Courseiva
Security Profiles →easyMultiple Choice

NSE4 Security Profiles Practice Question

Which FortiGate security feature can be used to block outgoing emails that contain specific keywords, such as confidential information?

⚠ Common exam trap

A common mix-up: candidates confuse Email Filter with Antivirus or Web Filter, mistakenly thinking that keyword blocking is a general security function rather than a specific email content inspection feature.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Email Filter

Email Filter is the correct answer because it is the FortiGate security profile specifically designed to inspect SMTP, POP3, and IMAP traffic for content violations. It can block outgoing emails based on keyword patterns, such as 'confidential', by matching against defined filter rules in the email filter profile, which operates at the application layer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Email Filter

    Why this is correct

    Email Filter is the correct feature because it is specifically designed to inspect SMTP traffic, including outgoing email. It can block outbound spam using anti-spam techniques such as IP reputation, Bayesian filtering, and content analysis. This feature is protocol-aware for email and can enforce policies on both inbound and outbound messages.

  • ✗

    Web Filter

    Why it's wrong here

    Web Filter is not the correct feature because it focuses on controlling HTTP and HTTPS web traffic by categorizing URLs and blocking access to inappropriate or malicious websites. It does not parse SMTP or email protocol content, so it cannot analyze or block outgoing email spam messages. Web filtering operates at the web layer, not the email layer.

  • ✗

    Application Control

    Why it's wrong here

    Application Control is not the correct feature because it identifies and controls network applications by signature, regardless of port, to enforce application usage policies. While it may recognize SMTP as an application traffic type, it does not examine email message content or determine spam status. It can block an email client or protocol entirely, but it lacks the context to filter unsolicited bulk email.

  • ✗

    Antivirus

    Why it's wrong here

    Antivirus is not the correct feature because it scans files, attachments, and web content for malware signatures, such as viruses and worms. Even if an email attachment contains malware, antivirus does not classify email as spam; spam is defined by unsolicited bulk messaging, not by malicious code. Therefore, antivirus cannot replace email filtering for blocking outgoing spam.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.