Be able to read IKE debug output, explain DPD and INITIAL_CONTACT effects on tunnel state, assign SAML IdP versus SP roles correctly, and verify ZTNA proxy policy certificate enforcement. The key is matching each symptom to the right FortiGate feature and log evidence.
Start practicing
Advanced VPN and Zero Trust — choose a session length
Free · No account required
Domain overview
This domain covers FortiGate IPsec and SSL VPN troubleshooting, IKE behavior, SAML and ZTNA proxy policy enforcement. Questions present short operational scenarios: reading 'diagnose vpn ike log' output, interpreting DPD and INITIAL_CONTACT events, and validating certificate-based ZTNA access to web applications.
Exam objectives
Dead Peer Detection behavior and IKE event interpretation using diagnose vpn ike log
SAML IdP/SP role assignment on FortiGate for cloud application single sign-on
ZTNA proxy-based policy enforcement with client certificate validation on endpoints
IPsec tunnel stability factors including INITIAL_CONTACT notifications and peer identity
Confusing Dead Peer Detection with IKE keepalive or assuming DPD tears down tunnels only on one side
Mixing up SAML IdP and SP roles, so FortiGate is configured on the wrong side of the login flow
Assuming ZTNA proxy policy alone enforces client certificates without correct certificate inspection settings
Click any question to see the full explanation and answer options, or start a focused practice session above.
A company is implementing Zero Trust Network Access using Fortinet's ZTNA solution. They have deployed a FortiGate as the ZTNA gateway and are using FortiClient as the ZTNA agent. Users report that they can initiate ZTNA connections but the connections drop after a few minutes. The FortiGate logs show that the ZTNA session is being terminated due to a endpoint compliance check failure. Which action should the administrator take to resolve this issue?
2During a ZTNA deployment, an administrator notices that traffic from a specific internal application is being routed through the ZTNA gateway but is not reaching the destination server. The FortiGate policy allows the traffic, and the client has a valid ZTNA connection. What is the most likely cause of the issue?
3A company uses FortiGate ZTNA to provide remote access to an internal web application. The application requires client certificates for authentication. The administrator has configured the ZTNA rule to use certificate authentication. However, users report that they are prompted for credentials repeatedly. What is the most likely cause?
4In a Zero Trust Network Access architecture, which component acts as the policy enforcement point for access decisions?
5During a ZTNA implementation, the administrator configures a ZTNA rule for an internal application but users cannot connect. The FortiGate policy is correct and the application is reachable from the FortiGate. What is the most likely misconfiguration?
6Which TWO of the following are required components for a Fortinet ZTNA solution? (Select two.)
7A multinational corporation is implementing ZTNA for remote access to a critical internal application hosted on a server with IP 10.0.1.200:8443. The FortiGate is deployed at the edge with WAN IP 203.0.113.50. The administrator configures a ZTNA rule with proxy destination 10.0.1.200:8443, a firewall policy allowing traffic from the ZTNA gateway to the internal server, and a VIP for port forwarding for testing. However, remote users report that they can establish a ZTNA connection to the gateway but the application page fails to load, showing a blank page after a long delay. The FortiGate logs show no errors, and the debug output indicates that the proxy successfully forwarded the request to 10.0.1.200:8443 and received a response. The internal server team confirms the application is working correctly for on-site users. What is the most likely cause?
8A healthcare provider is deploying ZTNA to secure access to an internal electronic health records (EHR) system. The EHR system is composed of multiple web services running on different ports behind a load balancer with IP 10.0.10.100. The load balancer listens on ports 443, 8443, and 9090. The administrator configures a single ZTNA rule with proxy destination 10.0.10.100:443, expecting that the other ports will be accessed via the same rule. However, users report that they can only access the service on port 443; connections to ports 8443 and 9090 fail. The FortiGate logs show that requests to other ports are being dropped. What should the administrator do to resolve this?
9A network administrator is troubleshooting an IPsec VPN tunnel between two FortiGate devices. The tunnel is established, but traffic is not passing. Which configuration should the administrator check first?
10A company uses SSL VPN with FortiGate for remote access. Users report that after connecting, they can access internal web servers but cannot ping them. Which configuration is most likely missing?
11Refer to the exhibit. A tunnel interface is configured with IP 10.0.1.1/30 and remote-ip 10.0.1.2/30. The phase2 defines src-subnet as 10.0.1.0/30 and dst-subnet as 10.0.2.0/30. What is the most likely problem with this configuration?
12Which TWO features are required to implement an always-on SSL VPN tunnel with FortiGate that automatically reconnects when the user's network changes?
13Which THREE conditions must be met for an IPsec VPN to successfully establish phase2?
14An administrator is configuring SSL VPN on FortiGate and wants to allow users to access internal applications via a web portal without installing any client software. Which SSL VPN mode should be used?
15A FortiGate is configured with an IPsec VPN that uses certificate-based authentication. The VPN fails to establish. The administrator checks the phase1 debug and sees the message: 'no suitable certificate found'. What is the most likely cause?
16A multinational company uses FortiGate devices as VPN gateways to connect its headquarters (HQ) and branch offices via IPsec VPN tunnels. The company is migrating its remote access solution from IPsec VPN to SSL VPN using FortiClient. Currently, 500 remote users connect via IPsec VPN with pre-shared keys and XAuth authentication. The migration must be seamless with minimal downtime, and users must continue to authenticate using their existing Active Directory credentials. The SSL VPN portal must provide access to internal web applications and some legacy TCP-based applications that do not support HTTP. The security team requires that all traffic between remote users and the internal network be encrypted and that the SSL VPN use a certificate from a public CA to avoid certificate warnings on client devices. The IT team wants to use FortiToken for two-factor authentication (2FA) for all VPN users. Which of the following is the most appropriate course of action to meet all requirements?
17A company's FortiGate is configured with multiple IPsec VPN tunnels to branch offices. One tunnel keeps dropping and re-establishing every few minutes. The logs show 'IPsec SA negotiation failed' with error 'proposal mismatch'. What is the most likely cause?
18Drag and drop the steps to configure a FortiGate as a DHCP server into the correct order.
19Drag and drop the steps to configure a FortiGate VDOM in multi-VDOM mode into the correct order.
20An administrator wants to enforce that only devices with the latest antivirus signatures and a corporate disk encryption solution can access a sensitive application via ZTNA. Which two FortiClient EMS components must be configured? (Choose two.)
21You run the following command on a FortiGate: 'diagnose vpn ike gateway list' and see that the DPD status for a VPN peer is 'dead'. What does this indicate?
22Which FortiGate feature allows an administrator to define a granular policy based on the security posture of the endpoint device, such as OS version, antivirus status, and disk encryption, before granting access to a protected application?
23An administrator is troubleshooting a ZTNA issue where users are able to authenticate but the application access is still blocked. The ZTNA status on FortiClient shows 'Connected' but the application does not load. What is the MOST likely cause?
24An administrator is deploying ZTNA for a legacy application that uses a fixed IP address and port. Which ZTNA component is responsible for securely proxying traffic from the user to the application without exposing the application's actual network location?
25An administrator wants to enforce that only devices with corporate-owned certificates can establish an IPsec VPN tunnel. Which IPsec authentication method should be configured?
26A FortiGate administrator needs to integrate with FortiNAC to enforce network access control for wired and wireless devices. The administrator wants FortiNAC to dynamically assign VLANs based on the device's security posture. Which FortiNAC feature enables this?
27An administrator is deploying ZTNA with FortiClient EMS to secure access to a corporate web application. Which THREE components are required for a successful ZTNA deployment? (Choose three.)
28A FortiGate administrator wants to ensure that only devices with an up-to-date antivirus and OS patch level can access a sensitive application published via ZTNA. Which ZTNA component should the administrator configure to enforce this requirement?
29An administrator is troubleshooting an IPsec VPN tunnel that fails to establish. The configuration uses certificates for authentication. The admin sees the following log message: 'Certificate validation failed: unable to get local issuer certificate.' What is the most likely cause?
30An administrator configures FortiGate as a SAML identity provider (IdP) for a cloud application. The application (SP) initiates the login. Users are redirected to the FortiGate login page and authenticate successfully, but then receive an error from the SP. What is a common cause?
31A network administrator is troubleshooting a scenario where remote users can connect via FortiClient VPN but cannot access internal resources. The FortiGate has a valid IPsec VPN configuration. Which THREE checks should the administrator perform to resolve the issue?
32An administrator configures ZTNA with FortiClient EMS. The goal is to restrict access to an internal application based on device posture. The administrator configures a ZTNA tag for 'Compliant' that checks antivirus and OS patch status. Which TWO additional steps are required on the FortiGate to enforce access based on this tag?
33A network administrator is troubleshooting an IPsec VPN tunnel between Site A (FortiGate) and Site B (third-party VPN peer). The tunnel fails to establish. On FortiGate, phase1 status shows 'up' but phase2 status remains 'down'. What is the MOST likely cause?
34Which feature in FortiOS enables a FortiGate to act as a proxy for client-initiated connections to internal applications without requiring a VPN client, by verifying device posture and user identity?
35An administrator configures a hub-and-spoke ADVPN with FortiGate at the hub and multiple remote sites. After setup, spokes establish shortcuts directly. However, traffic between two spokes consistently goes through the hub even though shortcuts should exist. Running 'diagnose npu np6 ipsec peercache' shows no shortcut entries. What is the MOST likely reason?
36A FortiGate administrator wants to use SAML SSO to authenticate VPN users. The FortiGate will act as the service provider (SP) and an external identity provider (IdP) will be used. Which of the following must be configured on the FortiGate to enable SAML authentication for SSL VPN?
37What is the primary purpose of Dead Peer Detection (DPD) in an IPsec VPN configuration?
38In FortiGate's ZTNA, what is the purpose of a 'ZTNA tag'?
39A FortiGate administrator wants to integrate ZTNA with FortiClient EMS to control access to an internal application based on device posture. The admin has configured a ZTNA tag in EMS for 'AntiVirus enabled' and created a ZTNA rule in FortiGate. What additional configuration is required on the FortiGate to enforce access based on the ZTNA tag?
40An organization wants to implement Zero Trust Network Access (ZTNA) to secure access to an internal web application. The current network uses FortiGate as the firewall. Which component is required to enforce ZTNA policies on the FortiGate?
41You run 'diagnose vpn ike gateway list' and see the following: gateway name: HUB_GW version: IKEv2 state: UP mode: main local: 10.0.0.1:500 remote: 203.0.113.5:500 auth: psk dpd: on rekey: 86400 num_peers: 2 total_tunnels: 2 auto-discovery: enabled What does the 'auto-discovery: enabled' indicate about this VPN gateway?
42An administrator wants to enforce that only devices with antivirus software installed and running can access a sensitive application via ZTNA. Which ZTNA feature should be used to verify this requirement?
43A FortiGate is configured with multiple IPsec VPNs to remote branches. One of the branch VPN tunnels goes down frequently. The administrator runs 'diagnose vpn ike log' and sees repeated INITIAL_CONTACT notifications from the remote peer. What does this indicate?
44A company wants to ensure that only company-managed laptops with up-to-date antivirus can access the internal file server remotely. Which Fortinet solution integrates with FortiGate to enforce device compliance before granting ZTNA access?
45A FortiGate administrator configures a ZTNA access proxy rule to allow access to an internal application only if the user's device has the tag 'Compliant'. The tag is assigned by FortiClient EMS. However, a user with a compliant device is still blocked. The admin sees in the ZTNA logs that the tag is not being received. What should the administrator check FIRST?
46A company is deploying ZTNA to protect an internal application. They want to ensure that only users with devices that have disk encryption enabled and the latest OS patches can access the application. Which THREE components must be configured to achieve this?
47A FortiGate administrator is troubleshooting an IKEv2 VPN tunnel that fails to establish. The remote peer logs show 'no acceptable proposal' error. Which TWO possible causes should the administrator check?
48A FortiGate administrator wants to implement ZTNA to control access to an internal application server. Users will access the application via FortiClient. Which configuration step is REQUIRED to allow FortiClient to forward traffic to the ZTNA gateway?
49A FortiGate administrator wants to use Fortinac for network access control. Which of the following is the PRIMARY function of Fortinac in a network?
50An administrator is configuring a FortiGate as a SAML Identity Provider (IdP) for a third-party service provider. Which of the following is REQUIRED for the FortiGate IdP configuration?
51What is the purpose of Dead Peer Detection (DPD) in an IPsec VPN?
52A FortiGate is configured with ZTNA inline CASB to control access to a SaaS application. The administrator wants to block uploads of files containing credit card numbers. Which ZTNA inline CASB feature should be used?
53A FortiGate administrator is troubleshooting a ZTNA problem where users are unable to connect to an internal application via FortiClient. FortiClient reports 'Connection refused'. The FortiGate ZTNA gateway is configured correctly. Which THREE steps should the administrator take to diagnose the issue?
54A FortiGate is configured as a SAML service provider (SP) for ZTNA. Users authenticate via an external IdP. After authentication, users are not able to access applications even though the ZTNA proxy rule lists them. What should the administrator check FIRST?
55An administrator wants to enforce that only devices with antivirus software installed and up-to-date can access the corporate network. Which FortiGate feature should be used?
56In a hub-and-spoke VPN, spokes cannot communicate with each other directly. The administrator wants to allow direct spoke-to-spoke traffic without routing through the hub. Which technology should be configured?
57An administrator receives an error when trying to create a ZTNA proxy rule: 'The ZTNA proxy rule requires a valid application mapping.' What does this indicate?
58A FortiGate has multiple IPsec VPNs to different branch offices. The administrator notices that one VPN tunnel is flapping (going up and down repeatedly). From the CLI, 'diagnose vpn ike gateway list' shows the gateway state as 'up' but then quickly goes to 'down'. What is the MOST likely cause?
59Which of the following is a requirement for FortiGate to act as a SAML Identity Provider (IdP) for ZTNA?
60An administrator is configuring FortiClient EMS to enforce compliance for ZTNA. Which TWO settings are required on FortiGate to use compliance-based ZTNA tags?
61A network administrator is troubleshooting an IPsec VPN tunnel between two FortiGates. The tunnel is established but traffic is not passing. The administrator runs 'diagnose vpn ike log' and sees 'no matching policy for this IPsec SA'. What is the most likely cause?
62An organization wants to implement Zero Trust Network Access (ZTNA) to secure access to an internal application. The application is hosted on a server with IP 10.1.1.100. Which component acts as the intermediary between users and the application in FortiGate ZTNA?
63An administrator runs 'diagnose vpn ike gateway list' and sees that the IKE SA state is 'UP' but the IPsec SA state is 'DOWN'. The remote peer is a FortiGate. What is the most likely cause of this issue?
64An organization uses FortiClient EMS to enforce compliance on endpoints. They want to ensure that only devices with updated antivirus definitions can access the corporate VPN. Which FortiClient configuration should be applied?
65A FortiGate administrator configures SAML SSO with FortiGate as the Service Provider (SP) and an external IdP. Users report that they are prompted for credentials repeatedly without successful authentication. What is the most likely cause?
66A FortiGate administrator wants to use PKI certificates for IPsec VPN authentication instead of pre-shared keys. Which phase1 parameter must be set to 'signature' to enable certificate-based authentication?
67A FortiGate administrator enables Dead Peer Detection (DPD) on an IPsec VPN tunnel. What is the primary purpose of DPD?
68A network administrator is troubleshooting an IPsec VPN tunnel between two FortiGates. The tunnel is up but traffic is not passing. The administrator runs 'diagnose vpn ike gateway list' and sees that the IKE SA has been established. However, 'diagnose vpn tunnel list' shows no IPsec SA entries. What is the most likely cause?
69An administrator wants to ensure that FortiGate validates the identity of the remote VPN peer using a certificate during IKEv2 phase 1. Which authentication method should the administrator select in the IPsec phase 1 configuration?
70In a Fortinet ZTNA deployment, which component is responsible for forwarding decrypted traffic to the internal application server after the FortiGate proxy has performed SSL inspection?
71An administrator is configuring ZTNA inline CASB for a SaaS application. The goal is to block upload of files containing credit card numbers. Which configuration components are required?
72A FortiGate is configured as a ZTNA proxy. The administrator wants to ensure that only devices with a specific ZTNA tag assigned by FortiClient EMS are allowed to access the application. Which two configuration steps are required? (Choose two.)
73An administrator wants to ensure that only devices with up-to-date antivirus software can access a sensitive application via ZTNA. Which FortiGate feature should be used to enforce this requirement?
74A FortiGate is configured as a ZTNA proxy for a web application. Users report that after authenticating, they receive a '502 Bad Gateway' error. What is the most likely cause?
75A FortiGate administrator wants to use PKI certificates for IKEv2 authentication instead of pre-shared keys. Which phase1 configuration parameter must be changed to support certificate-based authentication?
76A FortiGate has an IPsec VPN with a remote peer that uses IKEv2. The administrator wants to ensure that child SA rekeying uses PFS (Perfect Forward Secrecy) with Diffie-Hellman group 14. Which CLI command should the administrator configure on the FortiGate's phase 2 proposal?
77A FortiGate administrator is configuring ZTNA to provide secure access to an internal application. The application is hosted on a server with IP 10.0.1.100 and port 8080. The administrator creates a ZTNA rule on the FortiGate as an access proxy. What is the correct configuration for the ZTNA rule's 'Application Access' entry?
78A FortiGate administrator is using FortiNAC to enforce network access control for wired endpoints. The administrator wants to quarantine any endpoint that fails antivirus compliance. Which action should be configured in the FortiNAC policy to achieve this?
79An administrator wants to configure a multi-peer IPsec VPN where one FortiGate (hub) connects to multiple remote FortiGates (spokes) using a single phase 1 interface with dynamic IP addresses. Which configuration is required on the hub?
80A ZTNA rule is configured to allow access to an internal application only if the client device has the ZTNA tag 'Compliant' and the user is authenticated via SAML. The FortiGate is acting as ZTNA proxy. A user successfully authenticates but the device is not tagged. What happens when the user tries to access the application?
81An administrator is troubleshooting an IPsec VPN tunnel between two FortiGates. The tunnel is up, but traffic is not passing. The administrator runs 'diagnose vpn tunnel list' and sees that both phase 1 and phase 2 are up. The policy allows traffic from both sides. What should the administrator check next?
82A network administrator is troubleshooting an IPsec VPN tunnel that is not coming up. The configuration uses IKEv2 with pre-shared keys. The administrator runs 'diagnose vpn ike log-filter' and sees no logs. What is the most likely cause?
83An organization wants to implement Zero Trust Network Access (ZTNA) to secure access to an internal application. The application is accessed via HTTPS. Which component must be configured on the FortiGate to act as a reverse proxy for the application?
84An administrator wants to enforce that only devices with up-to-date antivirus software can access corporate resources via ZTNA. Which FortiClient feature should be used to enforce this requirement?
85An organization uses FortiNAC for network access control. They want to enforce that only corporate-managed devices with up-to-date patches can access the production VLAN. Which THREE components must be integrated or configured?
86A company is deploying ZTNA to replace their legacy VPN. They want to ensure that only users with a valid certificate and compliant antivirus can access the internal application. Which TWO components are required on the FortiGate for this deployment?
87An administrator is troubleshooting an OSPF over IPsec VPN overlay. The OSPF neighbor state is stuck in EXSTART. The VPN tunnel is up. Which TWO issues could cause this?
88An administrator has deployed a ZTNA configuration on a FortiGate where remote users authenticate through FortiClient EMS. The administrator wants to ensure that only devices with an up-to-date operating system and active antivirus are granted access to an internal web application. The FortiGate is configured as the ZTNA access proxy. Which FortiGate component or configuration is required to enforce these device compliance checks?
89A network administrator is configuring an IPsec VPN on a FortiGate to connect to a remote peer that uses a dynamic IP address. The administrator wants to ensure that the tunnel can be initiated by the remote peer and that the FortiGate accepts connections from any IP, as long as the peer ID matches. Which configuration should the administrator use?
90A FortiGate administrator is configuring an IPsec VPN with IKEv2. The remote peer is behind a NAT device and has a dynamic public IP. The administrator wants the FortiGate to act as the responder and allow the remote peer to initiate the tunnel, while ensuring that only the remote peer's unique ID (FQDN) is accepted. Which configuration on the FortiGate is required to achieve this?
91A FortiGate is configured as a ZTNA access proxy for an internal application. The administrator wants to enforce device compliance using FortiClient EMS tags before allowing access. Which configuration step is required to ensure that only endpoints with a specific EMS tag can access the application?
92A FortiGate is the hub of an IPsec VPN and also terminates SSL VPN for remote users. The administrator wants remote users to access internal resources only after the FortiGate validates the endpoint's compliance through FortiClient EMS, and wants the validation to happen before the user is placed in a VPN address pool. Which SSL VPN configuration element enforces endpoint compliance during the connection handshake?
93A FortiGate administrator is deploying ZTNA for remote users who connect through FortiClient. The administrator wants to enforce device compliance based on the FortiClient EMS tags. The FortiGate is already integrated with FortiClient EMS. Which configuration step is required to use EMS tags in a ZTNA policy?
94A FortiGate administrator is configuring a ZTNA rule that uses a proxy-based policy to inspect traffic to a web application. The administrator wants to ensure that only users who have a valid certificate installed on their endpoint are allowed access. The certificate is issued by the corporate PKI and is stored in the user's certificate store. Which ZTNA configuration element should the administrator use to enforce this requirement?
95A FortiGate administrator is configuring an IPsec VPN with IKEv2. The administrator wants to ensure that the VPN tunnel uses perfect forward secrecy (PFS) for phase 2. Which parameter must be configured in the phase 2 proposal?
96A FortiGate administrator is configuring ZTNA to provide access to an internal web application. The administrator wants to ensure that only devices with a specific security posture tag are allowed access. The ZTNA rule is configured with a policy that references a device group synced from FortiClient EMS. However, when a user attempts to access the application, the connection is denied even though the device has the correct tag. What is the most likely cause?
97A FortiGate administrator is deploying ZTNA to protect an internal application. Users connect with FortiClient, which establishes a tunnel to the FortiGate. The administrator wants the FortiGate to verify the user's identity and device posture before allowing access to the application. Which FortiGate feature performs this verification as part of the ZTNA access proxy?
98A FortiGate administrator is configuring a ZTNA rule to protect an internal web server. The administrator wants to ensure that only users who authenticate via SAML and whose devices have the latest antivirus signature are allowed access. Which FortiGate feature must be used to enforce this?
99A FortiGate administrator is deploying ZTNA to replace SSL VPN for remote access. The requirement is that endpoint posture (antivirus status, OS patch level) must be verified before a user is allowed to reach internal web applications through the ZTNA proxy, and that posture must be re-evaluated on each new connection. Which FortiGate configuration element is required to enforce this dynamic, per-connection posture check?
100A FortiGate administrator is implementing Zero Trust Network Access (ZTNA) for remote users accessing internal applications. The administrator wants to ensure that only authenticated and compliant devices can access the applications, and that all traffic is inspected. Which two actions are required to achieve this? (Choose two.)
101An administrator is building an ADVPN with a single hub and many spokes. Spokes are behind NAT devices and receive dynamic public IP addresses. The administrator wants shortcuts to form directly between spokes without routing traffic through the hub. Which combination of features must be configured on the hub and spokes to allow shortcut negotiation to succeed in this environment?
102A FortiGate administrator has deployed ZTNA with FortiClient EMS tagging. A remote user's endpoint is tagged as 'Compliant' in EMS, but the FortiGate ZTNA policy still denies the user's connection to the internal web application. The administrator confirmed the EMS connector status on the FortiGate shows 'Connected' and the tag is visible in the FortiGate's device inventory. What is the most likely cause of the access denial?
103A FortiGate administrator is deploying ZTNA with a FortiClient EMS that tags endpoints as 'compliant' or 'non-compliant'. The administrator wants the FortiGate to grant access only to endpoints that FortiClient EMS has tagged as compliant, while still allowing non-compliant endpoints to reach a remediation portal. Which two configuration elements on the FortiGate must be aligned to enforce this?
104A FortiGate administrator is configuring an IPsec VPN with multiple peers for redundancy. The administrator wants to ensure that if the primary peer becomes unreachable, the tunnel fails over to the secondary peer automatically. Which configuration is required to achieve this?
105A FortiGate administrator is troubleshooting a ZTNA access proxy rule that is not matching traffic from a specific user group. The rule is configured with a source of 'ZTNA_Users' and a destination of the internal web server. The administrator confirms that the user is authenticated and has the correct EMS tag. Which FortiGate CLI command should the administrator use to verify that the ZTNA rule is being evaluated correctly?
106A FortiGate administrator is troubleshooting a site-to-site IPsec tunnel that intermittently drops. The administrator runs 'diagnose vpn ike gateway list' and observes that the tunnel re-establishes every few minutes, and 'diagnose debug application ike -1' shows repeated INVALID_KE_PAYLOAD notifications. The remote peer is a third-party gateway that only supports a specific Diffie-Hellman group. What is the most likely cause of the repeated renegotiation?
107A FortiGate administrator is setting up a ZTNA environment where FortiClient EMS is used to tag endpoints. The administrator wants to create a firewall policy that allows access to a web application only for users whose endpoints have the tag 'Compliant'. Which configuration step is required to use the tag in the firewall policy?
108A FortiGate administrator is deploying ZTNA to provide secure access to internal web applications. The administrator wants to ensure that only devices with up-to-date antivirus signatures are granted access. Which FortiGate component should be used to enforce this requirement?
109An administrator is configuring an IPsec VPN on a FortiGate that will interoperate with a third-party peer. The peer requires the use of a specific encryption domain and does not support IKEv2. The administrator wants to ensure that only specific subnets are permitted through the tunnel, while all other traffic is excluded from the SA. Which configuration element on the FortiGate directly controls which traffic is selected for the IPsec tunnel?
110A FortiGate administrator is configuring an IPsec VPN to a remote peer behind a device that performs NAT. The administrator notices that the tunnel establishes but rekeys fail after the Phase 1 lifetime expires. Which setting should the administrator enable on the FortiGate to allow the IKE negotiation to survive NAT and pass through the NAT device reliably?
111An administrator deploys ZTNA with FortiGate as the access proxy for internal web applications. Users authenticate through FortiClient EMS, and device posture checks must be enforced before access is granted. A user with a compliant laptop can reach the application, but when the same user connects from a personal device that fails the posture check, the connection is still allowed. The administrator verifies the ZTNA rule is enabled and the EMS connector is up. Which configuration element is most likely missing to enforce device posture?
112A FortiGate administrator is configuring a route-based IPsec VPN to a cloud provider. The provider requires that only traffic for the 10.20.0.0/16 network be sent through the tunnel, and that the FortiGate present a specific local subnet of 192.168.10.0/24 as its source. The administrator wants to avoid policy-based VPN configuration. Which configuration approach correctly defines the traffic selectors for this route-based tunnel?
113A FortiGate administrator is deploying ZTNA to provide access to internal applications for remote users. The administrator wants to ensure that users can only access the specific applications they are authorized for, and that the ZTNA access proxy performs authentication and authorization before forwarding traffic. Which FortiGate component must be configured to define the protected applications and the authentication rules for ZTNA access?
114A FortiGate administrator is implementing Zero Trust Network Access (ZTNA) for remote users accessing an internal web application. The administrator wants to ensure that only users who have authenticated and whose devices meet posture requirements can reach the application, and that the application itself is never directly exposed to the internet. Which two FortiGate configuration steps are required to achieve this? (Choose two.)
115An administrator is configuring ZTNA inline CASB on a FortiGate to control access to a sanctioned SaaS application. The requirement is to block uploads of files containing credit card numbers while allowing normal business uploads. The administrator creates an access proxy rule and a CASB profile with a data loss prevention sensor. During testing, uploads of files with credit card numbers are still allowed. Which action should the administrator take to enforce the block?
116A FortiGate administrator is implementing Zero Trust Network Access using ZTNA tags from FortiClient EMS to control access to internal applications. The administrator must ensure that devices losing compliance are denied access and that only managed endpoints can reach the applications. Which two configuration actions are required to meet these goals? (Choose two.)
117A network administrator is setting up an IPsec VPN between two FortiGates. The administrator wants to ensure that if the VPN tunnel goes down, the FortiGate can automatically re-establish it without manual intervention. Which IPsec feature should the administrator enable to detect peer failures and trigger tunnel renegotiation?
118A FortiGate administrator is troubleshooting an IPsec VPN where Phase 1 completes but Phase 2 fails to establish. The administrator reviews the Phase 2 configuration and notices that the local and remote subnets do not match between the two peers. Which action should the administrator take to resolve the Phase 2 failure?
119A FortiGate is configured as a hub in an ADVPN with multiple spokes. The administrator notices that some spokes are not learning routes from other spokes, even though the ADVPN tunnel is up. The hub is using BGP for routing. Which configuration on the hub is required to enable spoke-to-spoke route propagation?
120A FortiGate administrator is troubleshooting an IPsec VPN tunnel that fails to establish. The administrator runs 'diagnose vpn ike gateway list' and sees the tunnel state as 'connecting' but no phase2 selectors are listed. Which step should the administrator take next to identify the issue?
121A FortiGate administrator is troubleshooting a ZTNA deployment. Users report that they can access the ZTNA application, but the EMS tags are not being enforced. The administrator verifies that the FortiGate is connected to FortiClient EMS and that the EMS tags exist. What is the most likely cause?
122A FortiGate administrator is configuring ZTNA inline CASB to control access to a SaaS application. The administrator wants to block uploads of files containing sensitive data while allowing other operations. Which ZTNA inline CASB configuration is required to achieve this?
123A FortiGate administrator is configuring an IPsec VPN tunnel to a remote site that is behind a NAT device. The administrator notices that the tunnel establishes, but traffic intermittently fails. Which setting should be adjusted to improve reliability?
124A FortiGate administrator is configuring an ADVPN with a hub-and-spoke topology. The administrator wants to ensure that spoke-to-spoke traffic can be dynamically established without traversing the hub for every packet. The administrator also wants to ensure that the shortcut tunnels are only established when necessary and are torn down when no longer used. Which two statements about ADVPN shortcut tunnels on FortiGate are correct? (Choose two.)
125A FortiGate administrator is implementing ZTNA in reverse-proxy mode to protect an internal web application. Remote users authenticate through FortiClient with EMS tags, and the administrator wants to enforce that only users with a valid certificate and a compliant endpoint can access the application. After configuring the ZTNA server and access proxy, the administrator notices that users without the certificate are still able to reach the application. What is the most likely cause?
126A FortiGate administrator is configuring an IPsec VPN with IKEv2 between two sites. The administrator wants to ensure that the VPN tunnel uses perfect forward secrecy (PFS) and that the phase 2 selectors are restricted to specific subnets. Which two configuration elements are required to meet these goals? (Choose two.)
127A FortiGate administrator is configuring ZTNA to protect an internal application and wants to ensure that only users who authenticate with a valid client certificate and whose devices pass posture checks can connect. The administrator has configured FortiClient EMS integration and a ZTNA access proxy rule. During testing, users without client certificates are still able to reach the application after providing username and password. Which setting should the administrator verify to enforce certificate-based authentication?
128A FortiGate administrator is implementing ZTNA to control access to internal web applications. The administrator wants to ensure that only devices with a valid FortiClient EMS tag can access the applications. Which ZTNA component must be configured on the FortiGate to enforce this?
129A FortiGate administrator is setting up a ZTNA rule to allow access to an internal application only for users who are members of the 'Finance' group in FortiClient EMS. The administrator has already configured the ZTNA server and access proxy. Which additional configuration is required on the FortiGate to enforce this group membership?
130An administrator is deploying an ADVPN with a hub and two spokes. The hub is behind a NAT device and has a static public IP, while both spokes are behind NAT with dynamic public IPs. The administrator wants the spokes to establish shortcuts directly between each other. Which configuration is required for the shortcut to form?
131A FortiGate administrator is configuring SSL VPN for remote users. The administrator wants to ensure that users can only access specific internal resources based on their user group. Which SSL VPN configuration mode should be used to provide granular access control?
132A FortiGate administrator is troubleshooting an IPsec VPN tunnel that fails to establish. The administrator runs 'diagnose vpn ike gateway list' and sees that the IKE gateway is stuck in the 'connecting' state. The administrator confirms that the pre-shared key matches on both peers. Which action should the administrator take next to identify the cause?
133A FortiGate administrator has configured a ZTNA access proxy for an internal web application and wants to enforce device compliance before allowing access. The administrator has integrated FortiClient EMS and created ZTNA tags for compliant devices. Users with compliant devices are still being denied access. The firewall policy references the ZTNA server and the tag. What should the administrator verify first?
134A FortiGate administrator is troubleshooting an IPsec VPN that uses IKEv2 and certificate authentication. The tunnel fails to establish, and the administrator sees that the phase 1 negotiation reaches the point of exchanging certificates but then fails. The administrator wants to verify the certificate-related configuration. Which two actions should the administrator take to resolve the issue? (Choose two.)
135A FortiGate administrator is configuring an IPsec VPN with IKEv2 and wants to ensure that the tunnel uses perfect forward secrecy (PFS). Which phase2 configuration is required?
136A FortiGate administrator is configuring a ZTNA rule to protect an internal application. The administrator wants to ensure that only devices with a specific compliance tag are allowed, while all other devices are denied. The administrator has already created the ZTNA server and the FortiClient EMS tags. What is the correct way to enforce this requirement in the firewall policy?
137A FortiGate administrator is configuring an IPsec VPN with IKEv2 between two sites. The administrator wants to ensure that only specific subnets are allowed over the tunnel and that the tunnel uses strong encryption. After configuring phase1 and phase2, the administrator notices that the tunnel is up, but traffic from a subnet that should be allowed is not passing. The administrator runs 'diagnose vpn tunnel list' and sees that the tunnel is established. What is the most likely reason for the traffic not passing?
138A FortiGate administrator is configuring a ZTNA rule to allow access to an internal web application only for users who authenticate with multi-factor authentication (MFA). The administrator has configured the ZTNA rule to require the 'MFA' tag from FortiClient EMS. However, users who have MFA enabled are still being denied access. What is the most likely reason?
Deep-dive questions
The most-searched questions in this domain — detailed explanations, worked examples, full answer breakdowns.
Be able to read IKE debug output, explain DPD and INITIAL_CONTACT effects on tunnel state, assign SAML IdP versus SP roles correctly, and verify ZTNA proxy policy certificate enforcement. The key is matching each symptom to the right FortiGate feature and log evidence.
The Courseiva NSE7 question bank contains 138 questions in the Advanced VPN and Zero Trust domain, covering the 20% of the exam attributed to this domain in the official Fortinet blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Advanced VPN and Zero Trust domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included