nerdexam
FortinetFortinet

NSE4 · Question #242

NSE4 Question #242: Real Exam Question with Answer & Explanation

The correct answer is C: FortiGuard Distribution Network configuration. An administrator with a VDOM:root scope can configure resources within the root VDOM but is restricted from global system-level configurations, such as FortiGuard Distribution Network settings.

Submitted by kavita_s· Apr 18, 2026FortiGate Deployment and System Configuration

Question

A FortiGate unit is configured with multiple VDOMs. An administrative account on the device has been assigned a Scope value of VDOM:root. Which of the following items would an administrator logging in using this account NOT be able to configure?

Options

  • AFirewall addresses
  • BDHCP servers
  • CFortiGuard Distribution Network configuration
  • DPPTP VPN configuration

Explanation

An administrator with a VDOM:root scope can configure resources within the root VDOM but is restricted from global system-level configurations, such as FortiGuard Distribution Network settings.

Common mistakes.

  • A. Firewall addresses are VDOM-specific configurations and can be managed by an administrator within their assigned VDOM scope.
  • B. DHCP servers are VDOM-specific services and can be configured by an administrator within their assigned VDOM scope.
  • D. PPTP VPN configurations are VDOM-specific and can be managed by an administrator within their assigned VDOM scope.

Concept tested. FortiGate VDOM administrator scope and global settings

Reference. https://docs.fortinet.com/document/fortigate/7.0.0/administration-guide/339414/about-administrators-profiles-and-scopes

Topics

#VDOMs#Administrative Scope#Global Settings#FortiGuard Configuration

Community Discussion

No community discussion yet for this question.

Full NSE4 PracticeBrowse All NSE4 Questions