Courseiva
Advanced VPN and Zero Trust →mediumMultiple Choice

NSE7 Advanced VPN and Zero Trust Practice Question

A FortiGate administrator configures a ZTNA access proxy rule to allow access to an internal application only if the user's device has the tag 'Compliant'. The tag is assigned by FortiClient EMS. However, a user with a compliant device is still blocked. The admin sees in the ZTNA logs that the tag is not being received. What should the administrator check FIRST?

⚠ Common exam trap

The trap is that candidates focus on the client side or the rule itself, but the log message 'tag not received' is a strong hint that the integration channel (EMS connector) is the root cause — always check the data source before the consumer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ensure the EMS connector is configured under Security Fabric > External Connectors

For a FortiGate to receive ZTNA device tags from FortiClient EMS, the EMS connector must be configured under Security Fabric > External Connectors. Without this connector, the FortiGate has no channel to query or receive tag information, so ZTNA rules referencing tags like 'Compliant' will fail even if the client is healthy. The log showing 'tag not received' points directly at the missing or broken EMS integration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Verify that the FortiClient is connected to the internet

    Why it's wrong here

    Internet connectivity is not the tag-delivery path; FortiClient EMS pushes device tags to FortiGate over the EMS-FortiGate connection, so the FortiGate's EMS connector status and tag visibility matter first. It is tempting because FortiClient needs connectivity to EMS, but that is a separate link from the FortiGate's tag receipt.

  • ✗

    Confirm that the ZTNA rule is enabled and using the correct port

    Why it's wrong here

    Rule enablement and port configuration affect whether the proxy rule matches traffic at all, yet the logs show the rule evaluating and failing on the absent tag, so the tag source is the fault. It is tempting because a disabled rule or wrong port also blocks users, but those produce no tag-evaluation entry.

  • ✗

    Check if the application server is reachable from the FortiGate

    Why it's wrong here

    Application server reachability governs the final proxy leg, not tag receipt; the logs already show the tag never arrived, so the failure precedes that connection. It is tempting because blocked access often means an unreachable backend, but here the ZTNA rule never matched on the missing tag.

  • ✓

    Ensure the EMS connector is configured under Security Fabric > External Connectors

    Why this is correct

    Tags originate from FortiClient EMS, so the FortiGate cannot receive them without the EMS connector configured under Security Fabric > External Connectors. Without that connector, the ZTNA log shows no tag, blocking the compliant user.

About these practice questions

Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.