Courseiva
Authentication and VPN →easyMultiple Select

NSE4 Authentication and VPN Practice Question

An administrator needs to configure ZTNA (Zero Trust Network Access) on a FortiGate to provide secure remote access to an internal application. Which components are required for a basic ZTNA configuration? (Choose three.)

⚠ Common exam trap

Many exam-takers confuse ZTNA with traditional VPNs and incorrectly assume an IPsec tunnel is mandatory, when in fact ZTNA uses a TLS reverse proxy and does not require any VPN tunnel.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ZTNA proxy (application gateway)

The ZTNA proxy (application gateway) is the core component that terminates client connections and forwards them to internal applications after verifying device and user identity. It acts as a reverse proxy, enforcing access policies before allowing any traffic to reach the protected resource. Without this gateway, the FortiGate cannot mediate ZTNA connections.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    IPsec VPN tunnel

    Why it's wrong here

    IPsec VPN tunnel: Incorrect. IPsec operates at Layer 3, encrypting all traffic between a client and a VPN gateway, which grants broad network-level access to the internal subnet. ZTNA, in contrast, is an application-layer access control mechanism that uses SSL/TLS and a proxy to connect a user only to a specific application, not to the entire network. Deploying an IPsec tunnel would expose the whole network and violate the least-privilege principle central to zero trust.

  • ✓

    ZTNA proxy (application gateway)

    Why this is correct

    ZTNA proxy (application gateway): Correct. The ZTNA proxy is the FortiGate's application-layer reverse proxy that terminates the user's HTTPS connection and forwards requests to the internal application server. It validates the user's identity and device posture before proxying any traffic, and it only exposes the specific application port, not the full network. This proxy is the core enforcement point for ZTNA policy.

  • ✗

    Captive portal

    Why it's wrong here

    Captive portal: Incorrect. A captive portal is a network access control (NAC) feature that intercepts HTTP/HTTPS access and forces unauthenticated users to a login or registration page, typically for Wi-Fi or LAN access. It is designed for initial network admission, not for continuous per-application authorization, and it cannot evaluate device posture or selectively proxy individual applications. ZTNA requires post-authentication, context-aware control at the application layer.

  • ✓

    ZTNA rule (policy) on the FortiGate

    Why this is correct

    ZTNA rule (policy) on the FortiGate: Correct. The ZTNA rule is a firewall policy that binds the ZTNA proxy to a specific set of users, device posture checks, and source/destination addresses, effectively defining 'who can access this application under what conditions.' Without this policy, the proxy would not know how to enforce identity-based decisions or apply access control. The rule is the authorization layer that puts the zero-trust decision into effect.

  • ✓

    Access proxy (or application) configuration

    Why this is correct

    Access proxy (or application) configuration: Correct. This configuration on the FortiGate defines the actual backend application's hostname, IP, port, and connection parameters, telling the ZTNA proxy how to reach it when a user is authorized. It also allows you to set such details as SNI, health checks, and TLS settings for the application. Unlike the proxy itself, which handles the front-end client connection, this config specifies the back-end target; it is a required component for ZTNA to work.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.