Courseiva

NSE7 Advanced VPN and Zero Trust Practice Question

A FortiGate is configured as a ZTNA proxy for a web application. Users report that after authenticating, they receive a '502 Bad Gateway' error. What is the most likely cause?

⚠ Common exam trap

NSE7 often tests whether candidates can distinguish HTTP error codes in proxy scenarios — 502 means the proxy cannot reach the backend, while 401/403 indicate auth/posture issues, and 503 indicates the service itself is unavailable.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The backend server is unreachable from the FortiGate.

A '502 Bad Gateway' error from a reverse proxy like FortiGate's ZTNA proxy indicates that the proxy successfully received the client request but could not reach the backend server. The most likely cause is that the backend server is unreachable from the FortiGate — due to network issues, firewall rules, or the server being down. This is the classic meaning of a 502 in proxy architectures.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The backend server is unreachable from the FortiGate.

    Why this is correct

    A 502 Bad Gateway means the FortiGate's ZTNA proxy could not establish a connection to the protected backend server. Authentication succeeded, so the failure lies upstream of the client, pointing to an unreachable or down backend.

  • ✗

    The ZTNA proxy is not configured with a valid SSL certificate.

    Why it's wrong here

    An invalid certificate causes browser TLS warnings or handshake failures, not a 502, which indicates the proxy could not obtain a valid response from the backend server. Certificate configuration is tempting because ZTNA proxies do terminate TLS, but that is the correct fix when clients cannot establish the connection at all.

  • ✗

    The user's device posture is not compliant.

    Why it's wrong here

    Non-compliant posture triggers a posture-check denial or redirect, not a 502, which signals the proxy reached no valid upstream response. Posture checks are tempting because they gate ZTNA access, but they are the correct cause when users are blocked before authentication completes, not after.

  • ✗

    The ZTNA rule is not using the correct source interface.

    Why it's wrong here

    An incorrect source interface prevents the ZTNA rule from matching, so traffic is dropped or bypasses the proxy entirely rather than producing a 502 from an established proxy session. Interface selection is tempting because rule matching depends on it, but it is the correct cause when connections never reach the proxy.

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.