Courseiva

NSE7 Advanced VPN and Zero Trust Practice Question

A FortiGate administrator is configuring a ZTNA rule that uses a proxy-based policy to inspect traffic to a web application. The administrator wants to ensure that only users who have a valid certificate installed on their endpoint are allowed access. The certificate is issued by the corporate PKI and is stored in the user's certificate store. Which ZTNA configuration element should the administrator use to enforce this requirement?

⚠ Common exam trap

The trap here is assuming that FortiClient EMS compliance checks alone can enforce certificate-based access, when only client certificate authentication in the proxy rule validates the certificate during the connection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Client certificate authentication in the ZTNA proxy rule

Client certificate authentication in the ZTNA proxy rule is the correct choice because it enforces certificate validation during the TLS handshake. The FortiGate acts as a proxy and can request a client certificate, verify it against a trusted CA, and check revocation. This provides strong authentication that the user possesses a valid certificate from the corporate PKI. Other options either rely on endpoint compliance reporting or are for different access methods, and they do not provide the same cryptographic assurance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Client certificate authentication in the ZTNA proxy rule

    Why this is correct

    Client certificate authentication in a ZTNA proxy rule requires the client to present a valid certificate during the TLS handshake. The FortiGate validates the certificate against a configured CA and can enforce additional checks such as revocation status. This directly ensures that only users with a valid corporate PKI certificate are granted access, matching the scenario's requirement.

  • ✗

    ZTNA tagging with a dynamic firewall address

    Why it's wrong here

    ZTNA tagging uses FortiClient EMS tags to dynamically populate firewall addresses based on endpoint compliance. It does not validate client certificates presented during the TLS handshake. While tagging can enforce compliance, it relies on the EMS agent reporting, not on the presence of a specific certificate in the user's certificate store. This would not satisfy the requirement to check for a valid certificate.

  • ✗

    FortiClient EMS compliance rule with certificate check

    Why it's wrong here

    FortiClient EMS compliance rules can check for the presence of certificates on the endpoint, but they do not validate the certificate during the ZTNA connection. The EMS check is performed by the FortiClient agent and reported to the FortiGate, which is separate from the TLS handshake. An attacker could bypass the check by spoofing the EMS report, whereas client certificate authentication provides cryptographic proof.

  • ✗

    SSL VPN with certificate authentication

    Why it's wrong here

    SSL VPN with certificate authentication is used for remote access VPN, not for ZTNA proxy rules. While it can enforce client certificates, it does not apply to ZTNA traffic to web applications. The scenario specifically mentions a ZTNA rule with a proxy-based policy, so SSL VPN configuration is irrelevant and would not enforce the requirement for ZTNA access.

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.