Courseiva
Advanced VPN and Zero Trust →mediumMultiple Choice

NSE7 Advanced VPN and Zero Trust Practice Question

A FortiGate administrator needs to integrate with FortiNAC to enforce network access control for wired and wireless devices. The administrator wants FortiNAC to dynamically assign VLANs based on the device's security posture. Which FortiNAC feature enables this?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

NAC policies

NAC policies define rules for device classification and VLAN assignment based on posture assessment results.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DHCP fingerprinting

    Why it's wrong here

    DHCP fingerprinting identifies device operating system from DHCP request attributes, feeding device profiling rather than posture-based VLAN assignment. It is tempting because it informs access decisions, and would be correct when the goal is identifying unknown endpoints by OS signature rather than applying a VLAN from a security-posture evaluation.

  • ✓

    NAC policies

    Why this is correct

    NAC policies are the rule engine that evaluates a device's security posture and host attributes, then applies the matching VLAN assignment to the switch port or wireless SSID. This satisfies the requirement for dynamic, posture-based VLAN assignment rather than static port configuration.

  • ✗

    RADIUS accounting

    Why it's wrong here

    RADIUS accounting reports session start, stop and usage data for billing and auditing; it carries no posture attribute that triggers VLAN reassignment. It is tempting because it flows through the same RADIUS path as authorisation, and would be correct when the requirement is tracking session duration or bandwidth consumption.

  • ✗

    SNMP traps

    Why it's wrong here

    SNMP traps deliver asynchronous device notifications such as link state changes to FortiNAC, but they do not convey endpoint security posture for VLAN decisions. It is tempting because FortiNAC consumes SNMP for topology awareness, and would be correct when monitoring switch port or interface events rather than enforcing posture.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.