Courseiva

NSE7 Advanced VPN and Zero Trust Practice Question

An administrator has deployed a ZTNA configuration on a FortiGate where remote users authenticate through FortiClient EMS. The administrator wants to ensure that only devices with an up-to-date operating system and active antivirus are granted access to an internal web application. The FortiGate is configured as the ZTNA access proxy. Which FortiGate component or configuration is required to enforce these device compliance checks?

⚠ Common exam trap

It's easy for candidates to confuse authentication with authorization based on device posture, assuming that any form of certificate or VPN automatically enforces compliance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure a ZTNA server with a tag that references the FortiClient EMS compliance tags and apply it in the ZTNA policy.

ZTNA on FortiGate integrates with FortiClient EMS to receive compliance tags. Using these tags in a ZTNA policy allows enforcement of device posture before granting access. This dynamic tagging ensures that only devices meeting the defined compliance criteria can reach the protected application, aligning with zero-trust principles.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure an IPsec VPN tunnel between FortiClient and FortiGate and apply a firewall policy with antivirus scanning.

    Why it's wrong here

    IPsec VPN with antivirus scanning inspects traffic for malware but does not check endpoint compliance such as OS patch level. It also changes the access method from ZTNA to traditional VPN, which is not the stated architecture. This does not provide the granular, pre-access device checks required.

  • ✗

    Create a firewall policy that uses a schedule to allow access only during business hours, assuming devices are patched.

    Why it's wrong here

    A time-based schedule does not assess device compliance. It merely restricts access by time, which is unrelated to OS updates or antivirus status. This would not enforce the required security posture and could allow non-compliant devices during allowed hours. Thus, it fails to meet the scenario's requirements.

  • ✓

    Configure a ZTNA server with a tag that references the FortiClient EMS compliance tags and apply it in the ZTNA policy.

    Why this is correct

    FortiGate ZTNA can use dynamic tags received from FortiClient EMS to enforce endpoint compliance. The ZTNA policy can match on these tags, ensuring only compliant devices access the protected resource. This is the correct method for integrating EMS compliance checks into ZTNA access decisions.

  • ✗

    Enable client certificate authentication on the ZTNA server and require a specific certificate issued by the EMS.

    Why it's wrong here

    Client certificates verify identity, not device compliance posture. They do not check OS patch level or antivirus status. While certificates can be part of authentication, they do not enforce the dynamic compliance requirements described. Therefore, this approach does not meet the scenario's need for real-time compliance enforcement.

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.