Courseiva
Advanced VPN and Zero Trust →mediumMultiple Choice

NSE7 Advanced VPN and Zero Trust Practice Question

A FortiGate administrator is troubleshooting a ZTNA deployment. Users report that they can access the ZTNA application, but the EMS tags are not being enforced. The administrator verifies that the FortiGate is connected to FortiClient EMS and that the EMS tags exist. What is the most likely cause?

⚠ Common exam trap

The trap here is assuming that EMS tag enforcement is automatic once EMS is connected, when actually the ZTNA rule must explicitly include a posture check for the tags.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The ZTNA rule does not include a device posture check for the EMS tags.

EMS tag enforcement in ZTNA requires a device posture check in the ZTNA rule. If the rule does not reference EMS tags, they are ignored. The administrator confirmed EMS connectivity and tag existence, so the missing posture check is the likely cause. Other options either would prevent access entirely or are unrelated to tag enforcement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The FortiClient EMS tags are not synchronized with the FortiGate.

    Why it's wrong here

    The administrator verified that the FortiGate is connected to EMS and tags exist. If synchronization were the issue, tags might not appear. However, the problem is that tags are not enforced, which points to rule configuration rather than synchronization. This option is less likely given the verification.

  • ✗

    The ZTNA server configuration is missing the application mapping.

    Why it's wrong here

    If the application mapping were missing, users would not be able to access the application at all. Since users can access it, the mapping is present. The issue is enforcement of EMS tags, not access. This option is incorrect.

  • ✗

    The firewall policy allowing ZTNA traffic does not have UTM profiles applied.

    Why it's wrong here

    UTM profiles are for security inspection, not for EMS tag enforcement. The absence of UTM profiles would not affect tag enforcement. The enforcement is handled by the ZTNA rule's posture check. This option is irrelevant to the issue.

  • ✓

    The ZTNA rule does not include a device posture check for the EMS tags.

    Why this is correct

    If the ZTNA rule lacks a device posture check that references EMS tags, then tags are not enforced. The rule may allow access based solely on user authentication. This is the most likely cause because the FortiGate is connected to EMS and tags exist, but the rule is not configured to use them. This is the correct answer.

About these practice questions

Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.