NSE4 Authentication and VPN Practice Question
An administrator needs to configure ZTNA (Zero Trust Network Access) on a FortiGate to provide secure remote access to an internal application. Which components are required for a basic ZTNA configuration? (Choose three.)
⚠ Common exam trap
Many exam-takers confuse ZTNA with traditional VPNs and incorrectly assume an IPsec tunnel is mandatory, when in fact ZTNA uses a TLS reverse proxy and does not require any VPN tunnel.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ZTNA proxy (application gateway)
The ZTNA proxy (application gateway) is the core component that terminates client connections and forwards them to internal applications after verifying device and user identity. It acts as a reverse proxy, enforcing access policies before allowing any traffic to reach the protected resource. Without this gateway, the FortiGate cannot mediate ZTNA connections.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
IPsec VPN tunnel
Why it's wrong here
IPsec VPN tunnel: Incorrect. IPsec operates at Layer 3, encrypting all traffic between a client and a VPN gateway, which grants broad network-level access to the internal subnet. ZTNA, in contrast, is an application-layer access control mechanism that uses SSL/TLS and a proxy to connect a user only to a specific application, not to the entire network. Deploying an IPsec tunnel would expose the whole network and violate the least-privilege principle central to zero trust.
- ✓
ZTNA proxy (application gateway)
Why this is correct
ZTNA proxy (application gateway): Correct. The ZTNA proxy is the FortiGate's application-layer reverse proxy that terminates the user's HTTPS connection and forwards requests to the internal application server. It validates the user's identity and device posture before proxying any traffic, and it only exposes the specific application port, not the full network. This proxy is the core enforcement point for ZTNA policy.
- ✗
Captive portal
Why it's wrong here
Captive portal: Incorrect. A captive portal is a network access control (NAC) feature that intercepts HTTP/HTTPS access and forces unauthenticated users to a login or registration page, typically for Wi-Fi or LAN access. It is designed for initial network admission, not for continuous per-application authorization, and it cannot evaluate device posture or selectively proxy individual applications. ZTNA requires post-authentication, context-aware control at the application layer.
- ✓
ZTNA rule (policy) on the FortiGate
Why this is correct
ZTNA rule (policy) on the FortiGate: Correct. The ZTNA rule is a firewall policy that binds the ZTNA proxy to a specific set of users, device posture checks, and source/destination addresses, effectively defining 'who can access this application under what conditions.' Without this policy, the proxy would not know how to enforce identity-based decisions or apply access control. The rule is the authorization layer that puts the zero-trust decision into effect.
- ✓
Access proxy (or application) configuration
Why this is correct
Access proxy (or application) configuration: Correct. This configuration on the FortiGate defines the actual backend application's hostname, IP, port, and connection parameters, telling the ZTNA proxy how to reach it when a user is authorized. It also allows you to set such details as SNI, health checks, and TLS settings for the application. Unlike the proxy itself, which handles the front-end client connection, this config specifies the back-end target; it is a required component for ZTNA to work.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.