Courseiva

NSE7 Advanced VPN and Zero Trust Practice Question

During a ZTNA implementation, the administrator configures a ZTNA rule for an internal application but users cannot connect. The FortiGate policy is correct and the application is reachable from the FortiGate. What is the most likely misconfiguration?

⚠ Common exam trap

Watch out — candidates often confuse ZTNA rule misconfiguration with firewall policy issues or client-side routing, but the exam specifically tests that the ZTNA rule's proxy destination must exactly match the internal application's IP and port for the proxy to forward traffic correctly.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The ZTNA rule's proxy destination IP or port is wrong.

The ZTNA rule defines the mapping between the external proxy address and the internal application's actual IP and port. If the proxy destination IP or port is misconfigured, the FortiGate's ZTNA proxy cannot forward traffic to the correct internal server, even though the firewall policy and network connectivity are otherwise valid. This is a common misconfiguration when the internal application's IP or service port differs from what is specified in the ZTNA rule.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The firewall policy is set to deny traffic from the ZTNA gateway.

    Why it's wrong here

    ZTNA traffic reaches the access proxy, not a deny rule; a deny policy from the ZTNA gateway would also contradict the stem's statement that the FortiGate policy is correct. It is tempting because firewall denies commonly block access, but here the failure lies in ZTNA rule or client configuration instead.

  • ✗

    The client does not have a route to the internal application.

    Why it's wrong here

    ZTNA tunnels client traffic through the FortiGate access proxy, so the client needs no direct route to the internal application; routing is handled by the gateway. It is tempting because missing routes cause connectivity failures in conventional VPN setups, but ZTNA abstracts that path away.

  • ✗

    The client's FortiClient agent is not authenticated.

    Why it's wrong here

    An unauthenticated FortiClient agent is a plausible ZTNA failure, but the stem states the FortiGate policy is correct and the application reachable, pointing instead to a ZTNA rule or portal misconfiguration. It is tempting because authentication failures commonly block ZTNA access, yet agent authentication is a prerequisite checked before policy evaluation.

  • ✓

    The ZTNA rule's proxy destination IP or port is wrong.

    Why this is correct

    ZTNA access proxy rules forward traffic to the real application using the configured destination IP and port. If these are wrong, the FortiGate cannot reach the backend service, so users fail to connect even though the policy matches and the application is otherwise reachable.

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.