Courseiva
Advanced VPN and Zero Trust →mediumMultiple Choice

NSE7 Advanced VPN and Zero Trust Practice Question

A FortiGate administrator has deployed ZTNA with FortiClient EMS tagging. A remote user's endpoint is tagged as 'Compliant' in EMS, but the FortiGate ZTNA policy still denies the user's connection to the internal web application. The administrator confirmed the EMS connector status on the FortiGate shows 'Connected' and the tag is visible in the FortiGate's device inventory. What is the most likely cause of the access denial?

⚠ Common exam trap

The trap here is assuming that a visible EMS tag guarantees the ZTNA policy will be reached, ignoring top-down policy evaluation order.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The ZTNA firewall policy references the tag as a source address, but the user's traffic is being matched by a broader policy above it that denies access.

A correctly tagged endpoint can still be denied if a policy earlier in the top-down evaluation order matches the traffic first. The FortiGate applies the first matching firewall policy, so a broad deny or restrictive allow placed above the ZTNA tag-based policy will intercept the connection before the tag-based rule is evaluated. Verifying policy order and specificity resolves the denial.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The ZTNA firewall policy references the tag as a source address, but the user's traffic is being matched by a broader policy above it that denies access.

    Why this is correct

    Firewall policies are evaluated top-down, and the first matching policy is applied. If a broader deny or restrictive policy appears above the ZTNA tag-based policy and matches the user's source, destination, or service, the ZTNA policy is never reached. This is the most common reason a correctly tagged device still gets denied despite the EMS connector showing Connected and the tag being visible in inventory.

  • ✗

    FortiClient EMS requires the endpoint to be re-registered with the FortiGate before the tag can be used in a ZTNA policy.

    Why it's wrong here

    Re-registration is not required for ZTNA tag-based policies. The FortiGate learns tags dynamically through the EMS connector, and once the tag appears in the device inventory, it can be referenced in a ZTNA firewall policy. Requiring re-registration would defeat the purpose of dynamic compliance tagging and is not part of the standard FortiGate ZTNA workflow with FortiClient EMS.

  • ✗

    The ZTNA policy must use the EMS tag as a destination address rather than a source address to match the endpoint.

    Why it's wrong here

    In FortiGate ZTNA policies, EMS tags are used to identify the endpoint as the source of traffic, not the destination. The destination is typically the protected application or ZTNA server. Using the tag as a destination would be technically incorrect and would not match the user's outbound connection to the internal web application.

  • ✗

    The FortiGate requires a valid SSL certificate on the endpoint before it will honor any EMS compliance tag in a ZTNA policy.

    Why it's wrong here

    FortiGate does not require an endpoint SSL certificate to honor EMS compliance tags. Tags are transmitted from FortiClient EMS to the FortiGate over the EMS connector using the authorized EMS connection, and endpoint certificate validation is not part of the tag enforcement path. Requiring a client certificate would be a separate authentication mechanism, not a prerequisite for tag-based ZTNA.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.