Courseiva

NSE7 Advanced VPN and Zero Trust Practice Question

A FortiGate administrator is deploying ZTNA to provide secure access to internal web applications. The administrator wants to ensure that only devices with up-to-date antivirus signatures are granted access. Which FortiGate component should be used to enforce this requirement?

⚠ Common exam trap

The trap here is assuming that ZTNA proxy rules or firewall antivirus profiles can enforce endpoint compliance, when in fact compliance enforcement requires FortiClient EMS integration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

FortiClient EMS compliance rules.

In FortiGate ZTNA, endpoint compliance is enforced through integration with FortiClient EMS. FortiClient EMS compliance rules define the required posture, such as antivirus signature version, and FortiGate queries EMS for the compliance status of the device. ZTNA rules then use this information to allow or deny access. This ensures that only compliant devices can reach protected applications.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SSL VPN portal with host checking.

    Why it's wrong here

    SSL VPN portal with host checking is used for SSL VPN connections, not for ZTNA. While host checking can verify endpoint compliance, it is specific to SSL VPN and does not apply to ZTNA proxy access. ZTNA uses a different mechanism, typically involving FortiClient EMS tags and ZTNA rules.

  • ✗

    ZTNA proxy rules with application mapping.

    Why it's wrong here

    ZTNA proxy rules with application mapping are used to define which applications are accessible through the ZTNA proxy. They do not enforce endpoint compliance such as antivirus signature updates. Application mapping is about identifying and controlling access to specific applications, not about assessing device health.

  • ✗

    Firewall policies with antivirus security profiles.

    Why it's wrong here

    Firewall policies with antivirus security profiles inspect traffic for viruses but do not enforce endpoint compliance before granting access. They are applied to traffic that is already allowed by the policy. They cannot check if the endpoint has up-to-date antivirus signatures; they only scan the traffic for malicious content.

  • ✓

    FortiClient EMS compliance rules.

    Why this is correct

    FortiClient EMS compliance rules allow administrators to define endpoint posture requirements, such as up-to-date antivirus signatures, and enforce them. When integrated with FortiGate ZTNA, the FortiGate can query FortiClient EMS for device compliance status and grant or deny access based on those rules. This is the correct component for enforcing endpoint compliance in a ZTNA deployment.

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.