Courseiva

NSE4 High Availability and Diagnostics Practice Question

A FortiGate administrator configures a ZTNA rule to protect an internal web server. The rule uses an access proxy. Which component on the FortiGate terminates the incoming ZTNA connection?

⚠ Common exam trap

NSE4 often tests the confusion between the ZTNA application (the protected resource) and the ZTNA gateway (the component that terminates the connection), so candidates pick the resource instead of the terminator.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ZTNA gateway

In FortiGate ZTNA, the access proxy is hosted on the FortiGate itself, and the component that terminates the incoming ZTNA connection from the endpoint is the ZTNA gateway (also called the access proxy gateway). The ZTNA gateway performs the TLS termination and enforces the ZTNA rule, then proxies the traffic to the protected internal server. This is why the FortiGate can inspect and apply zero-trust policy without exposing the server directly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ZTNA tag

    Why it's wrong here

    ZTNA tags are security attributes assigned to users or devices to verify identity and enforce access policy. They act as credentials that the ZTNA gateway validates after the client establishes a connection, but they do not provide any network endpoint or TLS termination. The tag itself is a data point in the rule, not a physical or logical point where the connection is received.

  • ✗

    SSL inspection profile

    Why it's wrong here

    An SSL inspection profile is used to decrypt traffic for deep content inspection, such as anti-virus or data loss prevention. However, in a ZTNA rule, the FortiGate ZTNA gateway already terminates the client's TLS connection, so the SSL inspection profile is not responsible for that termination. The profile may be applied post-decryption for deep scanning, but it is never the point where the ZTNA connection logically ends.

  • ✗

    ZTNA application

    Why it's wrong here

    A ZTNA application defines the backend server—its IP address and port—that the client wants to reach after passing the policy. It is the destination resource, not the entry point. The client connects to the ZTNA gateway, and the gateway then proxies the decrypted and verified session to the ZTNA application. Therefore, the application is on the far side of the termination point, not the terminating element itself.

  • ✓

    ZTNA gateway

    Why this is correct

    The ZTNA gateway is the correct answer because it is the network entity that accepts inbound client connections, terminates the TLS session, authenticates the user, validates ZTNA tags, and proxies the session to the configured ZTNA application. In FortiOS, you configure a ZTNA gateway with a virtual host, a port, and an SSL certificate. This is where the client's connection logically ends and the internal connection to the backend application begins.

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.