Courseiva

NSE7 Advanced VPN and Zero Trust Practice Question

An administrator configures ZTNA with FortiClient EMS. The goal is to restrict access to an internal application based on device posture. The administrator configures a ZTNA tag for 'Compliant' that checks antivirus and OS patch status. Which TWO additional steps are required on the FortiGate to enforce access based on this tag?

⚠ Common exam trap

NSE7 often tests the misconception that simply creating a ZTNA tag is sufficient, ignoring the need for a ZTNA policy and access proxy to enforce it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a ZTNA policy that includes the 'Compliant' tag as a required condition

Option B is correct because the FortiGate enforces ZTNA tag-based posture by referencing the 'Compliant' tag as a matching condition inside a ZTNA policy (ztna-policy), which is what actually allows or denies the user's traffic based on device posture. Option C is correct because ZTNA on FortiGate requires a ZTNA access proxy (ztna access-proxy) that defines the protected internal application, its real server, and the listening/portal parameters; without it there is no ZTNA object for the policy to protect. Option A is not required because SSL deep inspection is a UTM/content-inspection feature and is not needed to match ZTNA tags. Option D is not required because the FortiClient EMS certificate is used for EMS fabric authorization/connector trust, not for enforcing a ZTNA tag in the access policy. Option E is not required because a plain firewall policy with the EMS connector as source does not enforce ZTNA tag posture; tag enforcement is done through the ZTNA policy and access proxy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable SSL deep inspection on the firewall policy

    Why it's wrong here

    Deep inspection decrypts TLS traffic to detect threats; it does not evaluate ZTNA posture tags. Enforcement needs the tag applied to the policy and the EMS fabric connector/ZTNA tag reference configured on the FortiGate. Deep inspection would be correct where malware inspection inside encrypted sessions is the requirement.

  • ✓

    Create a ZTNA policy that includes the 'Compliant' tag as a required condition

    Why this is correct

    The tag alone enforces nothing; a ZTNA policy on the FortiGate must reference the 'Compliant' tag as a matching condition so posture status drives the allow or deny decision. Without this policy binding, the tag is merely reported by FortiClient EMS and never evaluated.

  • ✓

    Create a ZTNA access proxy for the internal application

    Why this is correct

    ZTNA requires an access proxy to front the internal application, terminating client connections and applying posture checks before forwarding traffic. Creating the access proxy on the FortiGate satisfies the enforcement point the tag-based policy needs to protect the application.

  • ✗

    Import the FortiClient EMS certificate to FortiGate

    Why it's wrong here

    Importing the EMS certificate only establishes trust for the connection between FortiGate and EMS; it enforces no posture check by itself. It is tempting because certificate import is a genuine prerequisite for EMS connectivity, but the tag must still be applied as a firewall policy source to restrict access.

  • ✗

    Configure a firewall policy with source set to the EMS connector

    Why it's wrong here

    Setting the firewall policy source to the EMS connector matches traffic by EMS identity, not by the ZTNA tag, so posture compliance is never evaluated and non-compliant devices pass. It is tempting because EMS connector objects are used in ZTNA policies, but the tag must appear as the policy source.

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.