NSE7 Advanced VPN and Zero Trust Practice Question
A FortiGate administrator is configuring SSL VPN for remote users. The administrator wants to ensure that users can only access specific internal resources based on their user group. Which SSL VPN configuration mode should be used to provide granular access control?
⚠ Common exam trap
The trap here is thinking that web mode bookmarks or split tunneling settings alone can enforce granular access control, when in fact firewall policies based on user groups and destinations are required.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Tunnel mode with firewall policies that match user groups and specific internal subnets.
SSL VPN tunnel mode combined with firewall policies that reference user groups and specific internal subnets provides granular access control. The firewall policies determine which users can access which resources, based on their group membership. This is the standard method for enforcing least privilege in SSL VPN deployments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Web mode with a portal configured to show only specific bookmarks.
Why it's wrong here
Web mode with bookmarks can restrict which applications are visible, but it does not enforce access control at the network level. Users might still access other resources if they know the URLs. Granular access control requires firewall policies that reference user groups to permit or deny traffic to specific destinations.
- ✗
Web mode with a realm that maps to an LDAP group.
Why it's wrong here
A realm in web mode can map to an LDAP group for authentication, but it does not provide granular access control to internal resources. Authentication only verifies identity; authorization to specific subnets is enforced by firewall policies. Web mode is limited to web-based applications and does not grant full network access.
- ✓
Tunnel mode with firewall policies that match user groups and specific internal subnets.
Why this is correct
In tunnel mode, the SSL VPN client receives an IP address and routes traffic to internal resources. By creating firewall policies that match user groups and specific destination subnets, the administrator can enforce granular access control. Only users in the allowed groups can reach the defined resources, while others are denied.
- ✗
Tunnel mode with split tunneling disabled.
Why it's wrong here
Tunnel mode with split tunneling disabled forces all traffic through the VPN, but it does not inherently provide granular access control based on user groups. Access control is applied through firewall policies that match user groups, regardless of split tunneling. Disabling split tunneling affects traffic routing, not resource-level permissions.
Visual reference
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.