NSE4 High Availability and Diagnostics Practice Question
A FortiGate administrator wants to configure Zero Trust Network Access (ZTNA) to secure access to an internal application. What is required on the FortiGate?
⚠ Common exam trap
NSE4 often tests whether candidates confuse ZTNA with traditional SSL VPN — the trap is selecting 'VPN tunnel' because ZTNA sounds like remote access, when ZTNA's defining feature is the access proxy (ZTNA server + rule) that avoids a full tunnel.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A ZTNA server and a ZTNA rule
FortiGate ZTNA requires configuring a ZTNA server (which defines the protected application, its real server, and the access proxy/certificate) and a ZTNA rule (which binds the server to users/groups and enforcement). Together they let the FortiGate act as an access proxy that authenticates users and brokers connections to the internal app without a full VPN tunnel.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A FortiClient EMS subscription
Why it's wrong here
FortiClient EMS is useful for gathering endpoint compliance and generating ZTNA tags, but it is not a mandatory component for basic ZTNA. A FortiGate can enforce ZTNA using certificate-based identity or other authentication methods without EMS. The core ZTNA configuration relies on an access proxy and a rule, making EMS optional rather than a required subscription.
- ✗
A VPN tunnel to the application
Why it's wrong here
ZTNA is specifically designed to replace full-tunnel VPNs by using TLS-based access proxying. The FortiGate terminates TLS connections from clients and forwards them to the internal application after identity and context checks, so no VPN tunnel to the application is needed. A VPN would expose the entire network and lacks granular per-application control. Therefore, a VPN is not a ZTNA requirement; in fact, ZTNA eliminates the need for it.
- ✓
A ZTNA server and a ZTNA rule
Why this is correct
A ZTNA server defines the internal application's host and port, while a ZTNA rule (configured in the firewall policy) specifies who can access it and what access proxy settings apply. Together they establish the FortiGate as an access proxy that authenticates users and enforces least-privilege access. Without these two objects, the FortiGate has no way to publish or protect the application, making them the core requirement for zero-trust network access.
- ✗
A firewall policy with SSL inspection enabled
Why it's wrong here
SSL inspection is commonly enabled alongside ZTNA to decrypt traffic and allow security features like IPS to inspect content, but it is not a foundational requirement. ZTNA functions based on the ZTNA server and rule, even without deep inspection, because identity and access control occur at the proxy layer. SSL inspection only enhances visibility and threat prevention, so failing to enable it does not prevent ZTNA from working. Thus, this option, while compatible, is not the primary requirement.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.