Courseiva

NSE7 Advanced VPN and Zero Trust Practice Question

In a Zero Trust Network Access architecture, which component acts as the policy enforcement point for access decisions?

⚠ Common exam trap

It's easy for candidates to confuse the ZTNA gateway (PEP) with the EMS (controller) or FortiClient (client), but only the gateway sits inline and enforces access decisions based on the ZTNA access proxy protocol.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

FortiGate ZTNA gateway

In a Zero Trust Network Access (ZTNA) architecture, the FortiGate ZTNA gateway acts as the policy enforcement point (PEP). It terminates encrypted ZTNA tunnels from FortiClient agents, inspects traffic against configured access policies, and enforces decisions based on identity, device posture, and context. This is distinct from the control plane (FortiClient EMS) or logging (FortiAnalyzer).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    FortiClient agent

    Why it's wrong here

    FortiClient enforces posture and tunnels traffic on the endpoint, but access decisions are made and enforced by the FortiGate acting as the ZTNA policy enforcement point. FortiClient is the correct choice when the question asks for the component that collects device posture and initiates the connection.

  • ✗

    FortiAnalyzer

    Why it's wrong here

    FortiAnalyzer aggregates logs, analytics and compliance reports; it holds no inline traffic path, so it cannot enforce allow or deny decisions. It is the right choice when the question asks where ZTNA events are logged, correlated and reported for auditing rather than enforced.

  • ✓

    FortiGate ZTNA gateway

    Why this is correct

    The FortiGate ZTNA gateway terminates the client tunnel and enforces access policy per session, granting or denying each request to internal applications. It is the enforcement point, while the EMS or fabric connector supplies identity and posture context used in those decisions.

  • ✗

    FortiClient EMS

    Why it's wrong here

    FortiClient EMS manages endpoints, profiles and tags, feeding posture data to the enforcement point; it does not itself allow or deny sessions. EMS is the correct answer when the question asks which component centrally administers FortiClient configuration and dynamic access tags.

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.