NSE7 Advanced VPN and Zero Trust Practice Question
An administrator is configuring ZTNA inline CASB for a SaaS application. The goal is to block upload of files containing credit card numbers. Which configuration components are required?
⚠ Common exam trap
NSE7 often tests the misconception that endpoint DLP or web filtering alone can enforce SaaS DLP — candidates must recognize that inline CASB requires ZTNA application configuration, a CASB profile, and SSL inspection to inspect encrypted SaaS traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a ZTNA application with a CASB profile and SSL inspection
ZTNA inline CASB for a SaaS application requires configuring a ZTNA application entry that includes a CASB profile and SSL inspection. The CASB profile defines the DLP rules (e.g., blocking credit card numbers), and SSL inspection decrypts the traffic so the CASB can inspect file uploads. This combination is the required configuration to enforce inline DLP on SaaS uploads.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use FortiClient to enforce DLP on endpoints
Why it's wrong here
FortiClient endpoint DLP inspects files locally before they leave the device, so it cannot inspect traffic to a SaaS application or block uploads from unmanaged endpoints. It is tempting because endpoint DLP suits scenarios where all users run managed FortiClient and the requirement is on-device data loss prevention, not inline CASB inspection.
- ✗
Configure an IPsec VPN between FortiGate and the SaaS provider
Why it's wrong here
An IPsec VPN only encrypts traffic between the FortiGate and the SaaS provider; it cannot inspect file contents for credit card numbers. It is tempting because IPsec secures connectivity to cloud services, and would be correct for protecting data in transit, not for inline CASB data-loss prevention.
- ✓
Configure a ZTNA application with a CASB profile and SSL inspection
Why this is correct
SSL inspection decrypts the TLS session so the CASB profile can inspect file payloads for credit card patterns before upload completes. Without decryption, the traffic is opaque and data-loss rules cannot match content. The ZTNA application binds the CASB profile to the SaaS destination, satisfying the inline blocking requirement.
- ✗
Configure a web filter profile with DLP sensor
Why it's wrong here
A web filter profile inspects HTTP destinations and categories, not file payloads, so it cannot detect credit card numbers inside uploads. It is tempting because web filtering genuinely blocks SaaS access by URL category, and pairing it with a DLP sensor sounds comprehensive. Inline CASB instead requires a DLP profile applied to the SaaS application's traffic.
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.