Courseiva

NSE7 Advanced VPN and Zero Trust Practice Question

An administrator wants to enforce that only devices with the latest antivirus signatures and a corporate disk encryption solution can access a sensitive application via ZTNA. Which two FortiClient EMS components must be configured? (Choose two.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Device posture checks

Option A (Device posture checks) is correct because posture checks in FortiClient EMS evaluate endpoint compliance conditions such as antivirus signature currency and disk encryption status, which are exactly the requirements the administrator wants to enforce. Option D (ZTNA tags) is correct because FortiClient EMS dynamically assigns ZTNA tags to endpoints based on posture results, and these tags are then used in ZTNA firewall policies to allow or deny access to the sensitive application. Together, posture checks generate the compliance data and ZTNA tags translate that data into enforceable access control. Option B (VPN tunnels) is not needed because ZTNA provides application-level access without requiring a traditional VPN tunnel. Option C (SAML SSO) is an identity authentication mechanism and does not by itself verify antivirus signatures or disk encryption compliance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Device posture checks

    Why this is correct

    Device posture checks in FortiClient EMS evaluate endpoint compliance conditions such as antivirus signature currency and disk encryption status. They produce the compliance result that ZTNA enforcement then uses to permit or deny access to the sensitive application.

  • ✗

    VPN tunnels

    Why it's wrong here

    VPN tunnels carry remote-access traffic; they enforce nothing about antivirus signature freshness or disk encryption. The scenario needs FortiClient EMS compliance rules and ZTNA tagging to gate access on endpoint posture. VPN tunnels would be the right component for encrypted remote connectivity, not for posture-based application access control.

  • ✗

    SAML SSO

    Why it's wrong here

    SAML SSO authenticates user identity to the application; it carries no endpoint posture data, so antivirus signature status and disk encryption cannot be evaluated. SAML suits federated identity across cloud apps. Enforcing device compliance requires EMS compliance profiles and ZTNA tagging rules that inspect endpoint telemetry.

  • ✓

    ZTNA tags

    Why this is correct

    ZTNA tags are the mechanism that carries endpoint posture—antivirus signature status and disk encryption state—from FortiClient EMS to FortiGate, satisfying the requirement that only compliant devices reach the sensitive application. Without tags, FortiGate cannot evaluate device health, so access control remains identity-based rather than posture-based.

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.