NSE7 Advanced VPN and Zero Trust Practice Question
A FortiGate administrator is configuring a ZTNA rule that uses a proxy-based policy to inspect traffic to a web application. The administrator wants to ensure that only users who have a valid certificate installed on their endpoint are allowed access. The certificate is issued by the corporate PKI and is stored in the user's certificate store. Which ZTNA configuration element should the administrator use to enforce this requirement?
⚠ Common exam trap
The trap here is assuming that FortiClient EMS compliance checks alone can enforce certificate-based access, when only client certificate authentication in the proxy rule validates the certificate during the connection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Client certificate authentication in the ZTNA proxy rule
Client certificate authentication in the ZTNA proxy rule is the correct choice because it enforces certificate validation during the TLS handshake. The FortiGate acts as a proxy and can request a client certificate, verify it against a trusted CA, and check revocation. This provides strong authentication that the user possesses a valid certificate from the corporate PKI. Other options either rely on endpoint compliance reporting or are for different access methods, and they do not provide the same cryptographic assurance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Client certificate authentication in the ZTNA proxy rule
Why this is correct
Client certificate authentication in a ZTNA proxy rule requires the client to present a valid certificate during the TLS handshake. The FortiGate validates the certificate against a configured CA and can enforce additional checks such as revocation status. This directly ensures that only users with a valid corporate PKI certificate are granted access, matching the scenario's requirement.
- ✗
ZTNA tagging with a dynamic firewall address
Why it's wrong here
ZTNA tagging uses FortiClient EMS tags to dynamically populate firewall addresses based on endpoint compliance. It does not validate client certificates presented during the TLS handshake. While tagging can enforce compliance, it relies on the EMS agent reporting, not on the presence of a specific certificate in the user's certificate store. This would not satisfy the requirement to check for a valid certificate.
- ✗
FortiClient EMS compliance rule with certificate check
Why it's wrong here
FortiClient EMS compliance rules can check for the presence of certificates on the endpoint, but they do not validate the certificate during the ZTNA connection. The EMS check is performed by the FortiClient agent and reported to the FortiGate, which is separate from the TLS handshake. An attacker could bypass the check by spoofing the EMS report, whereas client certificate authentication provides cryptographic proof.
- ✗
SSL VPN with certificate authentication
Why it's wrong here
SSL VPN with certificate authentication is used for remote access VPN, not for ZTNA proxy rules. While it can enforce client certificates, it does not apply to ZTNA traffic to web applications. The scenario specifically mentions a ZTNA rule with a proxy-based policy, so SSL VPN configuration is irrelevant and would not enforce the requirement for ZTNA access.
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.