Courseiva
Authentication and VPN →mediumMultiple Choice

NSE4 Authentication and VPN Practice Question

An admin needs to configure an SSL VPN for remote users that only provides access to specific internal applications, not full network access. What feature should be configured?

⚠ Common exam trap

Many candidates confuse 'web mode portal' (Option D) with application-specific access, but web mode only provides a browser-based gateway and does not inherently restrict network-layer access without additional split tunneling or firewall policies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Split tunneling

Split tunneling (Option C) is the correct feature because it allows the SSL VPN to route only traffic destined for specific internal applications through the encrypted tunnel, while all other traffic goes directly to the internet. This meets the requirement of providing access to specific internal applications without granting full network access, as split tunneling uses routing policies to selectively forward traffic based on destination IP addresses or application ports.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Full tunneling

    Why it's wrong here

    Full tunneling is incorrect because it routes all client traffic, including Internet-bound traffic, through the FortiGate SSL VPN tunnel. This provides access to the entire network beyond the intended internal subnets, which is broader than the requirement and can introduce latency and bandwidth congestion. Full tunneling does not allow granular selection of specific subnets or applications, so it fails to meet the need for selective internal access.

  • ✗

    Client certificate authentication

    Why it's wrong here

    Client certificate authentication is an authentication method that verifies the remote user's identity via a digital certificate, but it does not control network access or define which subnets are reachable. After successful authentication, the admin still needs separate access control mechanisms like routing and firewall policies to restrict traffic. Thus, while it may enhance security, it does not address the requirement of allowing access to specific internal applications.

  • ✓

    Split tunneling

    Why this is correct

    Split tunneling is correct because it enables the administrator to define specific destination subnets that are routed through the SSL VPN tunnel, while all other traffic goes directly to the client's local network or Internet. This allows remote users to reach only the intended internal applications without exposing the entire corporate network. Split tunneling is configured via destination-based routing on the FortiGate, making it the precise access-control method for this scenario.

  • ✗

    Web mode portal

    Why it's wrong here

    Web mode portal is incorrect because it provides access only to pre-configured web applications through a browser-based portal, using HTTP/HTTPS proxying rather than full IP-layer connectivity. It cannot deliver access to arbitrary internal applications that require client-server protocols, nor does it define subnets for network-level routing. Therefore, it is too limited for the requirement of granting access to specific internal applications.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.