NSE4 Authentication and VPN Practice Question
An admin needs to configure an SSL VPN for remote users that only provides access to specific internal applications, not full network access. What feature should be configured?
⚠ Common exam trap
Many candidates confuse 'web mode portal' (Option D) with application-specific access, but web mode only provides a browser-based gateway and does not inherently restrict network-layer access without additional split tunneling or firewall policies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Split tunneling
Split tunneling (Option C) is the correct feature because it allows the SSL VPN to route only traffic destined for specific internal applications through the encrypted tunnel, while all other traffic goes directly to the internet. This meets the requirement of providing access to specific internal applications without granting full network access, as split tunneling uses routing policies to selectively forward traffic based on destination IP addresses or application ports.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Full tunneling
Why it's wrong here
Full tunneling is incorrect because it routes all client traffic, including Internet-bound traffic, through the FortiGate SSL VPN tunnel. This provides access to the entire network beyond the intended internal subnets, which is broader than the requirement and can introduce latency and bandwidth congestion. Full tunneling does not allow granular selection of specific subnets or applications, so it fails to meet the need for selective internal access.
- ✗
Client certificate authentication
Why it's wrong here
Client certificate authentication is an authentication method that verifies the remote user's identity via a digital certificate, but it does not control network access or define which subnets are reachable. After successful authentication, the admin still needs separate access control mechanisms like routing and firewall policies to restrict traffic. Thus, while it may enhance security, it does not address the requirement of allowing access to specific internal applications.
- ✓
Split tunneling
Why this is correct
Split tunneling is correct because it enables the administrator to define specific destination subnets that are routed through the SSL VPN tunnel, while all other traffic goes directly to the client's local network or Internet. This allows remote users to reach only the intended internal applications without exposing the entire corporate network. Split tunneling is configured via destination-based routing on the FortiGate, making it the precise access-control method for this scenario.
- ✗
Web mode portal
Why it's wrong here
Web mode portal is incorrect because it provides access only to pre-configured web applications through a browser-based portal, using HTTP/HTTPS proxying rather than full IP-layer connectivity. It cannot deliver access to arbitrary internal applications that require client-server protocols, nor does it define subnets for network-level routing. Therefore, it is too limited for the requirement of granting access to specific internal applications.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.