Courseiva

NSE7 Advanced VPN and Zero Trust Practice Question

A FortiGate administrator is implementing Zero Trust Network Access using ZTNA tags from FortiClient EMS to control access to internal applications. The administrator must ensure that devices losing compliance are denied access and that only managed endpoints can reach the applications. Which two configuration actions are required to meet these goals? (Choose two.)

⚠ Common exam trap

The trap here is focusing on certificates and routing for ZTNA when the actual enforcement depends on EMS authorization and tag matching in the access-proxy policy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Authorize the FortiGate on FortiClient EMS so it can receive endpoint compliance tags through the EMS connector.

Enforcing posture-based ZTNA requires two things: the FortiGate must be authorized on FortiClient EMS so the EMS connector can deliver dynamic compliance tags, and a ZTNA access-proxy policy must match those tags to allow or deny application access. Together they ensure only compliant, managed endpoints reach the internal applications and that access is revoked when compliance is lost.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable SSL VPN host checking and bind it to the same user group used by the ZTNA policy.

    Why it's wrong here

    SSL VPN host checking applies to SSL VPN portal logins and does not govern ZTNA proxy sessions. Binding it to the user group would not affect whether ZTNA requests are allowed based on EMS tags. This action adds unrelated configuration and does not contribute to denying non-compliant devices on the ZTNA path.

  • ✗

    Configure a static route for the ZTNA application subnets pointing to the EMS connector interface.

    Why it's wrong here

    The EMS connector is a management channel for tag exchange, not a data path for application traffic. Routing application subnets toward it would not deliver traffic to the ZTNA proxy and would break connectivity. ZTNA traffic follows normal routing to the access-proxy virtual interface, so this action is unrelated to enforcing compliance tags.

  • ✓

    Authorize the FortiGate on FortiClient EMS so it can receive endpoint compliance tags through the EMS connector.

    Why this is correct

    The EMS connector on the FortiGate only receives dynamic endpoint tags after the FortiGate is authorized on FortiClient EMS. Without this authorization, the FortiGate cannot learn which endpoints are compliant, so tag-based ZTNA policies would never match. Authorizing the FortiGate is therefore a prerequisite for enforcing posture-driven access decisions in this scenario.

  • ✗

    Import the EMS server certificate into the FortiGate's local certificate store and set it as the ZTNA server certificate.

    Why it's wrong here

    The ZTNA server certificate is presented to clients connecting to the ZTNA portal and is unrelated to receiving compliance tags from EMS. While certificate trust matters for the EMS connector, importing the EMS certificate as the ZTNA server certificate does not enable tag-based enforcement. This action does not help deny non-compliant endpoints or restrict access to managed devices.

  • ✓

    Create a ZTNA access-proxy policy that matches the EMS compliance tags and apply it to the ZTNA server rule.

    Why this is correct

    The access-proxy policy is where tag matching is enforced for ZTNA traffic. By referencing EMS compliance tags as the source, the policy grants access only while the endpoint remains compliant and denies it once the tag is removed. Applying this policy to the ZTNA server rule ensures that internal application requests are evaluated against live posture, meeting the requirement.

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.