A FortiGate administrator is designing a content inspection strategy to block phishing emails with malicious attachments but minimize impact on legitimate business emails. Which combination of settings should be configured to meet this requirement?
- Enable attachment scanning with strict quarantine for all suspicious files without exception and disable phishing email detection.
- Configure phishing email detection with a quarantine action and enable attachment scanning with selective file type blocking and heuristics.Correct
- Apply spam filtering only and rely on manual review of attachments to identify phishing attempts.
- Use keyword and phrase inspection exclusively to detect phishing content without scanning attachments.
Rationale
Option 1 is correct because combining phishing email detection with quarantine and selective attachment scanning balances security and business continuity by filtering suspicious attachments based on type and heuristics. Option 0 is too strict, likely causing false positives and business disruption by quarantining all suspicious files indiscriminately. Option 2 is insufficient since spam filtering alone does not detect embedded malicious attachments effectively. Option 3 neglects attachment threats, missing many phishing vectors that rely on harmful files.