NSE7 Advanced VPN and Zero Trust Practice Question
A FortiGate administrator needs to integrate with FortiNAC to enforce network access control for wired and wireless devices. The administrator wants FortiNAC to dynamically assign VLANs based on the device's security posture. Which FortiNAC feature enables this?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
NAC policies
NAC policies define rules for device classification and VLAN assignment based on posture assessment results.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DHCP fingerprinting
Why it's wrong here
DHCP fingerprinting identifies device operating system from DHCP request attributes, feeding device profiling rather than posture-based VLAN assignment. It is tempting because it informs access decisions, and would be correct when the goal is identifying unknown endpoints by OS signature rather than applying a VLAN from a security-posture evaluation.
- ✓
NAC policies
Why this is correct
NAC policies are the rule engine that evaluates a device's security posture and host attributes, then applies the matching VLAN assignment to the switch port or wireless SSID. This satisfies the requirement for dynamic, posture-based VLAN assignment rather than static port configuration.
- ✗
RADIUS accounting
Why it's wrong here
RADIUS accounting reports session start, stop and usage data for billing and auditing; it carries no posture attribute that triggers VLAN reassignment. It is tempting because it flows through the same RADIUS path as authorisation, and would be correct when the requirement is tracking session duration or bandwidth consumption.
- ✗
SNMP traps
Why it's wrong here
SNMP traps deliver asynchronous device notifications such as link state changes to FortiNAC, but they do not convey endpoint security posture for VLAN decisions. It is tempting because FortiNAC consumes SNMP for topology awareness, and would be correct when monitoring switch port or interface events rather than enforcing posture.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.