. This directly addresses the stated requirement.
- VLAN forwarding depends on consistent tagging between the switch and FortiGate interfaces. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to carry several isolated layer-3 segments over a shared physical trunk.
- VDOMs create virtual FortiGate instances with separate routing, policy, and administrative contexts. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to carry several isolated layer-3 segments over a shared physical trunk.
- A planned VDOM migration preserves isolation while allowing central tools to manage the resulting logical device. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to carry several isolated layer-3 segments over a shared physical trunk.
- Inter-VDOM links provide a controlled path between otherwise separated virtual domains. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to carry several isolated layer-3 segments over a shared physical trunk.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, create VLAN subinterfaces with the correct 802.1Q tags and assign addressing and policy per segment. VLAN subinterfaces provide logical layer-3 interfaces over a tagged physical link.
Question 2
The security team at Fabrikam Manufacturing wants to provide strong administrative and routing separation for two business units on one FortiGate. Which configuration or operational action most directly satisfies that goal? Choose the smallest targeted change. The change must be validated on a pilot device before broader rollout.
- Place the business units in separate VDOMs and delegate administration according to the required boundary
- Create the tenant VDOM, migrate its interfaces and objects deliberately, then manage it through the intended central-management ADOM model
- Create VLAN subinterfaces with the correct 802.1Q tags and assign addressing and policy per segment
- Use an inter-VDOM link and explicit routing and firewall policies for the approved flows
- Match the FortiGate VLAN ID and trunk configuration to the upstream switch design and verify tags on the wire
Correct answer: A
Explanation
- VDOMs create virtual FortiGate instances with separate routing, policy, and administrative contexts. This directly addresses the stated requirement.
- A planned VDOM migration preserves isolation while allowing central tools to manage the resulting logical device. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to provide strong administrative and routing separation for two business units on one FortiGate.
- VLAN subinterfaces provide logical layer-3 interfaces over a tagged physical link. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to provide strong administrative and routing separation for two business units on one FortiGate.
- Inter-VDOM links provide a controlled path between otherwise separated virtual domains. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to provide strong administrative and routing separation for two business units on one FortiGate.
- VLAN forwarding depends on consistent tagging between the switch and FortiGate interfaces. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to provide strong administrative and routing separation for two business units on one FortiGate.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, place the business units in separate VDOMs and delegate administration according to the required boundary. VDOMs create virtual FortiGate instances with separate routing, policy, and administrative contexts.
Question 3
An incident at Wingtip Energy requires the network security architect to allow controlled communication between two VDOMs without collapsing them into one security domain. What should be done first? The answer must address the stated cause rather than a different feature. Existing production IP addressing must remain unchanged.
- Create the tenant VDOM, migrate its interfaces and objects deliberately, then manage it through the intended central-management ADOM model
- Create VLAN subinterfaces with the correct 802.1Q tags and assign addressing and policy per segment
- Match the FortiGate VLAN ID and trunk configuration to the upstream switch design and verify tags on the wire
- Use an inter-VDOM link and explicit routing and firewall policies for the approved flows
- Place the business units in separate VDOMs and delegate administration according to the required boundary
Correct answer: D
Explanation
- A planned VDOM migration preserves isolation while allowing central tools to manage the resulting logical device. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to allow controlled communication between two VDOMs without collapsing them into one security domain.
- VLAN subinterfaces provide logical layer-3 interfaces over a tagged physical link. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to allow controlled communication between two VDOMs without collapsing them into one security domain.
- VLAN forwarding depends on consistent tagging between the switch and FortiGate interfaces. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to allow controlled communication between two VDOMs without collapsing them into one security domain.
- Inter-VDOM links provide a controlled path between otherwise separated virtual domains. This directly addresses the stated requirement.
- VDOMs create virtual FortiGate instances with separate routing, policy, and administrative contexts. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to allow controlled communication between two VDOMs without collapsing them into one security domain.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use an inter-VDOM link and explicit routing and firewall policies for the approved flows. Inter-VDOM links provide a controlled path between otherwise separated virtual domains.
Question 4
For a FortiGate/FortiManager/FortiAnalyzer 7.6 deployment at Lucerne Publishing, which option correctly addresses the need to prevent a VLAN-tag mismatch from silently placing traffic in the wrong logical interface? Preserve the existing design unless the requirement says otherwise. The resulting configuration must remain centrally auditable.
- Use an inter-VDOM link and explicit routing and firewall policies for the approved flows
- Create VLAN subinterfaces with the correct 802.1Q tags and assign addressing and policy per segment
- Match the FortiGate VLAN ID and trunk configuration to the upstream switch design and verify tags on the wire
- Create the tenant VDOM, migrate its interfaces and objects deliberately, then manage it through the intended central-management ADOM model
- Place the business units in separate VDOMs and delegate administration according to the required boundary
Correct answer: C
Explanation
- Inter-VDOM links provide a controlled path between otherwise separated virtual domains. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prevent a VLAN-tag mismatch from silently placing traffic in the wrong logical interface.
- VLAN subinterfaces provide logical layer-3 interfaces over a tagged physical link. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prevent a VLAN-tag mismatch from silently placing traffic in the wrong logical interface.
- VLAN forwarding depends on consistent tagging between the switch and FortiGate interfaces. This directly addresses the stated requirement.
- A planned VDOM migration preserves isolation while allowing central tools to manage the resulting logical device. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prevent a VLAN-tag mismatch from silently placing traffic in the wrong logical interface.
- VDOMs create virtual FortiGate instances with separate routing, policy, and administrative contexts. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prevent a VLAN-tag mismatch from silently placing traffic in the wrong logical interface.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, match the FortiGate VLAN ID and trunk configuration to the upstream switch design and verify tags on the wire. VLAN forwarding depends on consistent tagging between the switch and FortiGate interfaces.
Question 5
Bellows College has verified basic IP reachability. The remaining requirement is to move one tenant into a dedicated VDOM while preserving centralized oversight. Which action should the team take? Prefer a change that is reversible and easy to verify. A known-good rollback point is available before the change.
- Use an inter-VDOM link and explicit routing and firewall policies for the approved flows
- Create the tenant VDOM, migrate its interfaces and objects deliberately, then manage it through the intended central-management ADOM model
- Create VLAN subinterfaces with the correct 802.1Q tags and assign addressing and policy per segment
- Match the FortiGate VLAN ID and trunk configuration to the upstream switch design and verify tags on the wire
- Place the business units in separate VDOMs and delegate administration according to the required boundary
Correct answer: B
Explanation
- Inter-VDOM links provide a controlled path between otherwise separated virtual domains. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to move one tenant into a dedicated VDOM while preserving centralized oversight.
- A planned VDOM migration preserves isolation while allowing central tools to manage the resulting logical device. This directly addresses the stated requirement.
- VLAN subinterfaces provide logical layer-3 interfaces over a tagged physical link. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to move one tenant into a dedicated VDOM while preserving centralized oversight.
- VLAN forwarding depends on consistent tagging between the switch and FortiGate interfaces. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to move one tenant into a dedicated VDOM while preserving centralized oversight.
- VDOMs create virtual FortiGate instances with separate routing, policy, and administrative contexts. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to move one tenant into a dedicated VDOM while preserving centralized oversight.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, create the tenant VDOM, migrate its interfaces and objects deliberately, then manage it through the intended central-management ADOM model. A planned VDOM migration preserves isolation while allowing central tools to manage the resulting logical device.
Question 6
At Tailspin Toys, the security infrastructure engineer must carry several isolated layer-3 segments over a shared physical trunk. Which action best addresses the requirement? The team needs an auditable result. The design must preserve the current segmentation boundaries.
- Use an inter-VDOM link and explicit routing and firewall policies for the approved flows
- Create VLAN subinterfaces with the correct 802.1Q tags and assign addressing and policy per segment
- Create the tenant VDOM, migrate its interfaces and objects deliberately, then manage it through the intended central-management ADOM model
- Match the FortiGate VLAN ID and trunk configuration to the upstream switch design and verify tags on the wire
- Place the business units in separate VDOMs and delegate administration according to the required boundary
Correct answer: B
Explanation
- Inter-VDOM links provide a controlled path between otherwise separated virtual domains. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to carry several isolated layer-3 segments over a shared physical trunk.
- VLAN subinterfaces provide logical layer-3 interfaces over a tagged physical link. This directly addresses the stated requirement.
- A planned VDOM migration preserves isolation while allowing central tools to manage the resulting logical device. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to carry several isolated layer-3 segments over a shared physical trunk.
- VLAN forwarding depends on consistent tagging between the switch and FortiGate interfaces. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to carry several isolated layer-3 segments over a shared physical trunk.
- VDOMs create virtual FortiGate instances with separate routing, policy, and administrative contexts. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to carry several isolated layer-3 segments over a shared physical trunk.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, create VLAN subinterfaces with the correct 802.1Q tags and assign addressing and policy per segment. VLAN subinterfaces provide logical layer-3 interfaces over a tagged physical link.
Question 7
During an enterprise firewall change at Humongous Insurance, the team needs to provide strong administrative and routing separation for two business units on one FortiGate. What should it do? Use normal enterprise Fortinet administration practice. The team is not allowed to disable the security feature globally.
- Place the business units in separate VDOMs and delegate administration according to the required boundary
- Create the tenant VDOM, migrate its interfaces and objects deliberately, then manage it through the intended central-management ADOM model
- Use an inter-VDOM link and explicit routing and firewall policies for the approved flows
- Match the FortiGate VLAN ID and trunk configuration to the upstream switch design and verify tags on the wire
- Create VLAN subinterfaces with the correct 802.1Q tags and assign addressing and policy per segment
Correct answer: A
Explanation
- VDOMs create virtual FortiGate instances with separate routing, policy, and administrative contexts. This directly addresses the stated requirement.
- A planned VDOM migration preserves isolation while allowing central tools to manage the resulting logical device. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to provide strong administrative and routing separation for two business units on one FortiGate.
- Inter-VDOM links provide a controlled path between otherwise separated virtual domains. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to provide strong administrative and routing separation for two business units on one FortiGate.
- VLAN forwarding depends on consistent tagging between the switch and FortiGate interfaces. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to provide strong administrative and routing separation for two business units on one FortiGate.
- VLAN subinterfaces provide logical layer-3 interfaces over a tagged physical link. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to provide strong administrative and routing separation for two business units on one FortiGate.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, place the business units in separate VDOMs and delegate administration according to the required boundary. VDOMs create virtual FortiGate instances with separate routing, policy, and administrative contexts.
Question 8
A production review at Margie Travel identifies this requirement: allow controlled communication between two VDOMs without collapsing them into one security domain. Which Fortinet action is most appropriate? Assume the platform versions are compatible with the feature. The symptom appeared immediately after a planned configuration change.
- Place the business units in separate VDOMs and delegate administration according to the required boundary
- Match the FortiGate VLAN ID and trunk configuration to the upstream switch design and verify tags on the wire
- Create the tenant VDOM, migrate its interfaces and objects deliberately, then manage it through the intended central-management ADOM model
- Create VLAN subinterfaces with the correct 802.1Q tags and assign addressing and policy per segment
- Use an inter-VDOM link and explicit routing and firewall policies for the approved flows
Correct answer: E
Explanation
- VDOMs create virtual FortiGate instances with separate routing, policy, and administrative contexts. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to allow controlled communication between two VDOMs without collapsing them into one security domain.
- VLAN forwarding depends on consistent tagging between the switch and FortiGate interfaces. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to allow controlled communication between two VDOMs without collapsing them into one security domain.
- A planned VDOM migration preserves isolation while allowing central tools to manage the resulting logical device. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to allow controlled communication between two VDOMs without collapsing them into one security domain.
- VLAN subinterfaces provide logical layer-3 interfaces over a tagged physical link. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to allow controlled communication between two VDOMs without collapsing them into one security domain.
- Inter-VDOM links provide a controlled path between otherwise separated virtual domains. This directly addresses the stated requirement.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use an inter-VDOM link and explicit routing and firewall policies for the approved flows. Inter-VDOM links provide a controlled path between otherwise separated virtual domains.
Question 9
While troubleshooting at Northwind Health, the network security architect needs to prevent a VLAN-tag mismatch from silently placing traffic in the wrong logical interface. What is the best next step? No unrelated control should be weakened. Logs from the affected traffic are available for verification.
- Use an inter-VDOM link and explicit routing and firewall policies for the approved flows
- Create the tenant VDOM, migrate its interfaces and objects deliberately, then manage it through the intended central-management ADOM model
- Place the business units in separate VDOMs and delegate administration according to the required boundary
- Match the FortiGate VLAN ID and trunk configuration to the upstream switch design and verify tags on the wire
- Create VLAN subinterfaces with the correct 802.1Q tags and assign addressing and policy per segment
Correct answer: D
Explanation
- Inter-VDOM links provide a controlled path between otherwise separated virtual domains. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prevent a VLAN-tag mismatch from silently placing traffic in the wrong logical interface.
- A planned VDOM migration preserves isolation while allowing central tools to manage the resulting logical device. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prevent a VLAN-tag mismatch from silently placing traffic in the wrong logical interface.
- VDOMs create virtual FortiGate instances with separate routing, policy, and administrative contexts. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prevent a VLAN-tag mismatch from silently placing traffic in the wrong logical interface.
- VLAN forwarding depends on consistent tagging between the switch and FortiGate interfaces. This directly addresses the stated requirement.
- VLAN subinterfaces provide logical layer-3 interfaces over a tagged physical link. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prevent a VLAN-tag mismatch from silently placing traffic in the wrong logical interface.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, match the FortiGate VLAN ID and trunk configuration to the upstream switch design and verify tags on the wire. VLAN forwarding depends on consistent tagging between the switch and FortiGate interfaces.
Question 10
Blue Yonder Airlines is standardizing a FortiOS 7.6 enterprise deployment. Which approach should it use to move one tenant into a dedicated VDOM while preserving centralized oversight? The team will validate the result immediately after the change. The equivalent configuration works correctly at a separate site.
- Use an inter-VDOM link and explicit routing and firewall policies for the approved flows
- Create VLAN subinterfaces with the correct 802.1Q tags and assign addressing and policy per segment
- Create the tenant VDOM, migrate its interfaces and objects deliberately, then manage it through the intended central-management ADOM model
- Place the business units in separate VDOMs and delegate administration according to the required boundary
- Match the FortiGate VLAN ID and trunk configuration to the upstream switch design and verify tags on the wire
Correct answer: C
Explanation
- Inter-VDOM links provide a controlled path between otherwise separated virtual domains. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to move one tenant into a dedicated VDOM while preserving centralized oversight.
- VLAN subinterfaces provide logical layer-3 interfaces over a tagged physical link. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to move one tenant into a dedicated VDOM while preserving centralized oversight.
- A planned VDOM migration preserves isolation while allowing central tools to manage the resulting logical device. This directly addresses the stated requirement.
- VDOMs create virtual FortiGate instances with separate routing, policy, and administrative contexts. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to move one tenant into a dedicated VDOM while preserving centralized oversight.
- VLAN forwarding depends on consistent tagging between the switch and FortiGate interfaces. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to move one tenant into a dedicated VDOM while preserving centralized oversight.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, create the tenant VDOM, migrate its interfaces and objects deliberately, then manage it through the intended central-management ADOM model. A planned VDOM migration preserves isolation while allowing central tools to manage the resulting logical device.
Question 11
A change ticket for Trey Research states that administrators must carry several isolated layer-3 segments over a shared physical trunk. Which choice is correct? The change is taking place in a controlled maintenance window. The change must be reversible within the same maintenance window.
- Place the business units in separate VDOMs and delegate administration according to the required boundary
- Use an inter-VDOM link and explicit routing and firewall policies for the approved flows
- Create VLAN subinterfaces with the correct 802.1Q tags and assign addressing and policy per segment
- Match the FortiGate VLAN ID and trunk configuration to the upstream switch design and verify tags on the wire
- Create the tenant VDOM, migrate its interfaces and objects deliberately, then manage it through the intended central-management ADOM model
Correct answer: C
Explanation
- VDOMs create virtual FortiGate instances with separate routing, policy, and administrative contexts. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to carry several isolated layer-3 segments over a shared physical trunk.
- Inter-VDOM links provide a controlled path between otherwise separated virtual domains. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to carry several isolated layer-3 segments over a shared physical trunk.
- VLAN subinterfaces provide logical layer-3 interfaces over a tagged physical link. This directly addresses the stated requirement.
- VLAN forwarding depends on consistent tagging between the switch and FortiGate interfaces. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to carry several isolated layer-3 segments over a shared physical trunk.
- A planned VDOM migration preserves isolation while allowing central tools to manage the resulting logical device. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to carry several isolated layer-3 segments over a shared physical trunk.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, create VLAN subinterfaces with the correct 802.1Q tags and assign addressing and policy per segment. VLAN subinterfaces provide logical layer-3 interfaces over a tagged physical link.
Question 12
The security team at Apex Retail wants to provide strong administrative and routing separation for two business units on one FortiGate. Which configuration or operational action most directly satisfies that goal? Choose the smallest targeted change. The device is already synchronized with its central-management database.
- Create the tenant VDOM, migrate its interfaces and objects deliberately, then manage it through the intended central-management ADOM model
- Use an inter-VDOM link and explicit routing and firewall policies for the approved flows
- Create VLAN subinterfaces with the correct 802.1Q tags and assign addressing and policy per segment
- Match the FortiGate VLAN ID and trunk configuration to the upstream switch design and verify tags on the wire
- Place the business units in separate VDOMs and delegate administration according to the required boundary
Correct answer: E
Explanation
- A planned VDOM migration preserves isolation while allowing central tools to manage the resulting logical device. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to provide strong administrative and routing separation for two business units on one FortiGate.
- Inter-VDOM links provide a controlled path between otherwise separated virtual domains. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to provide strong administrative and routing separation for two business units on one FortiGate.
- VLAN subinterfaces provide logical layer-3 interfaces over a tagged physical link. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to provide strong administrative and routing separation for two business units on one FortiGate.
- VLAN forwarding depends on consistent tagging between the switch and FortiGate interfaces. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to provide strong administrative and routing separation for two business units on one FortiGate.
- VDOMs create virtual FortiGate instances with separate routing, policy, and administrative contexts. This directly addresses the stated requirement.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, place the business units in separate VDOMs and delegate administration according to the required boundary. VDOMs create virtual FortiGate instances with separate routing, policy, and administrative contexts.
Question 13
An incident at Proseware Media requires the NOC engineer to allow controlled communication between two VDOMs without collapsing them into one security domain. What should be done first? The answer must address the stated cause rather than a different feature. The current routing table contains the expected connected networks.
- Place the business units in separate VDOMs and delegate administration according to the required boundary
- Match the FortiGate VLAN ID and trunk configuration to the upstream switch design and verify tags on the wire
- Create VLAN subinterfaces with the correct 802.1Q tags and assign addressing and policy per segment
- Create the tenant VDOM, migrate its interfaces and objects deliberately, then manage it through the intended central-management ADOM model
- Use an inter-VDOM link and explicit routing and firewall policies for the approved flows
Correct answer: E
Explanation
- VDOMs create virtual FortiGate instances with separate routing, policy, and administrative contexts. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to allow controlled communication between two VDOMs without collapsing them into one security domain.
- VLAN forwarding depends on consistent tagging between the switch and FortiGate interfaces. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to allow controlled communication between two VDOMs without collapsing them into one security domain.
- VLAN subinterfaces provide logical layer-3 interfaces over a tagged physical link. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to allow controlled communication between two VDOMs without collapsing them into one security domain.
- A planned VDOM migration preserves isolation while allowing central tools to manage the resulting logical device. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to allow controlled communication between two VDOMs without collapsing them into one security domain.
- Inter-VDOM links provide a controlled path between otherwise separated virtual domains. This directly addresses the stated requirement.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use an inter-VDOM link and explicit routing and firewall policies for the approved flows. Inter-VDOM links provide a controlled path between otherwise separated virtual domains.
Question 14
For a FortiGate/FortiManager/FortiAnalyzer 7.6 deployment at City Power & Light, which option correctly addresses the need to prevent a VLAN-tag mismatch from silently placing traffic in the wrong logical interface? Preserve the existing design unless the requirement says otherwise. Basic IP reachability to the remote endpoint has already been verified.
- Create VLAN subinterfaces with the correct 802.1Q tags and assign addressing and policy per segment
- Match the FortiGate VLAN ID and trunk configuration to the upstream switch design and verify tags on the wire
- Use an inter-VDOM link and explicit routing and firewall policies for the approved flows
- Create the tenant VDOM, migrate its interfaces and objects deliberately, then manage it through the intended central-management ADOM model
- Place the business units in separate VDOMs and delegate administration according to the required boundary
Correct answer: B
Explanation
- VLAN subinterfaces provide logical layer-3 interfaces over a tagged physical link. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prevent a VLAN-tag mismatch from silently placing traffic in the wrong logical interface.
- VLAN forwarding depends on consistent tagging between the switch and FortiGate interfaces. This directly addresses the stated requirement.
- Inter-VDOM links provide a controlled path between otherwise separated virtual domains. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prevent a VLAN-tag mismatch from silently placing traffic in the wrong logical interface.
- A planned VDOM migration preserves isolation while allowing central tools to manage the resulting logical device. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prevent a VLAN-tag mismatch from silently placing traffic in the wrong logical interface.
- VDOMs create virtual FortiGate instances with separate routing, policy, and administrative contexts. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prevent a VLAN-tag mismatch from silently placing traffic in the wrong logical interface.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, match the FortiGate VLAN ID and trunk configuration to the upstream switch design and verify tags on the wire. VLAN forwarding depends on consistent tagging between the switch and FortiGate interfaces.
Question 15
VanArsdel has verified basic IP reachability. The remaining requirement is to move one tenant into a dedicated VDOM while preserving centralized oversight. Which action should the team take? Prefer a change that is reversible and easy to verify. Hardware replacement is outside the approved change scope.
- Create VLAN subinterfaces with the correct 802.1Q tags and assign addressing and policy per segment
- Create the tenant VDOM, migrate its interfaces and objects deliberately, then manage it through the intended central-management ADOM model
- Use an inter-VDOM link and explicit routing and firewall policies for the approved flows
- Match the FortiGate VLAN ID and trunk configuration to the upstream switch design and verify tags on the wire
- Place the business units in separate VDOMs and delegate administration according to the required boundary
Correct answer: B
Explanation
- VLAN subinterfaces provide logical layer-3 interfaces over a tagged physical link. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to move one tenant into a dedicated VDOM while preserving centralized oversight.
- A planned VDOM migration preserves isolation while allowing central tools to manage the resulting logical device. This directly addresses the stated requirement.
- Inter-VDOM links provide a controlled path between otherwise separated virtual domains. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to move one tenant into a dedicated VDOM while preserving centralized oversight.
- VLAN forwarding depends on consistent tagging between the switch and FortiGate interfaces. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to move one tenant into a dedicated VDOM while preserving centralized oversight.
- VDOMs create virtual FortiGate instances with separate routing, policy, and administrative contexts. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to move one tenant into a dedicated VDOM while preserving centralized oversight.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, create the tenant VDOM, migrate its interfaces and objects deliberately, then manage it through the intended central-management ADOM model. A planned VDOM migration preserves isolation while allowing central tools to manage the resulting logical device.
Question 16
At Woodgrove Bank, the Fortinet administrator must carry several isolated layer-3 segments over a shared physical trunk. Which action best addresses the requirement? The team needs an auditable result. The requirement applies only to one policy, peer, or managed device group.
- Use an inter-VDOM link and explicit routing and firewall policies for the approved flows
- Match the FortiGate VLAN ID and trunk configuration to the upstream switch design and verify tags on the wire
- Create the tenant VDOM, migrate its interfaces and objects deliberately, then manage it through the intended central-management ADOM model
- Create VLAN subinterfaces with the correct 802.1Q tags and assign addressing and policy per segment
- Place the business units in separate VDOMs and delegate administration according to the required boundary
Correct answer: D
Explanation
- Inter-VDOM links provide a controlled path between otherwise separated virtual domains. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to carry several isolated layer-3 segments over a shared physical trunk.
- VLAN forwarding depends on consistent tagging between the switch and FortiGate interfaces. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to carry several isolated layer-3 segments over a shared physical trunk.
- A planned VDOM migration preserves isolation while allowing central tools to manage the resulting logical device. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to carry several isolated layer-3 segments over a shared physical trunk.
- VLAN subinterfaces provide logical layer-3 interfaces over a tagged physical link. This directly addresses the stated requirement.
- VDOMs create virtual FortiGate instances with separate routing, policy, and administrative contexts. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to carry several isolated layer-3 segments over a shared physical trunk.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, create VLAN subinterfaces with the correct 802.1Q tags and assign addressing and policy per segment. VLAN subinterfaces provide logical layer-3 interfaces over a tagged physical link.
Question 17
During an enterprise firewall change at Alpine Ski House, the team needs to provide strong administrative and routing separation for two business units on one FortiGate. What should it do? Use normal enterprise Fortinet administration practice. The team must avoid broadening administrative trust or permissions.
- Create VLAN subinterfaces with the correct 802.1Q tags and assign addressing and policy per segment
- Place the business units in separate VDOMs and delegate administration according to the required boundary
- Create the tenant VDOM, migrate its interfaces and objects deliberately, then manage it through the intended central-management ADOM model
- Match the FortiGate VLAN ID and trunk configuration to the upstream switch design and verify tags on the wire
- Use an inter-VDOM link and explicit routing and firewall policies for the approved flows
Correct answer: B
Explanation
- VLAN subinterfaces provide logical layer-3 interfaces over a tagged physical link. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to provide strong administrative and routing separation for two business units on one FortiGate.
- VDOMs create virtual FortiGate instances with separate routing, policy, and administrative contexts. This directly addresses the stated requirement.
- A planned VDOM migration preserves isolation while allowing central tools to manage the resulting logical device. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to provide strong administrative and routing separation for two business units on one FortiGate.
- VLAN forwarding depends on consistent tagging between the switch and FortiGate interfaces. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to provide strong administrative and routing separation for two business units on one FortiGate.
- Inter-VDOM links provide a controlled path between otherwise separated virtual domains. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to provide strong administrative and routing separation for two business units on one FortiGate.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, place the business units in separate VDOMs and delegate administration according to the required boundary. VDOMs create virtual FortiGate instances with separate routing, policy, and administrative contexts.
Question 18
A production review at Datum Corporation identifies this requirement: allow controlled communication between two VDOMs without collapsing them into one security domain. Which Fortinet action is most appropriate? Assume the platform versions are compatible with the feature. The design must preserve existing centralized logging and telemetry.
- Match the FortiGate VLAN ID and trunk configuration to the upstream switch design and verify tags on the wire
- Create VLAN subinterfaces with the correct 802.1Q tags and assign addressing and policy per segment
- Use an inter-VDOM link and explicit routing and firewall policies for the approved flows
- Place the business units in separate VDOMs and delegate administration according to the required boundary
- Create the tenant VDOM, migrate its interfaces and objects deliberately, then manage it through the intended central-management ADOM model
Correct answer: C
Explanation
- VLAN forwarding depends on consistent tagging between the switch and FortiGate interfaces. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to allow controlled communication between two VDOMs without collapsing them into one security domain.
- VLAN subinterfaces provide logical layer-3 interfaces over a tagged physical link. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to allow controlled communication between two VDOMs without collapsing them into one security domain.
- Inter-VDOM links provide a controlled path between otherwise separated virtual domains. This directly addresses the stated requirement.
- VDOMs create virtual FortiGate instances with separate routing, policy, and administrative contexts. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to allow controlled communication between two VDOMs without collapsing them into one security domain.
- A planned VDOM migration preserves isolation while allowing central tools to manage the resulting logical device. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to allow controlled communication between two VDOMs without collapsing them into one security domain.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use an inter-VDOM link and explicit routing and firewall policies for the approved flows. Inter-VDOM links provide a controlled path between otherwise separated virtual domains.
Question 19
While troubleshooting at Contoso Finance, the NOC engineer needs to prevent a VLAN-tag mismatch from silently placing traffic in the wrong logical interface. What is the best next step? No unrelated control should be weakened. Production subnets cannot be renumbered as part of this change.
- Match the FortiGate VLAN ID and trunk configuration to the upstream switch design and verify tags on the wire
- Use an inter-VDOM link and explicit routing and firewall policies for the approved flows
- Create the tenant VDOM, migrate its interfaces and objects deliberately, then manage it through the intended central-management ADOM model
- Place the business units in separate VDOMs and delegate administration according to the required boundary
- Create VLAN subinterfaces with the correct 802.1Q tags and assign addressing and policy per segment
Correct answer: A
Explanation
- VLAN forwarding depends on consistent tagging between the switch and FortiGate interfaces. This directly addresses the stated requirement.
- Inter-VDOM links provide a controlled path between otherwise separated virtual domains. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prevent a VLAN-tag mismatch from silently placing traffic in the wrong logical interface.
- A planned VDOM migration preserves isolation while allowing central tools to manage the resulting logical device. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prevent a VLAN-tag mismatch from silently placing traffic in the wrong logical interface.
- VDOMs create virtual FortiGate instances with separate routing, policy, and administrative contexts. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prevent a VLAN-tag mismatch from silently placing traffic in the wrong logical interface.
- VLAN subinterfaces provide logical layer-3 interfaces over a tagged physical link. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prevent a VLAN-tag mismatch from silently placing traffic in the wrong logical interface.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, match the FortiGate VLAN ID and trunk configuration to the upstream switch design and verify tags on the wire. VLAN forwarding depends on consistent tagging between the switch and FortiGate interfaces.
Question 20
Litware Logistics is standardizing a FortiOS 7.6 enterprise deployment. Which approach should it use to move one tenant into a dedicated VDOM while preserving centralized oversight? The team will validate the result immediately after the change. A maintenance window is open, but service interruption must be minimized.
- Place the business units in separate VDOMs and delegate administration according to the required boundary
- Match the FortiGate VLAN ID and trunk configuration to the upstream switch design and verify tags on the wire
- Use an inter-VDOM link and explicit routing and firewall policies for the approved flows
- Create the tenant VDOM, migrate its interfaces and objects deliberately, then manage it through the intended central-management ADOM model
- Create VLAN subinterfaces with the correct 802.1Q tags and assign addressing and policy per segment
Correct answer: D
Explanation
- VDOMs create virtual FortiGate instances with separate routing, policy, and administrative contexts. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to move one tenant into a dedicated VDOM while preserving centralized oversight.
- VLAN forwarding depends on consistent tagging between the switch and FortiGate interfaces. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to move one tenant into a dedicated VDOM while preserving centralized oversight.
- Inter-VDOM links provide a controlled path between otherwise separated virtual domains. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to move one tenant into a dedicated VDOM while preserving centralized oversight.
- A planned VDOM migration preserves isolation while allowing central tools to manage the resulting logical device. This directly addresses the stated requirement.
- VLAN subinterfaces provide logical layer-3 interfaces over a tagged physical link. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to move one tenant into a dedicated VDOM while preserving centralized oversight.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, create the tenant VDOM, migrate its interfaces and objects deliberately, then manage it through the intended central-management ADOM model. A planned VDOM migration preserves isolation while allowing central tools to manage the resulting logical device.
Question 21
A change ticket for Wide World Importers states that administrators must carry several isolated layer-3 segments over a shared physical trunk. Which choice is correct? The change is taking place in a controlled maintenance window. The team must preserve existing certificate-trust relationships unless the requirement explicitly changes them.
- Place the business units in separate VDOMs and delegate administration according to the required boundary
- Create VLAN subinterfaces with the correct 802.1Q tags and assign addressing and policy per segment
- Match the FortiGate VLAN ID and trunk configuration to the upstream switch design and verify tags on the wire
- Create the tenant VDOM, migrate its interfaces and objects deliberately, then manage it through the intended central-management ADOM model
- Use an inter-VDOM link and explicit routing and firewall policies for the approved flows
Correct answer: B
Explanation
- VDOMs create virtual FortiGate instances with separate routing, policy, and administrative contexts. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to carry several isolated layer-3 segments over a shared physical trunk.
- VLAN subinterfaces provide logical layer-3 interfaces over a tagged physical link. This directly addresses the stated requirement.
- VLAN forwarding depends on consistent tagging between the switch and FortiGate interfaces. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to carry several isolated layer-3 segments over a shared physical trunk.
- A planned VDOM migration preserves isolation while allowing central tools to manage the resulting logical device. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to carry several isolated layer-3 segments over a shared physical trunk.
- Inter-VDOM links provide a controlled path between otherwise separated virtual domains. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to carry several isolated layer-3 segments over a shared physical trunk.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, create VLAN subinterfaces with the correct 802.1Q tags and assign addressing and policy per segment. VLAN subinterfaces provide logical layer-3 interfaces over a tagged physical link.
Question 22
The security team at Relecloud wants to provide strong administrative and routing separation for two business units on one FortiGate. Which configuration or operational action most directly satisfies that goal? Choose the smallest targeted change. The change will be reviewed later using the configuration and event audit trail.
- Create the tenant VDOM, migrate its interfaces and objects deliberately, then manage it through the intended central-management ADOM model
- Create VLAN subinterfaces with the correct 802.1Q tags and assign addressing and policy per segment
- Use an inter-VDOM link and explicit routing and firewall policies for the approved flows
- Place the business units in separate VDOMs and delegate administration according to the required boundary
- Match the FortiGate VLAN ID and trunk configuration to the upstream switch design and verify tags on the wire
Correct answer: D
Explanation
- A planned VDOM migration preserves isolation while allowing central tools to manage the resulting logical device. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to provide strong administrative and routing separation for two business units on one FortiGate.
- VLAN subinterfaces provide logical layer-3 interfaces over a tagged physical link. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to provide strong administrative and routing separation for two business units on one FortiGate.
- Inter-VDOM links provide a controlled path between otherwise separated virtual domains. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to provide strong administrative and routing separation for two business units on one FortiGate.
- VDOMs create virtual FortiGate instances with separate routing, policy, and administrative contexts. This directly addresses the stated requirement.
- VLAN forwarding depends on consistent tagging between the switch and FortiGate interfaces. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to provide strong administrative and routing separation for two business units on one FortiGate.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, place the business units in separate VDOMs and delegate administration according to the required boundary. VDOMs create virtual FortiGate instances with separate routing, policy, and administrative contexts.
Question 23
An incident at Adventure Works requires the network operations engineer to allow controlled communication between two VDOMs without collapsing them into one security domain. What should be done first? The answer must address the stated cause rather than a different feature. The chosen approach must continue to work as additional branch sites are added.
- Create the tenant VDOM, migrate its interfaces and objects deliberately, then manage it through the intended central-management ADOM model
- Create VLAN subinterfaces with the correct 802.1Q tags and assign addressing and policy per segment
- Match the FortiGate VLAN ID and trunk configuration to the upstream switch design and verify tags on the wire
- Use an inter-VDOM link and explicit routing and firewall policies for the approved flows
- Place the business units in separate VDOMs and delegate administration according to the required boundary
Correct answer: D
Explanation
- A planned VDOM migration preserves isolation while allowing central tools to manage the resulting logical device. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to allow controlled communication between two VDOMs without collapsing them into one security domain.
- VLAN subinterfaces provide logical layer-3 interfaces over a tagged physical link. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to allow controlled communication between two VDOMs without collapsing them into one security domain.
- VLAN forwarding depends on consistent tagging between the switch and FortiGate interfaces. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to allow controlled communication between two VDOMs without collapsing them into one security domain.
- Inter-VDOM links provide a controlled path between otherwise separated virtual domains. This directly addresses the stated requirement.
- VDOMs create virtual FortiGate instances with separate routing, policy, and administrative contexts. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to allow controlled communication between two VDOMs without collapsing them into one security domain.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use an inter-VDOM link and explicit routing and firewall policies for the approved flows. Inter-VDOM links provide a controlled path between otherwise separated virtual domains.
Question 24
For a FortiGate/FortiManager/FortiAnalyzer 7.6 deployment at Fourth Coffee, which option correctly addresses the need to prevent a VLAN-tag mismatch from silently placing traffic in the wrong logical interface? Preserve the existing design unless the requirement says otherwise. A second engineer will verify the result using independent operational evidence.
- Create the tenant VDOM, migrate its interfaces and objects deliberately, then manage it through the intended central-management ADOM model
- Use an inter-VDOM link and explicit routing and firewall policies for the approved flows
- Match the FortiGate VLAN ID and trunk configuration to the upstream switch design and verify tags on the wire
- Create VLAN subinterfaces with the correct 802.1Q tags and assign addressing and policy per segment
- Place the business units in separate VDOMs and delegate administration according to the required boundary
Correct answer: C
Explanation
- A planned VDOM migration preserves isolation while allowing central tools to manage the resulting logical device. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prevent a VLAN-tag mismatch from silently placing traffic in the wrong logical interface.
- Inter-VDOM links provide a controlled path between otherwise separated virtual domains. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prevent a VLAN-tag mismatch from silently placing traffic in the wrong logical interface.
- VLAN forwarding depends on consistent tagging between the switch and FortiGate interfaces. This directly addresses the stated requirement.
- VLAN subinterfaces provide logical layer-3 interfaces over a tagged physical link. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prevent a VLAN-tag mismatch from silently placing traffic in the wrong logical interface.
- VDOMs create virtual FortiGate instances with separate routing, policy, and administrative contexts. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prevent a VLAN-tag mismatch from silently placing traffic in the wrong logical interface.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, match the FortiGate VLAN ID and trunk configuration to the upstream switch design and verify tags on the wire. VLAN forwarding depends on consistent tagging between the switch and FortiGate interfaces.
Question 25
Coho Winery has verified basic IP reachability. The remaining requirement is to move one tenant into a dedicated VDOM while preserving centralized oversight. Which action should the team take? Prefer a change that is reversible and easy to verify. The team requires a deterministic rollback path if validation fails.
- Match the FortiGate VLAN ID and trunk configuration to the upstream switch design and verify tags on the wire
- Create the tenant VDOM, migrate its interfaces and objects deliberately, then manage it through the intended central-management ADOM model
- Create VLAN subinterfaces with the correct 802.1Q tags and assign addressing and policy per segment
- Place the business units in separate VDOMs and delegate administration according to the required boundary
- Use an inter-VDOM link and explicit routing and firewall policies for the approved flows
Correct answer: B
Explanation
- VLAN forwarding depends on consistent tagging between the switch and FortiGate interfaces. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to move one tenant into a dedicated VDOM while preserving centralized oversight.
- A planned VDOM migration preserves isolation while allowing central tools to manage the resulting logical device. This directly addresses the stated requirement.
- VLAN subinterfaces provide logical layer-3 interfaces over a tagged physical link. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to move one tenant into a dedicated VDOM while preserving centralized oversight.
- VDOMs create virtual FortiGate instances with separate routing, policy, and administrative contexts. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to move one tenant into a dedicated VDOM while preserving centralized oversight.
- Inter-VDOM links provide a controlled path between otherwise separated virtual domains. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to move one tenant into a dedicated VDOM while preserving centralized oversight.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, create the tenant VDOM, migrate its interfaces and objects deliberately, then manage it through the intended central-management ADOM model. A planned VDOM migration preserves isolation while allowing central tools to manage the resulting logical device.