Courseiva

NSE7 Advanced VPN and Zero Trust Practice Question

A FortiGate administrator is deploying ZTNA with a FortiClient EMS that tags endpoints as 'compliant' or 'non-compliant'. The administrator wants the FortiGate to grant access only to endpoints that FortiClient EMS has tagged as compliant, while still allowing non-compliant endpoints to reach a remediation portal. Which two configuration elements on the FortiGate must be aligned to enforce this?

⚠ Common exam trap

The trap here is believing that AD group membership or traffic inspection can substitute for FortiClient EMS compliance tags.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A FortiClient EMS fabric connector with the correct EMS tags, and firewall policies that use those tags as source or destination criteria.

FortiClient EMS tags are surfaced on FortiGate through the EMS fabric connector. The FortiGate must be configured with the connector (host, credentials, and tag synchronization) so EMS tags become usable address objects, and firewall or ZTNA policies must reference those tag objects as match criteria. A separate policy can then allow non-compliant endpoints to reach the remediation portal.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A ZTNA server with an SSL certificate and a firewall policy referencing an EMS-tag-based address object, plus a second policy permitting non-compliant endpoints to the remediation portal.

    Why it's wrong here

    ZTNA servers and policies are needed, but the stem specifically asks about FortiClient EMS tag enforcement. Simply referencing an EMS-tag address object does not by itself synchronize tags; the FortiGate must have the EMS connector configured and the tag must be resolved via the fabric connector. A ZTNA server alone does not enforce EMS compliance tags.

  • ✗

    An LDAP connector to Active Directory and user group policies that map AD groups to the compliant tag.

    Why it's wrong here

    LDAP/AD integration provides user identity, not endpoint compliance state. AD group membership cannot substitute for FortiClient EMS compliance tags because compliance reflects the endpoint's posture (AV, patch level, etc.), not directory membership. Using AD groups here would grant or deny access based on identity rather than compliance, which is the opposite of the requirement.

  • ✗

    A ZTNA proxy rule with an inline CASB profile and a DLP sensor that inspects endpoint traffic for compliance indicators.

    Why it's wrong here

    Inline CASB and DLP inspect data flows for SaaS usage and data leakage; they do not determine endpoint compliance posture. Compliance tags come from FortiClient EMS telemetry, not from traffic inspection. Using CASB/DLP here would not enforce the compliant/non-compliant distinction and would add unnecessary inspection overhead.

  • ✓

    A FortiClient EMS fabric connector with the correct EMS tags, and firewall policies that use those tags as source or destination criteria.

    Why this is correct

    The FortiGate must have the FortiClient EMS fabric connector configured so it can query EMS for endpoint tags, and the firewall or ZTNA policies must reference those EMS tag objects as match criteria. Without the connector, tags are not resolvable; without policy references, tags do not gate traffic. Together they enforce compliant-only access while a separate policy can permit remediation traffic.

About these practice questions

Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.