NSE4 Security Profiles Practice Question
Which FortiGate security feature can be used to block outgoing emails that contain specific keywords, such as confidential information?
⚠ Common exam trap
A common mix-up: candidates confuse Email Filter with Antivirus or Web Filter, mistakenly thinking that keyword blocking is a general security function rather than a specific email content inspection feature.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Email Filter
Email Filter is the correct answer because it is the FortiGate security profile specifically designed to inspect SMTP, POP3, and IMAP traffic for content violations. It can block outgoing emails based on keyword patterns, such as 'confidential', by matching against defined filter rules in the email filter profile, which operates at the application layer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Email Filter
Why this is correct
Email Filter is the correct feature because it is specifically designed to inspect SMTP traffic, including outgoing email. It can block outbound spam using anti-spam techniques such as IP reputation, Bayesian filtering, and content analysis. This feature is protocol-aware for email and can enforce policies on both inbound and outbound messages.
- ✗
Web Filter
Why it's wrong here
Web Filter is not the correct feature because it focuses on controlling HTTP and HTTPS web traffic by categorizing URLs and blocking access to inappropriate or malicious websites. It does not parse SMTP or email protocol content, so it cannot analyze or block outgoing email spam messages. Web filtering operates at the web layer, not the email layer.
- ✗
Application Control
Why it's wrong here
Application Control is not the correct feature because it identifies and controls network applications by signature, regardless of port, to enforce application usage policies. While it may recognize SMTP as an application traffic type, it does not examine email message content or determine spam status. It can block an email client or protocol entirely, but it lacks the context to filter unsolicited bulk email.
- ✗
Antivirus
Why it's wrong here
Antivirus is not the correct feature because it scans files, attachments, and web content for malware signatures, such as viruses and worms. Even if an email attachment contains malware, antivirus does not classify email as spam; spam is defined by unsolicited bulk messaging, not by malicious code. Therefore, antivirus cannot replace email filtering for blocking outgoing spam.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.