NSE4 Security Profiles Practice Question
Which security profile is used to detect and prevent spam email messages?
⚠ Common exam trap
Test-takers frequently confuse the Email Filter profile with the Antivirus profile, assuming spam detection is part of malware scanning, but FortiGate separates these functions: Antivirus handles file-based threats, while Email Filter handles message-based classification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Email filter profile
The Email Filter profile is specifically designed to detect and prevent spam by analyzing SMTP traffic, applying techniques such as DNS-based Blackhole Lists (DNSBL), email reputation filtering, and heuristic analysis to identify unsolicited bulk email. Unlike other security profiles, it operates at the application layer for email protocols (SMTP, POP3, IMAP) to enforce anti-spam policies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DLP profile
Why it's wrong here
Data Loss Prevention profiles in FortiOS are designed to inspect content for sensitive patterns such as social security numbers, credit card numbers, and other confidential data to prevent unauthorized egress. They operate on the payload of traffic and are not capable of distinguishing between legitimate correspondence and unsolicited bulk email; their classification logic is based on data identifiers, not message semantics or sender reputation. Thus, applying a DLP profile to SMTP traffic would not detect or quarantine spam.
- ✗
Web filter profile
Why it's wrong here
Web filter profiles function as a content and category-based gateway for HTTP and HTTPS traffic, restricting access to URLs that fall under categories like social media or phishing. When configured in a FortiGate policy, the web filter engine evaluates the destination host and requested URI path, not the envelope, headers, or body of an email message. Because SMTP traffic is not an HTTP request, a web filter profile will be bypassed entirely for mail sessions and cannot provide any level of spam protection.
- ✓
Email filter profile
Why this is correct
The email filter profile is the dedicated antispam engine within FortiGate, combining sender IP/domain blacklists, DNS-based blocklists, and real-time content analysis with ML-based classification. It inspects SMTP sessions by examining the message envelope, MIME headers, and body against a library of spam signatures and heuristics, while also performing Sender Policy Framework, DKIM, and DMARC verification. This profile can automatically quarantine, tag, or drop unwanted messages, making it the correct choice for spam detection.
- ✗
Antivirus profile
Why it's wrong here
Antivirus profiles focus on malware identification by scanning file signatures, emulating code, and using sandboxing to detect viruses, worms, and ransomware in attachments or web downloads. While a malicious attachment may accompany a spam email, an AV signature check does not evaluate whether a message is unsolicited, misleading, or bulk, which is the core definition of spam. In a defense-in-depth setup, the antivirus profile is a complementary layer, but it is not the security profile that detects spam itself.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.