NSE7 Advanced VPN and Zero Trust Practice Question
A FortiGate administrator is configuring ZTNA inline CASB to control access to a SaaS application. The administrator wants to block uploads of files containing sensitive data while allowing other operations. Which ZTNA inline CASB configuration is required to achieve this?
⚠ Common exam trap
The trap here is assuming that CASB or application control alone can block uploads based on file content, when DLP is required for content inspection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a ZTNA rule with an inline CASB profile that has a DLP profile configured to block files with sensitive data.
ZTNA inline CASB on FortiGate can inspect traffic to SaaS applications using security profiles. To block uploads of files containing sensitive data, a DLP profile must be configured with rules that detect sensitive data and set the action to block. This DLP profile is then referenced in the inline CASB profile within the ZTNA rule. This combination allows the FortiGate to inspect file contents and block only those that match sensitive data patterns, while allowing other uploads.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a ZTNA rule with an inline CASB profile and enable 'sensitive-data-block' in the CASB settings.
Why it's wrong here
There is no 'sensitive-data-block' setting in the inline CASB profile. Sensitive data blocking is achieved through a DLP profile, which is separate from the CASB profile. The CASB profile handles application discovery and control, while DLP handles content inspection. This option references a non-existent setting and would not enforce the required blocking.
- ✗
Create a ZTNA rule with a CASB profile that has 'file-upload-block' enabled.
Why it's wrong here
While CASB profiles can block file uploads, they do not inspect file contents for sensitive data. The requirement is to block only files containing sensitive data, not all uploads. A blanket file-upload-block would be too restrictive. Instead, a DLP profile is needed to inspect content and block based on data patterns. This option does not provide the granularity required.
- ✓
Create a ZTNA rule with an inline CASB profile that has a DLP profile configured to block files with sensitive data.
Why this is correct
ZTNA inline CASB uses security profiles, including DLP, to inspect traffic to SaaS applications. By attaching a DLP profile that detects and blocks sensitive data, the FortiGate can prevent uploads of such files. The ZTNA rule applies the inline CASB profile to the traffic, and the DLP profile enforces the blocking action. This is the correct configuration to meet the requirement.
- ✗
Create a ZTNA rule with an application control profile that blocks the upload action for the SaaS application.
Why it's wrong here
Application control can block specific actions, but it does not inspect file contents for sensitive data. It can block uploads entirely, but not conditionally based on data content. The requirement is to block only sensitive files, which requires DLP inspection. Application control alone cannot achieve this level of granularity. Therefore, this option is insufficient.
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.