NSE7 Advanced VPN and Zero Trust Practice Question
An administrator is deploying ZTNA for a legacy application that uses a fixed IP address and port. Which ZTNA component is responsible for securely proxying traffic from the user to the application without exposing the application's actual network location?
⚠ Common exam trap
NSE7 often tests the misconception that ZTNA relies solely on VPN or EMS for access, when the access proxy is the component that actually proxies and hides the application.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ZTNA access proxy
The ZTNA access proxy is responsible for securely proxying traffic from the user to the application, hiding the application's actual network location. It acts as a reverse proxy that enforces access policies based on user identity and device posture, ensuring that only authorized users can reach the application without exposing it directly to the network.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
ZTNA access proxy
Why this is correct
The ZTNA access proxy terminates the user connection and establishes a separate connection to the application, so the application's real IP address and port are never exposed. It enforces policy per session, satisfying the requirement to hide the legacy application's network location.
- ✗
ZTNA inline CASB
Why it's wrong here
An inline CASB inspects and governs traffic to sanctioned SaaS and cloud applications; it does not proxy arbitrary legacy TCP applications on a fixed IP and port. It is tempting because CASB sits inline in the traffic path, but that inline inspection targets cloud-service APIs, not application-location masking.
- ✗
IPsec VPN gateway
Why it's wrong here
An IPsec VPN gateway grants network-level access to a subnet, so the application's real IP and port remain reachable once the tunnel is up. It is tempting because it does encrypt remote access, but ZTNA's secure application proxy, not a VPN concentrator, hides the application's network location.
- ✗
FortiClient EMS
Why it's wrong here
FortiClient EMS manages endpoint agents, posture and configuration; it does not proxy user traffic or conceal an application's network location. It is tempting because FortiClient is the ZTNA client component, but EMS is the management plane, whereas the secure application proxy performs the actual traffic brokering.
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.