NSE4 · Question #226
Which of the following statements are correct regarding virtual domains (VDOMs)? (Select all that apply.)
The correct answer is A. VDOMs divide a single FortiGate unit into two or more virtual units that function as multiple, B. A management VDOM handles SNMP, logging, alert email, and FDN-based updates. C. VDOMs share firmware versions, as well as antivirus and IPS databases. VDOMs partition a FortiGate into multiple virtual devices, sharing system-level resources like firmware and security databases, with a designated management VDOM handling global services.
Question
Which of the following statements are correct regarding virtual domains (VDOMs)? (Select all that apply.)
Options
- AVDOMs divide a single FortiGate unit into two or more virtual units that function as multiple,
- BA management VDOM handles SNMP, logging, alert email, and FDN-based updates.
- CVDOMs share firmware versions, as well as antivirus and IPS databases.
- DOnly administrative users with a 'super_admin' profile will be able to enter multiple VDOMs to
How the community answered
(41 responses)- A90% (37)
- D10% (4)
Why each option
VDOMs partition a FortiGate into multiple virtual devices, sharing system-level resources like firmware and security databases, with a designated management VDOM handling global services.
Virtual Domains (VDOMs) enable a single FortiGate unit to be logically segmented into two or more independent virtual FortiGates, each with its own configuration, interfaces, routing, and policies.
In a VDOM deployment, one VDOM (typically the 'root' VDOM) is designated as the management VDOM, responsible for global FortiGate functions such as SNMP, system-wide logging, alert emails, and FortiGuard updates for antivirus and IPS databases.
Despite operating as distinct virtual units, VDOMs running on the same physical FortiGate unit share the underlying operating system firmware version and the globally downloaded antivirus, IPS, and other security service databases from FortiGuard.
While 'super_admin' users can access all VDOMs, it is also possible to create administrative profiles that allow specific users to access a selected subset of VDOMs, not exclusively 'super_admin'.
Concept tested: VDOM architecture and shared/isolated resources
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/23472/what-is-a-vdom
Topics
Community Discussion
No community discussion yet for this question.