Courseiva
Advanced VPN and Zero Trust →mediumMultiple Choice

NSE7 Advanced VPN and Zero Trust Practice Question

A ZTNA rule is configured to allow access to an internal application only if the client device has the ZTNA tag 'Compliant' and the user is authenticated via SAML. The FortiGate is acting as ZTNA proxy. A user successfully authenticates but the device is not tagged. What happens when the user tries to access the application?

⚠ Common exam trap

NSE7 often tests the misconception that successful SAML authentication alone grants ZTNA access; candidates must remember that ZTNA requires both identity and device posture, and missing tags result in denial, not auto-tagging or redirection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The user is denied access

ZTNA rules on FortiGate enforce both user authentication and device posture (ZTNA tags) as conditions. If the device lacks the required 'Compliant' tag, the rule does not match, so the traffic is denied even though SAML authentication succeeded. ZTNA is zero-trust: authentication alone is insufficient without device compliance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The user is denied access

    Why this is correct

    ZTNA rules require every configured condition to match; the 'Compliant' ZTNA tag is mandatory alongside SAML authentication. With the device untagged, the rule does not match, so the FortiGate ZTNA proxy denies the user's access to the internal application.

  • ✗

    The FortiGate dynamically assigns the 'Compliant' tag to the device

    Why it's wrong here

    Tags are assigned by FortiClient EMS based on endpoint compliance checks, not by the FortiGate enforcing the rule. The FortiGate only reads the tag as a matching condition. Dynamic assignment would let a non-compliant device self-certify, defeating the posture requirement entirely.

  • ✗

    The user is redirected to a device registration portal

    Why it's wrong here

    FortiGate ZTNA proxy returns an access-denied or block response when the device tag check fails; it does not host or redirect to a registration portal. Redirection to enrolment is an EMS/agent onboarding function. The rule requires both SAML authentication and the 'Compliant' tag, so the missing tag denies access.

  • ✗

    The user is granted access because authentication succeeded

    Why it's wrong here

    The ZTNA rule demands two conditions: SAML authentication and the 'Compliant' device tag. Satisfying only authentication leaves the tag condition unmet, so the FortiGate proxy denies the request. Granting access on authentication alone would defeat device posture checking, which is the point of ZTNA tagging.

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.