NSE7 Advanced VPN and Zero Trust Practice Question
A FortiGate administrator is deploying ZTNA to provide secure access to internal web applications. The administrator wants to ensure that only devices with up-to-date antivirus signatures are granted access. Which FortiGate component should be used to enforce this requirement?
⚠ Common exam trap
The trap here is assuming that ZTNA proxy rules or firewall antivirus profiles can enforce endpoint compliance, when in fact compliance enforcement requires FortiClient EMS integration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
FortiClient EMS compliance rules.
In FortiGate ZTNA, endpoint compliance is enforced through integration with FortiClient EMS. FortiClient EMS compliance rules define the required posture, such as antivirus signature version, and FortiGate queries EMS for the compliance status of the device. ZTNA rules then use this information to allow or deny access. This ensures that only compliant devices can reach protected applications.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SSL VPN portal with host checking.
Why it's wrong here
SSL VPN portal with host checking is used for SSL VPN connections, not for ZTNA. While host checking can verify endpoint compliance, it is specific to SSL VPN and does not apply to ZTNA proxy access. ZTNA uses a different mechanism, typically involving FortiClient EMS tags and ZTNA rules.
- ✗
ZTNA proxy rules with application mapping.
Why it's wrong here
ZTNA proxy rules with application mapping are used to define which applications are accessible through the ZTNA proxy. They do not enforce endpoint compliance such as antivirus signature updates. Application mapping is about identifying and controlling access to specific applications, not about assessing device health.
- ✗
Firewall policies with antivirus security profiles.
Why it's wrong here
Firewall policies with antivirus security profiles inspect traffic for viruses but do not enforce endpoint compliance before granting access. They are applied to traffic that is already allowed by the policy. They cannot check if the endpoint has up-to-date antivirus signatures; they only scan the traffic for malicious content.
- ✓
FortiClient EMS compliance rules.
Why this is correct
FortiClient EMS compliance rules allow administrators to define endpoint posture requirements, such as up-to-date antivirus signatures, and enforce them. When integrated with FortiGate ZTNA, the FortiGate can query FortiClient EMS for device compliance status and grant or deny access based on those rules. This is the correct component for enforcing endpoint compliance in a ZTNA deployment.
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.