NSE7 Advanced VPN and Zero Trust Practice Question
A FortiGate administrator is implementing Zero Trust Network Access (ZTNA) for remote users accessing an internal web application. The administrator wants to ensure that only users who have authenticated and whose devices meet posture requirements can reach the application, and that the application itself is never directly exposed to the internet. Which two FortiGate configuration steps are required to achieve this? (Choose two.)
⚠ Common exam trap
The trap here is thinking that publishing the application via a DNAT VIP is part of ZTNA, when ZTNA specifically avoids direct exposure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a firewall policy that matches ZTNA traffic and enforces user authentication and device posture via EMS tags.
ZTNA requires a ZTNA server to define the external FQDN and internal application mapping with a server certificate, and a firewall policy to enforce authentication and device posture using user groups and FortiClient EMS tags. Together these broker access without exposing the application directly to the internet.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a firewall policy that matches ZTNA traffic and enforces user authentication and device posture via EMS tags.
Why this is correct
The firewall policy is where authentication and posture enforcement are applied. By matching ZTNA traffic and referencing user groups plus FortiClient EMS tags, the policy ensures only authenticated and compliant devices are permitted. This is the enforcement point that ties identity and posture to access, which is central to the Zero Trust requirement.
- ✗
Configure a site-to-site IPsec VPN between the remote user's device and the FortiGate.
Why it's wrong here
Site-to-site IPsec is for connecting networks, not individual remote users, and it does not provide per-user authentication or device posture checks. ZTNA uses an access proxy with FortiClient, not a network-level tunnel. Deploying site-to-site IPsec here would not meet the Zero Trust requirement and would not scale to individual remote users.
- ✗
Publish the internal application through a public IP with a DNAT VIP so remote users can connect directly.
Why it's wrong here
Publishing the application with a DNAT VIP directly exposes it to the internet, which contradicts the requirement that the application never be directly exposed. ZTNA is specifically designed to avoid direct exposure by brokering access through the FortiGate. Using a VIP would bypass the ZTNA access proxy and undermine the Zero Trust model.
- ✗
Enable inline CASB on the policy to inspect SaaS application usage.
Why it's wrong here
Inline CASB governs access to and data flow within SaaS applications; it does not broker access to an internal web application. Enabling it here would not provide the ZTNA access proxy or posture enforcement needed. CASB is relevant when the destination is a cloud SaaS service, not an internal application accessed via ZTNA.
- ✓
Configure a ZTNA server that maps an external FQDN to the internal application and references a server certificate.
Why this is correct
A ZTNA server defines the externally reachable FQDN and the internal application mapping, and it terminates the client connection using a server certificate. This is what allows remote users to reach the application through the FortiGate without the application being directly exposed. Without a ZTNA server, there is no access proxy to broker the connection.
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.