NSE7 Advanced VPN and Zero Trust Practice Question
A FortiGate administrator is implementing ZTNA to control access to internal web applications. The administrator wants to ensure that only devices with a valid FortiClient EMS tag can access the applications. Which ZTNA component must be configured on the FortiGate to enforce this?
⚠ Common exam trap
The trap here is assuming that SSL VPN host-check or firewall user groups can enforce device posture for ZTNA, when only ZTNA proxy policies with device posture checks provide that capability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ZTNA proxy policy with a device posture check referencing the EMS tag.
ZTNA on FortiGate uses proxy policies to enforce access control at the application level. To restrict access based on device compliance, the administrator must configure a ZTNA proxy policy that includes a device posture check referencing the FortiClient EMS tag. This ensures that only devices with the correct tag are allowed, aligning with zero-trust access principles.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Firewall policy with a source user group synchronized from EMS.
Why it's wrong here
A firewall policy with a user group from EMS can control access based on user identity, but it does not enforce device posture tags. ZTNA requires device posture checks to ensure the device meets compliance requirements. Without a ZTNA proxy policy that includes device posture, the FortiGate cannot verify the EMS tag, allowing potentially non-compliant devices to access the applications.
- ✗
SSL VPN portal with a host-check profile referencing the EMS tag.
Why it's wrong here
While SSL VPN host-check profiles can enforce endpoint compliance, they are used for remote access VPN, not for ZTNA proxy access to internal web applications. ZTNA requires a proxy policy to inspect and control traffic to applications. Using SSL VPN would not provide the granular, application-level access control that ZTNA offers in this scenario.
- ✓
ZTNA proxy policy with a device posture check referencing the EMS tag.
Why this is correct
ZTNA proxy policies on FortiGate can enforce device posture by referencing tags from FortiClient EMS. By configuring a proxy policy that includes a device posture check, the FortiGate verifies that the connecting device has the required EMS tag before granting access. This ensures that only compliant devices can reach the internal web applications, aligning with zero-trust principles.
- ✗
IPsec VPN tunnel with extended authentication using EMS tags.
Why it's wrong here
IPsec VPN with XAuth can authenticate users, but it does not enforce device posture based on EMS tags for application access. ZTNA is designed for application-level access control with device posture. Using IPsec VPN would not provide the necessary granularity and would not integrate with EMS tags for ZTNA enforcement, making it unsuitable for this requirement.
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.