NSE4 High Availability and Diagnostics Practice Question
A FortiGate administrator configures a ZTNA rule to protect an internal web server. The rule uses an access proxy. Which component on the FortiGate terminates the incoming ZTNA connection?
⚠ Common exam trap
NSE4 often tests the confusion between the ZTNA application (the protected resource) and the ZTNA gateway (the component that terminates the connection), so candidates pick the resource instead of the terminator.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ZTNA gateway
In FortiGate ZTNA, the access proxy is hosted on the FortiGate itself, and the component that terminates the incoming ZTNA connection from the endpoint is the ZTNA gateway (also called the access proxy gateway). The ZTNA gateway performs the TLS termination and enforces the ZTNA rule, then proxies the traffic to the protected internal server. This is why the FortiGate can inspect and apply zero-trust policy without exposing the server directly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ZTNA tag
Why it's wrong here
ZTNA tags are security attributes assigned to users or devices to verify identity and enforce access policy. They act as credentials that the ZTNA gateway validates after the client establishes a connection, but they do not provide any network endpoint or TLS termination. The tag itself is a data point in the rule, not a physical or logical point where the connection is received.
- ✗
SSL inspection profile
Why it's wrong here
An SSL inspection profile is used to decrypt traffic for deep content inspection, such as anti-virus or data loss prevention. However, in a ZTNA rule, the FortiGate ZTNA gateway already terminates the client's TLS connection, so the SSL inspection profile is not responsible for that termination. The profile may be applied post-decryption for deep scanning, but it is never the point where the ZTNA connection logically ends.
- ✗
ZTNA application
Why it's wrong here
A ZTNA application defines the backend server—its IP address and port—that the client wants to reach after passing the policy. It is the destination resource, not the entry point. The client connects to the ZTNA gateway, and the gateway then proxies the decrypted and verified session to the ZTNA application. Therefore, the application is on the far side of the termination point, not the terminating element itself.
- ✓
ZTNA gateway
Why this is correct
The ZTNA gateway is the correct answer because it is the network entity that accepts inbound client connections, terminates the TLS session, authenticates the user, validates ZTNA tags, and proxies the session to the configured ZTNA application. In FortiOS, you configure a ZTNA gateway with a virtual host, a port, and an SSL certificate. This is where the client's connection logically ends and the internal connection to the backend application begins.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.