An organization is designing a Zero Trust Network Access solution with Fortinet. They want to ensure that only devices with up-to-date antivirus software can access sensitive applications. Which component is responsible for enforcing this requirement?
Trap 1: FortiAnalyzer
FortiAnalyzer is for logging and reporting, not enforcement.
Trap 2: FortiAuthenticator
FortiAuthenticator handles authentication, not endpoint compliance.
Trap 3: FortiGate ZTNA gateway
The ZTNA gateway enforces access based on tags, but tags are generated by EMS.
- A
FortiAnalyzer
Why it fails: FortiAnalyzer is for logging and reporting, not enforcement.
- B
FortiClient EMS
FortiClient EMS acts as the endpoint management server, collecting compliance telemetry such as antivirus version and status from managed endpoints. It tags non-compliant devices, and FortiGate ZTNA policies then deny those devices access to sensitive applications.
- C
FortiAuthenticator
Why it fails: FortiAuthenticator handles authentication, not endpoint compliance.
- D
FortiGate ZTNA gateway
Why it fails: The ZTNA gateway enforces access based on tags, but tags are generated by EMS.