nerdexam
Fortinet

NSE4 · Question #363

Which statement best describes what SSL VPN Client Integrity Check does?

The correct answer is B. Detects the Windows client security applications running in the SSL VPN client's PCs. SSL VPN Client Integrity Check assesses the security posture of the connecting client device by detecting specific security applications and system configurations.

Submitted by eva_at· Apr 18, 2026VPN and ZTNA

Question

Which statement best describes what SSL VPN Client Integrity Check does?

Options

  • ABlocks SSL VPN connection attempts from users that has been blacklisted.
  • BDetects the Windows client security applications running in the SSL VPN client's PCs.
  • CValidates the SSL VPN user credential.
  • DVerifies which SSL VPN portal must be presented to each SSL VPN user.
  • EVerifies that the latest SSL VPN client is installed in the client's PC.

How the community answered

(34 responses)
  • A
    6% (2)
  • B
    91% (31)
  • E
    3% (1)

Why each option

SSL VPN Client Integrity Check assesses the security posture of the connecting client device by detecting specific security applications and system configurations.

ABlocks SSL VPN connection attempts from users that has been blacklisted.

Blocking blacklisted users is typically handled by authentication mechanisms and user group policies, not specifically by the Client Integrity Check.

BDetects the Windows client security applications running in the SSL VPN client's PCs.Correct

SSL VPN Client Integrity Check (also known as Host Check or Endpoint Security) inspects the client's operating system to determine if required security applications (like antivirus, firewall, or specific patches) are present and running, ensuring the endpoint meets defined security standards before allowing VPN access.

CValidates the SSL VPN user credential.

User credential validation is handled by authentication servers (e.g., local, RADIUS, LDAP), not by the Client Integrity Check.

DVerifies which SSL VPN portal must be presented to each SSL VPN user.

Presenting the correct SSL VPN portal is determined by user group membership and portal mapping, not by Client Integrity Check.

EVerifies that the latest SSL VPN client is installed in the client's PC.

While some integrity checks might verify client software versions, the primary and broader function is detecting the *presence and state of security applications* and system health, not just the VPN client version.

Concept tested: SSL VPN Client Integrity Check functionality

Source: https://docs.fortinet.com/document/fortigate/7.4.0/fortios-handbook/268962/client-integrity-check

Topics

#SSL VPN#Client Integrity Check#Endpoint Security#Host Check

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice