Courseiva
Advanced VPN and Zero TrustmediumMultiple SelectObjective-mapped

NSE7 Advanced VPN and Zero Trust Practice Question

A FortiGate is configured as a ZTNA proxy for an internal application. Users authenticate via SAML with FortiGate as the IdP. The administrator wants to enforce that only devices with a valid ZTNA tag can access the application. Which TWO configurations are required?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create a ZTNA rule with tag conditions.

To enforce that only devices with a valid ZTNA tag can access the application, two configurations are required: creating a ZTNA rule with tag conditions (D) and enabling ZTNA tags on the firewall policy that permits access (E). The ZTNA rule defines which tags are allowed, and the firewall policy must have ZTNA tags enabled to apply the rule. Option B (configuring EMS to push tags) is a prerequisite but not an enforcement configuration; options A and C are not required since SAML handles authentication and FortiClient is not mandatory on the proxy itself.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Install a client certificate on each device for authentication.

    Why it's wrong here

    Incorrect. Installing a client certificate is not required because authentication is handled via SAML with FortiGate as the IdP, not certificate-based.

  • Configure FortiClient EMS to push compliance tags to FortiGate.

    Why it's wrong here

    Incorrect. While FortiClient EMS must push compliance tags to FortiGate, this is a prerequisite for tag availability, not a configuration required for the enforcement itself.

  • Set the ZTNA proxy to require FortiClient on the client device.

    Why it's wrong here

    Incorrect. Setting the ZTNA proxy to require FortiClient is not necessary; FortiClient is used for endpoint tagging but the proxy does not need to enforce its presence.

  • Create a ZTNA rule with tag conditions.

    Why this is correct

    Correct. A ZTNA rule with tag conditions is required to specify which ZTNA tags are permitted for access to the application.

  • Enable ZTNA tags on the firewall policy that permits access to the application.

    Why this is correct

    Correct. Enabling ZTNA tags on the firewall policy allows the policy to use ZTNA rules, thus enforcing tag-based access control.

About these practice questions

This NSE7 question is part of Courseiva's 940-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on NSE7

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company is deploying ZTNA to protect an internal application. They want to ensure that only users with devices that have disk encryption enabled and the latest OS patches can access the application. Which THREE components must be configured to achieve this?

hard
  • A.FortiNAC for network admission control
  • B.IPsec VPN to encrypt traffic between client and FortiGate
  • C.FortiClient on the endpoint device
  • D.FortiGate ZTNA access proxy with tag-based rules
  • E.FortiClient EMS to define compliance policies and assign tags

Why C: To enforce device posture requirements like disk encryption and OS patch level, you need FortiClient on the device to report posture, FortiClient EMS to define compliance policies and generate tags, and FortiGate ZTNA proxy to check those tags before granting access.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.