Courseiva
Security Profiles →mediumMultiple Choice

NSE4 Security Profiles Practice Question

An administrator is configuring email filtering on FortiGate to block spam. Which of the following is required for FortiGate to filter inbound email directly?

⚠ Common exam trap

Candidates often assume FortiGate requires a separate FortiMail appliance for any email filtering, but FortiGate's SMTP proxy feature provides direct inbound email filtering without additional hardware.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The FortiGate must be configured as an SMTP proxy

FortiGate can filter inbound email directly only when it is configured as an SMTP proxy, which allows it to intercept and inspect SMTP traffic at the application layer. This proxy mode enables the FortiGate to apply email filtering profiles, including anti-spam and antivirus, to SMTP sessions without requiring a separate appliance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    FortiMail must be deployed as a separate appliance

    Why it's wrong here

    FortiMail is a dedicated email security gateway that integrates with the FortiGate ecosystem, but it is not a mandatory component for email filtering. The FortiGate itself provides built-in email filtering through its UTM profiles, such as email filter, antivirus, and antispam, which can inspect SMTP traffic directly. Deploying FortiMail is an optional, more advanced solution for high-volume environments, not a requirement for configuring email filtering on the FortiGate.

  • ✓

    The FortiGate must be configured as an SMTP proxy

    Why this is correct

    The FortiGate must be configured to operate as an SMTP proxy in the security policy to intercept and filter email traffic on port 25. In this proxy mode, the FortiGate acts as a relay that receives, inspects, and forwards email, allowing the UTM email filter and antivirus profiles to examine the message body, headers, and attachments. This is the standard method to apply email filtering on FortiGate; without proxy mode, the device would only see IP and port information, not the mail content.

  • ✗

    SSL deep inspection must be enabled for SMTP traffic

    Why it's wrong here

    SSL deep inspection is only required if you need to filter SMTPS, which is SMTP encrypted over SSL/TLS (typically on ports 465 or 587). For plaintext SMTP on port 25, the FortiGate can inspect the email content directly without any decryption, so deep inspection is not a prerequisite for basic email filtering. Enabling deep inspection on SMTP traffic is a supplemental step for encrypted email, not a blanket requirement per the question's scenario.

  • ✗

    The email filtering profile must be applied to a policy covering port 110

    Why it's wrong here

    Port 110 is the POP3 protocol, which is used by email clients to download messages from a server, not for sending or relaying email between servers. Email filtering on the FortiGate targets SMTP traffic on port 25, the standard protocol for Internet mail transfer; applying the filter profile to a policy covering port 110 would have no effect on email that is being routed via SMTP. The profile must be attached to the specific policy that permits SMTP traffic to be properly enforced.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.