Courseiva

NSE7 Advanced VPN and Zero Trust Practice Question

An organization uses FortiClient EMS to enforce compliance on endpoints. They want to ensure that only devices with updated antivirus definitions can access the corporate VPN. Which FortiClient configuration should be applied?

⚠ Common exam trap

The trap is confusing the mechanism (compliance rule in EMS) with enforcement points (firewall policy, ZTNA tag); the question asks for the configuration that checks antivirus definitions, which is the compliance rule.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a compliance rule in FortiClient EMS to check antivirus definitions

To enforce compliance based on antivirus definitions, a compliance rule must be created in FortiClient EMS that checks the antivirus definition status. This rule is then used in a ZTNA or VPN policy to allow or deny access. Firewall policies, ZTNA tags, or CASB alone do not check antivirus definitions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a compliance rule in FortiClient EMS to check antivirus definitions

    Why this is correct

    A compliance rule in FortiClient EMS queries the endpoint's antivirus signature version and flags non-compliant devices, satisfying the requirement that only endpoints with updated definitions reach the VPN. FortiClient EMS then shares this compliance status with FortiGate, which enforces it through the VPN portal's host-check policy.

  • ✗

    Use a firewall policy to block traffic from non-compliant devices

    Why it's wrong here

    A firewall policy can block traffic, but it cannot itself determine antivirus definition currency; that posture must come from FortiClient EMS compliance rules feeding the policy. It is tempting because policy enforcement is the visible outcome, yet without EMS compliance data the policy has no antivirus criterion to match.

  • ✗

    Configure a ZTNA tag that requires updated antivirus

    Why it's wrong here

    A ZTNA tag alone does not evaluate antivirus signature freshness; FortiClient EMS compliance rules must define the antivirus-definition check, with the tag applied as the resulting posture. It is tempting because tags drive ZTNA access decisions, but tags are the outcome of compliance verification, not the verification itself.

  • ✗

    Enable CASB in the ZTNA proxy

    Why it's wrong here

    CASB inspects cloud-application traffic for shadow IT and data exposure; it does not assess endpoint antivirus definition currency, so it cannot gate VPN access on that posture. It is tempting because CASB sits in the ZTNA proxy path, but its inspection targets SaaS usage rather than endpoint compliance state.

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.