NSE7 Advanced VPN and Zero Trust Practice Question
A FortiGate administrator is deploying ZTNA to replace SSL VPN for remote access. The requirement is that endpoint posture (antivirus status, OS patch level) must be verified before a user is allowed to reach internal web applications through the ZTNA proxy, and that posture must be re-evaluated on each new connection. Which FortiGate configuration element is required to enforce this dynamic, per-connection posture check?
⚠ Common exam trap
The trap here is assuming that SSL VPN host checking and ZTNA posture enforcement are interchangeable, when only the EMS-tag-based access-proxy policy evaluates posture dynamically for ZTNA traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A ZTNA server object referencing an access-proxy policy, with an EMS connector tag used as the policy source.
ZTNA on FortiGate enforces access through an access-proxy policy, and endpoint posture is expressed as EMS connector tags that FortiClient EMS updates. Because the policy matches those tags at connection time, a device that falls out of compliance stops matching and loses access on its next request, satisfying the per-connection posture requirement. Identity-only mechanisms cannot deliver this behaviour.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
An SSL VPN portal with host-check enforcement bound to the user group.
Why it's wrong here
SSL VPN host checking validates posture only at tunnel login time and is tied to the SSL VPN portal, not to ZTNA proxy traffic. Because the requirement is per-connection re-evaluation for ZTNA access to internal web applications, an SSL VPN host-check policy cannot provide the continuous, per-session posture enforcement described and would leave ZTNA traffic evaluated only by static firewall policy.
- ✗
An IPsec dial-up tunnel with extended authentication and a peer group tied to the user group.
Why it's wrong here
IPsec dial-up with XAuth authenticates a user at tunnel establishment, but posture compliance data from FortiClient EMS is not carried in this way and the tunnel would not be re-evaluated per web request. This design also does not use the ZTNA proxy path, so it cannot enforce dynamic endpoint posture for internal web application access as required.
- ✗
A firewall authentication rule using a local user group with two-factor authentication enabled.
Why it's wrong here
Firewall authentication verifies identity, not endpoint posture, and it does not consult FortiClient EMS compliance tags. Even with two-factor authentication, the policy would grant access based solely on credentials, so an unhealthy endpoint could still reach the internal applications. This fails the stated requirement that antivirus and patch status be checked before and during access.
- ✓
A ZTNA server object referencing an access-proxy policy, with an EMS connector tag used as the policy source.
Why this is correct
ZTNA access-proxy policies match on EMS connector tags that represent live endpoint posture, so each new proxy connection is evaluated against current compliance state. Binding the access-proxy policy to the EMS connector tag is what makes posture dynamic and per-connection, which is exactly the behaviour requested for protecting the internal web applications behind the ZTNA server.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.