NSE7 Advanced VPN and Zero Trust Practice Question
A FortiGate administrator is troubleshooting a ZTNA access proxy rule that is not matching traffic from a specific user group. The rule is configured with a source of 'ZTNA_Users' and a destination of the internal web server. The administrator confirms that the user is authenticated and has the correct EMS tag. Which FortiGate CLI command should the administrator use to verify that the ZTNA rule is being evaluated correctly?
⚠ Common exam trap
The trap here is using authentication debugging commands when the issue is with ZTNA rule evaluation, not authentication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
diagnose wad debug enable category ztna
The 'diagnose wad debug enable category ztna' command enables detailed debugging of ZTNA processing in the WAD daemon, which handles access proxy rules. It shows rule matching, user identification, and any errors. Other commands like 'diagnose firewall auth list' only show authentication status, while 'fnbamd' debugging is for authentication daemon issues. For ZTNA rule matching, WAD debug is the correct tool.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
diagnose wad debug enable category ztna
Why this is correct
The 'diagnose wad debug enable category ztna' command enables debugging for ZTNA processing in the WAD daemon. It provides detailed logs about ZTNA rule matching, including source, destination, and user information. This is essential for troubleshooting why a ZTNA rule is not matching traffic. It shows the evaluation process and any errors.
- ✗
diagnose debug application fnbamd -1
Why it's wrong here
This command enables debugging for the FNBAMD daemon, which handles authentication. It is useful for troubleshooting authentication issues but does not cover ZTNA rule matching. Since the user is already authenticated, this command would not help identify why the ZTNA rule is not matching. It is not the correct tool for this scenario.
- ✗
diagnose vpn ike gateway list
Why it's wrong here
This command lists IPsec IKE gateways and their status. It is unrelated to ZTNA access proxy rules. Using this command would not provide any information about ZTNA rule evaluation or matching. It is a distractor because it is a common VPN troubleshooting command but not applicable here.
- ✗
diagnose firewall auth list
Why it's wrong here
This command displays authenticated firewall users and their group memberships. While it can confirm that the user is authenticated, it does not show ZTNA rule evaluation or matching. It is useful for verifying authentication status but does not provide insight into why a ZTNA rule is not matching. Therefore, it is not the best command for this specific troubleshooting.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.