Courseiva

NSE7 Advanced VPN and Zero Trust Practice Question

An organization wants to implement Zero Trust Network Access (ZTNA) to secure access to an internal web application. The current network uses FortiGate as the firewall. Which component is required to enforce ZTNA policies on the FortiGate?

⚠ Common exam trap

NSE7 often tests the misconception that authentication (FortiAuthenticator) or logging (FortiAnalyzer) components enforce ZTNA, when the FortiGate itself must be configured as the access proxy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

FortiGate ZTNA proxy configuration

To enforce ZTNA policies on a FortiGate, you must configure the FortiGate as a ZTNA access proxy, which inspects and controls traffic to the internal application based on device posture and identity tags. This is done via the ZTNA proxy configuration on the FortiGate, which acts as the policy enforcement point. Without this, the FortiGate cannot apply ZTNA rules to the traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    FortiSandbox for content inspection

    Why it's wrong here

    FortiSandbox performs sandboxing and content inspection of files and traffic; it supplies no device identity or posture data for ZTNA policy enforcement. FortiSandbox suits advanced threat detection and detonation, not the FortiClient EMS role ZTNA requires.

  • ✗

    FortiAnalyzer for log analysis

    Why it's wrong here

    FortiAnalyzer collects, correlates and reports logs; it does not provide the device posture and tag information FortiGate needs to enforce ZTNA. FortiAnalyzer suits centralised logging, analytics and compliance reporting, not acting as the ZTNA fabric connector.

  • ✓

    FortiGate ZTNA proxy configuration

    Why this is correct

    ZTNA on FortiGate requires the access proxy, configured via the ZTNA proxy settings, to intercept and broker user traffic to the internal web application. This proxy enforces the zero-trust policy, verifying identity and posture before granting access rather than relying on network location.

  • ✗

    FortiAuthenticator for RADIUS authentication

    Why it's wrong here

    FortiAuthenticator supplies RADIUS authentication, but ZTNA policy enforcement on FortiGate requires FortiClient EMS to provide device posture and tag information. RADIUS alone verifies identity, not device trust. FortiAuthenticator would be the right choice for centralised two-factor authentication or RADIUS offload, not for ZTNA tagging.

About these practice questions

Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.