NSE7 Advanced VPN and Zero Trust Practice Question
A FortiGate administrator is configuring a ZTNA rule to protect an internal application. The administrator wants to ensure that only devices with a specific compliance tag are allowed, while all other devices are denied. The administrator has already created the ZTNA server and the FortiClient EMS tags. What is the correct way to enforce this requirement in the firewall policy?
⚠ Common exam trap
The trap here is thinking that a deny policy placed after an allow policy will block non-compliant devices, when the allow policy must itself require the compliance tag to match.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a firewall policy that references the ZTNA server and includes the compliance tag as a source or destination condition, so only tagged devices match the allow rule.
ZTNA tag enforcement is achieved by referencing the ZTNA server in the firewall policy and adding the compliance tag as a matching condition. Only devices that present the tag match the allow policy; all others are denied by the implicit deny. Separate deny policies, ZTNA server mappings, and schedules do not provide the required tag-based control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a firewall policy with the ZTNA server as the destination and a schedule that only allows access during business hours, which implicitly blocks non-compliant devices.
Why it's wrong here
A schedule controls when a policy is active, not which devices are allowed. It does not evaluate device compliance tags, so non-compliant devices could still access the application during the allowed hours. The requirement is to restrict access based on a compliance tag, which must be a policy matching condition.
- ✗
Create a firewall policy that allows all users to the ZTNA server, then create a separate deny policy for non-compliant devices below it.
Why it's wrong here
Firewall policies are evaluated from top to bottom, so an allow policy above a deny policy would permit all users before the deny policy is reached. To enforce compliance, the allow policy itself must include the compliance tag as a matching condition. A separate deny policy below an allow-all policy would never be evaluated for the permitted traffic.
- ✓
Create a firewall policy that references the ZTNA server and includes the compliance tag as a source or destination condition, so only tagged devices match the allow rule.
Why this is correct
ZTNA tag-based enforcement is implemented by referencing the ZTNA server in the policy and using the compliance tag as a matching condition. Only devices that have the tag will match the allow policy, and all others will fall through to the implicit deny. This directly enforces the requirement without needing a separate deny rule.
- ✗
Configure the ZTNA server to require the compliance tag in its application mapping, which automatically denies untagged devices at the proxy level.
Why it's wrong here
The ZTNA server defines the protected application and access proxy behavior, but tag enforcement is performed by the firewall policy. Application mappings do not include compliance tag conditions for device posture. Relying on the ZTNA server alone would not enforce the tag requirement as described.
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.