NSE4 High Availability and Diagnostics Practice Question
An administrator is configuring ZTNA (Zero Trust Network Access) on a FortiGate. The administrator needs to ensure that only clients with a valid posture assessment can access an internal application. Which access proxy setting must be configured to enforce this requirement?
⚠ Common exam trap
The trap is conflating authentication mechanisms (certificates, MFA) with posture assessment; candidates pick certificate or MFA options thinking they enforce device health when only ZTNA tags reflect posture.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a ZTNA rule with a ZTNA tag requirement
ZTNA on FortiGate enforces zero trust by requiring clients to present a valid ZTNA tag, which is issued only after a successful posture assessment by FortiClient EMS. Configuring a ZTNA rule with a tag requirement ensures that only endpoints meeting the posture policy can reach the protected application through the access proxy. This is the mechanism that ties posture validation to access enforcement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable SSL deep inspection on the access proxy
Why it's wrong here
SSL deep inspection enables the FortiGate to decrypt and inspect application-layer traffic for threats, but it does not evaluate the endpoint's compliance status or assign ZTNA tags. Posture enforcement in ZTNA relies on FortiClient telemetry and the dynamic tags generated from that telemetry, not on the content of decrypted sessions. Simply enabling SSL deep inspection on the access proxy will not reject a non-compliant device; it only makes the traffic visible for other security controls.
- ✓
Configure a ZTNA rule with a ZTNA tag requirement
Why this is correct
Configuring a ZTNA rule with a ZTNA tag requirement is the only option that directly enforces security posture. The FortiGate requires that the connecting client present a specific tag that is only issued after the endpoint passes posture checks such as patching and host firewall status. If the tag is absent or does not match the required value, the rule blocks access. This tag-based enforcement is the core mechanism for zero-trust posture verification in Fortinet's ZTNA.
- ✗
Set the access proxy to use certificate-based authentication
Why it's wrong here
Setting the access proxy to use certificate-based authentication verifies the identity of the user or device via a signed certificate, but it does not assess the current security state of that device. A certificate is a static credential; a device that was compliant when the certificate was issued could later become infected or misconfigured and still be authenticated. ZTNA tags, in contrast, are dynamic and are updated based on real-time FortiClient telemetry, so certificate authentication cannot substitute for posture enforcement.
- ✗
Enable multi-factor authentication on the access proxy
Why it's wrong here
Enabling multi-factor authentication on the access proxy adds a second authentication factor, such as a code from an authenticator app, but it only proves the user knows or possesses additional credentials. It does not check whether the endpoint has the required security posture, such as up-to-date OS patches or an enabled firewall. MFA protects against credential theft but leaves the door open for a compromised or non-compliant device that has valid credentials.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on NSE4
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A FortiGate administrator is configuring ZTNA (Zero Trust Network Access) to secure access to an internal application. Which two components must be configured to create a ZTNA rule? (Choose two.)
hard- A.ZTNA tag
- ✓ B.ZTNA gateway
- C.VPN tunnel
- ✓ D.ZTNA application
- E.SSL certificate
Why B: Option B (ZTNA gateway) is correct because the ZTNA gateway (configured as a ZTNA server/access proxy on the FortiGate) is the enforcement point that proxies and inspects client traffic to the protected application, and it must exist before a ZTNA rule can reference it. Option D (ZTNA application) is correct because the ZTNA rule must specify the protected application (the real server/application object published through the ZTNA gateway) that clients are allowed to reach. Together, the ZTNA gateway and ZTNA application are the two required building blocks referenced by a ZTNA firewall rule. Option A (ZTNA tag) is not required to create the rule itself; tags are used for dynamic client/device posture grouping and are optional unless you want tag-based matching. Option C (VPN tunnel) is incorrect because ZTNA is designed as a client-based, per-application access model that does not require an IPsec or SSL VPN tunnel. Option E (SSL certificate) is incorrect because, while certificates may be used for authentication or the gateway's TLS service, a certificate is not a mandatory component that defines a ZTNA rule.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.