Courseiva
Security Profiles →mediumMultiple Select

Block Spam Emails to Internal Mail Server: Email Filter Profile Configuration

A FortiGate administrator wants to block spam emails sent to the company's mail server. The mail server is behind the FortiGate. Which THREE configurations should be applied?

Quick Answer

The answer is to create an Email Filter profile with spam detection enabled, apply that profile to a firewall policy handling SMTP traffic, and enable FortiGuard spam filtering. This combination works because the FortiGate must first inspect the mail traffic at the application layer via a firewall policy, then use the Email Filter profile to scan for spam signatures, while FortiGuard provides the real-time threat intelligence needed to identify and block unwanted messages before they reach the internal mail server. On the Fortinet NSE 4 exam, this scenario tests your understanding of how security profiles integrate with firewall policies to protect internal resources, and a common trap is forgetting that the profile alone does nothing without being attached to a policy. Remember the three-step chain: Policy, Profile, and FortiGuard—think of it as the “PPF” rule to ensure you never miss a required component.

⚠ Common exam trap

It's easy for candidates to confuse DLP or Application Control with email-specific spam filtering, failing to recognize that only the Email Filter profile with FortiGuard antispam can inspect SMTP message bodies and headers for spam content.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable FortiGuard spam filtering in the Email Filter profile

Option C is correct because the FortiGate's Email Filter profile relies on FortiGuard Anti-Spam service to detect and tag/block spam based on FortiGuard's spam signature and IP reputation databases. Option E is correct because an Email Filter profile must first be created and its spam detection (and optionally other checks like banned words, DNSBL, HELO checks) enabled before it can take any action. Option D is correct because an Email Filter profile only takes effect when it is applied to the firewall policy that permits the SMTP traffic destined to the internal mail server. Option A is not correct because DLP on FortiGate handles data leakage patterns (credit cards, SSNs, file types) rather than spam detection. Option B is not correct because Application Control identifies and blocks applications by signature/behavior, not spam content within SMTP sessions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable DLP to filter spam

    Why it's wrong here

    DLP inspects content for data leakage patterns such as credit card or personal data; it does not perform sender reputation or spam signature analysis. DLP is the correct control when the requirement is preventing sensitive information from leaving the network.

  • ✗

    Configure Application Control to block email applications

    Why it's wrong here

    Application Control identifies and blocks applications by signature, not email content, so it cannot classify inbound messages as spam. It is the right choice when the goal is restricting which applications, such as peer-to-peer tools, may traverse the firewall.

  • ✓

    Enable FortiGuard spam filtering in the Email Filter profile

    Why this is correct

    Enabling FortiGuard spam filtering within the Email Filter profile activates the cloud-based spam signature and reputation service. This satisfies the requirement to block spam, since the FortiGate must query FortiGuard to classify and reject unsolicited mail before it reaches the protected mail server.

  • ✓

    Apply the Email Filter profile to the firewall policy that allows SMTP traffic to the mail server

    Why this is correct

    Attaching the Email Filter profile to the SMTP-permitting firewall policy enforces spam inspection on traffic flowing to the mail server. Without this binding, the profile exists but is never applied, so the stem's requirement to actually block inbound spam is unmet.

  • ✓

    Create an Email Filter profile with spam detection enabled

    Why this is correct

    Creating an Email Filter profile with spam detection enabled establishes the inspection container holding the anti-spam settings. This satisfies the stem's requirement because the profile must exist before FortiGuard spam filtering can be enabled and bound to a policy.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on NSE4

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A FortiGate administrator wants to block spam emails destined for internal users. The FortiGate receives SMTP traffic on port 25. What is the most effective way to filter spam using the email filter profile?

medium
  • A.Enable spam filtering in the antivirus profile
  • ✓ B.Apply an email filter profile to a firewall policy that allows SMTP traffic
  • C.Use a DNS filter to block spam domains
  • D.Configure a web filter to block webmail

Why B: An email filter profile is specifically designed to inspect SMTP traffic and apply anti-spam techniques such as RBL, MIME header checks, and heuristic analysis. By applying the email filter profile to a firewall policy that allows SMTP traffic on port 25, the FortiGate can intercept and filter spam before it reaches internal users.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.