Courseiva
Authentication and VPN →easyMultiple Select

NSE4 Authentication and VPN Practice Question

An organization wants to implement ZTNA (Zero Trust Network Access) on their FortiGate. Which TWO components are essential for ZTNA? (Select two.)

⚠ Common exam trap

Many candidates confuse ZTNA with traditional VPN solutions, mistakenly thinking a dedicated tunnel or static IP is required, when in fact ZTNA operates at the application layer without persistent network tunnels.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Client certificates for device posture verification

Client certificates are essential for ZTNA because they enable device posture verification, ensuring that only trusted and compliant devices can access protected resources. FortiGate uses client certificates to validate the device's identity and health status before granting access, which is a core principle of Zero Trust.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Client certificates for device posture verification

    Why this is correct

    In Fortinet ZTNA, client certificates serve as the primary mechanism for device posture verification. A certificate installed on an endpoint allows the FortiGate access proxy to verify that the device has been provisioned by the organization, is not compromised, and meets compliance requirements such as OS version, antivirus status, or patch level. This certificate-based device trust is crucial for zero trust because it ties the user's session to a validated, healthy endpoint, and it overrides any assumptions based on network location.

  • ✓

    Identity Provider (IdP) for user authentication

    Why this is correct

    ZTNA requires a strong identity provider (IdP) to authenticate users and enforce multifactor authentication. The FortiGate or ZTNA access proxy integrates with the IdP via SAML or OIDC, receiving an authentication assertion that confirms the user's identity. Only after the IdP validates the user and any MFA challenges is a session established, and the proxy then grants access to the specific application based on policies. This makes the IdP an indispensable component for verifying who is requesting access, independent of where they connect from.

  • ✗

    A dedicated VPN tunnel

    Why it's wrong here

    A dedicated VPN tunnel is the antithesis of ZTNA's application-centric access model. Traditional VPNs place the remote client on the internal network, granting excessively broad access and creating a large attack surface. ZTNA replaces this with a granular access proxy that initiates a secure connection per session to the requested application, without placing the client on the LAN. Since the proxy is application-aware and can verify user/device identity at each request, a persistent tunnel is unnecessary and actually weakens security.

  • ✗

    A static IP address for the client

    Why it's wrong here

    A static IP address is an irrelevant trust attribute in a ZTNA model. Because users may legitimately access applications from home, cellular, or unknown public networks, the source IP is dynamic and cannot be used to determine trust. ZTNA policies are enforced at the application session layer using the user's authenticated identity and device certificate, not the client IP. Requiring a static IP would be impractical and would contradict the principle of least privilege, since trust is established through cryptographic credentials rather than network location.

  • ✗

    A RADIUS server for two-factor authentication

    Why it's wrong here

    RADIUS servers are traditionally used for network access authentication, but they are not a mandatory component for ZTNA. Modern identity providers used in ZTNA architectures already include MFA capabilities such as one-time passwords, push notifications, or WebAuthn, which are handled during the SAML/OIDC authentication flow. Adding a separate RADIUS server for two-factor authentication would duplicate effort and complicate the architecture, and it would not replace the IdP's role in asserting the user's identity to the ZTNA access proxy.

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.