Courseiva
Security Profiles →mediumMultiple Choice

NSE4 Security Profiles Practice Question

A FortiGate administrator wants to block spam emails destined for internal users. The FortiGate receives SMTP traffic on port 25. What is the most effective way to filter spam using the email filter profile?

⚠ Common exam trap

Test-takers frequently confuse the email filter profile with the antivirus profile, assuming antivirus handles all email threats, but antivirus only scans for malware, not spam.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Apply an email filter profile to a firewall policy that allows SMTP traffic

An email filter profile is specifically designed to inspect SMTP traffic and apply anti-spam techniques such as RBL, MIME header checks, and heuristic analysis. By applying the email filter profile to a firewall policy that allows SMTP traffic on port 25, the FortiGate can intercept and filter spam before it reaches internal users.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable spam filtering in the antivirus profile

    Why it's wrong here

    FortiGate's antivirus profile is strictly a malware scanner that inspects files, executables, and attachments for virus signatures; it has no content- or reputation-based antispam engine and is not designed to classify message body or header characteristics. Because spam filtering is implemented only in the dedicated email filter profile, toggling 'spam filtering' in the antivirus profile is impossible. Applying the antivirus profile alone leaves SMTP message streams untouched by any anti-spam logic, so spam mail passes through unimpeded.

  • ✓

    Apply an email filter profile to a firewall policy that allows SMTP traffic

    Why this is correct

    For inbound SMTP, the correct procedure is to create a firewall policy for the SMTP service and attach an email filter profile to that policy; the FortiOS inspection engine then applies FortiGuard Antispam category lookups, IP/DNSBL checks, header and MIME analysis, and banned-word rules to every accepted email. The email filter profile is the sole UTM object that contains antispam capabilities, and it is designed to operate on mail protocols (SMTP, POP3, IMAP) in proxy-based inspection mode. This policy-level attachment is exactly how a FortiGate administrator activates spam blocking in production.

  • ✗

    Use a DNS filter to block spam domains

    Why it's wrong here

    A DNS filter categorizes and blocks domain-name resolution based on FortiGuard web categories or custom domain lists, which prevents users from reaching websites but does not examine the contents of email messages. While it could theoretically block the DNS lookup of a spammer's known server before a message is sent, it cannot stop messages that are already destined to the internal email server or messages from hosts whose IPs are not domain-filtered. Spam detection relies on message body, header, and reputation data, not DNS queries generated by the email client or server, so this option is ineffective.

  • ✗

    Configure a web filter to block webmail

    Why it's wrong here

    Configuring a web filter to block webmail influences only HTTP/HTTPS webmail sessions such as Outlook Web Access or browser-based Gmail; it has no effect on the SMTP dialogue that a mail server or client uses for message transport. SMTP spam is delivered through port 25/587 connection, which web-filtering daemons never inspect, because they work on URL and HTTP content rather than on the binary mail transaction. Thus, even a strict web-filter policy that blocks every webmail category leaves the SMTP pipeline wide open for spam.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.