NSE7 Advanced VPN and Zero Trust Practice Question
A ZTNA rule is configured to allow access to an internal application only if the client device has the ZTNA tag 'Compliant' and the user is authenticated via SAML. The FortiGate is acting as ZTNA proxy. A user successfully authenticates but the device is not tagged. What happens when the user tries to access the application?
⚠ Common exam trap
NSE7 often tests the misconception that successful SAML authentication alone grants ZTNA access; candidates must remember that ZTNA requires both identity and device posture, and missing tags result in denial, not auto-tagging or redirection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The user is denied access
ZTNA rules on FortiGate enforce both user authentication and device posture (ZTNA tags) as conditions. If the device lacks the required 'Compliant' tag, the rule does not match, so the traffic is denied even though SAML authentication succeeded. ZTNA is zero-trust: authentication alone is insufficient without device compliance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The user is denied access
Why this is correct
ZTNA rules require every configured condition to match; the 'Compliant' ZTNA tag is mandatory alongside SAML authentication. With the device untagged, the rule does not match, so the FortiGate ZTNA proxy denies the user's access to the internal application.
- ✗
The FortiGate dynamically assigns the 'Compliant' tag to the device
Why it's wrong here
Tags are assigned by FortiClient EMS based on endpoint compliance checks, not by the FortiGate enforcing the rule. The FortiGate only reads the tag as a matching condition. Dynamic assignment would let a non-compliant device self-certify, defeating the posture requirement entirely.
- ✗
The user is redirected to a device registration portal
Why it's wrong here
FortiGate ZTNA proxy returns an access-denied or block response when the device tag check fails; it does not host or redirect to a registration portal. Redirection to enrolment is an EMS/agent onboarding function. The rule requires both SAML authentication and the 'Compliant' tag, so the missing tag denies access.
- ✗
The user is granted access because authentication succeeded
Why it's wrong here
The ZTNA rule demands two conditions: SAML authentication and the 'Compliant' device tag. Satisfying only authentication leaves the tag condition unmet, so the FortiGate proxy denies the request. Granting access on authentication alone would defeat device posture checking, which is the point of ZTNA tagging.
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.