Courseiva
Advanced VPN and Zero Trust →mediumMultiple Choice

NSE7 Advanced VPN and Zero Trust Practice Question

A FortiGate administrator is implementing ZTNA in reverse-proxy mode to protect an internal web application. Remote users authenticate through FortiClient with EMS tags, and the administrator wants to enforce that only users with a valid certificate and a compliant endpoint can access the application. After configuring the ZTNA server and access proxy, the administrator notices that users without the certificate are still able to reach the application. What is the most likely cause?

⚠ Common exam trap

The trap here is assuming that enabling ZTNA automatically enforces client certificates, when in fact the access proxy rule must explicitly require them.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The access proxy rule is missing a client-certificate requirement, so it allows any user who matches the source criteria.

In ZTNA reverse-proxy mode, the access proxy rule is the enforcement point for authentication and authorization. If the rule does not explicitly require a client certificate, users without one can still access the application as long as they meet other conditions. The administrator must edit the access proxy rule to add a client-certificate requirement. This ensures that only users presenting a valid certificate are allowed, closing the bypass.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The FortiClient EMS tags are not being synchronized, so the FortiGate cannot evaluate endpoint compliance.

    Why it's wrong here

    EMS tag synchronization issues would affect endpoint compliance checks, not certificate validation. The scenario specifically mentions users without a certificate gaining access, which points to a missing certificate requirement rather than a tagging problem. If EMS tags were the issue, compliant users might be denied or non-compliant users allowed based on tags, but the certificate would still be enforced independently. The symptom described does not match a tag synchronization failure.

  • ✓

    The access proxy rule is missing a client-certificate requirement, so it allows any user who matches the source criteria.

    Why this is correct

    In FortiGate ZTNA reverse-proxy mode, the access proxy rule defines the authentication and authorization conditions. If the rule does not explicitly require a client certificate, users without one can still pass if they meet other criteria. The administrator must edit the access proxy rule to require a valid client certificate. This is the most likely cause because the symptom is selective bypass of certificate enforcement while other authentication still works.

  • ✗

    The ZTNA server is configured in transparent mode, which bypasses client certificate checks.

    Why it's wrong here

    FortiGate ZTNA supports reverse-proxy and transparent modes, but transparent mode does not inherently bypass client certificate checks. In transparent mode, the FortiGate acts as a Layer 2 bridge and can still enforce certificate-based authentication if configured. The scenario describes reverse-proxy mode, so transparent mode is not relevant. The issue is not the mode but the absence of a certificate requirement in the access proxy rule.

  • ✗

    The ZTNA server is configured to use HTTP instead of HTTPS, so client certificates are not validated.

    Why it's wrong here

    If the ZTNA server were using HTTP, the access proxy would not request or validate client certificates, but this would also prevent any certificate-based authentication from working. The scenario states that users with certificates are authenticated successfully; only those without are improperly allowed. Changing to HTTPS alone would not fix the missing enforcement because the certificate requirement is enforced by the access proxy rule, not merely by the protocol. The root cause lies in the policy matching logic, not the transport protocol.

About these practice questions

Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.