Courseiva

NSE7 Advanced VPN and Zero Trust Practice Question

In FortiGate's ZTNA, what is the purpose of a 'ZTNA tag'?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To identify a device's compliance status and attributes for policy enforcement.

ZTNA tags are dynamic attributes (e.g., OS type, antivirus status) assigned to devices based on posture checks. They are used in firewall policies to grant access based on device compliance, not for routing or QoS.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    To identify a device's compliance status and attributes for policy enforcement.

    Why this is correct

    A ZTNA tag is a dynamic attribute, typically populated by FortiClient EMS, describing device compliance and posture. FortiGate ZTNA rules match these tags to decide whether a device is permitted, enforcing zero-trust access based on verified device state rather than network location.

  • ✗

    To mark packets for quality of service (QoS) prioritization.

    Why it's wrong here

    ZTNA tags identify endpoints and users so FortiGate can enforce zero-trust access decisions; they are not packet markings for QoS. QoS prioritisation uses DSCP or 802.1p values in firewall shaping policies. The confusion arises because both involve labels, but ZTNA tags drive authentication and authorisation, not queue scheduling.

  • ✗

    To label network interfaces for traffic steering.

    Why it's wrong here

    ZTNA tags attach to users, devices and applications for dynamic access control; they do not label interfaces for traffic steering. Interface steering uses SD-WAN rules, zones and policy routes. Tagging is tempting because it implies grouping, but FortiGate's ZTNA tags populate policy matching criteria, not interface selection logic.

  • ✗

    To assign a security level to application traffic.

    Why it's wrong here

    ZTNA tags are metadata objects applied to users, devices or applications to drive dynamic access policy; they do not set a security level on traffic. Security levels are enforced by firewall policies and profiles. Tagging is tempting because it sounds like classification, but FortiGate's ZTNA tags feed policy matching, not traffic grading.

About these practice questions

Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.