Courseiva
Advanced VPN and Zero Trust →mediumMultiple Select

NSE7 Advanced VPN and Zero Trust Practice Question

A FortiGate is configured as a ZTNA proxy. The administrator wants to ensure that only devices with a specific ZTNA tag assigned by FortiClient EMS are allowed to access the application. Which two configuration steps are required? (Choose two.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a ZTNA access rule with a condition matching the tag

Option E is correct because the FortiGate must first learn the ZTNA tags that FortiClient EMS assigns to endpoints; this is done by configuring the EMS connector (FortiClient EMS fabric connector) and importing/synchronizing the tags, which then appear under ZTNA tags on the FortiGate. Option D is correct because enforcement of a specific tag is performed by a ZTNA access rule (access-proxy rule) whose condition matches the imported tag, so only devices presenting that tag are granted access to the protected application. Option A is incorrect because simply setting the ZTNA proxy as the destination with an 'allow only ZTNA' style setting does not itself match a specific EMS tag; tag-based authorization requires the access rule in D. Option B is incorrect because a policy allowing all traffic to the ZTNA proxy would not restrict access by tag and would undermine the requirement. Option C is incorrect because there is no 'set ztna-tag' interface command; tags are matched in ZTNA access rules, not enabled on an interface.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure a firewall policy with the ZTNA proxy as destination and enable 'allow only ZTNA'

    Why it's wrong here

    Enabling 'allow only ZTNA' on the policy restricts access to ZTNA-tagged sessions, but the tag itself must still be matched; the stem requires the specific EMS-assigned tag. It is tempting because this setting is genuinely part of ZTNA proxy policy configuration, and would suffice if any valid ZTNA tag were acceptable.

  • ✗

    Create a firewall policy allowing all traffic to the ZTNA proxy

    Why it's wrong here

    A permit-all policy to the ZTNA proxy bypasses tag enforcement entirely, so untagged devices reach the application. It is tempting because a broad allow rule is a normal starting point when building policy scaffolding, and would be correct only if every device were already trusted.

  • ✗

    Enable 'set ztna-tag' on the FortiGate interface

    Why it's wrong here

    'set ztna-tag' is not a valid interface-level command; tags are assigned by FortiClient EMS and matched in firewall policy objects, not enabled on interfaces. It is tempting because interface-level ZTNA settings do exist, and would be relevant when binding a proxy to an interface, not for tag enforcement.

  • ✓

    Create a ZTNA access rule with a condition matching the tag

    Why this is correct

    The access rule must include a condition matching the specific ZTNA tag so FortiGate only admits devices carrying that EMS-assigned attribute. Without this tag condition, the rule cannot distinguish compliant devices from others, defeating the zero-trust requirement.

  • ✓

    Import the ZTNA tag from EMS into FortiGate

    Why this is correct

    FortiGate must import the ZTNA tag from FortiClient EMS before it can be referenced in a firewall policy, satisfying the requirement that only tagged devices gain access. Without this import, the tag does not exist locally and the policy cannot enforce the device-based restriction.

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.