NSE7 Advanced VPN and Zero Trust Practice Question
A FortiGate administrator is configuring a ZTNA rule to protect an internal web server. The administrator wants to ensure that only users who authenticate via SAML and whose devices have the latest antivirus signature are allowed access. Which FortiGate feature must be used to enforce this?
⚠ Common exam trap
The trap here is assuming that SSL VPN host checking is equivalent to ZTNA posture checks, but ZTNA provides application-specific access with EMS integration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ZTNA proxy policy with user group and device posture check.
To enforce both SAML authentication and device posture checks for application access, the administrator must use a ZTNA proxy policy. This policy integrates with FortiClient EMS to receive device tags and enforces access based on user group and posture. Other options either provide broader network access or lack the granular application-level control required.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Firewall policy with user authentication and antivirus scanning.
Why it's wrong here
A firewall policy with user authentication and antivirus scanning can enforce user identity and scan traffic, but it does not check device posture (e.g., antivirus signature version). It also does not provide the reverse proxy capabilities of ZTNA. This option lacks the necessary device compliance enforcement.
- ✓
ZTNA proxy policy with user group and device posture check.
Why this is correct
A ZTNA proxy policy allows the administrator to combine user authentication (via SAML) and device posture checks (such as antivirus signature version). This policy enforces access based on both identity and device compliance, meeting the requirement. It is the core component for ZTNA access control.
- ✗
SSL VPN with host checking and SAML authentication.
Why it's wrong here
SSL VPN with host checking can enforce device compliance and SAML authentication, but it grants network-level access, not application-specific access. ZTNA is designed for granular application access. While it could work, it is not the feature specifically meant for ZTNA scenarios and may provide broader access than intended.
- ✗
IPsec VPN with extended authentication (XAuth) and FortiClient compliance.
Why it's wrong here
IPsec VPN with XAuth and FortiClient compliance is used for remote access VPNs, not for ZTNA. It does not provide application-level proxy policies. This option would not enforce the specific ZTNA requirements and is not the correct feature.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.