NSE4 Authentication and VPN Practice Question
A FortiGate administrator is configuring ZTNA for a web application. Which TWO components are required for a ZTNA configuration to function?
⚠ Common exam trap
Many exam-takers confuse ZTNA with traditional VPN technologies (SSL VPN or IPsec VPN) or assume a standard firewall policy is mandatory, when in fact ZTNA operates as a separate, identity-centric access control layer that requires ZTNA rules and tags as its fundamental building blocks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ZTNA rules
ZTNA rules are the core policy mechanism that defines access control for ZTNA applications, specifying which users and devices can access which resources based on identity and device posture. Without ZTNA rules, the FortiGate cannot enforce the granular, identity-based access decisions that ZTNA requires.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SSL VPN
Why it's wrong here
SSL VPN is a remote-access tunneling technology that encapsulates all traffic and, after login, grants users a virtual network adapter with broad network-layer access. In contrast, ZTNA uses a purpose-built access proxy to broker each request based on identity, device posture, and destination service. Enabling SSL VPN on the FortiGate neither creates ZTNA rules nor applies least-privilege per-application policies, so it cannot be the mechanism for ZTNA web application protection.
- ✗
IPsec VPN
Why it's wrong here
An IPsec VPN establishes an encrypted tunnel at the network layer, typically granting full subnet access to remote users or connecting site-to-site networks. ZTNA does not require any such tunnel; it performs allow/deny decisions at the application layer via the access proxy and ZTNA rules. In fact, forcing traffic through an IPsec tunnel would subvert ZTNA's per-request verification because traffic would already have unrestricted network-path access.
- ✓
ZTNA rules
Why this is correct
ZTNA rules are the central policy object in FortiOS that define which users and devices—identified by ZTNA tags—may access a specific protected application, and what action to take. When a client makes an HTTPS request through the ZTNA access proxy, the proxy evaluates matching ZTNA rules to allow or deny the session, making this the correct answer. These rules replace traditional firewall policies for application-level access control, not SSL VPN or IPsec.
- ✓
ZTNA tags
Why this is correct
ZTNA tags are dynamic posture labels assigned to endpoints by FortiClient EMS based on OS, up-to-date antivirus, and other compliance checks. These tags are embedded in the client certificate presented when the endpoint connects to the FortiGate access proxy, giving the ZTNA proxy the real-time trust information it needs. While tags are critical inputs to ZTNA rules, they are data attributes rather than access policies, so they are part of the answer but not the controlling rule.
- ✗
Firewall policy
Why it's wrong here
A traditional firewall policy matches traffic based on 5-tuple information such as source/destination IP, port, and protocol, and is evaluated in sequential order. ZTNA, by contrast, evaluates the request at the application layer after terminating the client HTTPS session in the access proxy; it does not rely on the classic firewall policy logic. Because the question asks what defines ZTNA access, the correct object is a ZTNA rule, not a legacy firewall policy.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.