Courseiva

NSE7 Advanced VPN and Zero Trust Practice Question

A FortiGate administrator is implementing Zero Trust Network Access (ZTNA) for remote users accessing internal applications. The administrator wants to ensure that only authenticated and compliant devices can access the applications, and that all traffic is inspected. Which two actions are required to achieve this? (Choose two.)

⚠ Common exam trap

The trap here is thinking that SSL VPN or a specific ZTNA mode is required, while the core requirements are application mappings and posture integration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable device posture checking by integrating FortiClient EMS with the FortiGate.

To implement ZTNA with Zero Trust principles, you must define the applications via a ZTNA server with application mappings, and integrate FortiClient EMS to enforce device posture. These two actions ensure that only authenticated and compliant devices can access the specified applications. The ZTNA server proxies the traffic, and the EMS integration provides the necessary compliance data for policy decisions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set the ZTNA server to use 'transparent' mode instead of 'proxy' mode for all applications.

    Why it's wrong here

    The choice between transparent and proxy mode depends on the application and network design. Transparent mode is used when the ZTNA server is inline and the client's IP is preserved, while proxy mode terminates the connection. Neither mode is universally required for ZTNA; it depends on the deployment. The key requirements are application mappings and posture checking, not a specific mode.

  • ✗

    Create a firewall policy that allows all traffic from the ZTNA server to the internal network.

    Why it's wrong here

    A firewall policy that allows all traffic would bypass the Zero Trust principle of least privilege. Instead, policies should be specific, allowing only the necessary traffic from the ZTNA server to the protected applications. An allow-all policy would defeat the purpose of ZTNA and could expose the network to unauthorized access. The policy should match the ZTNA server and destination applications with appropriate security profiles.

  • ✓

    Enable device posture checking by integrating FortiClient EMS with the FortiGate.

    Why this is correct

    Integrating FortiClient EMS allows the FortiGate to receive device posture tags, such as compliance status. These tags can then be used in firewall policies to enforce that only compliant devices access applications. Without this integration, the FortiGate cannot verify device posture, and ZTNA would not be able to enforce Zero Trust principles based on device health. This is a critical component for compliance enforcement.

  • ✓

    Configure a ZTNA server with application mappings for each internal application.

    Why this is correct

    A ZTNA server is required to define the applications that users can access. Application mappings specify the internal servers and ports. Without this, the FortiGate does not know which applications to proxy and protect. This is a fundamental step in ZTNA deployment. The ZTNA server acts as the gateway for access, enforcing policies and providing secure connectivity.

  • ✗

    Configure SSL VPN for remote users to connect before accessing ZTNA applications.

    Why it's wrong here

    ZTNA is designed to provide access without requiring a full SSL VPN tunnel. Remote users typically connect via FortiClient or a web browser to the ZTNA server, which then proxies the application. Requiring SSL VPN adds an unnecessary layer and does not align with the Zero Trust model of direct, per-application access. ZTNA can be used independently of SSL VPN.

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.