Courseiva

NSE7 Advanced VPN and Zero Trust Practice Question

An administrator is configuring ZTNA inline CASB for a SaaS application. The goal is to block upload of files containing credit card numbers. Which configuration components are required?

⚠ Common exam trap

NSE7 often tests the misconception that endpoint DLP or web filtering alone can enforce SaaS DLP — candidates must recognize that inline CASB requires ZTNA application configuration, a CASB profile, and SSL inspection to inspect encrypted SaaS traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure a ZTNA application with a CASB profile and SSL inspection

ZTNA inline CASB for a SaaS application requires configuring a ZTNA application entry that includes a CASB profile and SSL inspection. The CASB profile defines the DLP rules (e.g., blocking credit card numbers), and SSL inspection decrypts the traffic so the CASB can inspect file uploads. This combination is the required configuration to enforce inline DLP on SaaS uploads.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use FortiClient to enforce DLP on endpoints

    Why it's wrong here

    FortiClient endpoint DLP inspects files locally before they leave the device, so it cannot inspect traffic to a SaaS application or block uploads from unmanaged endpoints. It is tempting because endpoint DLP suits scenarios where all users run managed FortiClient and the requirement is on-device data loss prevention, not inline CASB inspection.

  • ✗

    Configure an IPsec VPN between FortiGate and the SaaS provider

    Why it's wrong here

    An IPsec VPN only encrypts traffic between the FortiGate and the SaaS provider; it cannot inspect file contents for credit card numbers. It is tempting because IPsec secures connectivity to cloud services, and would be correct for protecting data in transit, not for inline CASB data-loss prevention.

  • ✓

    Configure a ZTNA application with a CASB profile and SSL inspection

    Why this is correct

    SSL inspection decrypts the TLS session so the CASB profile can inspect file payloads for credit card patterns before upload completes. Without decryption, the traffic is opaque and data-loss rules cannot match content. The ZTNA application binds the CASB profile to the SaaS destination, satisfying the inline blocking requirement.

  • ✗

    Configure a web filter profile with DLP sensor

    Why it's wrong here

    A web filter profile inspects HTTP destinations and categories, not file payloads, so it cannot detect credit card numbers inside uploads. It is tempting because web filtering genuinely blocks SaaS access by URL category, and pairing it with a DLP sensor sounds comprehensive. Inline CASB instead requires a DLP profile applied to the SaaS application's traffic.

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.