Courseiva
Advanced VPN and Zero Trust →mediumMultiple Choice

NSE7 Advanced VPN and Zero Trust Practice Question

A FortiGate is configured as a ZTNA access proxy for an internal application. The administrator wants to enforce device compliance using FortiClient EMS tags before allowing access. Which configuration step is required to ensure that only endpoints with a specific EMS tag can access the application?

⚠ Common exam trap

The trap here is thinking that simply referencing an EMS tag in a rule is enough, without first establishing the EMS fabric connector and tag synchronization.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure FortiClient EMS as a fabric connector and synchronize EMS tags.

Enforcing device compliance via EMS tags in ZTNA requires FortiGate to be integrated with FortiClient EMS using a fabric connector. This integration synchronizes EMS tags, which can then be used as source objects in ZTNA rules. Without this, tags are not available, and compliance cannot be enforced. Other steps like device detection or deny actions are secondary.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set the ZTNA rule action to 'deny' for non-compliant devices.

    Why it's wrong here

    While setting a deny action for non-compliant devices is part of the policy, it requires a source that identifies non-compliant devices. Without EMS tag integration, you cannot distinguish compliant from non-compliant devices. Thus, this action alone does not enforce EMS tag-based access. The prerequisite is the EMS connector configuration.

  • ✓

    Configure FortiClient EMS as a fabric connector and synchronize EMS tags.

    Why this is correct

    To use EMS tags in ZTNA rules, FortiGate must be integrated with FortiClient EMS via a fabric connector. This allows FortiGate to receive dynamic tag information about endpoints. After synchronization, the EMS tags become available as source objects in ZTNA rules. This is the essential step to enforce compliance based on EMS tags.

  • ✗

    Create a ZTNA rule with a source address of the EMS tag.

    Why it's wrong here

    ZTNA rules use source addresses that can be EMS tags, but simply referencing an EMS tag as a source does not enforce compliance. The tag must be dynamically populated by EMS based on compliance. Without proper EMS integration and tag assignment, the rule would not function as intended. This step alone is insufficient; additional configuration is needed.

  • ✗

    Enable 'device-detection' on the ZTNA rule.

    Why it's wrong here

    Device detection is used for identifying devices on the network, but it does not enforce EMS tag-based compliance. It may help with device profiling, but it does not integrate with EMS tags. Enabling device detection alone would not restrict access based on EMS compliance tags. Therefore, it is not the required step.

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.