NSE7 Advanced VPN and Zero Trust Practice Question
A FortiGate administrator wants to integrate ZTNA with FortiClient EMS to control access to an internal application based on device posture. The admin has configured a ZTNA tag in EMS for 'AntiVirus enabled' and created a ZTNA rule in FortiGate. What additional configuration is required on the FortiGate to enforce access based on the ZTNA tag?
⚠ Common exam trap
The trap is assuming ZTNA tag enforcement works without an EMS connector — candidates often pick SSL VPN or certificate options, but the exam tests that FortiGate must be an authorized EMS connector to import and enforce EMS-defined ZTNA tags.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the FortiGate as an EMS connector and import the tag
For FortiGate to enforce ZTNA tags created in FortiClient EMS, the FortiGate must be configured as an EMS connector so it can poll and import the tags. Once the EMS connector is authorized and the tags are imported, the ZTNA rule can match on those tags to grant or deny access based on device posture. Without the EMS connector, FortiGate has no visibility into the EMS-defined tags.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure SSL VPN to authenticate users and assign tags
Why it's wrong here
SSL VPN authenticates remote users and assigns tunnel-mode access, but ZTNA tags are delivered to FortiGate through the EMS fabric connector, not SSL VPN. SSL VPN is the right choice when remote users need tunnel access to internal resources, not posture-based application access.
- ✗
Install a client certificate on each FortiClient from the FortiGate
Why it's wrong here
Client certificates provide device identity for mutual TLS, but the ZTNA tag itself is synchronised from FortiClient EMS via the EMS fabric connector, which is what FortiGate needs to match in the ZTNA rule. Certificates suit certificate-based authentication scenarios, not posture tag enforcement.
- ✗
Enable ZTNA inline CASB in the antivirus profile
Why it's wrong here
Inline CASB in the antivirus profile inspects cloud application traffic for data loss and malware; it does not read EMS ZTNA tags or evaluate device posture. It is tempting because both features appear under security profiles, and would be correct for controlling SaaS application usage rather than posture-based access.
- ✓
Configure the FortiGate as an EMS connector and import the tag
Why this is correct
FortiGate must be configured as an EMS connector so it can poll FortiClient EMS and import the ZTNA tag. Without this connector, the firewall has no visibility of the 'AntiVirus enabled' tag, so the ZTNA rule cannot match device posture and enforcement fails.
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on NSE7
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An administrator wants to enforce that only devices with up-to-date antivirus software can access corporate resources via ZTNA. Which FortiClient feature should be used to enforce this requirement?
easy- A.VPN tunnel
- B.Web filter
- C.Application firewall
- ✓ D.ZTNA tags
Why D: ZTNA tags in FortiClient are dynamic posture attributes (such as antivirus status, OS patch level, and domain membership) that FortiGate/FortiClient EMS uses to make zero-trust access decisions. By tagging endpoints based on their antivirus being up-to-date, the administrator can enforce a policy that only tagged devices are allowed to reach corporate resources. This is the core mechanism Fortinet uses for ZTNA posture-based access control.
Variation 2. An administrator wants to ensure that only devices with up-to-date antivirus software can access a sensitive application via ZTNA. Which FortiGate feature should be used to enforce this requirement?
easy- ✓ A.ZTNA tags from FortiClient EMS
- B.SSL deep inspection profile
- C.Application control profile
- D.AntiVirus profile on the firewall policy
Why A: ZTNA tags from FortiClient EMS are used to enforce device posture requirements such as up-to-date antivirus software. FortiClient EMS assesses endpoint compliance and assigns tags, which FortiGate uses in ZTNA access policies to grant or deny access based on the tag. An AntiVirus profile on a firewall policy scans traffic content but does not directly check the device's antivirus status for ZTNA access.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.