Courseiva

NSE7 Advanced VPN and Zero Trust Practice Question

A FortiGate administrator is deploying ZTNA to protect an internal application. Users connect with FortiClient, which establishes a tunnel to the FortiGate. The administrator wants the FortiGate to verify the user's identity and device posture before allowing access to the application. Which FortiGate feature performs this verification as part of the ZTNA access proxy?

⚠ Common exam trap

The trap here is equating traditional NAT or VIP publishing with ZTNA, when only the ZTNA access proxy validates identity and posture before granting application access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ZTNA access proxy with authentication and posture check configured on the ZTNA server.

ZTNA enforcement happens at the access proxy, which is configured on the ZTNA server and performs authentication plus posture checks before allowing traffic to the internal application. It replaces traditional NAT-based publishing with identity- and compliance-aware access. Phase2 selectors, NAT, and VIP objects operate at the network layer and cannot verify user identity or device posture.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A firewall policy with NAT enabled to hide the internal application address.

    Why it's wrong here

    NAT translates addresses and ports but does not authenticate users or check endpoint posture. Enabling NAT on a policy would obscure the internal server address without adding any identity or compliance enforcement. It does not participate in ZTNA verification and would not prevent a non-compliant device from reaching the application if other controls are absent.

  • ✗

    A virtual IP (VIP) object that maps an external address to the application server.

    Why it's wrong here

    A VIP performs destination NAT to publish an internal server on an external address. It has no awareness of user identity or device posture and cannot enforce ZTNA policies. While a VIP might be used in traditional publishing, ZTNA replaces that model with an access proxy that performs authentication and compliance checks, so a VIP alone would not meet the requirement.

  • ✗

    IPsec phase2 selectors that restrict traffic to the application subnet.

    Why it's wrong here

    Phase2 selectors define which traffic is encrypted and permitted through an IPsec tunnel, but they do not evaluate user identity or device posture. They operate at the network layer and cannot consult FortiClient EMS tags or authentication groups. Using selectors alone would grant access based on subnet reachability, not on ZTNA identity and compliance checks.

  • ✓

    ZTNA access proxy with authentication and posture check configured on the ZTNA server.

    Why this is correct

    The ZTNA access proxy terminates the client tunnel and enforces authentication and posture checks before forwarding traffic to the protected application. It is the component that validates the user's identity and device compliance as part of the ZTNA server configuration. This directly performs the verification the administrator requires for access to the internal application.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.