Courseiva
Advanced VPN and Zero Trust →mediumMultiple Choice

NSE7 Advanced VPN and Zero Trust Practice Question

A FortiGate administrator is deploying ZTNA to provide access to internal applications for remote users. The administrator wants to ensure that users can only access the specific applications they are authorized for, and that the ZTNA access proxy performs authentication and authorization before forwarding traffic. Which FortiGate component must be configured to define the protected applications and the authentication rules for ZTNA access?

⚠ Common exam trap

The trap here is assuming that a standard firewall policy or SSL VPN portal can provide ZTNA application-level access control without a ZTNA server configuration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A ZTNA server configuration that includes the virtual host, server certificate, and application mappings.

The ZTNA server configuration on the FortiGate is the component that defines the access proxy, including the virtual host, server certificate, and application mappings for protected applications. The ZTNA policy then references this server to enforce authentication and authorization. Without the ZTNA server, there is no application-level proxy to control access, so users could not be restricted to specific applications.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A firewall policy with the destination set to the internal application server's IP address and the action set to accept.

    Why it's wrong here

    A firewall policy alone does not provide ZTNA access proxy functionality. While it can permit traffic to an application server, it does not perform user authentication or application-level mapping. ZTNA requires a ZTNA server configuration to act as the access proxy, and the firewall policy references that server. Without the ZTNA server, the policy would simply allow direct network access, defeating the ZTNA model.

  • ✗

    An SSL VPN portal with a tunnel mode configuration that maps internal subnets to remote users.

    Why it's wrong here

    SSL VPN tunnel mode provides network-level access by assigning an IP address to the client and routing traffic to internal subnets. It does not provide application-level access control or per-application authentication. ZTNA is designed to replace this broad access model with application-specific access, so an SSL VPN portal is not the component that defines protected applications for ZTNA.

  • ✓

    A ZTNA server configuration that includes the virtual host, server certificate, and application mappings.

    Why this is correct

    The ZTNA server on the FortiGate defines the access proxy that protects internal applications. It includes the virtual host name, the server certificate used for TLS, and the application mappings that specify which internal resources are published and how they are accessed. Authentication and authorization are enforced through the ZTNA policy that references the ZTNA server, ensuring users only reach authorized applications.

  • ✗

    An IPsec dial-up VPN with extended authentication configured on the phase 1 gateway.

    Why it's wrong here

    IPsec dial-up VPN with XAuth provides network-level access and authentication, but it does not define application mappings or perform application-level authorization. ZTNA requires an access proxy that understands application-level requests, which IPsec cannot provide. Therefore, an IPsec dial-up configuration is not the component used to define protected applications for ZTNA.

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.