NSE4 · Question #28
A FortiGate is configured with multiple VDOMs. An administrative account on the device has been assigned a Scope value of VDOM:root. Which of the following settings will this administrator be able…
The correct answer is A. Firewall addresses. B. DHCP servers. An administrator with VDOM:root scope can manage VDOM-specific configurations like firewall addresses and DHCP servers within the root VDOM, but not global system settings.
Question
A FortiGate is configured with multiple VDOMs. An administrative account on the device has been assigned a Scope value of VDOM:root. Which of the following settings will this administrator be able to configure? (Choose two.)
Options
- AFirewall addresses.
- BDHCP servers.
- CFortiGuard Distribution Network configuration.
- DSystem hostname.
How the community answered
(27 responses)- A93% (25)
- C4% (1)
- D4% (1)
Why each option
An administrator with VDOM:root scope can manage VDOM-specific configurations like firewall addresses and DHCP servers within the root VDOM, but not global system settings.
Firewall addresses are VDOM-specific objects, and an administrator with VDOM:root scope has the necessary permissions to configure them within the root VDOM.
DHCP servers are typically configured on interfaces within a VDOM, and an administrator with VDOM:root scope can configure DHCP servers on interfaces assigned to the root VDOM.
FortiGuard Distribution Network (FDN) configuration is a global setting that applies to the entire FortiGate unit, not a specific VDOM, and requires global administrative scope.
The system hostname is a global setting for the FortiGate unit, not a VDOM-specific configuration, and therefore requires global administrative scope to modify.
Concept tested: FortiGate VDOM administrator scope
Source: https://docs.fortinet.com/document/fortigate/7.4.0/admin-guides/894760/about-vdoms
Topics
Community Discussion
No community discussion yet for this question.