FortiGate Email Filtering Profile for Phishing Detection
A company wants to detect and block phishing emails that contain malicious links. Which FortiGate security profile should be used?
Quick Answer
The answer is the Email Filtering profile. This profile is the correct choice because it is specifically engineered to inspect SMTP, POP3, and IMAP traffic for phishing indicators, including malicious URLs embedded in email bodies and attachments, and can block or quarantine messages based on URL reputation, sender authentication checks like SPF/DKIM/DMARC, and content analysis. On the Fortinet NSE 7 Advanced Security NSE7 exam, this question tests your ability to distinguish between security profiles—a common trap is confusing the Email Filtering profile with the Web Filtering profile, but remember that Web Filtering handles HTTP/HTTPS traffic, not email protocols. A solid memory tip is to associate "phishing" with "email protocols" and thus "Email Filtering," not web traffic.
⚠ Common exam trap
Test-takers frequently confuse Web Filtering (which handles web traffic) with Email Filtering (which handles email protocols), assuming URL reputation checks in web filtering can block phishing links in emails, but FortiGate requires the Email Filtering profile to inspect SMTP/IMAP/POP3 traffic and apply email-specific actions like quarantine.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Email Filtering profile
FortiGate's Email Filtering profile is specifically designed to inspect SMTP, POP3, and IMAP traffic for phishing indicators, including malicious URLs in email bodies and attachments. It can block or quarantine emails based on URL reputation, sender authentication (SPF/DKIM/DMARC), and content analysis, directly addressing the requirement to detect and block phishing emails with malicious links.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Antivirus profile
Why it's wrong here
Antivirus scans attachments and payloads for malware signatures, but a phishing email whose only threat is a URL carries no malicious file to detect. Antivirus is correct when blocking known malware binaries transferred over SMTP, HTTP or FTP.
- ✗
Web Filtering profile
Why it's wrong here
Web Filtering inspects HTTP/HTTPS requests from clients browsing, not links embedded in inbound SMTP messages, so it cannot rewrite or strip URLs before delivery. It is the right profile for enforcing category-based browsing policy on outbound user web traffic.
- ✗
Data Leak Prevention profile
Why it's wrong here
Data Leak Prevention profiles inspect outbound traffic for sensitive data leaving the network; they do not evaluate inbound email link reputation. DLP is the correct choice when preventing credit-card numbers or source code from being exfiltrated by users.
- ✓
Email Filtering profile
Why this is correct
The Email Filtering profile inspects SMTP, IMAP and POP3 traffic, blocking messages based on sender reputation and embedded malicious URLs. It satisfies the requirement to detect and block phishing emails containing malicious links, which antivirus or web filtering alone cannot fully address.
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on NSE7
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company wants to protect its internal users from malicious files attached to emails. Which FortiGate feature should be configured to inspect SMTP traffic for malware?
easy- ✓ A.Antivirus
- B.Email Filter
- C.Web Filter
- D.IPS
Why A: FortiGate's Antivirus feature is designed to scan SMTP traffic for malware by inspecting email attachments and body content against virus signatures. When configured in a security policy, it intercepts SMTP sessions, buffers the email data, and performs real-time scanning to block or quarantine malicious files before delivery to internal users.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.