Courseiva
Security ProfilesmediumMultiple ChoiceObjective-mapped

Reduce False Positives in Spam Filtering: Increase Spam Threshold Score

A FortiGate administrator configures an email filter profile to block spam. Users report that some legitimate emails are being blocked. The administrator wants to reduce false positives while still blocking spam. What should the administrator do?

Quick Answer

The answer is to increase the spam threshold score. This is correct because spam filtering on FortiGate assigns a heuristic score to each email based on characteristics like content and sender reputation; a lower threshold means even mildly suspicious emails are blocked, causing false positives, while raising the threshold requires a higher score to trigger a block, thereby reducing false positives at the cost of potentially letting some spam through. On the Fortinet NSE 4 exam, this concept tests your understanding of how email filter profiles balance detection aggressiveness with user impact—a common trap is confusing the threshold direction, as lowering it actually increases false positives. Remember the memory tip: “Higher threshold, higher tolerance for legitimate mail; lower threshold, lower tolerance for spam.”

⚠ Common exam trap

Watch out — candidates often confuse increasing vs. decreasing the threshold, mistakenly thinking a lower threshold is more permissive, when in fact a lower threshold blocks more emails and increases false positives.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Increase the spam threshold score

Increasing the spam threshold score raises the bar for what is classified as spam, so only emails with a higher spam score (indicating stronger spam characteristics) are blocked. This reduces false positives because legitimate emails with lower scores will no longer be blocked, while still blocking high-scoring spam.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Disable the email filter profile

    Why it's wrong here

    Disabling the profile would stop blocking spam but also reduce security.

  • Increase the spam threshold score

    Why this is correct

    A higher threshold means emails need a higher spam score to be blocked, reducing false positives.

  • Decrease the spam threshold score

    Why it's wrong here

    Decreasing the spam threshold score would make the FortiGate's email filter more aggressive, causing it to block emails with lower spam scores. This action would unfortunately *increase* the number of legitimate emails incorrectly identified as spam (false positives), directly contradicting the administrator's goal to reduce them. This option is tempting because adjusting the threshold is relevant to spam filtering. It would be the correct choice if the objective were to block *more* spam, for instance, when users report too much spam getting through.

  • Enable the FortiGuard spam filter only

    Why it's wrong here

    Enabling only FortiGuard may not address false positives from other filter rules.

About these practice questions

One of 282 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on NSE4

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An administrator configures an email filter profile to block spam. Users complain that legitimate emails from a specific partner are being blocked. The admin wants to allow emails from that partner's domain without disabling spam filtering for other domains. What is the BEST approach?

medium
  • A.Add the partner's domain to the IP allowlist in the email filter profile
  • B.Increase the spam threshold until the emails pass
  • C.Disable spam filtering for the entire firewall policy
  • D.Create a separate firewall policy for the partner's traffic without email filtering

Why A: Adding the partner's domain to the IP allowlist in the email filter profile is the best approach because it creates a specific exception for that domain while keeping spam filtering active for all other traffic. The allowlist overrides the spam detection engine for matching senders, ensuring legitimate emails are not blocked without weakening the overall security posture.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.