Courseiva
Security Profiles →mediumMultiple Choice

NSE4 Security Profiles Practice Question

An administrator configures an email filter profile to block spam. Despite correct configuration, spam emails still reach users' inboxes. The FortiGate is deployed as a transparent bridge. What is the most likely reason?

⚠ Common exam trap

Many exam-takers assume email filtering works regardless of inspection mode, but FortiGate specifically requires proxy-based inspection for SMTP proxy features like email filter profiles to function.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The firewall policy is using flow-based inspection, which does not support SMTP proxy

In a transparent bridge deployment, FortiGate uses flow-based inspection by default, which does not support SMTP proxy-based email filtering. The email filter profile requires proxy-based inspection to intercept and block spam at the SMTP protocol level. Without enabling proxy-based inspection on the firewall policy, the FortiGate cannot apply the email filter profile effectively, allowing spam to pass through.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The FortiGate does not have a valid FortiGuard license

    Why it's wrong here

    A valid FortiGuard license is required for up-to-date spam signature databases and real-time IP/domain reputation checks, but FortiGate email filtering can still operate with locally defined blacklists, whitelists, and static keyword filters even without a license. Because the administrator configured an email filter profile with a block action, the absence of a FortiGuard license alone would not prevent the profile from taking effect on known local entries. The issue is more fundamental to how the firewall policy handles SMTP traffic, not the license status.

  • ✗

    The emails are encrypted with TLS and deep inspection is not enabled

    Why it's wrong here

    While TLS-encrypted SMTP sessions require deep inspection (SSL/TLS inspection) for the FortiGate to read message content, email filtering in proxy-based mode can still act on the SMTP envelope, such as sender/recipient addresses, even without decryption. However, in this scenario the FortiGate is deployed in transparent bridge mode and the policy is using flow-based inspection, which means the FortiGate is not acting as an SMTP proxy at all. Therefore, the lack of deep inspection is not the root cause; even with deep inspection enabled, flow-based inspection would not invoke the SMTP proxy engine to apply the email filter profile.

  • ✗

    The email filter profile is set to 'monitor' instead of 'block'

    Why it's wrong here

    If the email filter profile were set to 'monitor,' the FortiGate would generate logs but would not actively drop or reject the email, so the administrator would see the emails still arriving. But the scenario explicitly states the profile is configured to block, and the action for spam should be 'block' or 'discard,' not 'monitor.' Since the configured action is block, the problem must lie elsewhere—in this case, the firewall policy's flow-based inspection mode that prevents the proxy-based SMTP scanning from ever engaging.

  • ✓

    The firewall policy is using flow-based inspection, which does not support SMTP proxy

    Why this is correct

    Email filtering for SMTP on FortiGate is performed by the antivirus/email filter proxy engine, which only operates in proxy-based inspection mode. When a firewall policy is set to flow-based inspection, the FortiGate uses a streamlined forwarding path that does not support SMTP proxy functionality, so the email filter profile is silently ignored for that traffic. To enforce email filtering, the policy must use proxy-based inspection (or configure a transparent proxy), allowing the FortiGate to buffer and scan SMTP messages before forwarding them.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.