Courseiva
Security Profiles →mediumMultiple Choice

NSE4 Security Profiles Practice Question

An administrator configures an email filter profile to block spam. Users complain that legitimate emails from a specific partner are being blocked. The admin wants to allow emails from that partner's domain without disabling spam filtering for other domains. What is the BEST approach?

⚠ Common exam trap

Many candidates confuse increasing the spam threshold (a global sensitivity adjustment) with creating a targeted exception, or they incorrectly assume that disabling filtering entirely is the simplest fix, when FortiOS allows precise allowlisting within the same profile.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add the partner's domain to the IP allowlist in the email filter profile

Adding the partner's domain to the IP allowlist in the email filter profile is the best approach because it creates a specific exception for that domain while keeping spam filtering active for all other traffic. The allowlist overrides the spam detection engine for matching senders, ensuring legitimate emails are not blocked without weakening the overall security posture.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Add the partner's domain to the IP allowlist in the email filter profile

    Why this is correct

    Adding the partner's domain to the IP allowlist (or domain allowlist) in the email filter profile explicitly exempts that sender from spam scanning and blocking. This is a targeted action: only the partner's emails bypass the spam and content checks, while all other traffic remains subject to the full email filtering policy. It is the most efficient and secure way to ensure legitimate business emails are delivered without weakening protection for everyone else.

  • ✗

    Increase the spam threshold until the emails pass

    Why it's wrong here

    Increasing the spam threshold in the email filter profile raises the score that a message must exceed before it is marked as spam. This makes the entire filter less sensitive, so while the partner's emails might pass, so will more genuine spam and phishing attempts from all other senders. It is a global, blunt adjustment that increases risk for every user and is not a domain-specific solution to the partner problem.

  • ✗

    Disable spam filtering for the entire firewall policy

    Why it's wrong here

    Disabling spam filtering for the entire firewall policy removes all email inspection for every message traversing that policy, not just messages from the partner's domain. This creates a wide security gap, allowing spam, malware-laden attachments, and phishing URLs to reach all users through that policy. The partner's issue would be solved, but at the cost of opening the whole network to email-borne threats, making this an unacceptable trade-off.

  • ✗

    Create a separate firewall policy for the partner's traffic without email filtering

    Why it's wrong here

    Creating a separate firewall policy for partner traffic without email filtering might work if the partner's mail server can be matched strictly by source IP or interface, but it is not email-domain aware. If the partner sends from multiple IPs or shares an IP with other mail servers, the policy will either miss some emails or wrongly exempt unrelated traffic, and it adds complexity to manage alongside the existing policy. A dedicated allowlist in the email filter profile is simpler and precisely scoped to the partner's domain.

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.