NSE7 Advanced VPN and Zero Trust Practice Question
A FortiGate administrator has configured a ZTNA access proxy for an internal web application and wants to enforce device compliance before allowing access. The administrator has integrated FortiClient EMS and created ZTNA tags for compliant devices. Users with compliant devices are still being denied access. The firewall policy references the ZTNA server and the tag. What should the administrator verify first?
⚠ Common exam trap
The trap here is assuming that a compliant device automatically satisfies the policy, when the policy only matches if the tag name received from EMS matches the tag name configured on the FortiGate.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
That the ZTNA tags are correctly received from FortiClient EMS and that the tag names in the firewall policy match the tags assigned to the devices.
When ZTNA tag-based enforcement denies compliant users, the most common cause is a mismatch between the tags received from FortiClient EMS and the tag names referenced in the firewall policy. Confirming that the FortiGate has the expected tags and that the policy uses the exact same names is the correct first step. Certificate issues, protocol substitution, and policy ordering do not fit the reported symptom of denied compliant users.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
That the FortiGate is configured to use SSL VPN instead of ZTNA for the internal application, because ZTNA does not support tag-based policies.
Why it's wrong here
ZTNA on FortiOS does support tag-based policies through integration with FortiClient EMS, so replacing it with SSL VPN is unnecessary and incorrect. The denial is more likely caused by a tag mismatch or a policy ordering issue. This option misstates a core capability of ZTNA and would not resolve the described problem.
- ✗
That the ZTNA server is configured with a valid SSL certificate and that the certificate chain is trusted by the client.
Why it's wrong here
A certificate problem would typically cause a browser warning or a TLS failure, not a policy denial for compliant users who can reach the application. The scenario states that users are being denied access, which suggests the policy or tag evaluation is failing rather than the TLS handshake. Certificate validity is important but is not the first thing to check for this specific symptom.
- ✓
That the ZTNA tags are correctly received from FortiClient EMS and that the tag names in the firewall policy match the tags assigned to the devices.
Why this is correct
ZTNA policy matching depends on the tag names being identical between what FortiClient EMS sends and what the firewall policy references. If the tag is misspelled or not received, the policy will not match even if the device is compliant. Verifying tag reception and name matching is the most direct way to diagnose why compliant users are denied.
- ✗
That the firewall policy is placed after a broader allow policy that matches the same users and services.
Why it's wrong here
Policy order is a valid consideration, but the scenario specifically describes compliant users being denied while the ZTNA policy references the correct server and tag. If a broader allow policy were matching first, the users would be allowed, not denied. The denial points to a tag evaluation or matching problem rather than an earlier permit rule.
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.