Which THREE of the following are valid methods to deliver ZTNA tags to FortiClient? (Select three.)
Profiles can include tag assignments.
Why this answer
FortiClient configuration profiles allow administrators to define and push ZTNA tags directly to FortiClient endpoints via the EMS-managed policy framework. This is a core method because tags are applied based on device posture and user identity, enabling granular access control without relying on network-layer attributes.
Exam trap
The trap here is that candidates often confuse network-layer provisioning methods (like DHCP options or SNMP) with application-layer tag delivery mechanisms, assuming any protocol that can carry data can deliver ZTNA tags, but only EMS, FortiClient profiles, and FortiGate ZTNA tag delivery are designed for this purpose.