NSE4 Security Profiles Practice Question
An administrator is configuring email filtering on FortiGate to block spam. Which of the following is required for FortiGate to filter inbound email directly?
⚠ Common exam trap
Candidates often assume FortiGate requires a separate FortiMail appliance for any email filtering, but FortiGate's SMTP proxy feature provides direct inbound email filtering without additional hardware.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The FortiGate must be configured as an SMTP proxy
FortiGate can filter inbound email directly only when it is configured as an SMTP proxy, which allows it to intercept and inspect SMTP traffic at the application layer. This proxy mode enables the FortiGate to apply email filtering profiles, including anti-spam and antivirus, to SMTP sessions without requiring a separate appliance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
FortiMail must be deployed as a separate appliance
Why it's wrong here
FortiMail is a dedicated email security gateway that integrates with the FortiGate ecosystem, but it is not a mandatory component for email filtering. The FortiGate itself provides built-in email filtering through its UTM profiles, such as email filter, antivirus, and antispam, which can inspect SMTP traffic directly. Deploying FortiMail is an optional, more advanced solution for high-volume environments, not a requirement for configuring email filtering on the FortiGate.
- ✓
The FortiGate must be configured as an SMTP proxy
Why this is correct
The FortiGate must be configured to operate as an SMTP proxy in the security policy to intercept and filter email traffic on port 25. In this proxy mode, the FortiGate acts as a relay that receives, inspects, and forwards email, allowing the UTM email filter and antivirus profiles to examine the message body, headers, and attachments. This is the standard method to apply email filtering on FortiGate; without proxy mode, the device would only see IP and port information, not the mail content.
- ✗
SSL deep inspection must be enabled for SMTP traffic
Why it's wrong here
SSL deep inspection is only required if you need to filter SMTPS, which is SMTP encrypted over SSL/TLS (typically on ports 465 or 587). For plaintext SMTP on port 25, the FortiGate can inspect the email content directly without any decryption, so deep inspection is not a prerequisite for basic email filtering. Enabling deep inspection on SMTP traffic is a supplemental step for encrypted email, not a blanket requirement per the question's scenario.
- ✗
The email filtering profile must be applied to a policy covering port 110
Why it's wrong here
Port 110 is the POP3 protocol, which is used by email clients to download messages from a server, not for sending or relaying email between servers. Email filtering on the FortiGate targets SMTP traffic on port 25, the standard protocol for Internet mail transfer; applying the filter profile to a policy covering port 110 would have no effect on email that is being routed via SMTP. The profile must be attached to the specific policy that permits SMTP traffic to be properly enforced.
Visual reference
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.