Question 1
Q1A financial services company is implementing a Zero Trust Network Access (ZTNA) solution. The security policy requires that only corporate-owned Windows devices with the latest OS security patches and active antivirus protection can access the internal accounting application. An administrator has configured ZTNA tags in FortiClient EMS for these posture checks. Which component is responsible for enforcing the access decision based on these tags?
Show answer & explanation
Correct answer: C
In a Fortinet ZTNA solution, the FortiGate acts as the access proxy and enforcement point. It receives the connection request, queries the FortiClient EMS for the endpoint's posture tags, and then evaluates its ZTNA policy rules to either grant or deny access. FortiClient reports the posture, and EMS manages the tags, but FortiGate makes the final enforcement decision.