NSE7 Advanced VPN and Zero Trust Practice Question
An administrator wants to enforce that only devices with antivirus software installed and running can access a sensitive application via ZTNA. Which ZTNA feature should be used to verify this requirement?
⚠ Common exam trap
NSE7 often tests the confusion between ZTNA tags and other access control methods like NAC, leading candidates to choose NAC when the requirement is specifically for application access based on device posture.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ZTNA tags with device posture checks
ZTNA tags with device posture checks allow the FortiGate to evaluate the security posture of the endpoint, including whether antivirus software is installed and running. These tags are then used in firewall policies to grant or deny access to sensitive applications based on compliance. This directly enforces the requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ZTNA inline CASB
Why it's wrong here
Inline CASB inspects traffic to cloud applications for data loss and shadow IT, but does not query endpoint antivirus status as an access condition. It is tempting because CASB sits inline on application traffic, which is right when the requirement is governing sanctioned SaaS usage rather than verifying device posture.
- ✗
NAC with FortiNAC
Why it's wrong here
FortiNAC enforces network access control for devices on the LAN, using 802.1X and switch-level profiling; it does not broker application access or inspect posture for ZTNA sessions. It is tempting because NAC genuinely verifies endpoint compliance, but that is the correct choice for on-premises network admission, not application-level ZTNA enforcement.
- ✓
ZTNA tags with device posture checks
Why this is correct
ZTNA tags with device posture checks have FortiClient EMS inspect the endpoint and assign a tag only when antivirus is installed and running. The access proxy rule then matches that tag, satisfying the requirement that only protected devices reach the application.
- ✗
IPsec VPN with DPD
Why it's wrong here
IPsec VPN with dead peer detection maintains tunnel liveness between gateways; it inspects no endpoint security posture, so antivirus state cannot be evaluated. It is tempting because VPNs gate network access, but that is transport-level connectivity, correct when you need encrypted site-to-site links rather than per-device compliance checks.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.