Courseiva

NSE7 Advanced VPN and Zero Trust Practice Question

A FortiGate administrator wants to use Fortinac for network access control. Which of the following is the PRIMARY function of Fortinac in a network?

⚠ Common exam trap

NSE7 often tests the confusion between Fortinet products, so candidates pick firewall or sandbox functions (DPI, VPN, malware analysis) for FortiNAC when its actual role is identity- and posture-based network access control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Provide network access control by enforcing policies based on device identity and posture

FortiNAC's primary function is network access control (NAC): it identifies devices and users, assesses device posture (e.g., OS patches, antivirus status), and enforces access policies that determine whether a device is allowed on the network and at what level of access. This is the core purpose of FortiNAC in a Fortinet security fabric deployment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Perform deep packet inspection on all traffic

    Why it's wrong here

    FortiNAC performs network access control: device discovery, profiling, and enforcement of admission policy at the network edge. Deep packet inspection belongs to FortiGate's IPS and application control engines. Deep inspection is tempting because FortiNAC integrates with FortiGate, but it does not inspect packet payloads itself.

  • ✗

    Act as a VPN concentrator for remote access

    Why it's wrong here

    FortiNAC enforces admission policy for wired and wireless endpoints; VPN concentration is handled by FortiGate's SSL and IPsec VPN features. The VPN role is tempting because FortiNAC can gate remote-access endpoints via integration, but it does not terminate tunnels or assign addresses itself.

  • ✓

    Provide network access control by enforcing policies based on device identity and posture

    Why this is correct

    FortiNAC enforces access decisions at the network edge using device identity and posture assessment, satisfying the stem's requirement for network access control. It profiles endpoints, checks compliance, and dynamically assigns VLANs or blocks access, which is the primary function distinguishing it from firewalling or authentication alone.

  • ✗

    Provide a cloud-based sandbox for malware analysis

    Why it's wrong here

    FortiNAC handles network access control — profiling devices and applying admission policy; sandboxing is FortiSandbox's function. Sandboxing is tempting because both products feed indicators into FortiGate, yet FortiNAC does not detonate files or analyse malware behaviour in an isolated cloud environment.

About these practice questions

Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.