What is the function of Zero Trust Network Access (ZTNA) on a FortiGate?
ZTNA enables per-application, identity-based access control: the FortiGate acts as an access proxy, authenticating the user (via SAML, LDAP, or local login) and verifying device posture (using FortiClient or other telemetry) before allowing a short-lived, encrypted session to a specific internal application. This eliminates the need for a full VPN tunnel, enforcing least-privilege access while keeping the user unaware of the complete internal network.
Why this answer
ZTNA on FortiGate provides secure, identity-based access to internal applications without requiring a traditional VPN tunnel. It evaluates user identity and device posture before granting access, ensuring that only authorized users and compliant devices can reach specific applications. This aligns with the Zero Trust principle of 'never trust, always verify' and is implemented via FortiGate's ZTNA features, often integrated with FortiClient and FortiAuthenticator.
Exam trap
NSE4 often tests the misconception that ZTNA is a replacement for VPNs or firewalls, when it is actually a complementary access control mechanism that requires identity and posture checks.
How to eliminate wrong answers
Option B is wrong because ZTNA does not replace firewall policies; it works alongside them to provide granular, application-level access control, and firewall policies still govern other traffic. Option C is wrong because ZTNA does not encrypt all traffic between the FortiGate and the internet; encryption is typically handled by IPsec or TLS VPNs, and ZTNA focuses on access control, not bulk encryption. Option D is wrong because ZTNA is not a cloud-based subscription for antivirus updates; that describes FortiGuard services, while ZTNA is a network access security feature.