Courseiva

NSE7 Advanced VPN and Zero Trust Practice Question

A FortiGate administrator is setting up a ZTNA environment where FortiClient EMS is used to tag endpoints. The administrator wants to create a firewall policy that allows access to a web application only for users whose endpoints have the tag 'Compliant'. Which configuration step is required to use the tag in the firewall policy?

⚠ Common exam trap

The trap here is assuming that tags are added directly to ZTNA server rules or EMS compliance rules, when they must be referenced through dynamic firewall addresses in the policy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a dynamic firewall address that references the ZTNA tag.

To enforce ZTNA tag-based access in a firewall policy, the administrator must create a dynamic firewall address that references the ZTNA tag. This dynamic address is then used in the policy's source or destination field. The FortiGate populates the address with IPs of endpoints that have the tag, as reported by FortiClient EMS. This allows granular control based on endpoint compliance status.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure a ZTNA server and add the tag to the server's rule.

    Why it's wrong here

    A ZTNA server is used to define the protected application and its access rules, but tags are not directly added to the server's rule. Instead, tags are used in firewall policies via dynamic addresses. The ZTNA server configuration focuses on the application mapping and proxy settings, not on tag enforcement in the policy.

  • ✓

    Create a dynamic firewall address that references the ZTNA tag.

    Why this is correct

    To use ZTNA tags in firewall policies, you must create a dynamic firewall address that references the tag. This address object is then used as the source or destination in the policy. The FortiGate dynamically populates the address with IP addresses of endpoints that have the tag, as reported by FortiClient EMS. This is the standard method to enforce tag-based access.

  • ✗

    Enable ZTNA tagging in the global settings.

    Why it's wrong here

    ZTNA tagging is not enabled via a global setting. It is a feature that is automatically available when FortiClient EMS is integrated with the FortiGate. The administrator must configure the EMS connection and then create dynamic addresses for tags. There is no global toggle to enable ZTNA tagging; it is a matter of configuration.

  • ✗

    Add the tag to the FortiClient EMS compliance rule.

    Why it's wrong here

    Tags are generated by FortiClient EMS based on compliance rules, but you do not add the tag to the compliance rule itself. The compliance rule defines the conditions that must be met for an endpoint to be considered compliant. Once the endpoint meets the conditions, EMS assigns the tag. The firewall policy then uses that tag via a dynamic address.

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.