DLP Profile to Block Credit Card Numbers in Email
An administrator wants to prevent data leakage by blocking outbound emails that contain credit card numbers. Which security profile should be configured?
Quick Answer
The answer is a DLP profile. This is the correct security profile because Data Leak Prevention (DLP) profiles on FortiGate are specifically designed to inspect email content for sensitive data patterns, such as credit card numbers, using predefined or custom data classifiers. When a match is found, the profile can take action to block or quarantine the outbound email, directly preventing data leakage. On the Fortinet NSE 4 Network Security Professional exam, this question tests your understanding of which security feature handles content inspection for regulated data, often appearing alongside traps like antivirus or web filtering profiles, which do not scan for pattern-based sensitive information. A key memory tip is to associate DLP with "Data" and "Patterns"—if you need to block specific numbers or strings in the body of an email, think DLP, not AV or IPS.
⚠ Common exam trap
A common mix-up: candidates confuse DLP with Email Filter or Antivirus profiles, not realizing that DLP is the only profile that performs content-aware inspection for sensitive data patterns in outbound emails.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DLP profile
DLP (Data Loss Prevention) profiles are specifically designed to inspect content such as credit card numbers in outbound emails and block them to prevent data leakage. While other profiles handle spam, web access, or malware, only DLP can perform pattern-based content inspection on email bodies and attachments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Email Filter profile
Why it's wrong here
Email Filter profiles act on sender, recipient, subject and attachment characteristics, not on scanning message bodies for data patterns such as credit card numbers. They are tempting because they govern email flow, but they would be correct for blocking spam, phishing or specific senders and domains.
- ✗
Web Filter profile
Why it's wrong here
Web Filter profiles classify and control HTTP/HTTPS browsing by URL category, not SMTP email content, so they cannot inspect outbound messages for credit card numbers. They are tempting because they enforce content-based policy, but they would be correct for restricting web access by category or reputation.
- ✗
Antivirus profile
Why it's wrong here
Antivirus profiles scan for malware signatures and malicious payloads, not patterns like credit card numbers, so they cannot detect or block data leakage in outbound email. They are tempting because they inspect traffic content, but they would be correct for detecting viruses and exploits rather than sensitive-data exfiltration.
- ✓
DLP profile
Why this is correct
A DLP profile inspects email content for sensitive data patterns, such as credit card numbers, and blocks matching messages. This directly satisfies the stem's requirement to prevent data leakage via outbound email, since DLP is the only FortiGate profile that performs content-based pattern matching on data rather than application or protocol control.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on NSE4
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A FortiGate administrator needs to prevent data leakage by blocking the upload of files containing credit card numbers via web traffic. Which THREE components must be configured? (Choose three.)
medium- A.Application control profile to block file upload applications
- ✓ B.DLP profile with a rule to detect credit card numbers
- ✓ C.Firewall policy that applies the DLP profile and SSL inspection to the traffic
- D.Antivirus profile to scan the files for malware
- ✓ E.SSL deep inspection to decrypt HTTPS traffic
Why B: A DLP (Data Loss Prevention) profile is specifically designed to inspect content for sensitive data patterns, such as credit card numbers, using predefined or custom data patterns. When configured with a rule to detect credit card numbers, the DLP profile can block or log the upload of files containing such data over web traffic.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.