NSE4 Security Profiles Practice Question
Which FortiGate feature allows the administrator to scan SMTP, IMAP, and POP3 traffic for spam and apply actions such as tagging or discarding?
⚠ Common exam trap
Test-takers frequently confuse the Email Filter profile with the Antivirus profile, thinking spam is a type of virus, but spam detection uses different heuristics and databases (e.g., FortiGuard Antispam) than antivirus signatures.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Email filter profile
The Email Filter profile is the correct feature because it is specifically designed to scan SMTP, IMAP, and POP3 traffic for spam and phishing content. It allows administrators to apply actions such as tagging the subject line, discarding the email, or quarantining based on spam scores, blacklists, and heuristics.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Email filter profile
Why this is correct
The Email filter profile is the correct FortiGate feature for SMTP scanning. It performs protocol-aware inspection of SMTP, IMAP, and POP3 traffic, applying spam rules, IP reputation, header/content analysis, and optional greylisting to classify and block unsolicited messages. This is the only profile specifically designed to detect spam and phishing content inside email traffic, including SMTP relay conversations.
- ✗
Application control profile
Why it's wrong here
The Application control profile is not designed for SMTP spam scanning because it identifies and categorizes applications by their unique network signatures, not by the textual content of their payloads. While it can detect that SMTP protocol is being used, it does not parse email headers, body text, or attachments to make a spam judgment. Its purpose is to enforce application usage policies, such as allowing or blocking SMTP clients, rather than inspecting message content for spam characteristics.
- ✗
Antivirus profile
Why it's wrong here
The Antivirus profile is a wrong choice because it targets malware signatures and heuristics in files and attachments, not the spam classification of email content. Even if it scans SMTP attachments for viruses, it does not evaluate reputation, language, or header anomalies that define spam. Additionally, an antivirus profile alone would fail to detect plain-text spam or phishing messages that contain no malicious executable, since its scanning engine is not oriented toward unsolicited bulk email.
- ✗
Web filter profile
Why it's wrong here
The Web filter profile is incorrect because it operates exclusively on HTTP and HTTPS traffic, enforcing URL category and content reputation for web browsing sessions. It does not understand SMTP, IMAP, or POP3 protocols, so it cannot intercept or inspect email messages transmitted via these protocols. Applying a web filter to SMTP traffic would be a protocol mismatch, leaving spam emails completely uninspected; email-specific scanning requires an email filter profile.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.