NSE7 Advanced VPN and Zero Trust Practice Question
A FortiGate administrator is setting up a ZTNA environment where FortiClient EMS is used to tag endpoints. The administrator wants to create a firewall policy that allows access to a web application only for users whose endpoints have the tag 'Compliant'. Which configuration step is required to use the tag in the firewall policy?
⚠ Common exam trap
The trap here is assuming that tags are added directly to ZTNA server rules or EMS compliance rules, when they must be referenced through dynamic firewall addresses in the policy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a dynamic firewall address that references the ZTNA tag.
To enforce ZTNA tag-based access in a firewall policy, the administrator must create a dynamic firewall address that references the ZTNA tag. This dynamic address is then used in the policy's source or destination field. The FortiGate populates the address with IPs of endpoints that have the tag, as reported by FortiClient EMS. This allows granular control based on endpoint compliance status.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a ZTNA server and add the tag to the server's rule.
Why it's wrong here
A ZTNA server is used to define the protected application and its access rules, but tags are not directly added to the server's rule. Instead, tags are used in firewall policies via dynamic addresses. The ZTNA server configuration focuses on the application mapping and proxy settings, not on tag enforcement in the policy.
- ✓
Create a dynamic firewall address that references the ZTNA tag.
Why this is correct
To use ZTNA tags in firewall policies, you must create a dynamic firewall address that references the tag. This address object is then used as the source or destination in the policy. The FortiGate dynamically populates the address with IP addresses of endpoints that have the tag, as reported by FortiClient EMS. This is the standard method to enforce tag-based access.
- ✗
Enable ZTNA tagging in the global settings.
Why it's wrong here
ZTNA tagging is not enabled via a global setting. It is a feature that is automatically available when FortiClient EMS is integrated with the FortiGate. The administrator must configure the EMS connection and then create dynamic addresses for tags. There is no global toggle to enable ZTNA tagging; it is a matter of configuration.
- ✗
Add the tag to the FortiClient EMS compliance rule.
Why it's wrong here
Tags are generated by FortiClient EMS based on compliance rules, but you do not add the tag to the compliance rule itself. The compliance rule defines the conditions that must be met for an endpoint to be considered compliant. Once the endpoint meets the conditions, EMS assigns the tag. The firewall policy then uses that tag via a dynamic address.
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.