Virtual domain
One physical network device, commonly a firewall, run as several separate logical instances, each with its own interfaces, routing, security policy and administration.
A virtual domain is a single physical network device run as several separate logical instances. Each instance keeps its own interfaces, routing, security policy and, commonly, its own administrators, so one appliance can serve several departments or customers as though each had its own. The ISC2 exam outline lists virtual domains under logical segmentation in Domain 4. The term comes from vendor usage; the concept matters more than the label.
It sits one level above virtual routing and forwarding, which separates only the routing tables on one device; a virtual domain separates the whole policy and management context as well. A VLAN divides a switched network at layer 2, while a virtual domain divides the device that enforces policy between networks. Either way, the separation is configuration on shared hardware. A software flaw in the device, a misconfigured shared interface or an administrator account with rights across every instance can cross it, and the instances still share one device’s capacity and availability.
Exam relevance: a scenario is likely to describe one firewall serving several tenants or departments with separate rule sets and ask what makes that possible. Candidates are expected to place it as logical, not physical, network segmentation, and to remember that the isolation is only as strong as the shared platform and the administrative separation around it.