NSE7 Advanced VPN and Zero Trust Practice Question
An organization wants to implement Zero Trust Network Access (ZTNA) to secure access to an internal web application. The current network uses FortiGate as the firewall. Which component is required to enforce ZTNA policies on the FortiGate?
⚠ Common exam trap
NSE7 often tests the misconception that authentication (FortiAuthenticator) or logging (FortiAnalyzer) components enforce ZTNA, when the FortiGate itself must be configured as the access proxy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
FortiGate ZTNA proxy configuration
To enforce ZTNA policies on a FortiGate, you must configure the FortiGate as a ZTNA access proxy, which inspects and controls traffic to the internal application based on device posture and identity tags. This is done via the ZTNA proxy configuration on the FortiGate, which acts as the policy enforcement point. Without this, the FortiGate cannot apply ZTNA rules to the traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
FortiSandbox for content inspection
Why it's wrong here
FortiSandbox performs sandboxing and content inspection of files and traffic; it supplies no device identity or posture data for ZTNA policy enforcement. FortiSandbox suits advanced threat detection and detonation, not the FortiClient EMS role ZTNA requires.
- ✗
FortiAnalyzer for log analysis
Why it's wrong here
FortiAnalyzer collects, correlates and reports logs; it does not provide the device posture and tag information FortiGate needs to enforce ZTNA. FortiAnalyzer suits centralised logging, analytics and compliance reporting, not acting as the ZTNA fabric connector.
- ✓
FortiGate ZTNA proxy configuration
Why this is correct
ZTNA on FortiGate requires the access proxy, configured via the ZTNA proxy settings, to intercept and broker user traffic to the internal web application. This proxy enforces the zero-trust policy, verifying identity and posture before granting access rather than relying on network location.
- ✗
FortiAuthenticator for RADIUS authentication
Why it's wrong here
FortiAuthenticator supplies RADIUS authentication, but ZTNA policy enforcement on FortiGate requires FortiClient EMS to provide device posture and tag information. RADIUS alone verifies identity, not device trust. FortiAuthenticator would be the right choice for centralised two-factor authentication or RADIUS offload, not for ZTNA tagging.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.