Courseiva

NSE7 Advanced VPN and Zero Trust Practice Question

An administrator wants to enforce that only devices with antivirus software installed and running can access a sensitive application via ZTNA. Which ZTNA feature should be used to verify this requirement?

⚠ Common exam trap

NSE7 often tests the confusion between ZTNA tags and other access control methods like NAC, leading candidates to choose NAC when the requirement is specifically for application access based on device posture.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ZTNA tags with device posture checks

ZTNA tags with device posture checks allow the FortiGate to evaluate the security posture of the endpoint, including whether antivirus software is installed and running. These tags are then used in firewall policies to grant or deny access to sensitive applications based on compliance. This directly enforces the requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ZTNA inline CASB

    Why it's wrong here

    Inline CASB inspects traffic to cloud applications for data loss and shadow IT, but does not query endpoint antivirus status as an access condition. It is tempting because CASB sits inline on application traffic, which is right when the requirement is governing sanctioned SaaS usage rather than verifying device posture.

  • ✗

    NAC with FortiNAC

    Why it's wrong here

    FortiNAC enforces network access control for devices on the LAN, using 802.1X and switch-level profiling; it does not broker application access or inspect posture for ZTNA sessions. It is tempting because NAC genuinely verifies endpoint compliance, but that is the correct choice for on-premises network admission, not application-level ZTNA enforcement.

  • ✓

    ZTNA tags with device posture checks

    Why this is correct

    ZTNA tags with device posture checks have FortiClient EMS inspect the endpoint and assign a tag only when antivirus is installed and running. The access proxy rule then matches that tag, satisfying the requirement that only protected devices reach the application.

  • ✗

    IPsec VPN with DPD

    Why it's wrong here

    IPsec VPN with dead peer detection maintains tunnel liveness between gateways; it inspects no endpoint security posture, so antivirus state cannot be evaluated. It is tempting because VPNs gate network access, but that is transport-level connectivity, correct when you need encrypted site-to-site links rather than per-device compliance checks.

About these practice questions

Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.