DLP Configuration for Credit Card Detection via SMTP and HTTPS
Which security profile type is used to prevent sensitive data such as credit card numbers from being sent out of the network via email or web traffic?
⚠ Common exam trap
Watch out — candidates often confuse DLP with email filtering or web filtering, assuming that content inspection for sensitive data is handled by those profiles, but DLP is the only profile dedicated to data loss prevention with pattern-based content inspection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DLP profile
A DLP (Data Loss Prevention) profile is specifically designed to inspect content in transit (e.g., email, web traffic) and block or alert on sensitive data patterns such as credit card numbers, Social Security numbers, or other regulated data. Unlike other security profiles, DLP uses predefined or custom data identifiers and pattern matching to enforce data protection policies, making it the correct choice for preventing sensitive data exfiltration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Email filter profile
Why it's wrong here
In FortiOS, an email filter profile (also known as antispam/antiphishing) evaluates SMTP/IMAP/POP3 traffic using FortiGuard spam signatures, IP/domain reputation, and batched RBL checks to classify messages as spam, phishing, or legitimate email. These profiles can suppress malicious email but do not perform deep content inspection for confidential data patterns such as SSNs, credit card numbers, or classified document labels. Their primary objective is email hygiene, not data-loss prevention, so they would not block an outgoing spreadsheet containing personal data unless it was also caught by a separate DLP sensor.
- ✗
Antivirus profile
Why it's wrong here
An antivirus security profile scans content for malicious executables and code through FortiGuard's signature database, heuristics, and sandboxing, detecting trojans, ransomware, and exploits before the content reaches its destination. It classifies traffic based on malware indicators, not on the semantic content or sensitivity of the data inside a file; a PDF containing a customer list of Social Security numbers would be allowed if it had no malware payload. Therefore, antivirus protects against malicious software, not against the accidental exposure of sensitive information, leaving DLP as the dedicated prevention mechanism.
- ✗
Web filter profile
Why it's wrong here
A web filter profile enforces access control to internet resources by evaluating URL categories, FortiGuard rating, domain reputation, and web content types, blocking websites such as social media, gambling, or malicious sites based on policy. This profile looks at the destination and the category of the request, not at the body of HTTP/HTTPS requests or responses, so it cannot detect when users post confidential data to a web form or download a sensitive file from an approved site. Content-based data detection for web traffic is handled by a DLP profile, not by web filtering.
- ✓
DLP profile
Why this is correct
A DLP (Data Leak Prevention) profile uses dictionaries of sensitive data types—such as credit card numbers, US Social Security numbers, dates of birth, and custom regex patterns—and inspects traffic content at the application layer to detect matches in files, HTTP posts, emails, or FTP transfers. When a match occurs, the DLP sensor can log, alert, quarantine, or block the transaction, and it can be applied in a FortiGate security policy together with antivirus and web-filter profiles. Its purpose is specifically to prevent or control the unauthorized transfer of sensitive data, making it the correct profile for this requirement.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.