Courseiva
Security ProfilesmediumMultiple SelectObjective-mapped

Block Spam Emails to Internal Mail Server: Email Filter Profile Configuration

A FortiGate administrator wants to block spam emails sent to the company's mail server. The mail server is behind the FortiGate. Which THREE configurations should be applied?

Quick Answer

The answer is to create an Email Filter profile with spam detection enabled, apply that profile to a firewall policy handling SMTP traffic, and enable FortiGuard spam filtering. This combination works because the FortiGate must first inspect the mail traffic at the application layer via a firewall policy, then use the Email Filter profile to scan for spam signatures, while FortiGuard provides the real-time threat intelligence needed to identify and block unwanted messages before they reach the internal mail server. On the Fortinet NSE 4 exam, this scenario tests your understanding of how security profiles integrate with firewall policies to protect internal resources, and a common trap is forgetting that the profile alone does nothing without being attached to a policy. Remember the three-step chain: Policy, Profile, and FortiGuard—think of it as the “PPF” rule to ensure you never miss a required component.

⚠ Common exam trap

It's easy for candidates to confuse DLP or Application Control with email-specific spam filtering, failing to recognize that only the Email Filter profile with FortiGuard antispam can inspect SMTP message bodies and headers for spam content.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Enable FortiGuard spam filtering in the Email Filter profile

FortiGate's Email Filter profile integrates with FortiGuard's antispam service to block spam at the gateway. This profile uses real-time signature-based and heuristic analysis to identify and reject spam before it reaches the internal mail server.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enable DLP to filter spam

    Why it's wrong here

    DLP is for data leak prevention, not spam filtering.

  • Configure Application Control to block email applications

    Why it's wrong here

    App control blocks applications, not spam content within email.

  • Enable FortiGuard spam filtering in the Email Filter profile

    Why this is correct

    FortiGuard provides up-to-date spam signatures.

  • Apply the Email Filter profile to the firewall policy that allows SMTP traffic to the mail server

    Why this is correct

    The profile must be applied to the relevant policy.

  • Create an Email Filter profile with spam detection enabled

    Why this is correct

    Email filter profiles handle spam detection.

About these practice questions

Courseiva writes every NSE4 question from scratch — 282 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on NSE4

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A FortiGate administrator wants to block spam emails destined for internal users. The FortiGate receives SMTP traffic on port 25. What is the most effective way to filter spam using the email filter profile?

medium
  • A.Enable spam filtering in the antivirus profile
  • B.Apply an email filter profile to a firewall policy that allows SMTP traffic
  • C.Use a DNS filter to block spam domains
  • D.Configure a web filter to block webmail

Why B: An email filter profile is specifically designed to inspect SMTP traffic and apply anti-spam techniques such as RBL, MIME header checks, and heuristic analysis. By applying the email filter profile to a firewall policy that allows SMTP traffic on port 25, the FortiGate can intercept and filter spam before it reaches internal users.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.