Courseiva
Advanced VPN and Zero Trust →mediumMultiple Choice

NSE7 Advanced VPN and Zero Trust Practice Question

An administrator is deploying ZTNA for a legacy application that uses a fixed IP address and port. Which ZTNA component is responsible for securely proxying traffic from the user to the application without exposing the application's actual network location?

⚠ Common exam trap

NSE7 often tests the misconception that ZTNA relies solely on VPN or EMS for access, when the access proxy is the component that actually proxies and hides the application.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ZTNA access proxy

The ZTNA access proxy is responsible for securely proxying traffic from the user to the application, hiding the application's actual network location. It acts as a reverse proxy that enforces access policies based on user identity and device posture, ensuring that only authorized users can reach the application without exposing it directly to the network.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    ZTNA access proxy

    Why this is correct

    The ZTNA access proxy terminates the user connection and establishes a separate connection to the application, so the application's real IP address and port are never exposed. It enforces policy per session, satisfying the requirement to hide the legacy application's network location.

  • ✗

    ZTNA inline CASB

    Why it's wrong here

    An inline CASB inspects and governs traffic to sanctioned SaaS and cloud applications; it does not proxy arbitrary legacy TCP applications on a fixed IP and port. It is tempting because CASB sits inline in the traffic path, but that inline inspection targets cloud-service APIs, not application-location masking.

  • ✗

    IPsec VPN gateway

    Why it's wrong here

    An IPsec VPN gateway grants network-level access to a subnet, so the application's real IP and port remain reachable once the tunnel is up. It is tempting because it does encrypt remote access, but ZTNA's secure application proxy, not a VPN concentrator, hides the application's network location.

  • ✗

    FortiClient EMS

    Why it's wrong here

    FortiClient EMS manages endpoint agents, posture and configuration; it does not proxy user traffic or conceal an application's network location. It is tempting because FortiClient is the ZTNA client component, but EMS is the management plane, whereas the secure application proxy performs the actual traffic brokering.

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.