Courseiva
Advanced VPN and Zero Trust →mediumMultiple Choice

NSE7 Advanced VPN and Zero Trust Practice Question

A FortiGate administrator is deploying ZTNA for remote users who connect through FortiClient. The administrator wants to enforce device compliance based on the FortiClient EMS tags. The FortiGate is already integrated with FortiClient EMS. Which configuration step is required to use EMS tags in a ZTNA policy?

⚠ Common exam trap

The trap here is assuming that EMS tags are used directly in firewall policies or SSL VPN portals, rather than being referenced in ZTNA rules as device posture checks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a ZTNA rule and specify the EMS tags as a device posture check.

ZTNA rules on FortiGate can enforce device compliance by referencing EMS tags as device posture checks. The FortiGate queries FortiClient EMS for tags and applies them in the ZTNA rule to permit or deny access. This ensures that only compliant devices can reach protected resources. The other options either misplace EMS tags in firewall policies or confuse ZTNA with SSL VPN.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable ZTNA on the SSL VPN portal and map EMS tags to user groups.

    Why it's wrong here

    ZTNA is not enabled on the SSL VPN portal; it is a separate access method. Mapping EMS tags to user groups is not a standard configuration. ZTNA uses device posture tags directly in ZTNA rules. This option misrepresents how ZTNA integrates with EMS tags.

  • ✗

    Configure a ZTNA server and add the EMS tags as a source in the firewall policy.

    Why it's wrong here

    EMS tags are not directly used as a source in a firewall policy. ZTNA policies use device posture tags through the ZTNA rule configuration, not as traditional firewall policy sources. The source in a firewall policy typically refers to IP addresses or user groups, not EMS tags. Therefore, this option does not correctly integrate EMS tags into ZTNA enforcement.

  • ✓

    Create a ZTNA rule and specify the EMS tags as a device posture check.

    Why this is correct

    In ZTNA, device posture is enforced through ZTNA rules that reference EMS tags. The FortiGate retrieves tags from FortiClient EMS and uses them in the ZTNA rule to allow or deny access based on device compliance. This is the correct method to enforce EMS-based compliance for ZTNA.

  • ✗

    Define an address object for the EMS server and use it in a firewall policy.

    Why it's wrong here

    Creating an address object for the EMS server only allows the FortiGate to communicate with EMS; it does not enforce device compliance. ZTNA requires posture checks based on EMS tags, not just connectivity to the EMS server. This option does not achieve the goal of using EMS tags in ZTNA policies.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.