NSE4 Authentication and VPN Practice Question
In Fortinet ZTNA, what is the primary purpose of the ZTNA access proxy component?
⚠ Common exam trap
It's easy for candidates to confuse the ZTNA access proxy with a forward proxy or VPN concentrator, but Fortinet specifically designed it as a reverse proxy for internal application access, not for general web proxying or tunnel termination.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To proxy connections to internal applications after authentication and device verification
The ZTNA access proxy is the core component that mediates user access to internal applications. It intercepts client requests, enforces authentication and device posture checks (via FortiClient telemetry), and then proxies the connection to the protected application. This ensures no direct network access is granted; all traffic must pass through the proxy, which validates trust before forwarding.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To act as a forward proxy for web traffic
Why it's wrong here
The ZTNA access proxy is explicitly a reverse proxy, not a forward proxy. A forward proxy sits in front of clients and forwards their outbound requests to the internet, whereas FortiGate’s ZTNA access proxy sits in front of internal applications and mediates inbound client connections. FortiGate does have separate forward-proxy capabilities for web traffic, but that is not the ZTNA access proxy's role.
- ✗
To provide load balancing for multiple FortiGates
Why it's wrong here
Load balancing is a distinct FortiGate feature, typically handled by virtual servers, SLBC (Session Load Balancing Cluster), or external load balancers. The ZTNA access proxy's primary purpose is to broker secure access to internal applications by validating identity and device posture, not to distribute network traffic across multiple FortiGates. While ZTNA access proxy and load balancing can coexist in a design, they are not functionally the same thing.
- ✓
To proxy connections to internal applications after authentication and device verification
Why this is correct
This is the correct function: the ZTNA access proxy acts as a reverse proxy that terminates client requests to internal applications, enforcing authentication (often via SAML/OIDC) and device verification (via FortiClient EMS) before proxying the connection to the actual application server. This creates a zero-trust access model where access is granted per application, per user, and per device, rather than allowing broad network-level connectivity.
- ✗
To terminate IPsec VPN tunnels
Why it's wrong here
The ZTNA access proxy operates at the application layer (Layer 7) for HTTP/HTTPS flows, not at the network layer for IPsec tunnels. IPsec VPN termination is performed by FortiGate's dedicated VPN module, which handles encryption, AH/ESP, and tunnel negotiation. ZTNA and IPsec VPN are different access methods; the ZTNA access proxy does not process IPsec packets or tunnel establishment.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.