Courseiva
Authentication and VPN →easyMultiple Choice

NSE4 Authentication and VPN Practice Question

In Fortinet ZTNA, what is the primary purpose of the ZTNA access proxy component?

⚠ Common exam trap

It's easy for candidates to confuse the ZTNA access proxy with a forward proxy or VPN concentrator, but Fortinet specifically designed it as a reverse proxy for internal application access, not for general web proxying or tunnel termination.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To proxy connections to internal applications after authentication and device verification

The ZTNA access proxy is the core component that mediates user access to internal applications. It intercepts client requests, enforces authentication and device posture checks (via FortiClient telemetry), and then proxies the connection to the protected application. This ensures no direct network access is granted; all traffic must pass through the proxy, which validates trust before forwarding.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To act as a forward proxy for web traffic

    Why it's wrong here

    The ZTNA access proxy is explicitly a reverse proxy, not a forward proxy. A forward proxy sits in front of clients and forwards their outbound requests to the internet, whereas FortiGate’s ZTNA access proxy sits in front of internal applications and mediates inbound client connections. FortiGate does have separate forward-proxy capabilities for web traffic, but that is not the ZTNA access proxy's role.

  • ✗

    To provide load balancing for multiple FortiGates

    Why it's wrong here

    Load balancing is a distinct FortiGate feature, typically handled by virtual servers, SLBC (Session Load Balancing Cluster), or external load balancers. The ZTNA access proxy's primary purpose is to broker secure access to internal applications by validating identity and device posture, not to distribute network traffic across multiple FortiGates. While ZTNA access proxy and load balancing can coexist in a design, they are not functionally the same thing.

  • ✓

    To proxy connections to internal applications after authentication and device verification

    Why this is correct

    This is the correct function: the ZTNA access proxy acts as a reverse proxy that terminates client requests to internal applications, enforcing authentication (often via SAML/OIDC) and device verification (via FortiClient EMS) before proxying the connection to the actual application server. This creates a zero-trust access model where access is granted per application, per user, and per device, rather than allowing broad network-level connectivity.

  • ✗

    To terminate IPsec VPN tunnels

    Why it's wrong here

    The ZTNA access proxy operates at the application layer (Layer 7) for HTTP/HTTPS flows, not at the network layer for IPsec tunnels. IPsec VPN termination is performed by FortiGate's dedicated VPN module, which handles encryption, AH/ESP, and tunnel negotiation. ZTNA and IPsec VPN are different access methods; the ZTNA access proxy does not process IPsec packets or tunnel establishment.

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.