Courseiva
Advanced VPN and Zero Trust →mediumMultiple Choice

NSE7 Advanced VPN and Zero Trust Practice Question

A FortiGate administrator is deploying ZTNA to replace SSL VPN for remote access. The requirement is that endpoint posture (antivirus status, OS patch level) must be verified before a user is allowed to reach internal web applications through the ZTNA proxy, and that posture must be re-evaluated on each new connection. Which FortiGate configuration element is required to enforce this dynamic, per-connection posture check?

⚠ Common exam trap

The trap here is assuming that SSL VPN host checking and ZTNA posture enforcement are interchangeable, when only the EMS-tag-based access-proxy policy evaluates posture dynamically for ZTNA traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A ZTNA server object referencing an access-proxy policy, with an EMS connector tag used as the policy source.

ZTNA on FortiGate enforces access through an access-proxy policy, and endpoint posture is expressed as EMS connector tags that FortiClient EMS updates. Because the policy matches those tags at connection time, a device that falls out of compliance stops matching and loses access on its next request, satisfying the per-connection posture requirement. Identity-only mechanisms cannot deliver this behaviour.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    An SSL VPN portal with host-check enforcement bound to the user group.

    Why it's wrong here

    SSL VPN host checking validates posture only at tunnel login time and is tied to the SSL VPN portal, not to ZTNA proxy traffic. Because the requirement is per-connection re-evaluation for ZTNA access to internal web applications, an SSL VPN host-check policy cannot provide the continuous, per-session posture enforcement described and would leave ZTNA traffic evaluated only by static firewall policy.

  • ✗

    An IPsec dial-up tunnel with extended authentication and a peer group tied to the user group.

    Why it's wrong here

    IPsec dial-up with XAuth authenticates a user at tunnel establishment, but posture compliance data from FortiClient EMS is not carried in this way and the tunnel would not be re-evaluated per web request. This design also does not use the ZTNA proxy path, so it cannot enforce dynamic endpoint posture for internal web application access as required.

  • ✗

    A firewall authentication rule using a local user group with two-factor authentication enabled.

    Why it's wrong here

    Firewall authentication verifies identity, not endpoint posture, and it does not consult FortiClient EMS compliance tags. Even with two-factor authentication, the policy would grant access based solely on credentials, so an unhealthy endpoint could still reach the internal applications. This fails the stated requirement that antivirus and patch status be checked before and during access.

  • ✓

    A ZTNA server object referencing an access-proxy policy, with an EMS connector tag used as the policy source.

    Why this is correct

    ZTNA access-proxy policies match on EMS connector tags that represent live endpoint posture, so each new proxy connection is evaluated against current compliance state. Binding the access-proxy policy to the EMS connector tag is what makes posture dynamic and per-connection, which is exactly the behaviour requested for protecting the internal web applications behind the ZTNA server.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.