Courseiva

CCNA Advanced VPN and Zero Trust Questions

63 of 138 questions · Page 2/2 · Advanced VPN and Zero Trust · Answers revealed

76
MCQeasy

What is the purpose of Dead Peer Detection (DPD) in an IPsec VPN?

A.Detect loss of connectivity to the remote VPN peer
B.Detect if the VPN tunnel is using the correct encryption algorithm
C.Detect duplicate IP addresses on the network
D.Detect packet loss over the VPN tunnel
AnswerA

Dead Peer Detection sends periodic probes to the remote gateway and, when replies stop arriving, declares the peer dead and tears down the security association. This detects loss of connectivity to the remote VPN peer so traffic can fail over or renegotiate.

Why this answer

DPD is used to detect if the remote peer is still alive. It sends periodic messages and if no response is received, the tunnel is considered down. Option A is correct.

77
Multi-Selecthard

A FortiGate administrator is configuring an IPsec VPN with IKEv2 between two sites. The administrator wants to ensure that the VPN tunnel uses perfect forward secrecy (PFS) and that the phase 2 selectors are restricted to specific subnets. Which two configuration elements are required to meet these goals? (Choose two.)

Select 2 answers
A.Enable auto-negotiation in phase 2.
B.Configure local and remote subnets in the phase 2 selectors.
C.Set the phase 1 proposal to use a DH group.
D.Configure a DH group in phase 2 proposals.
E.Enable replay detection in phase 2.
AnswersB, D

Phase 2 selectors define the traffic that is allowed through the tunnel. To restrict the VPN to specific subnets, the administrator must configure the local and remote subnets in the phase 2 selectors. This ensures that only traffic between those subnets is encrypted and sent through the tunnel. Without this, the tunnel might use 0.0.0.0/0, allowing all traffic. Thus, this is required to meet the goal of restricted selectors.

Why this answer

To achieve PFS, a DH group must be configured in the phase 2 proposals, which triggers a new key exchange for each phase 2 SA. To restrict the tunnel to specific subnets, the local and remote subnets must be defined in the phase 2 selectors. Together, these two elements ensure that the VPN meets both the PFS and subnet restriction requirements.

Other options do not directly contribute to these goals.

Exam trap

The trap here is confusing phase 1 DH group with phase 2 PFS; PFS specifically requires a DH group in phase 2 proposals.

78
MCQhard

A FortiGate is configured with ZTNA inline CASB to control access to a SaaS application. The administrator wants to block uploads of files containing credit card numbers. Which ZTNA inline CASB feature should be used?

A.Web filter profile
B.Data leak prevention (DLP) profile
C.Antivirus profile
D.Application control profile
AnswerB

A DLP profile inspects file content traversing the ZTNA inline CASB proxy, matching patterns such as credit card numbers and blocking the upload action. This directly satisfies the requirement to prevent sensitive data exfiltration to the SaaS application, which URL filtering or application control cannot achieve.

Why this answer

ZTNA inline CASB can apply DLP (Data Loss Prevention) profiles to inspect content. To block uploads with credit card numbers, a DLP profile with a credit card number sensor should be applied to the ZTNA proxy rule. Option B is correct.

79
MCQeasy

A FortiGate administrator is configuring an IPsec VPN with IKEv2 and wants to ensure that the tunnel uses perfect forward secrecy (PFS). Which phase2 configuration is required?

A.Set 'pfs enable' in phase2 proposal.
B.Set 'pfs enable' in phase1 proposal.
C.Set 'pfs disable' in phase2 proposal.
D.Set 'dh-group 14' in phase1 proposal.
AnswerA

In FortiOS, PFS is enabled in the phase2 proposal by setting 'pfs enable'. This ensures that a new Diffie-Hellman exchange occurs for each phase2 rekey, providing perfect forward secrecy. Without this, the tunnel would not use PFS, and the requirement would not be met. This command is specific to phase2 and is the correct way to enable PFS.

Why this answer

Perfect forward secrecy in IPsec is enabled in the phase2 proposal by setting 'pfs enable'. This forces a new Diffie-Hellman exchange for each phase2 rekey, ensuring that compromised keys do not compromise past or future sessions. The phase1 dh-group setting is separate and does not enable PFS for phase2.

Exam trap

The trap here is confusing the phase1 dh-group setting with phase2 PFS, or placing the 'pfs enable' command in the wrong phase.

80
MCQeasy

Which feature in FortiOS enables a FortiGate to act as a proxy for client-initiated connections to internal applications without requiring a VPN client, by verifying device posture and user identity?

A.IPsec VPN with XAuth authentication
B.SSL VPN with web mode portal
C.FortiGate's explicit web proxy
D.ZTNA (Zero Trust Network Access) proxy
AnswerD

ZTNA proxy in FortiOS lets the FortiGate broker client-initiated connections to internal applications, enforcing user identity via Microsoft Entra ID and device posture checks before granting access. This satisfies the stem's constraint of no VPN client, unlike IPsec or SSL VPN tunnels that require client software.

Why this answer

ZTNA (Zero Trust Network Access) proxy in FortiOS allows a FortiGate to act as a proxy for client-initiated connections to internal applications, verifying device posture and user identity without requiring a full VPN client tunnel. This is the defining feature of FortiGate's ZTNA implementation, which uses FortiClient EMS for posture and FortiGate for policy enforcement.

Exam trap

NSE7 often tests whether candidates confuse ZTNA with SSL VPN or explicit proxy, so the trap is picking a VPN or proxy option that lacks the posture and identity verification that defines ZTNA.

How to eliminate wrong answers

Option A is wrong because IPsec VPN with XAuth still requires a VPN client and establishes a tunnel, which is not the proxy-based, clientless model described. Option B is wrong because SSL VPN web mode portal provides browser-based access but does not perform device posture verification in the ZTNA sense. Option C is wrong because the explicit web proxy is a general HTTP/HTTPS proxy without the identity and posture verification that defines ZTNA.

81
MCQhard

A FortiGate administrator is deploying ZTNA with a FortiClient EMS that tags endpoints as 'compliant' or 'non-compliant'. The administrator wants the FortiGate to grant access only to endpoints that FortiClient EMS has tagged as compliant, while still allowing non-compliant endpoints to reach a remediation portal. Which two configuration elements on the FortiGate must be aligned to enforce this?

A.A ZTNA server with an SSL certificate and a firewall policy referencing an EMS-tag-based address object, plus a second policy permitting non-compliant endpoints to the remediation portal.
B.An LDAP connector to Active Directory and user group policies that map AD groups to the compliant tag.
C.A ZTNA proxy rule with an inline CASB profile and a DLP sensor that inspects endpoint traffic for compliance indicators.
D.A FortiClient EMS fabric connector with the correct EMS tags, and firewall policies that use those tags as source or destination criteria.
AnswerD

The FortiGate must have the FortiClient EMS fabric connector configured so it can query EMS for endpoint tags, and the firewall or ZTNA policies must reference those EMS tag objects as match criteria. Without the connector, tags are not resolvable; without policy references, tags do not gate traffic. Together they enforce compliant-only access while a separate policy can permit remediation traffic.

Why this answer

FortiClient EMS tags are surfaced on FortiGate through the EMS fabric connector. The FortiGate must be configured with the connector (host, credentials, and tag synchronization) so EMS tags become usable address objects, and firewall or ZTNA policies must reference those tag objects as match criteria. A separate policy can then allow non-compliant endpoints to reach the remediation portal.

Exam trap

The trap here is believing that AD group membership or traffic inspection can substitute for FortiClient EMS compliance tags.

82
Multi-Selecthard

A FortiGate administrator is configuring an ADVPN with a hub-and-spoke topology. The administrator wants to ensure that spoke-to-spoke traffic can be dynamically established without traversing the hub for every packet. The administrator also wants to ensure that the shortcut tunnels are only established when necessary and are torn down when no longer used. Which two statements about ADVPN shortcut tunnels on FortiGate are correct? (Choose two.)

Select 2 answers
A.Shortcut tunnels are always established between all spokes at initial VPN bring-up, regardless of traffic patterns.
B.Shortcut tunnels can only be established between spokes that are in the same IP subnet.
C.Shortcut tunnels are established when a spoke receives a shortcut offer from the hub and the spoke has a route to the destination spoke's public IP.
D.Shortcut tunnels are torn down after a configured idle timeout when no traffic matches the shortcut, and traffic reverts to the hub path.
E.Shortcut tunnels require the hub to be removed from the routing path permanently once established.
AnswersC, D

In ADVPN, the hub sends a shortcut offer to the originating spoke when it detects traffic destined for another spoke. The originating spoke then attempts to establish a direct tunnel to the destination spoke. For this to succeed, the spoke must have a route to the destination spoke's public IP address, which is typically learned via the hub or through the underlay network. This allows spoke-to-spoke traffic to bypass the hub.

Why this answer

ADVPN shortcut tunnels are established on demand when the hub sends a shortcut offer and the originating spoke can reach the destination spoke's public IP. They are torn down after an idle timeout when no traffic matches, reverting traffic to the hub path. This dynamic creation and teardown optimizes spoke-to-spoke communication while preserving the hub as a fallback and control point.

Exam trap

The trap here is assuming that ADVPN shortcuts are permanent full-mesh tunnels or that the hub is eliminated, when they are actually on-demand and time-limited.

83
MCQmedium

A FortiGate administrator configures a ZTNA access proxy rule to allow access to an internal application only if the user's device has the tag 'Compliant'. The tag is assigned by FortiClient EMS. However, a user with a compliant device is still blocked. The admin sees in the ZTNA logs that the tag is not being received. What should the administrator check FIRST?

A.Verify that the FortiClient is connected to the internet
B.Confirm that the ZTNA rule is enabled and using the correct port
C.Check if the application server is reachable from the FortiGate
D.Ensure the EMS connector is configured under Security Fabric > External Connectors
AnswerD

Tags originate from FortiClient EMS, so the FortiGate cannot receive them without the EMS connector configured under Security Fabric > External Connectors. Without that connector, the ZTNA log shows no tag, blocking the compliant user.

Why this answer

For a FortiGate to receive ZTNA device tags from FortiClient EMS, the EMS connector must be configured under Security Fabric > External Connectors. Without this connector, the FortiGate has no channel to query or receive tag information, so ZTNA rules referencing tags like 'Compliant' will fail even if the client is healthy. The log showing 'tag not received' points directly at the missing or broken EMS integration.

Exam trap

The trap is that candidates focus on the client side or the rule itself, but the log message 'tag not received' is a strong hint that the integration channel (EMS connector) is the root cause — always check the data source before the consumer.

How to eliminate wrong answers

Option A is wrong because internet connectivity on the FortiClient is necessary but not sufficient — even a fully online client cannot deliver tags if the FortiGate lacks an EMS connector to receive them. Option B is wrong because if the ZTNA rule were disabled or using the wrong port, the log would show a rule mismatch or connection failure, not a missing tag. Option C is wrong because application server reachability is a downstream concern — the failure occurs at the tag-evaluation stage, before any traffic is forwarded to the app.

84
MCQmedium

You run the following command on a FortiGate: 'diagnose vpn ike gateway list' and see that the DPD status for a VPN peer is 'dead'. What does this indicate?

A.The remote peer has been manually disconnected from the network
B.The VPN tunnel is still up but the peer is not responding to DPD messages
C.The IKE SA is still active but the IPsec SA has expired
D.The VPN peer has been detected as unreachable and the tunnel is considered down
AnswerD

DPD 'dead' means the FortiGate sent dead peer detection probes and received no response within the configured retry interval, so the peer is treated as unreachable and the tunnel torn down. This differs from an idle but responsive peer, which reports 'alive'.

Why this answer

When 'diagnose vpn ike gateway list' shows DPD status as 'dead', it means the FortiGate has not received DPD (Dead Peer Detection) responses from the peer within the configured retry period, so it considers the peer unreachable and tears down the tunnel. The IKE SA and IPsec SAs are removed, and the tunnel is considered down. This is the correct interpretation of the 'dead' status.

Exam trap

NSE7 often tests the meaning of DPD statuses, so candidates may confuse 'dead' with a still-up tunnel or an expired IPsec SA, but 'dead' specifically means the peer is unreachable and the tunnel is down.

How to eliminate wrong answers

Option A is wrong because a manual disconnect would not necessarily show as 'dead'; it might show as 'disconnected' or the SA would be deleted. Option B is wrong because if the tunnel were still up, the DPD status would not be 'dead'; 'dead' indicates the tunnel is down. Option C is wrong because if the IKE SA were still active but the IPsec SA expired, the DPD status would not be 'dead'; DPD operates at the IKE level, and 'dead' means the IKE SA is also considered dead.

85
MCQhard

A FortiGate administrator is configuring ZTNA inline CASB to control access to a SaaS application. The administrator wants to block uploads of files containing sensitive data while allowing other operations. Which ZTNA inline CASB configuration is required to achieve this?

A.Create a ZTNA rule with an inline CASB profile and enable 'sensitive-data-block' in the CASB settings.
B.Create a ZTNA rule with a CASB profile that has 'file-upload-block' enabled.
C.Create a ZTNA rule with an inline CASB profile that has a DLP profile configured to block files with sensitive data.
D.Create a ZTNA rule with an application control profile that blocks the upload action for the SaaS application.
AnswerC

ZTNA inline CASB uses security profiles, including DLP, to inspect traffic to SaaS applications. By attaching a DLP profile that detects and blocks sensitive data, the FortiGate can prevent uploads of such files. The ZTNA rule applies the inline CASB profile to the traffic, and the DLP profile enforces the blocking action. This is the correct configuration to meet the requirement.

Why this answer

ZTNA inline CASB on FortiGate can inspect traffic to SaaS applications using security profiles. To block uploads of files containing sensitive data, a DLP profile must be configured with rules that detect sensitive data and set the action to block. This DLP profile is then referenced in the inline CASB profile within the ZTNA rule.

This combination allows the FortiGate to inspect file contents and block only those that match sensitive data patterns, while allowing other uploads.

Exam trap

The trap here is assuming that CASB or application control alone can block uploads based on file content, when DLP is required for content inspection.

86
MCQeasy

A FortiGate administrator is configuring SSL VPN for remote users. The administrator wants to ensure that users can only access specific internal resources based on their user group. Which SSL VPN configuration mode should be used to provide granular access control?

A.Web mode with a portal configured to show only specific bookmarks.
B.Web mode with a realm that maps to an LDAP group.
C.Tunnel mode with firewall policies that match user groups and specific internal subnets.
D.Tunnel mode with split tunneling disabled.
AnswerC

In tunnel mode, the SSL VPN client receives an IP address and routes traffic to internal resources. By creating firewall policies that match user groups and specific destination subnets, the administrator can enforce granular access control. Only users in the allowed groups can reach the defined resources, while others are denied.

Why this answer

SSL VPN tunnel mode combined with firewall policies that reference user groups and specific internal subnets provides granular access control. The firewall policies determine which users can access which resources, based on their group membership. This is the standard method for enforcing least privilege in SSL VPN deployments.

Exam trap

The trap here is thinking that web mode bookmarks or split tunneling settings alone can enforce granular access control, when in fact firewall policies based on user groups and destinations are required.

87
Multi-Selecteasy

An administrator wants to enforce that only devices with the latest antivirus signatures and a corporate disk encryption solution can access a sensitive application via ZTNA. Which two FortiClient EMS components must be configured? (Choose two.)

Select 2 answers
A.Device posture checks
B.VPN tunnels
C.SAML SSO
D.ZTNA tags
AnswersA, D

Device posture checks in FortiClient EMS evaluate endpoint compliance conditions such as antivirus signature currency and disk encryption status. They produce the compliance result that ZTNA enforcement then uses to permit or deny access to the sensitive application.

Why this answer

Option A (Device posture checks) is correct because posture checks in FortiClient EMS evaluate endpoint compliance conditions such as antivirus signature currency and disk encryption status, which are exactly the requirements the administrator wants to enforce. Option D (ZTNA tags) is correct because FortiClient EMS dynamically assigns ZTNA tags to endpoints based on posture results, and these tags are then used in ZTNA firewall policies to allow or deny access to the sensitive application. Together, posture checks generate the compliance data and ZTNA tags translate that data into enforceable access control.

Option B (VPN tunnels) is not needed because ZTNA provides application-level access without requiring a traditional VPN tunnel. Option C (SAML SSO) is an identity authentication mechanism and does not by itself verify antivirus signatures or disk encryption compliance.

88
Drag & Dropmedium

Drag and drop the steps to configure a FortiGate as a DHCP server into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence to configure a FortiGate as a DHCP server is: first select the interface that will serve DHCP, then enable DHCP on that interface, set the IP address scope (range), configure additional options such as default gateway and DNS servers, and finally apply the configuration. This order ensures dependencies are met and the configuration is valid.

89
MCQeasy

A FortiGate administrator is configuring a ZTNA rule to allow access to an internal web application only for users who authenticate with multi-factor authentication (MFA). The administrator has configured the ZTNA rule to require the 'MFA' tag from FortiClient EMS. However, users who have MFA enabled are still being denied access. What is the most likely reason?

A.The users are not using the correct SSL VPN client to connect.
B.The ZTNA rule is not applied to the correct user group.
C.The ZTNA rule is configured to use the wrong authentication scheme.
D.The 'MFA' tag is not being synchronized from FortiClient EMS to the FortiGate.
AnswerD

ZTNA relies on tags from FortiClient EMS to enforce compliance. If the 'MFA' tag is not synchronized, the FortiGate will not see that the user has MFA enabled, and the ZTNA rule will deny access. The administrator should verify that the EMS connector is properly configured and that the tag is being synchronized. This is a common issue when the EMS integration is not fully functional or when the tag is not correctly assigned in EMS.

Why this answer

ZTNA rules enforce access based on tags from FortiClient EMS. If the 'MFA' tag is not synchronized to the FortiGate, the rule cannot verify that the user has MFA, resulting in denial. The administrator must ensure the EMS connector is working and the tag is correctly assigned.

Other options would produce different symptoms.

Exam trap

The trap here is assuming that MFA configuration on the endpoint automatically grants the tag, without verifying that the tag is synchronized to the FortiGate.

90
MCQeasy

An administrator wants to ensure that FortiGate validates the identity of the remote VPN peer using a certificate during IKEv2 phase 1. Which authentication method should the administrator select in the IPsec phase 1 configuration?

A.Aggressive mode
B.Pre-shared key
C.EAP
D.Signature (RSA)
AnswerD

Signature (RSA) makes FortiGate verify the peer's certificate during IKEv2 phase 1, satisfying the requirement for certificate-based peer identity validation. The remote gateway proves possession of its private key by signing the IKEv2 exchange, and FortiGate validates that signature against a trusted CA certificate.

Why this answer

Selecting Signature (RSA) in the IPsec phase 1 configuration enables the FortiGate to use digital certificates for authentication, where the remote peer's identity is validated using its certificate. This meets the requirement of validating the identity of the remote VPN peer using a certificate during IKEv2 phase 1.

Exam trap

NSE7 often tests the confusion between authentication methods and exchange modes; candidates may select Aggressive mode thinking it provides certificate authentication, but it is just a mode.

How to eliminate wrong answers

Option A is wrong because Aggressive mode is an IKE phase 1 exchange mode, not an authentication method; it can be used with pre-shared keys or certificates but does not itself provide certificate validation. Option B is wrong because Pre-shared key uses a shared secret for authentication, not certificates. Option C is wrong because EAP (Extensible Authentication Protocol) is typically used for user authentication, often with RADIUS, and does not inherently use certificates for peer identity validation in IKEv2 phase 1.

91
MCQhard

An administrator is configuring ZTNA inline CASB for a SaaS application. The goal is to block upload of files containing credit card numbers. Which configuration components are required?

A.Use FortiClient to enforce DLP on endpoints
B.Configure an IPsec VPN between FortiGate and the SaaS provider
C.Configure a ZTNA application with a CASB profile and SSL inspection
D.Configure a web filter profile with DLP sensor
AnswerC

SSL inspection decrypts the TLS session so the CASB profile can inspect file payloads for credit card patterns before upload completes. Without decryption, the traffic is opaque and data-loss rules cannot match content. The ZTNA application binds the CASB profile to the SaaS destination, satisfying the inline blocking requirement.

Why this answer

ZTNA inline CASB for a SaaS application requires configuring a ZTNA application entry that includes a CASB profile and SSL inspection. The CASB profile defines the DLP rules (e.g., blocking credit card numbers), and SSL inspection decrypts the traffic so the CASB can inspect file uploads. This combination is the required configuration to enforce inline DLP on SaaS uploads.

Exam trap

NSE7 often tests the misconception that endpoint DLP or web filtering alone can enforce SaaS DLP — candidates must recognize that inline CASB requires ZTNA application configuration, a CASB profile, and SSL inspection to inspect encrypted SaaS traffic.

How to eliminate wrong answers

Option A is wrong because FortiClient endpoint DLP enforces data loss prevention on the endpoint, not inline CASB inspection of SaaS traffic, and does not meet the requirement for inline CASB blocking of uploads. Option B is wrong because an IPsec VPN between FortiGate and the SaaS provider is not a supported or practical configuration for SaaS CASB; SaaS providers do not terminate customer IPsec tunnels for this purpose. Option D is wrong because a web filter profile with a DLP sensor is used for web traffic filtering and DLP on HTTP/HTTPS, but it does not provide the CASB-specific application control and inline inspection needed for SaaS applications like the ZTNA CASB profile does.

92
MCQmedium

A FortiGate administrator is troubleshooting an IPsec VPN where Phase 1 completes but Phase 2 fails to establish. The administrator reviews the Phase 2 configuration and notices that the local and remote subnets do not match between the two peers. Which action should the administrator take to resolve the Phase 2 failure?

A.Increase the Phase 1 lifetime so the tunnel stays up longer during renegotiation.
B.Adjust the Phase 2 selectors on both peers so the local and remote subnet definitions mirror each other.
C.Enable PFS on both peers and set the same Diffie-Hellman group.
D.Change the Phase 1 authentication method from pre-shared key to certificates on both peers.
AnswerB

Phase 2 selectors define which traffic is encrypted. If the local subnet on one peer does not correspond to the remote subnet on the other, the proposal does not match and Phase 2 fails. Aligning the selectors so each peer's local subnet equals the other's remote subnet resolves the mismatch and allows the child SA to establish.

Why this answer

Phase 2 selectors must mirror each other: one peer's local subnet must equal the other peer's remote subnet. When they do not match, the child SA negotiation fails even though Phase 1 succeeds. Aligning the selectors on both peers restores the correct traffic selectors and allows Phase 2 to complete.

Exam trap

The trap here is assuming Phase 2 failures are caused by Phase 1 settings, when a selector mismatch is the actual cause.

93
MCQmedium

A network administrator is troubleshooting an IPsec VPN tunnel between two FortiGates. The tunnel is up but traffic is not passing. The administrator runs 'diagnose vpn ike gateway list' and sees that the IKE SA has been established. However, 'diagnose vpn tunnel list' shows no IPsec SA entries. What is the most likely cause?

A.The firewall policies are not configured to allow traffic through the tunnel
B.The phase 2 proposal (encryption, authentication, etc.) does not match between peers
C.The pre-shared key on both sides does not match
D.The interface MTU is set too low
AnswerB

A phase 2 mismatch prevents the IPsec SA from being negotiated, so Quick Mode fails while the IKE SA stays up. That matches the stem exactly: `diagnose vpn ike gateway list` shows an established IKE SA, but `diagnose vpn tunnel list` shows no IPsec SA entries. Phase 1 selectors and proposals are not the constraint here.

Why this answer

If the IKE SA is established but no IPsec SA entries appear in 'diagnose vpn tunnel list', the most likely cause is a Phase 2 proposal mismatch. Phase 1 (IKE SA) negotiates the secure channel, while Phase 2 (IPsec SA) negotiates the actual tunnel parameters. If the encryption, authentication, or other Phase 2 settings do not match, the IPsec SA will fail to establish, even though Phase 1 is up.

Exam trap

NSE7 often tests the distinction between Phase 1 and Phase 2 failures, so candidates may incorrectly blame firewall policies or pre-shared keys when the IKE SA is already up, missing that Phase 2 mismatch is the cause of missing IPsec SAs.

How to eliminate wrong answers

Option A is wrong because firewall policies affect traffic flow, not the establishment of IPsec SAs; if policies were missing, the tunnel could still be up but traffic would be blocked. Option C is wrong because a pre-shared key mismatch would prevent Phase 1 from establishing, so the IKE SA would not be up. Option D is wrong because MTU issues affect packet fragmentation and traffic flow, not the creation of IPsec SAs.

94
MCQhard

An administrator configures a hub-and-spoke ADVPN with FortiGate at the hub and multiple remote sites. After setup, spokes establish shortcuts directly. However, traffic between two spokes consistently goes through the hub even though shortcuts should exist. Running 'diagnose npu np6 ipsec peercache' shows no shortcut entries. What is the MOST likely reason?

A.The spokes are not running BGP over the ADVPN tunnels.
B.The firewall policies on the spokes do not allow shortcut traffic.
C.Shortcut tunnels are disabled on the hub phase1 configuration.
D.The network processor (NP6) is not enabled for IPsec acceleration.
AnswerA

Shortcuts require BGP to advertise spoke routes across the ADVPN overlay; without it, the hub cannot signal peers to build direct tunnels, so no shortcut entries appear in the NP6 peercache. The stem's missing shortcut condition is therefore explained by absent BGP peering between spokes.

Why this answer

In a hub-and-spoke ADVPN, BGP is required to propagate the spoke's private IP addresses (used as tunnel endpoints) across the overlay network. Without BGP, spokes do not learn each other's tunnel IPs, so they cannot initiate shortcut tunnels. The 'diagnose npu np6 ipsec peercache' command shows no shortcut entries because the shortcut negotiation never starts.

Exam trap

The trap here is that candidates often assume shortcut tunnels are automatically established once ADVPN is configured, overlooking the critical requirement of a dynamic routing protocol (BGP) to exchange tunnel endpoint addresses between spokes.

How to eliminate wrong answers

Option B is wrong because firewall policies on spokes control traffic forwarding, not the establishment of shortcut tunnels; if shortcuts are not formed, traffic will be forwarded via the hub regardless of policies. Option C is wrong because shortcut tunnels are enabled by default on the hub phase1 configuration, and disabling them would prevent all shortcut creation, but the question states shortcuts should exist, implying the hub configuration is correct. Option D is wrong because NP6 IPsec acceleration is a hardware offload feature that affects performance, not the control-plane logic of shortcut tunnel establishment.

95
MCQeasy

An organization uses FortiClient EMS to enforce compliance on endpoints. They want to ensure that only devices with updated antivirus definitions can access the corporate VPN. Which FortiClient configuration should be applied?

A.Create a compliance rule in FortiClient EMS to check antivirus definitions
B.Use a firewall policy to block traffic from non-compliant devices
C.Configure a ZTNA tag that requires updated antivirus
D.Enable CASB in the ZTNA proxy
AnswerA

A compliance rule in FortiClient EMS queries the endpoint's antivirus signature version and flags non-compliant devices, satisfying the requirement that only endpoints with updated definitions reach the VPN. FortiClient EMS then shares this compliance status with FortiGate, which enforces it through the VPN portal's host-check policy.

Why this answer

To enforce compliance based on antivirus definitions, a compliance rule must be created in FortiClient EMS that checks the antivirus definition status. This rule is then used in a ZTNA or VPN policy to allow or deny access. Firewall policies, ZTNA tags, or CASB alone do not check antivirus definitions.

Exam trap

The trap is confusing the mechanism (compliance rule in EMS) with enforcement points (firewall policy, ZTNA tag); the question asks for the configuration that checks antivirus definitions, which is the compliance rule.

How to eliminate wrong answers

Option B is wrong because a firewall policy blocks traffic based on IP/port, not endpoint compliance like antivirus definitions. Option C is wrong because a ZTNA tag is a label applied based on compliance rules; it does not itself check antivirus definitions. Option D is wrong because CASB is for cloud access security, not endpoint antivirus compliance.

96
MCQeasy

A multinational company uses FortiGate devices as VPN gateways to connect its headquarters (HQ) and branch offices via IPsec VPN tunnels. The company is migrating its remote access solution from IPsec VPN to SSL VPN using FortiClient. Currently, 500 remote users connect via IPsec VPN with pre-shared keys and XAuth authentication. The migration must be seamless with minimal downtime, and users must continue to authenticate using their existing Active Directory credentials. The SSL VPN portal must provide access to internal web applications and some legacy TCP-based applications that do not support HTTP. The security team requires that all traffic between remote users and the internal network be encrypted and that the SSL VPN use a certificate from a public CA to avoid certificate warnings on client devices. The IT team wants to use FortiToken for two-factor authentication (2FA) for all VPN users. Which of the following is the most appropriate course of action to meet all requirements?

A.Configure SSL VPN with a self-signed certificate and use the local password database for authentication. Enable FortiToken and configure the portal to provide both web and TCP forwarding applications.
B.Deploy SSL VPN with a public CA certificate, configure LDAP authentication against Active Directory, enable FortiToken for 2FA, and create a split-tunneling policy that uses both SSL VPN web mode and tunnel mode via FortiClient.
C.Set up SSL VPN with a public CA certificate, use LDAP for authentication, but do not enable FortiToken because it would require a separate token per user.
D.Create a new IPsec VPN configuration using certificate-based authentication and FortiToken, and gradually move users to the new IPsec VPN.
AnswerB

LDAP against Active Directory preserves existing credentials, FortiToken adds the required 2FA, a public CA certificate prevents client warnings, and combining web mode with tunnel mode via FortiClient covers both web apps and legacy TCP traffic while split tunnelling keeps internal traffic encrypted.

Why this answer

It meets all requirements: a public CA certificate avoids client certificate warnings, LDAP authentication against Active Directory allows seamless credential reuse, FortiToken provides the required 2FA, and combining SSL VPN web mode (for web apps) with tunnel mode via FortiClient (for legacy TCP applications) ensures full coverage. This approach minimizes downtime by migrating users gradually without changing their authentication backend.

Exam trap

The trap here is that candidates may think SSL VPN cannot handle non-HTTP applications, but FortiClient's tunnel mode with split tunneling or full tunneling can encapsulate any TCP/UDP traffic, making it suitable for legacy applications.

How to eliminate wrong answers

Option A is wrong because a self-signed certificate would cause certificate warnings on client devices, violating the requirement to avoid such warnings, and using the local password database does not integrate with existing Active Directory credentials. Option C is wrong because it explicitly disables FortiToken, failing the two-factor authentication requirement; the statement that FortiToken requires a separate token per user is incorrect—FortiToken can be assigned per user via the FortiGate or FortiAuthenticator. Option D is wrong because it proposes continuing with IPsec VPN instead of migrating to SSL VPN, and certificate-based authentication does not address the need for SSL VPN portal access to web and legacy TCP applications.

97
Multi-Selectmedium

An administrator is configuring FortiClient EMS to enforce compliance for ZTNA. Which TWO settings are required on FortiGate to use compliance-based ZTNA tags?

Select 2 answers
A.FortiClient EMS is added as a security fabric connector
B.The ZTNA proxy rule includes a condition for required ZTNA tags
C.SSL deep inspection is enabled on the firewall policy
D.A local user database is configured for authentication
E.FortiGate is configured as a SAML IdP
AnswersA, B

Compliance tags originate from FortiClient EMS, so the FortiGate must first learn them. Adding EMS as a security fabric connector establishes that channel, allowing the FortiGate to receive endpoint compliance posture and populate ZTNA tags.

Why this answer

Option A is correct because FortiGate must add FortiClient EMS as a Security Fabric connector (via Fabric Connectors > Endpoint/EMS) so it can receive the compliance-based ZTNA tags that EMS dynamically assigns to endpoints. Option B is correct because the ZTNA proxy policy must reference those tags as a matching condition (e.g., source 'ZTNA Tags' with the required compliance tag) for the tags to actually enforce access; without the tag condition, compliance data is never evaluated. Option C is not required: SSL deep inspection is a traffic-inspection feature and is unrelated to receiving or matching ZTNA compliance tags.

Option D is not required: ZTNA tag-based enforcement relies on EMS-assigned tags, not on a local user database for authentication. Option E is not required: FortiGate acting as a SAML IdP is an authentication scenario and is not needed to consume EMS compliance tags for ZTNA.

Exam trap

NSE7 often tests the misconception that SSL deep inspection or local authentication is required for ZTNA tags, when the actual requirements are the EMS Fabric connector and the tag condition in the proxy rule.

98
MCQhard

A FortiGate administrator is configuring a ZTNA rule that uses a proxy-based policy to inspect traffic to a web application. The administrator wants to ensure that only users who have a valid certificate installed on their endpoint are allowed access. The certificate is issued by the corporate PKI and is stored in the user's certificate store. Which ZTNA configuration element should the administrator use to enforce this requirement?

A.Client certificate authentication in the ZTNA proxy rule
B.ZTNA tagging with a dynamic firewall address
C.FortiClient EMS compliance rule with certificate check
D.SSL VPN with certificate authentication
AnswerA

Client certificate authentication in a ZTNA proxy rule requires the client to present a valid certificate during the TLS handshake. The FortiGate validates the certificate against a configured CA and can enforce additional checks such as revocation status. This directly ensures that only users with a valid corporate PKI certificate are granted access, matching the scenario's requirement.

Why this answer

Client certificate authentication in the ZTNA proxy rule is the correct choice because it enforces certificate validation during the TLS handshake. The FortiGate acts as a proxy and can request a client certificate, verify it against a trusted CA, and check revocation. This provides strong authentication that the user possesses a valid certificate from the corporate PKI.

Other options either rely on endpoint compliance reporting or are for different access methods, and they do not provide the same cryptographic assurance.

Exam trap

The trap here is assuming that FortiClient EMS compliance checks alone can enforce certificate-based access, when only client certificate authentication in the proxy rule validates the certificate during the connection.

99
MCQmedium

A FortiGate administrator is configuring an IPsec VPN with multiple peers for redundancy. The administrator wants to ensure that if the primary peer becomes unreachable, the tunnel fails over to the secondary peer automatically. Which configuration is required to achieve this?

A.Configure a single phase 1 with 'set remote-gw' as a DNS name that resolves to both peers, and enable DPD.
B.Create separate phase 1 configurations for each peer, and use a route-based VPN with multiple tunnel interfaces and a routing protocol to select the active path.
C.Use a single phase 1 with 'set remote-gw 0.0.0.0' and configure multiple dial-up VPNs, then rely on DPD to failover.
D.Configure a single phase 1 with multiple remote gateways and enable 'set dpd on-idle'.
AnswerB

To achieve redundancy with automatic failover, you need separate phase 1 configurations for each peer. Using route-based VPNs (with tunnel interfaces) allows dynamic routing protocols like BGP or OSPF to detect failures and reconverge, or you can use link monitoring with static routes. This setup ensures that if one peer goes down, traffic is rerouted through the other. This is the standard method for IPsec VPN redundancy.

Why this answer

Automatic failover between IPsec peers requires multiple phase 1 configurations, one for each peer. Route-based VPNs with tunnel interfaces allow dynamic routing protocols to detect failures and reconverge, or static routes with link monitoring can be used. This ensures that if the primary peer becomes unreachable, traffic is redirected to the secondary peer.

DPD alone only detects failure; it does not perform failover.

Exam trap

The trap here is assuming that DPD or a single phase 1 with a DNS name can provide automatic failover, but redundancy requires separate phase 1 entries and routing mechanisms.

100
MCQmedium

A company's FortiGate is configured with multiple IPsec VPN tunnels to branch offices. One tunnel keeps dropping and re-establishing every few minutes. The logs show 'IPsec SA negotiation failed' with error 'proposal mismatch'. What is the most likely cause?

A.Dead Peer Detection (DPD) configured too aggressively
B.Mismatched encryption or authentication algorithms between the two VPN peers
C.NAT-Traversal (NAT-T) not enabled
D.Pre-shared key mismatch
AnswerB

IPsec phase 2 requires both peers to agree on identical encryption and authentication algorithms, plus matching DH groups. A proposal mismatch means the two ends offer no common transform set, so the quick mode negotiation fails and the tunnel tears down, matching the repeated SA negotiation errors in the logs.

Why this answer

The error 'proposal mismatch' directly indicates that the two IPsec peers cannot agree on the security parameters for the IKE or IPsec SA. This occurs when the encryption algorithm (e.g., AES256 vs. AES128), authentication algorithm (e.g., SHA256 vs.

SHA1), Diffie-Hellman group, or lifetime values do not match between the FortiGate and the remote peer. The tunnel drops and re-establishes because the negotiation fails, and the FortiGate retries with the same mismatched proposal, leading to repeated failures.

Exam trap

The trap here is that candidates often confuse 'proposal mismatch' with authentication failures (pre-shared key) or connectivity issues (NAT-T/DPD), but the specific log message 'proposal mismatch' is a direct indicator of cryptographic parameter disagreement, not a key or transport layer problem.

How to eliminate wrong answers

Option A is wrong because Dead Peer Detection (DPD) being too aggressive would cause the tunnel to be torn down due to missed keepalives, not a 'proposal mismatch' error; DPD failures generate 'DPD timeout' or 'peer not responding' logs. Option C is wrong because NAT-Traversal (NAT-T) not being enabled would cause issues with UDP encapsulation when a NAT device is present, but the error would be 'no response from peer' or 'NAT detection failed', not a proposal mismatch. Option D is wrong because a pre-shared key mismatch would cause an authentication failure during IKE Phase 1, resulting in 'authentication failed' or 'invalid pre-shared key' errors, not a proposal mismatch.

101
MCQeasy

An administrator is configuring SSL VPN on FortiGate and wants to allow users to access internal applications via a web portal without installing any client software. Which SSL VPN mode should be used?

A.DTLS
B.Tunnel mode
C.Web mode
D.Split tunneling
AnswerC

Web mode delivers SSL VPN access entirely through a browser, proxying internal web applications without any client installation. This directly satisfies the stem's constraint of portal-based access with no software deployment, unlike tunnel mode, which requires FortiClient or a comparable client to establish the virtual adapter.

Why this answer

Web mode (option C) is correct because it enables users to access internal web applications through a FortiGate SSL VPN web portal using only a standard browser, with no client software installation required. The portal acts as a reverse proxy, translating HTTPS requests from the client to the internal application servers, making it ideal for clientless remote access.

Exam trap

The trap here is confusing 'Web mode' with 'Tunnel mode' because both are SSL VPN features, but only Web mode provides clientless access via a browser portal, whereas Tunnel mode always requires the FortiClient software to be installed.

How to eliminate wrong answers

Option A is wrong because DTLS (Datagram Transport Layer Security) is a protocol used to provide low-latency encryption for UDP-based traffic in SSL VPN tunnel mode, not a standalone SSL VPN mode for clientless web portal access. Option B is wrong because Tunnel mode requires the installation of the FortiClient SSL VPN client software on the user's device to create a virtual network interface and route all or specific traffic through the tunnel, which contradicts the requirement of no client software. Option D is wrong because Split tunneling is a routing configuration that determines whether traffic destined for the internet goes through the VPN tunnel or directly to the internet; it is not an SSL VPN mode and does not define how users access applications.

102
MCQmedium

An administrator deploys ZTNA with FortiGate as the access proxy for internal web applications. Users authenticate through FortiClient EMS, and device posture checks must be enforced before access is granted. A user with a compliant laptop can reach the application, but when the same user connects from a personal device that fails the posture check, the connection is still allowed. The administrator verifies the ZTNA rule is enabled and the EMS connector is up. Which configuration element is most likely missing to enforce device posture?

A.The FortiGate is not configured with a valid SSL certificate for the ZTNA access proxy.
B.The ZTNA rule is missing a schedule object, allowing access outside business hours.
C.The EMS connector is configured with the wrong port number for FortiClient EMS communication.
D.The ZTNA rule does not reference a device posture tag in the source or policy match criteria.
AnswerD

ZTNA posture enforcement requires the access proxy policy to match on a device posture tag synchronized from FortiClient EMS. Without referencing the EMS-issued tag in the policy, the FortiGate cannot differentiate compliant from non-compliant endpoints, so all authenticated users are treated equally and the personal device is permitted despite failing posture.

Why this answer

ZTNA posture enforcement on FortiGate depends on matching EMS-synchronized device tags within the access proxy policy. Authentication alone only proves identity; it does not prove device health. When the policy lacks a posture tag match, every authenticated user is authorized regardless of endpoint compliance.

Adding the appropriate EMS tag to the policy match criteria ensures non-compliant devices are denied even though they authenticate successfully.

Exam trap

The trap here is assuming that successful EMS connector registration automatically enforces posture, when the policy must explicitly match an EMS device tag.

103
MCQeasy

A FortiGate administrator is setting up a ZTNA environment where FortiClient EMS is used to tag endpoints. The administrator wants to create a firewall policy that allows access to a web application only for users whose endpoints have the tag 'Compliant'. Which configuration step is required to use the tag in the firewall policy?

A.Configure a ZTNA server and add the tag to the server's rule.
B.Create a dynamic firewall address that references the ZTNA tag.
C.Enable ZTNA tagging in the global settings.
D.Add the tag to the FortiClient EMS compliance rule.
AnswerB

To use ZTNA tags in firewall policies, you must create a dynamic firewall address that references the tag. This address object is then used as the source or destination in the policy. The FortiGate dynamically populates the address with IP addresses of endpoints that have the tag, as reported by FortiClient EMS. This is the standard method to enforce tag-based access.

Why this answer

To enforce ZTNA tag-based access in a firewall policy, the administrator must create a dynamic firewall address that references the ZTNA tag. This dynamic address is then used in the policy's source or destination field. The FortiGate populates the address with IPs of endpoints that have the tag, as reported by FortiClient EMS.

This allows granular control based on endpoint compliance status.

Exam trap

The trap here is assuming that tags are added directly to ZTNA server rules or EMS compliance rules, when they must be referenced through dynamic firewall addresses in the policy.

104
MCQmedium

A FortiGate administrator is troubleshooting an IPsec VPN tunnel that fails to establish. The administrator runs 'diagnose vpn ike gateway list' and sees that the IKE gateway is stuck in the 'connecting' state. The administrator confirms that the pre-shared key matches on both peers. Which action should the administrator take next to identify the cause?

A.Run 'get vpn ipsec tunnel summary' to check the tunnel status.
B.Run 'diagnose vpn tunnel list' to check the phase 2 selectors.
C.Run 'diagnose debug application ike -1' and check the debug output for proposal mismatches.
D.Run 'execute vpn ike gateway flush' to clear the IKE gateway and retry.
AnswerC

When an IKE gateway is stuck in 'connecting', it often indicates a phase 1 proposal mismatch or other negotiation failure. Enabling IKE debug with 'diagnose debug application ike -1' provides detailed logs of the negotiation, including proposed and received proposals. This helps identify mismatched encryption, authentication, or DH group settings. Since the pre-shared key is confirmed correct, the next step is to examine the IKE negotiation details. This is the most effective troubleshooting action.

Why this answer

When an IKE gateway is stuck in 'connecting', the most likely cause is a phase 1 negotiation failure, such as a proposal mismatch. Enabling IKE debug with 'diagnose debug application ike -1' provides detailed logs that reveal the exact reason for the failure, such as mismatched encryption or DH group. Other commands show status but not the negotiation details needed to pinpoint the issue.

Thus, IKE debugging is the correct next step.

Exam trap

The trap here is assuming that a matching pre-shared key guarantees phase 1 success; proposal mismatches are a common cause of stuck negotiations.

105
Multi-Selecthard

A FortiGate administrator is troubleshooting an IPsec VPN that uses IKEv2 and certificate authentication. The tunnel fails to establish, and the administrator sees that the phase 1 negotiation reaches the point of exchanging certificates but then fails. The administrator wants to verify the certificate-related configuration. Which two actions should the administrator take to resolve the issue? (Choose two.)

Select 2 answers
A.Ensure that the peer certificate is signed by a CA that is imported into the FortiGate and that the CA is used for peer authentication.
B.Configure the phase 1 proposal to use pre-shared key authentication instead of certificate authentication to bypass certificate validation.
C.Disable Dead Peer Detection on the phase 1 configuration so that the certificate exchange is not interrupted.
D.Set the phase 1 mode to aggressive instead of main mode to speed up certificate negotiation.
E.Verify that the local certificate used for IPsec is selected in the phase 1 configuration and that its private key is present on the FortiGate.
AnswersA, E

The FortiGate validates the peer certificate against a trusted CA. If the issuing CA is not imported or not referenced in the phase 1 peer authentication settings, the certificate exchange completes but validation fails. Importing the correct CA and selecting it for peer authentication is necessary for the tunnel to proceed past certificate validation.

Why this answer

Certificate-based IKEv2 requires both sides to present a local certificate with a usable private key and to validate the peer certificate against a trusted CA. The negotiation failure after certificate exchange points to a problem with the local certificate and key or with the CA used to validate the peer. Importing the correct CA and confirming the local certificate selection are the two actions that directly address these requirements.

Exam trap

The trap here is assuming that selecting a certificate in phase 1 is sufficient, when the FortiGate also needs the matching private key and a trusted CA for the peer certificate.

106
Multi-Selectmedium

Which THREE conditions must be met for an IPsec VPN to successfully establish phase2?

Select 3 answers
A.Proxy IDs (local and remote subnets) match on both sides
B.Firewall policies allow traffic between the subnets
C.Perfect Forward Secrecy (PFS) settings match if enabled
D.Phase2 proposals match between peers
E.NAT traversal is enabled on both sides
AnswersA, C, D

Phase 2 selectors define which source and destination subnets each peer encrypts. If the local and remote proxy IDs configured on each FortiGate do not mirror the other side's, the quick-mode negotiation fails because no matching security association can be built for the traffic.

Why this answer

For IPsec phase2 (Quick Mode) to establish, the proxy IDs (local and remote subnet selectors) must match on both peers, because mismatched selectors cause the responder to reject the Quick Mode proposal — so option A is correct. Option C is correct because if PFS is enabled, both peers must use the same Diffie-Hellman group (e.g., group 2, 5, or 14) during phase2; a mismatch in PFS settings or DH group will fail the key exchange. Option D is correct because phase2 proposals (encryption algorithm, hash, and SA lifetime) must match between peers for the IPsec SA to be negotiated successfully.

Option B is not a phase2 negotiation requirement — firewall policies permitting subnet traffic are needed for actual data flow, not for the IKE/IPsec SA establishment itself. Option E is also not required for phase2; NAT-T is only needed when NAT devices exist between peers and is negotiated in phase1, not a mandatory condition for phase2.

Exam trap

The trap here is that candidates often confuse firewall policy requirements with Phase 2 negotiation requirements, mistakenly thinking that firewall policies must allow traffic before Phase 2 can establish, when in fact Phase 2 only requires matching proxy IDs, proposals, and PFS settings.

107
MCQmedium

A company uses FortiGate ZTNA to provide remote access to an internal web application. The application requires client certificates for authentication. The administrator has configured the ZTNA rule to use certificate authentication. However, users report that they are prompted for credentials repeatedly. What is the most likely cause?

A.The user's password has expired.
B.The ZTNA rule is configured to use SAML authentication instead.
C.The client certificate is not trusted by the FortiGate.
D.The FortiClient EMS server is not reachable from the client.
AnswerC

FortiGate validates the client certificate against its trusted CA store during ZTNA certificate authentication. If the issuing CA is absent, validation fails and the FortiGate falls back to prompting for credentials, explaining the repeated prompts users report despite correct certificate configuration.

Why this answer

When a ZTNA rule is configured for certificate authentication, the FortiGate must trust the client certificate's issuing CA. If the CA certificate is not imported into the FortiGate's trusted CA list, the certificate chain validation fails, causing the authentication to be rejected and the client to be repeatedly prompted for credentials. This is the most common cause of repeated credential prompts in certificate-based ZTNA setups.

Exam trap

The trap here is that candidates often assume repeated credential prompts are caused by password issues or SAML misconfiguration, but in a certificate-based ZTNA rule, the root cause is almost always a trust issue with the client certificate's CA on the FortiGate.

How to eliminate wrong answers

Option A is wrong because a password expiration would not cause repeated credential prompts in a certificate-based authentication scenario; certificate authentication does not rely on user passwords. Option B is wrong because if the ZTNA rule were configured to use SAML, the user would be redirected to a SAML IdP for authentication, not repeatedly prompted for credentials in the same manner as a failing certificate handshake. Option D is wrong because the FortiClient EMS server being unreachable would affect endpoint compliance and posture checks, but not the certificate authentication process itself; the repeated credential prompt is a direct result of certificate validation failure, not EMS connectivity.

108
MCQmedium

An administrator configures FortiGate as a SAML identity provider (IdP) for a cloud application. The application (SP) initiates the login. Users are redirected to the FortiGate login page and authenticate successfully, but then receive an error from the SP. What is a common cause?

A.The SP's ACS (Assertion Consumer Service) URL is misconfigured on the FortiGate
B.The FortiGate's certificate is not trusted by the user's browser
C.The user's account is locked
D.The SAML attribute mapping is incorrect
AnswerA

The SP posts its SAML assertion to the ACS URL, so if that URL configured on the FortiGate IdP does not exactly match the SP's endpoint, authentication succeeds but the assertion is delivered nowhere valid, producing the SP error.

Why this answer

When FortiGate is the IdP, it must be configured with the SP's ACS URL and entity ID. If these are incorrect, the SAML assertion is not accepted by the SP.

109
MCQhard

An administrator runs 'diagnose vpn ike gateway list' and sees that the IKE SA state is 'UP' but the IPsec SA state is 'DOWN'. The remote peer is a FortiGate. What is the most likely cause of this issue?

A.The pre-shared key is incorrect
B.The tunnel interface is down
C.The Phase2 parameters (encryption, authentication, proxy IDs) do not match between the peers
D.The firewall policy on the remote FortiGate is blocking UDP 500
AnswerC

Phase 1 negotiates the IKE SA, which is UP, so peer identity and IKE proposals already match. Phase 2 builds the IPsec SA separately, so a DOWN IPsec SA with an UP IKE SA points to mismatched Phase 2 encryption, authentication, or proxy IDs between the peers.

Why this answer

When the IKE SA is UP but the IPsec SA is DOWN, Phase 1 (IKE) has succeeded but Phase 2 (IPsec) negotiation has failed. The most common cause is a mismatch in Phase 2 parameters — encryption/authentication algorithms, PFS settings, or proxy IDs (quick mode selectors) — between the two FortiGates. Since Phase 1 is up, the pre-shared key and basic reachability are already proven correct.

Exam trap

NSE7 often tests the ability to distinguish Phase 1 from Phase 2 failures — candidates who see 'DOWN' and blame the pre-shared key miss that an UP IKE SA already proves Phase 1 succeeded.

How to eliminate wrong answers

Option A is wrong because an incorrect pre-shared key would prevent Phase 1 from coming up, so the IKE SA would not be UP. Option B is wrong because a down tunnel interface would typically prevent both Phase 1 and Phase 2 from establishing, and the symptom would differ. Option D is wrong because if UDP 500 were blocked, Phase 1 would fail entirely; since IKE SA is UP, UDP 500 and 4500 are passing.

110
MCQmedium

A FortiGate administrator is configuring an IPsec VPN with IKEv2. The administrator wants to ensure that the VPN tunnel uses perfect forward secrecy (PFS) for phase 2. Which parameter must be configured in the phase 2 proposal?

A.Configure 'set auto-negotiate enable' in the phase 2 proposal.
B.Enable 'set pfs enable' and select a Diffie-Hellman group.
C.Use a stronger encryption algorithm such as AES-256 in phase 2.
D.Set the phase 2 keylife to a value lower than the phase 1 keylife.
AnswerB

In the phase 2 proposal, enabling PFS and selecting a DH group ensures that a new key exchange occurs for each phase 2 rekey, providing perfect forward secrecy. This setting must match on both peers. Without it, the tunnel uses the phase 1 keys, which reduces security.

Why this answer

To enable perfect forward secrecy in an IPsec VPN phase 2, the administrator must enable PFS and specify a Diffie-Hellman group in the phase 2 proposal. This forces a new key exchange for each phase 2 rekey, ensuring that session keys are not derived from the phase 1 key. Both peers must have matching PFS settings for the tunnel to establish.

Exam trap

The trap here is thinking that a shorter phase 2 keylife or stronger encryption provides perfect forward secrecy, when only a DH exchange does.

111
MCQmedium

An administrator is deploying ZTNA for a legacy application that uses a fixed IP address and port. Which ZTNA component is responsible for securely proxying traffic from the user to the application without exposing the application's actual network location?

A.ZTNA access proxy
B.ZTNA inline CASB
C.IPsec VPN gateway
D.FortiClient EMS
AnswerA

The ZTNA access proxy terminates the user connection and establishes a separate connection to the application, so the application's real IP address and port are never exposed. It enforces policy per session, satisfying the requirement to hide the legacy application's network location.

Why this answer

The ZTNA access proxy is responsible for securely proxying traffic from the user to the application, hiding the application's actual network location. It acts as a reverse proxy that enforces access policies based on user identity and device posture, ensuring that only authorized users can reach the application without exposing it directly to the network.

Exam trap

NSE7 often tests the misconception that ZTNA relies solely on VPN or EMS for access, when the access proxy is the component that actually proxies and hides the application.

How to eliminate wrong answers

Option B is wrong because ZTNA inline CASB is for cloud access security broker functionality, not for proxying traffic to internal applications. Option C is wrong because an IPsec VPN gateway provides network-level access, not application-level proxying, and does not hide the application's location in the same way. Option D is wrong because FortiClient EMS is an endpoint management server that provides posture data, but it does not proxy traffic.

112
MCQhard

An administrator is building an ADVPN with a single hub and many spokes. Spokes are behind NAT devices and receive dynamic public IP addresses. The administrator wants shortcuts to form directly between spokes without routing traffic through the hub. Which combination of features must be configured on the hub and spokes to allow shortcut negotiation to succeed in this environment?

A.Configure IKEv2 with auto-discovery sender and receiver, and enable NAT traversal on all participating FortiGates.
B.Enable IPsec aggregate interfaces and set net-device disable on all tunnel interfaces.
C.Enable exchange-interface-ip and set mode-cfg on the spokes while disabling DPD on the hub.
D.Set the hub as a dial-up server and configure the spokes with static VIP addresses on the NAT devices.
AnswerA

ADVPN shortcut negotiation uses IKEv2 auto-discovery sender and receiver roles to exchange shortcut offers and replies between spokes, while NAT traversal keeps the IKE and ESP traffic flowing through intervening NAT devices. Together these allow spokes with dynamic, NATed addresses to learn each other's reachable endpoints and build direct tunnels, which is precisely what the design requires.

Why this answer

ADVPN relies on IKEv2 auto-discovery to propagate shortcut offers from spoke to spoke through the hub, and on NAT traversal to keep IKE and ESP reachable across NAT devices. With auto-discovery sender and receiver roles configured and NAT traversal enabled, spokes with dynamic addresses can negotiate direct tunnels. Static addressing or unrelated interface features do not substitute for this signalling.

Exam trap

The trap here is believing that ADVPN shortcuts are negotiated by the hub on behalf of the spokes, when in fact the hub only relays auto-discovery messages and each spoke pair builds its own tunnel.

113
MCQmedium

A network administrator is configuring an IPsec VPN on a FortiGate to connect to a remote peer that uses a dynamic IP address. The administrator wants to ensure that the tunnel can be initiated by the remote peer and that the FortiGate accepts connections from any IP, as long as the peer ID matches. Which configuration should the administrator use?

A.Use a dial-up VPN with a pre-shared key and set the remote gateway to the peer's public IP address.
B.Set the remote gateway to 0.0.0.0 and configure a peer ID with the remote peer's identifier.
C.Configure the remote gateway as a fully qualified domain name (FQDN) and enable dynamic DNS updates.
D.Set the remote gateway to 0.0.0.0 and disable peer ID verification, relying on pre-shared key only.
AnswerB

When the remote peer has a dynamic IP, setting the remote gateway to 0.0.0.0 allows the FortiGate to accept connections from any IP. The peer ID is used to authenticate the remote peer. This is the standard method for dynamic IP peers in IPsec VPN configurations on FortiGate.

Why this answer

For a remote peer with a dynamic IP, the FortiGate must listen for incoming connections from any IP. Setting the remote gateway to 0.0.0.0 achieves this. The peer ID is then used to uniquely identify and authenticate the remote peer, ensuring that only the legitimate peer can establish the tunnel.

This combination is the correct approach.

Exam trap

The trap here is assuming that an FQDN or a specific IP address can handle dynamic IP changes without additional configuration, overlooking the need for 0.0.0.0 and peer ID.

114
MCQmedium

An administrator is configuring a FortiGate as a SAML Identity Provider (IdP) for a third-party service provider. Which of the following is REQUIRED for the FortiGate IdP configuration?

A.The SP's metadata must be imported as a firewall address
B.User accounts must be synchronized with an LDAP server
C.A certificate for signing SAML assertions
D.A pre-shared key between FortiGate and the SP
AnswerC

SAML assertions must be digitally signed so the service provider can verify they genuinely originate from the FortiGate IdP. A signing certificate is therefore mandatory; without it, the SP rejects assertions and SSO fails during trust validation.

Why this answer

When FortiGate acts as a SAML IdP, it must sign SAML assertions to prove their authenticity to the SP. A certificate is required for this signing, as the SP will validate the assertion using the IdP's public key. Without a signing certificate, the SAML response cannot be cryptographically verified, breaking the trust model defined in the SAML 2.0 specification.

Exam trap

The trap here is that candidates confuse SAML's asymmetric signing requirement with symmetric pre-shared keys used in VPNs, or assume that external user synchronization is mandatory, when in fact local users or other identity stores suffice.

How to eliminate wrong answers

Option A is wrong because SP metadata is imported as a SAML service provider object, not as a firewall address; firewall addresses are used for network policies, not SAML identity federation. Option B is wrong because user accounts can be defined locally on the FortiGate or via other identity sources such as RADIUS or FSSO; LDAP synchronization is not mandatory for SAML IdP operation. Option D is wrong because SAML uses asymmetric cryptography (X.509 certificates) for signing and optionally encryption, not a pre-shared key; a PSK is used in protocols like IPsec or IKE, not in SAML.

115
Multi-Selecthard

An administrator configures ZTNA with FortiClient EMS. The goal is to restrict access to an internal application based on device posture. The administrator configures a ZTNA tag for 'Compliant' that checks antivirus and OS patch status. Which TWO additional steps are required on the FortiGate to enforce access based on this tag?

Select 2 answers
A.Enable SSL deep inspection on the firewall policy
B.Create a ZTNA policy that includes the 'Compliant' tag as a required condition
C.Create a ZTNA access proxy for the internal application
D.Import the FortiClient EMS certificate to FortiGate
E.Configure a firewall policy with source set to the EMS connector
AnswersB, C

The tag alone enforces nothing; a ZTNA policy on the FortiGate must reference the 'Compliant' tag as a matching condition so posture status drives the allow or deny decision. Without this policy binding, the tag is merely reported by FortiClient EMS and never evaluated.

Why this answer

Option B is correct because the FortiGate enforces ZTNA tag-based posture by referencing the 'Compliant' tag as a matching condition inside a ZTNA policy (ztna-policy), which is what actually allows or denies the user's traffic based on device posture. Option C is correct because ZTNA on FortiGate requires a ZTNA access proxy (ztna access-proxy) that defines the protected internal application, its real server, and the listening/portal parameters; without it there is no ZTNA object for the policy to protect. Option A is not required because SSL deep inspection is a UTM/content-inspection feature and is not needed to match ZTNA tags.

Option D is not required because the FortiClient EMS certificate is used for EMS fabric authorization/connector trust, not for enforcing a ZTNA tag in the access policy. Option E is not required because a plain firewall policy with the EMS connector as source does not enforce ZTNA tag posture; tag enforcement is done through the ZTNA policy and access proxy.

Exam trap

NSE7 often tests the misconception that simply creating a ZTNA tag is sufficient, ignoring the need for a ZTNA policy and access proxy to enforce it.

116
Multi-Selecthard

A FortiGate administrator is implementing Zero Trust Network Access using ZTNA tags from FortiClient EMS to control access to internal applications. The administrator must ensure that devices losing compliance are denied access and that only managed endpoints can reach the applications. Which two configuration actions are required to meet these goals? (Choose two.)

Select 2 answers
A.Enable SSL VPN host checking and bind it to the same user group used by the ZTNA policy.
B.Configure a static route for the ZTNA application subnets pointing to the EMS connector interface.
C.Authorize the FortiGate on FortiClient EMS so it can receive endpoint compliance tags through the EMS connector.
D.Import the EMS server certificate into the FortiGate's local certificate store and set it as the ZTNA server certificate.
E.Create a ZTNA access-proxy policy that matches the EMS compliance tags and apply it to the ZTNA server rule.
AnswersC, E

The EMS connector on the FortiGate only receives dynamic endpoint tags after the FortiGate is authorized on FortiClient EMS. Without this authorization, the FortiGate cannot learn which endpoints are compliant, so tag-based ZTNA policies would never match. Authorizing the FortiGate is therefore a prerequisite for enforcing posture-driven access decisions in this scenario.

Why this answer

Enforcing posture-based ZTNA requires two things: the FortiGate must be authorized on FortiClient EMS so the EMS connector can deliver dynamic compliance tags, and a ZTNA access-proxy policy must match those tags to allow or deny application access. Together they ensure only compliant, managed endpoints reach the internal applications and that access is revoked when compliance is lost.

Exam trap

The trap here is focusing on certificates and routing for ZTNA when the actual enforcement depends on EMS authorization and tag matching in the access-proxy policy.

117
Multi-Selectmedium

A FortiGate administrator is implementing Zero Trust Network Access (ZTNA) for remote users accessing an internal web application. The administrator wants to ensure that only users who have authenticated and whose devices meet posture requirements can reach the application, and that the application itself is never directly exposed to the internet. Which two FortiGate configuration steps are required to achieve this? (Choose two.)

Select 2 answers
A.Create a firewall policy that matches ZTNA traffic and enforces user authentication and device posture via EMS tags.
B.Configure a site-to-site IPsec VPN between the remote user's device and the FortiGate.
C.Publish the internal application through a public IP with a DNAT VIP so remote users can connect directly.
D.Enable inline CASB on the policy to inspect SaaS application usage.
E.Configure a ZTNA server that maps an external FQDN to the internal application and references a server certificate.
AnswersA, E

The firewall policy is where authentication and posture enforcement are applied. By matching ZTNA traffic and referencing user groups plus FortiClient EMS tags, the policy ensures only authenticated and compliant devices are permitted. This is the enforcement point that ties identity and posture to access, which is central to the Zero Trust requirement.

Why this answer

ZTNA requires a ZTNA server to define the external FQDN and internal application mapping with a server certificate, and a firewall policy to enforce authentication and device posture using user groups and FortiClient EMS tags. Together these broker access without exposing the application directly to the internet.

Exam trap

The trap here is thinking that publishing the application via a DNAT VIP is part of ZTNA, when ZTNA specifically avoids direct exposure.

118
MCQmedium

A FortiGate administrator is configuring a ZTNA rule to protect an internal web server. The administrator wants to ensure that only users who authenticate via SAML and whose devices have the latest antivirus signature are allowed access. Which FortiGate feature must be used to enforce this?

A.Firewall policy with user authentication and antivirus scanning.
B.ZTNA proxy policy with user group and device posture check.
C.SSL VPN with host checking and SAML authentication.
D.IPsec VPN with extended authentication (XAuth) and FortiClient compliance.
AnswerB

A ZTNA proxy policy allows the administrator to combine user authentication (via SAML) and device posture checks (such as antivirus signature version). This policy enforces access based on both identity and device compliance, meeting the requirement. It is the core component for ZTNA access control.

Why this answer

To enforce both SAML authentication and device posture checks for application access, the administrator must use a ZTNA proxy policy. This policy integrates with FortiClient EMS to receive device tags and enforces access based on user group and posture. Other options either provide broader network access or lack the granular application-level control required.

Exam trap

The trap here is assuming that SSL VPN host checking is equivalent to ZTNA posture checks, but ZTNA provides application-specific access with EMS integration.

119
MCQeasy

In a Zero Trust Network Access architecture, which component acts as the policy enforcement point for access decisions?

A.FortiClient agent
B.FortiAnalyzer
C.FortiGate ZTNA gateway
D.FortiClient EMS
AnswerC

The FortiGate ZTNA gateway terminates the client tunnel and enforces access policy per session, granting or denying each request to internal applications. It is the enforcement point, while the EMS or fabric connector supplies identity and posture context used in those decisions.

Why this answer

In a Zero Trust Network Access (ZTNA) architecture, the FortiGate ZTNA gateway acts as the policy enforcement point (PEP). It terminates encrypted ZTNA tunnels from FortiClient agents, inspects traffic against configured access policies, and enforces decisions based on identity, device posture, and context. This is distinct from the control plane (FortiClient EMS) or logging (FortiAnalyzer).

Exam trap

The trap here is that candidates confuse the ZTNA gateway (PEP) with the EMS (controller) or FortiClient (client), but only the gateway sits inline and enforces access decisions based on the ZTNA access proxy protocol.

How to eliminate wrong answers

Option A is wrong because FortiClient is the ZTNA client that initiates connections and reports device posture, not the enforcement point. Option B is wrong because FortiAnalyzer is a logging and analytics platform that collects logs and generates reports, not a real-time policy enforcement component. Option D is wrong because FortiClient EMS is the management server that distributes ZTNA configurations and verifies device compliance, but it does not enforce access decisions inline.

120
MCQeasy

A company wants to ensure that only company-managed laptops with up-to-date antivirus can access the internal file server remotely. Which Fortinet solution integrates with FortiGate to enforce device compliance before granting ZTNA access?

A.FortiClient EMS
B.FortiAnalyzer
C.FortiSandbox
D.FortiWeb
AnswerA

FortiClient EMS integrates with FortiGate to enforce ZTNA device compliance, checking endpoint posture such as antivirus status and management ownership before granting access. It satisfies the stem's constraint that only company-managed laptops with up-to-date antivirus reach the internal file server remotely, using endpoint telemetry tags rather than network location.

Why this answer

FortiClient EMS is the endpoint management server that maintains compliance posture (antivirus status, OS patch level, running processes) for managed endpoints and shares that information with FortiGate via the ZTNA fabric. FortiGate consults EMS tags and compliance rules before allowing a device to reach the internal file server, so only compliant company-managed laptops pass the ZTNA access check.

Exam trap

NSE7 often tests the confusion between logging/analytics appliances (FortiAnalyzer), sandboxing (FortiSandbox), and WAFs (FortiWeb) versus the actual endpoint compliance authority — candidates who pick based on 'security product' familiarity rather than the specific ZTNA role will choose wrong.

How to eliminate wrong answers

Option B is wrong because FortiAnalyzer is a logging, analytics, and reporting appliance — it stores and correlates logs but does not manage endpoint compliance or participate in ZTNA access decisions. Option C is wrong because FortiSandbox is a threat-detection and sandboxing platform for suspicious files and URLs, not an endpoint compliance authority. Option D is wrong because FortiWeb is a web application firewall that protects published web apps from Layer 7 attacks; it does not enforce endpoint posture for ZTNA.

121
MCQhard

A FortiGate is configured with multiple IPsec VPNs to remote branches. One of the branch VPN tunnels goes down frequently. The administrator runs 'diagnose vpn ike log' and sees repeated INITIAL_CONTACT notifications from the remote peer. What does this indicate?

A.The remote peer is rekeying the VPN tunnel
B.The local FortiGate has a mismatched pre-shared key
C.A dead peer detection timeout occurred
D.The remote peer has rebooted or restarted its VPN service
AnswerD

INITIAL_CONTACT is sent when an IKE peer starts without existing security associations, so repeated notifications mean the branch device or its VPN daemon is restarting, tearing down and renegotiating the tunnel. This directly explains the frequent outages observed on that branch VPN.

Why this answer

An INITIAL_CONTACT notification is sent by an IKE peer when it establishes a new IKE SA and wants the remote peer to delete any existing IKE SAs associated with the same identity. This is standard behavior after a reboot, VPN service restart, or when the peer loses its state and re-initiates from scratch. Repeated INITIAL_CONTACT messages therefore indicate the remote branch device is repeatedly restarting or flapping its VPN daemon, not a normal rekey or DPD event.

Exam trap

NSE7 often tests the distinction between IKE notification types, so candidates confuse INITIAL_CONTACT with rekey or DPD events and pick the wrong cause of tunnel flapping.

How to eliminate wrong answers

Option A is wrong because rekeying is signaled by CREATE_CHILD_SA or QUICK_MODE exchanges (or IKEv2 CREATE_CHILD_SA with REKEY_SA), not by INITIAL_CONTACT; rekeys preserve the existing IKE SA and do not trigger deletion of peer SAs. Option B is wrong because a pre-shared key mismatch causes AUTHENTICATION_FAILED or INVALID_ID_INFORMATION notifications during IKE_AUTH, not INITIAL_CONTACT. Option C is wrong because DPD timeouts produce DPD/R_U_THERE or IKEv2 liveness failures and eventual SA deletion, not an INITIAL_CONTACT from the remote peer.

122
MCQmedium

A FortiGate administrator is configuring ZTNA to protect an internal application and wants to ensure that only users who authenticate with a valid client certificate and whose devices pass posture checks can connect. The administrator has configured FortiClient EMS integration and a ZTNA access proxy rule. During testing, users without client certificates are still able to reach the application after providing username and password. Which setting should the administrator verify to enforce certificate-based authentication?

A.The firewall policy from the ZTNA server to the application must include a certificate-based user group.
B.The SSL VPN settings must be configured to require client certificates for ZTNA users.
C.The ZTNA access proxy rule must require client certificate authentication in its authentication settings.
D.The FortiClient EMS connector must be configured to issue client certificates to endpoints.
AnswerC

To enforce client certificates, the access proxy rule’s authentication configuration must explicitly require certificate authentication, typically by selecting the client certificate option and referencing the trusted CA. If only password authentication is enabled, users without certificates can still authenticate, so the certificate requirement is not enforced at the proxy.

Why this answer

Client certificate enforcement for ZTNA is controlled by the access proxy rule’s authentication settings. The rule must be configured to require certificate authentication and reference the trusted CA that signed the client certificates. If the rule only permits password authentication, users without certificates can still authenticate, so the certificate requirement is effectively absent regardless of EMS or backend policy configuration.

Exam trap

The trap here is conflating EMS posture management or SSL VPN certificate settings with ZTNA client certificate enforcement, which lives in the access proxy rule’s authentication configuration.

123
MCQhard

A FortiGate administrator is implementing ZTNA to control access to internal web applications. The administrator wants to ensure that only devices with a valid FortiClient EMS tag can access the applications. Which ZTNA component must be configured on the FortiGate to enforce this?

A.Firewall policy with a source user group synchronized from EMS.
B.SSL VPN portal with a host-check profile referencing the EMS tag.
C.ZTNA proxy policy with a device posture check referencing the EMS tag.
D.IPsec VPN tunnel with extended authentication using EMS tags.
AnswerC

ZTNA proxy policies on FortiGate can enforce device posture by referencing tags from FortiClient EMS. By configuring a proxy policy that includes a device posture check, the FortiGate verifies that the connecting device has the required EMS tag before granting access. This ensures that only compliant devices can reach the internal web applications, aligning with zero-trust principles.

Why this answer

ZTNA on FortiGate uses proxy policies to enforce access control at the application level. To restrict access based on device compliance, the administrator must configure a ZTNA proxy policy that includes a device posture check referencing the FortiClient EMS tag. This ensures that only devices with the correct tag are allowed, aligning with zero-trust access principles.

Exam trap

The trap here is assuming that SSL VPN host-check or firewall user groups can enforce device posture for ZTNA, when only ZTNA proxy policies with device posture checks provide that capability.

124
MCQeasy

What is the primary purpose of Dead Peer Detection (DPD) in an IPsec VPN configuration?

A.To establish a backup tunnel in case the primary tunnel fails.
B.To detect if a VPN peer is alive by sending periodic probes and bringing down the tunnel if no response is received.
C.To automatically renegotiate IKE phase1 keys before they expire.
D.To verify the integrity of encrypted packets using HMAC authentication.
AnswerB

DPD sends periodic encrypted probes (IKE notify payloads) to the peer; if no response arrives within the configured retry and idle intervals, FortiGate tears down the IPsec SA and routes traffic elsewhere, preventing black-holed packets over a silently failed peer.

Why this answer

Dead Peer Detection (DPD) sends periodic R-U-THERE probes (RFC 3706) to a VPN peer and expects an R-U-THERE-ACK response. If no response arrives within a configured threshold, DPD declares the peer dead and tears down the tunnel, allowing failover or renegotiation. This prevents traffic from being black-holed into a dead tunnel.

Exam trap

NSE7 often tests the confusion between DPD and IKE/IPsec keepalive or rekey timers — candidates pick the key renegotiation answer because both involve timers, missing that DPD specifically detects peer liveness.

How to eliminate wrong answers

Option A is wrong because DPD detects peer failure; it doesn't establish backup tunnels — that's the role of redundant tunnel configurations or routing protocols like BGP. Option C is wrong because IKE key renegotiation is handled by lifetime timers (IKE SA and IPsec SA lifetimes), not DPD. Option D is wrong because packet integrity via HMAC is provided by IPsec's authentication header (AH) or ESP authentication, not DPD.

125
Multi-Selectmedium

A FortiGate administrator is troubleshooting an IKEv2 VPN tunnel that fails to establish. The remote peer logs show 'no acceptable proposal' error. Which TWO possible causes should the administrator check?

Select 2 answers
A.The remote peer's IP address is unreachable
B.The phase1 encryption algorithm or integrity algorithm is mismatched
C.The local FortiGate has the wrong IKE version configured
D.The remote peer's pre-shared key is incorrect
E.The Diffie-Hellman group configured is not supported by both peers
AnswersB, E

A mismatch in phase1 encryption or integrity algorithms causes the responder to reject the initiator's proposal, producing the 'no acceptable proposal' error. IKEv2 requires both peers to agree on identical encryption and integrity algorithms during SA negotiation, so verifying these settings on both gateways resolves the failure.

Why this answer

Option B is correct because the 'no acceptable proposal' error in IKEv2 specifically indicates that the responder could not find a matching proposal in the IKE_SA_INIT exchange, which is typically caused by a mismatch in the phase1 encryption algorithm (e.g., AES256 vs 3DES) or integrity algorithm (e.g., SHA256 vs SHA1) between the two peers. Option E is also correct because the Diffie-Hellman group is part of the IKEv2 SA proposal; if one peer offers a DH group (e.g., group 14) that the other peer does not support or has not configured, the responder rejects the proposal with the same 'no acceptable proposal' error. Option A is not correct because an unreachable peer would produce timeout or no-response errors rather than a proposal rejection, since the IKE exchange would never reach the proposal comparison stage.

Option C is not correct because an IKE version mismatch (IKEv1 vs IKEv2) would cause the peers to fail to parse each other's messages entirely, resulting in different errors such as 'invalid major version' or no response, not 'no acceptable proposal'. Option D is not correct because an incorrect pre-shared key is detected during the IKE_AUTH exchange after the proposal has already been accepted, producing an authentication failure error rather than a proposal rejection.

Exam trap

NSE7 often tests the distinction between Phase 1 proposal failures ('no acceptable proposal') and Phase 2 or authentication failures (PSK mismatch, proxy-ID mismatch), so candidates wrongly pick PSK or reachability for a proposal error.

126
MCQeasy

A FortiGate administrator is configuring a route-based IPsec VPN to a cloud provider. The provider requires that only traffic for the 10.20.0.0/16 network be sent through the tunnel, and that the FortiGate present a specific local subnet of 192.168.10.0/24 as its source. The administrator wants to avoid policy-based VPN configuration. Which configuration approach correctly defines the traffic selectors for this route-based tunnel?

A.Configure phase 2 selectors with local address 192.168.10.0/24 and remote address 10.20.0.0/16, and add a static route for 10.20.0.0/16 pointing to the tunnel interface.
B.Create a policy-based IPsec VPN with firewall policies referencing the tunnel and define the source and destination addresses in those policies.
C.Configure phase 2 selectors as 0.0.0.0/0 to 0.0.0.0/0 and rely on firewall policies to restrict traffic to the required subnets.
D.Set the tunnel interface IP to 192.168.10.1/24 and configure a route for 0.0.0.0/0 through the tunnel, allowing the provider to filter traffic.
AnswerA

For a route-based IPsec tunnel, the phase 2 selectors define the proxy IDs exchanged with the peer, while a static route directs matching traffic into the tunnel interface. Setting the local selector to 192.168.10.0/24 and the remote to 10.20.0.0/16 matches the cloud provider's requirement, and the route ensures only that destination is sent through the tunnel.

Why this answer

Route-based IPsec uses phase 2 selectors as proxy IDs and relies on routing to steer traffic into the tunnel interface. Configuring the local selector as 192.168.10.0/24 and the remote as 10.20.0.0/16 satisfies the provider, and a static route for 10.20.0.0/16 to the tunnel interface ensures only the intended destination is sent through the VPN.

Exam trap

The trap here is assuming that route-based tunnels ignore traffic selectors, when phase 2 proxy IDs are still negotiated and must match what the remote gateway expects.

127
MCQeasy

A FortiGate is configured as a ZTNA proxy for a web application. Users report that after authenticating, they receive a '502 Bad Gateway' error. What is the most likely cause?

A.The backend server is unreachable from the FortiGate.
B.The ZTNA proxy is not configured with a valid SSL certificate.
C.The user's device posture is not compliant.
D.The ZTNA rule is not using the correct source interface.
AnswerA

A 502 Bad Gateway means the FortiGate's ZTNA proxy could not establish a connection to the protected backend server. Authentication succeeded, so the failure lies upstream of the client, pointing to an unreachable or down backend.

Why this answer

A '502 Bad Gateway' error from a reverse proxy like FortiGate's ZTNA proxy indicates that the proxy successfully received the client request but could not reach the backend server. The most likely cause is that the backend server is unreachable from the FortiGate — due to network issues, firewall rules, or the server being down. This is the classic meaning of a 502 in proxy architectures.

Exam trap

NSE7 often tests whether candidates can distinguish HTTP error codes in proxy scenarios — 502 means the proxy cannot reach the backend, while 401/403 indicate auth/posture issues, and 503 indicates the service itself is unavailable.

How to eliminate wrong answers

Option B is wrong because an invalid SSL certificate would typically cause a certificate warning or a 503/SSL handshake error, not a 502 Bad Gateway — the proxy would still be able to reach the backend. Option C is wrong because a non-compliant device posture would result in an authentication or authorization failure (e.g., access denied page), not a 502 error after successful authentication. Option D is wrong because an incorrect source interface on the ZTNA rule would prevent the rule from matching, likely causing a connection timeout or access denied, not a 502 from the proxy.

128
MCQmedium

An administrator receives an error when trying to create a ZTNA proxy rule: 'The ZTNA proxy rule requires a valid application mapping.' What does this indicate?

A.The FortiClient EMS is not reachable
B.The application mapping object is not defined
C.The SSL certificate is missing
D.The firewall policy is not in place
AnswerB

A ZTNA proxy rule requires an application mapping object to define the protected application's FQDN, port, and certificate. Without that mapping, the rule has no target to proxy, so FortiGate rejects creation until the mapping is defined and referenced.

Why this answer

A ZTNA proxy rule maps an external FQDN/port to an internal application. The error means the application mapping (which defines the internal server) is missing or misconfigured.

129
MCQmedium

A company is implementing Zero Trust Network Access using Fortinet's ZTNA solution. They have deployed a FortiGate as the ZTNA gateway and are using FortiClient as the ZTNA agent. Users report that they can initiate ZTNA connections but the connections drop after a few minutes. The FortiGate logs show that the ZTNA session is being terminated due to a endpoint compliance check failure. Which action should the administrator take to resolve this issue?

A.Review and adjust the endpoint compliance rules in FortiClient EMS.
B.Disable endpoint compliance checks on the FortiGate.
C.Increase the session timeout on the FortiGate ZTNA gateway.
D.Change the authentication method from certificate to LDAP.
AnswerA

Endpoint compliance checks are evaluated by FortiClient EMS, which tags endpoints and signals the FortiGate ZTNA gateway; the gateway terminates sessions when a tag is revoked. Adjusting the compliance rules in EMS resolves the failing check that causes the recurring session teardown.

Why this answer

The FortiGate logs explicitly indicate that the ZTNA session is being terminated due to an endpoint compliance check failure. This means the FortiGate is enforcing compliance rules defined in FortiClient EMS, and when the endpoint fails those checks (e.g., missing antivirus updates, firewall disabled), the session is dropped. Reviewing and adjusting the compliance rules in EMS allows the administrator to align the requirements with the actual endpoint posture or correct the misconfiguration causing the failure.

Exam trap

The trap here is that candidates may confuse session timeout (a timer-based disconnect) with compliance enforcement (a policy-based disconnect), leading them to incorrectly choose option C instead of recognizing that the log message directly points to a compliance rule issue in EMS.

How to eliminate wrong answers

Option B is wrong because disabling endpoint compliance checks on the FortiGate would bypass the Zero Trust principle entirely, leaving the network vulnerable to non-compliant endpoints, and does not address the root cause of why compliance checks are failing. Option C is wrong because increasing the session timeout would not prevent the session from being terminated due to a compliance check failure; the timeout controls idle session duration, not compliance enforcement. Option D is wrong because changing the authentication method from certificate to LDAP does not affect endpoint compliance checks; ZTNA session termination due to compliance failure is independent of the authentication method used.

130
MCQeasy

Which of the following is a requirement for FortiGate to act as a SAML Identity Provider (IdP) for ZTNA?

A.A public IP address on the WAN interface
B.A configured user database and SAML IdP settings
C.Integration with FortiClient EMS
D.An SSL certificate from a public CA
AnswerB

Acting as a SAML IdP requires a local user database to authenticate users against, plus the SAML IdP settings defining entity ID, endpoints and signing certificate. Both are prerequisites for issuing assertions to ZTNA service providers.

Why this answer

For a FortiGate to act as a SAML Identity Provider for ZTNA, it must have a configured user database (local or remote) and SAML IdP settings enabled, because SAML requires an identity source and IdP metadata to issue assertions. The FortiGate then generates IdP metadata that the SAML SP (such as FortiClient EMS or a ZTNA client) consumes. Without a user store and IdP configuration, no SAML assertions can be produced.

Exam trap

NSE7 often tests the confusion between IdP-side requirements and SP-side or transport-side requirements; the trap is selecting a plausible-sounding but non-essential item like a public IP or public CA certificate instead of the core identity and SAML configuration.

How to eliminate wrong answers

Option A is wrong because a public IP on the WAN interface is not required for the FortiGate to function as a SAML IdP; IdP functionality is about identity assertion, not WAN reachability, and internal or private addressing can work depending on topology. Option C is wrong because FortiClient EMS integration is relevant to ZTNA endpoint posture and SP-side configuration, not a prerequisite for the FortiGate to act as the SAML IdP itself. Option D is wrong because a public CA certificate is not mandatory for SAML IdP operation; a self-signed or internal CA certificate can be used as long as the SP trusts it, and SAML signing/encryption relies on the configured certificate, not specifically a public CA one.

131
MCQmedium

A FortiGate administrator is deploying ZTNA for remote users who connect through FortiClient. The administrator wants to enforce device compliance based on the FortiClient EMS tags. The FortiGate is already integrated with FortiClient EMS. Which configuration step is required to use EMS tags in a ZTNA policy?

A.Enable ZTNA on the SSL VPN portal and map EMS tags to user groups.
B.Configure a ZTNA server and add the EMS tags as a source in the firewall policy.
C.Create a ZTNA rule and specify the EMS tags as a device posture check.
D.Define an address object for the EMS server and use it in a firewall policy.
AnswerC

In ZTNA, device posture is enforced through ZTNA rules that reference EMS tags. The FortiGate retrieves tags from FortiClient EMS and uses them in the ZTNA rule to allow or deny access based on device compliance. This is the correct method to enforce EMS-based compliance for ZTNA.

Why this answer

ZTNA rules on FortiGate can enforce device compliance by referencing EMS tags as device posture checks. The FortiGate queries FortiClient EMS for tags and applies them in the ZTNA rule to permit or deny access. This ensures that only compliant devices can reach protected resources.

The other options either misplace EMS tags in firewall policies or confuse ZTNA with SSL VPN.

Exam trap

The trap here is assuming that EMS tags are used directly in firewall policies or SSL VPN portals, rather than being referenced in ZTNA rules as device posture checks.

132
MCQmedium

A FortiGate administrator is implementing ZTNA in reverse-proxy mode to protect an internal web application. Remote users authenticate through FortiClient with EMS tags, and the administrator wants to enforce that only users with a valid certificate and a compliant endpoint can access the application. After configuring the ZTNA server and access proxy, the administrator notices that users without the certificate are still able to reach the application. What is the most likely cause?

A.The FortiClient EMS tags are not being synchronized, so the FortiGate cannot evaluate endpoint compliance.
B.The access proxy rule is missing a client-certificate requirement, so it allows any user who matches the source criteria.
C.The ZTNA server is configured in transparent mode, which bypasses client certificate checks.
D.The ZTNA server is configured to use HTTP instead of HTTPS, so client certificates are not validated.
AnswerB

In FortiGate ZTNA reverse-proxy mode, the access proxy rule defines the authentication and authorization conditions. If the rule does not explicitly require a client certificate, users without one can still pass if they meet other criteria. The administrator must edit the access proxy rule to require a valid client certificate. This is the most likely cause because the symptom is selective bypass of certificate enforcement while other authentication still works.

Why this answer

In ZTNA reverse-proxy mode, the access proxy rule is the enforcement point for authentication and authorization. If the rule does not explicitly require a client certificate, users without one can still access the application as long as they meet other conditions. The administrator must edit the access proxy rule to add a client-certificate requirement.

This ensures that only users presenting a valid certificate are allowed, closing the bypass.

Exam trap

The trap here is assuming that enabling ZTNA automatically enforces client certificates, when in fact the access proxy rule must explicitly require them.

133
MCQmedium

A FortiGate administrator wants to use SAML SSO to authenticate VPN users. The FortiGate will act as the service provider (SP) and an external identity provider (IdP) will be used. Which of the following must be configured on the FortiGate to enable SAML authentication for SSL VPN?

A.A RADIUS server pointing to the IdP and an authentication rule.
B.An LDAP server with the IdP's certificate and a matching policy.
C.A user group with SAML authentication method and an SSL VPN portal referencing that group.
D.A local user with SAML attributes and a firewall policy referencing that user.
AnswerC

SAML SSO requires a user group configured with the SAML authentication method, plus an SSL VPN portal that references it. The group binds the IdP assertion to FortiGate policy, and the portal determines what authenticated users may access.

Why this answer

To enable SAML SSO for SSL VPN on FortiGate, the administrator must configure a user group with the SAML authentication method that references the external IdP, and then reference that group in the SSL VPN portal settings. This establishes the trust relationship where FortiGate acts as the SP and redirects authentication to the IdP. Without the user group and portal binding, SAML authentication cannot be applied to VPN users.

Exam trap

NSE7 often tests the specific FortiGate objects required for SAML SSO, and candidates frequently confuse SAML with RADIUS or LDAP, or assume a local user object is sufficient.

How to eliminate wrong answers

Option A is wrong because RADIUS is a different authentication protocol and is not used for SAML SSO; pointing a RADIUS server to an IdP does not implement SAML. Option B is wrong because LDAP is a directory protocol, not a SAML federation protocol, and importing an IdP certificate alone does not configure SAML authentication. Option D is wrong because SAML authentication is not configured on a local user object; it requires a user group with the SAML method and proper portal or policy references.

134
MCQmedium

A FortiGate administrator is configuring ZTNA to provide secure access to an internal application. The application is hosted on a server with IP 10.0.1.100 and port 8080. The administrator creates a ZTNA rule on the FortiGate as an access proxy. What is the correct configuration for the ZTNA rule's 'Application Access' entry?

A.External port: 0, Mapped port: 8080, Destination: 10.0.1.100
B.External port: 8080, Mapped port: 443, Destination: 10.0.1.100
C.External port: 443, Mapped port: 443, Destination: 10.0.1.100
D.External port: 443, Mapped port: 8080, Destination: 10.0.1.100
AnswerD

The access proxy terminates client TLS on 443 and forwards to the real service. Mapping external port 443 to destination 10.0.1.100 on port 8080 lets the ZTNA rule reach the internal application listening on 8080 while clients connect on the standard HTTPS port.

Why this answer

For ZTNA access proxy, the external port is the port clients connect to (typically 443 for HTTPS), and the mapped port is the internal server port (8080). The destination is the internal server IP. Therefore, option D is correct: external port 443, mapped port 8080, destination 10.0.1.100.

135
MCQmedium

A network administrator is troubleshooting an IPsec VPN tunnel between two FortiGates. The tunnel is established but traffic is not passing. The administrator runs 'diagnose vpn ike log' and sees 'no matching policy for this IPsec SA'. What is the most likely cause?

A.The phase2 selectors do not match between peers
B.There is no firewall policy allowing traffic from the local network to the remote network via the VPN tunnel interface
C.The pre-shared key is mismatched
D.The tunnel interface is administratively down
AnswerB

The log indicates the IKE SA negotiated selectors but no firewall policy permits that traffic. FortiGate requires an explicit policy matching source, destination and the VPN tunnel interface; without it, packets are dropped before entering the tunnel.

Why this answer

The log message 'no matching policy for this IPsec SA' on a FortiGate means the IKE/IPsec SA was negotiated successfully but no firewall policy matches the traffic that needs to traverse the tunnel. In FortiOS, a firewall policy with the tunnel interface as the outgoing interface (and matching source/destination) is required for traffic to be encrypted and forwarded. Without it, the tunnel stays up but no data flows.

Exam trap

The trap is conflating IKE negotiation failures (PSK mismatch, phase2 selector mismatch) with traffic-forwarding failures — candidates see 'IPsec SA' in the log and assume the SA itself is broken, when the message actually points to a missing firewall policy, not a VPN parameter problem.

How to eliminate wrong answers

Option A is wrong because mismatched phase2 selectors would cause the IKE negotiation to fail with a 'no proposal chosen' or 'phase2 mismatch' error, not a 'no matching policy' message — and the tunnel would not establish at all. Option C is wrong because a mismatched pre-shared key causes phase1 to fail with 'PSK mismatch' or 'authentication failed', preventing the tunnel from coming up entirely. Option D is wrong because an administratively down tunnel interface would show the interface as down in 'diagnose vpn tunnel list' and would not produce the specific 'no matching policy for this IPsec SA' log line.

136
MCQeasy

A FortiGate administrator wants to ensure that only devices with an up-to-date antivirus and OS patch level can access a sensitive application published via ZTNA. Which ZTNA component should the administrator configure to enforce this requirement?

A.ZTNA proxy configuration
B.ZTNA tags with posture checks
C.SSL VPN portal settings
D.Firewall policy with application control
AnswerB

ZTNA tags with posture checks let FortiClient EMS evaluate endpoint antivirus and OS patch status, then assign tags that the access proxy rule matches. This enforces the stated requirement that only up-to-date devices reach the sensitive application.

Why this answer

ZTNA tags with posture checks allow the FortiGate to verify endpoint compliance (e.g., antivirus version, OS patch level) before granting access to a ZTNA-published application. The FortiGate collects posture data from the FortiClient endpoint and compares it against configured compliance rules; only devices that meet the requirements receive the appropriate ZTNA tag and are allowed through the ZTNA proxy.

Exam trap

The trap here is that candidates often confuse the ZTNA proxy configuration (which handles traffic forwarding and authentication) with the tag-based posture enforcement mechanism, assuming that the proxy itself can enforce endpoint compliance without the separate tag and posture check system.

How to eliminate wrong answers

Option A is wrong because the ZTNA proxy configuration defines the access proxy settings (e.g., application mapping, authentication) but does not itself enforce endpoint posture checks; it relies on tags to determine access. Option C is wrong because SSL VPN portal settings are used for traditional SSL VPN access, not for ZTNA, and do not support posture-based tagging or endpoint compliance verification. Option D is wrong because a firewall policy with application control can inspect traffic and block applications, but it cannot perform endpoint posture checks (e.g., antivirus or OS patch level) required for ZTNA compliance enforcement.

137
MCQmedium

A FortiGate administrator is troubleshooting a ZTNA deployment. Users report that they can access the ZTNA application, but the EMS tags are not being enforced. The administrator verifies that the FortiGate is connected to FortiClient EMS and that the EMS tags exist. What is the most likely cause?

A.The FortiClient EMS tags are not synchronized with the FortiGate.
B.The ZTNA server configuration is missing the application mapping.
C.The firewall policy allowing ZTNA traffic does not have UTM profiles applied.
D.The ZTNA rule does not include a device posture check for the EMS tags.
AnswerD

If the ZTNA rule lacks a device posture check that references EMS tags, then tags are not enforced. The rule may allow access based solely on user authentication. This is the most likely cause because the FortiGate is connected to EMS and tags exist, but the rule is not configured to use them. This is the correct answer.

Why this answer

EMS tag enforcement in ZTNA requires a device posture check in the ZTNA rule. If the rule does not reference EMS tags, they are ignored. The administrator confirmed EMS connectivity and tag existence, so the missing posture check is the likely cause.

Other options either would prevent access entirely or are unrelated to tag enforcement.

Exam trap

The trap here is assuming that EMS tag enforcement is automatic once EMS is connected, when actually the ZTNA rule must explicitly include a posture check for the tags.

138
MCQeasy

A FortiGate administrator wants to use PKI certificates for IKEv2 authentication instead of pre-shared keys. Which phase1 configuration parameter must be changed to support certificate-based authentication?

A.Set the authentication method to 'signature'.
B.Set the proposal to include DH groups 14 or higher.
C.Configure 'local-gw' with the certificate's CN.
D.Enable 'peer-id-option' and set it to 'any'.
AnswerA

Setting the phase1 authentication method to 'signature' replaces pre-shared key authentication with digital certificate exchange, satisfying the requirement for PKI-based IKEv2 authentication. FortiGate then validates peer certificates against the configured CA, using RSA or ECDSA signatures during the IKEv2 exchange rather than a shared secret.

Why this answer

In FortiOS IPsec phase1 configuration, the 'authentication-method' parameter controls how the peers authenticate during IKEv2. Setting it to 'signature' instructs the FortiGate to use digital signatures (RSA or ECDSA) with X.509 certificates instead of pre-shared keys. This is the mandatory change to enable certificate-based authentication; other parameters like 'certificate' and 'remote-certificate' are then used to specify the actual certificates.

Exam trap

NSE7 often tests the confusion between authentication method and other phase1 parameters like DH groups or peer ID options, causing candidates to overlook that 'authentication-method' must be explicitly set to 'signature' to enable certificate-based authentication.

How to eliminate wrong answers

Option B is wrong because DH groups are used for key exchange (PFS) and do not control the authentication method; they are independent of certificate vs. PSK authentication. Option C is wrong because 'local-gw' specifies the local gateway IP address for the IPsec tunnel, not a certificate CN; the certificate is selected via the 'certificate' parameter.

Option D is wrong because 'peer-id-option' controls how the peer ID is validated (e.g., from certificate subject), but it does not enable certificate authentication itself; the authentication method must still be set to 'signature'.

← PreviousPage 2 of 2 · 138 questions total

Ready to test yourself?

Try a timed practice session using only Advanced VPN and Zero Trust questions.