NSE7 Advanced VPN and Zero Trust Practice Question
A FortiGate administrator configures a ZTNA access proxy rule to allow access to an internal application only if the user's device has the tag 'Compliant'. The tag is assigned by FortiClient EMS. However, a user with a compliant device is still blocked. The admin sees in the ZTNA logs that the tag is not being received. What should the administrator check FIRST?
⚠ Common exam trap
The trap is that candidates focus on the client side or the rule itself, but the log message 'tag not received' is a strong hint that the integration channel (EMS connector) is the root cause — always check the data source before the consumer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ensure the EMS connector is configured under Security Fabric > External Connectors
For a FortiGate to receive ZTNA device tags from FortiClient EMS, the EMS connector must be configured under Security Fabric > External Connectors. Without this connector, the FortiGate has no channel to query or receive tag information, so ZTNA rules referencing tags like 'Compliant' will fail even if the client is healthy. The log showing 'tag not received' points directly at the missing or broken EMS integration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Verify that the FortiClient is connected to the internet
Why it's wrong here
Internet connectivity is not the tag-delivery path; FortiClient EMS pushes device tags to FortiGate over the EMS-FortiGate connection, so the FortiGate's EMS connector status and tag visibility matter first. It is tempting because FortiClient needs connectivity to EMS, but that is a separate link from the FortiGate's tag receipt.
- ✗
Confirm that the ZTNA rule is enabled and using the correct port
Why it's wrong here
Rule enablement and port configuration affect whether the proxy rule matches traffic at all, yet the logs show the rule evaluating and failing on the absent tag, so the tag source is the fault. It is tempting because a disabled rule or wrong port also blocks users, but those produce no tag-evaluation entry.
- ✗
Check if the application server is reachable from the FortiGate
Why it's wrong here
Application server reachability governs the final proxy leg, not tag receipt; the logs already show the tag never arrived, so the failure precedes that connection. It is tempting because blocked access often means an unreachable backend, but here the ZTNA rule never matched on the missing tag.
- ✓
Ensure the EMS connector is configured under Security Fabric > External Connectors
Why this is correct
Tags originate from FortiClient EMS, so the FortiGate cannot receive them without the EMS connector configured under Security Fabric > External Connectors. Without that connector, the ZTNA log shows no tag, blocking the compliant user.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.