View Full Fortinet FCP_FML_AD-7.4 Exam Dumps and Practice Test Dumps.
Q41. What can a protected domain relay setting control?
- Antivirus updates
- Delivery to the protected mail server
- Administrator passwords
- Interface speed
Correct Answer: 2. Delivery to the protected mail server
Explanation
A protected domain configuration helps FortiMail determine how email for a protected recipient domain should be handled and delivered. In gateway deployments, the configuration can identify the mail server that receives accepted messages after FortiMail completes security processing. Correct relay information is important because an incorrect destination can cause deferred messages or failed delivery. Protected domain settings also contribute to determining whether traffic is considered inbound. Antivirus updates, administrator passwords, and interface speed are separate system functions. Proper protected domain configuration therefore supports both accurate mail routing and correct policy processing for protected recipients.
Q42. What can a system quarantine store?
- DNS records
- Administrator sessions
- Routing tables
- Messages requiring administrator review
Correct Answer: 4. Messages requiring administrator review
Explanation
A system quarantine can hold messages that FortiMail security controls have prevented from normal delivery. Reasons may include spam detection, antivirus findings, content violations, or another configured security action. Administrators can review quarantined messages and decide whether they should be released, deleted, or otherwise handled. Quarantine provides a controlled location for suspicious messages instead of immediately delivering or permanently discarding them. It is different from a deferred queue, which normally contains messages waiting for another delivery attempt. DNS records, routing tables, and administrator sessions are not stored in the message quarantine.
Q43. What can FortiMail use Bayesian filtering to detect?
- Spam characteristics
- Network loops
- Disk failures
- Administrator lockouts
Correct Answer: 1. Spam characteristics
Explanation
Bayesian filtering evaluates message characteristics using statistical information learned from examples of spam and legitimate email. FortiMail can use Bayesian analysis as one of several antispam techniques within an antispam profile. Combining multiple spam detection methods usually provides stronger protection than relying on one technique alone. Administrators should ensure that antispam settings match organizational requirements and avoid excessive false positives. Bayesian filtering is not designed to identify routing loops, disk failures, or administrator login problems. Its purpose is to help classify email according to patterns that indicate whether a message is likely to be spam.
Q44. What does an IP policy normally apply to?
- Only message attachments
- Only mailbox storage
- SMTP connection characteristics
- Only archived email
Correct Answer: 3. SMTP connection characteristics
Explanation
An IP policy applies controls according to network information associated with the SMTP session. In gateway deployments, the SMTP client address is important when FortiMail evaluates policy matching. Transparent deployments can also consider the SMTP server address. An IP policy can reference profiles that control authentication, antispam processing, antivirus behavior, and other security functions. This allows different SMTP sources to receive different protection or relay treatment. IP policies are not limited to message attachments, mailbox storage, or archived email. Their primary role is applying security behavior based on connection and addressing characteristics of the SMTP session.
Q45. What does a recipient policy allow an administrator to vary?
- Security profiles by recipient
- Hardware fan speed
- Disk partition size
- DNS server ownership
Correct Answer: 1. Security profiles by recipient
Explanation
Recipient policies allow FortiMail administrators to apply different security settings according to recipient addresses or groups. For example, one user group may require stronger antispam controls while another may require encryption or specialized content filtering. Recipient policies can reference several profiles and can distinguish between inbound and outbound message processing based on protected domain relationships. This gives administrators granular control over email protection without applying identical settings to every user. Hardware fan speed, disk partitions, and DNS ownership are unrelated. Recipient policies are primarily used to customize message security processing for specific recipients or groups.
Q46. What can an archive account be used for?
- SMTP relay authentication
- Administrator login
- DNS lookup
- Storing archived message copies
Correct Answer: 4. Storing archived message copies
Explanation
An archive account provides a destination for messages that FortiMail archives according to policy. Archiving can support compliance, investigations, retention requirements, or internal record keeping. Messages selected for archiving are retained separately from normal delivery and quarantine processes. Administrators should ensure that archive storage capacity and retention requirements align with organizational policy. An archive account does not provide SMTP relay authentication or administrator login access. It is also unrelated to DNS lookup behavior. Its purpose is to support structured retention of email copies that must remain available for future review or compliance requirements.
Q47. What does a DNS block list help identify?
- Local mailbox size
- Known suspicious sending hosts
- Administrator privileges
- Attachment passwords
Correct Answer: 2. Known suspicious sending hosts
Explanation
A DNS block list can identify sending IP addresses that have been associated with spam or other unwanted email activity. FortiMail can query configured block list services during antispam processing and use the result when determining how to handle an SMTP connection or message. DNS block lists are only one spam detection method and are commonly combined with other techniques to improve overall accuracy. Administrators should choose reputable services because inaccurate lists can create false positives. DNS block lists do not determine mailbox size, administrator privileges, or attachment passwords. Their focus is reputation based identification of suspicious senders.
Q48. What can a content action perform after a match?
- Increase interface speed
- Create DNS records
- Apply configured message handling
- Reset administrator passwords
Correct Answer: 3. Apply configured message handling
Explanation
When FortiMail content filtering detects a configured pattern or condition, the associated content action determines what happens next. Depending on policy requirements, the action can influence message delivery, quarantine, notification, encryption, or other supported handling. Separating detection conditions from actions provides flexibility because administrators can define different responses for different content risks. Content actions are applied as part of message security processing and should be tested carefully to avoid unintended disruption. They do not modify interface speed, create DNS records, or reset administrator passwords. Their role is controlling message treatment after content rules match.
Q49. What can an authentication server profile reference?
- Only local disk space
- Only network routes
- Only antivirus signatures
- External identity services
Correct Answer: 4. External identity services
Explanation
FortiMail can use authentication server profiles to connect with external identity services such as LDAP or other supported authentication systems. This allows organizations to use centralized identity information rather than creating separate credentials for every email security function. External authentication can support SMTP relay, user access, and other FortiMail services depending on configuration. Correct server addresses, credentials, search parameters, and connectivity are important for successful authentication. Disk space, routing tables, and antivirus signatures are unrelated to identity validation. Authentication server profiles help FortiMail verify users against established organizational identity systems.
Q50. What does an email header contain?
- Message addressing and routing information
- Only attachment data
- Only encrypted body text
- Only antivirus results
Correct Answer: 1. Message addressing and routing information
Explanation
Email headers contain important metadata about a message, including sender and recipient information, message identifiers, timestamps, and routing details added as the email passes between systems. FortiMail can inspect header information during policy processing, spam detection, content filtering, and troubleshooting. Administrators can also review headers when investigating suspicious messages or delivery problems. Headers are separate from the body and attachments, although all parts can participate in security inspection. They do not contain only antivirus results or encrypted body content. Understanding headers is important for analyzing SMTP flow and identifying message origin and routing behavior.
Q51. What can a FortiSandbox integration improve?
- Mailbox quotas
- DNS zone creation
- Detection of advanced malicious files
- Administrator account naming
Correct Answer: 3. Detection of advanced malicious files
Explanation
FortiMail can integrate with FortiSandbox to provide deeper analysis of suspicious attachments or files. Sandbox analysis can help detect advanced malware that may not be identified immediately through traditional signature based antivirus scanning. Suspicious content can be submitted for behavioral analysis, and the resulting verdict can influence message handling. This adds an additional layer of protection against sophisticated or previously unknown threats. FortiSandbox integration does not control mailbox quotas, DNS zones, or administrator naming. Its main purpose is strengthening malware detection through advanced analysis of potentially dangerous email content.
Q52. What does SMTP authentication help prevent?
- Local archiving
- Unauthorized relay use
- DNS resolution
- Antivirus updates
Correct Answer: 2. Unauthorized relay use
Explanation
SMTP authentication requires a user or client to prove identity before being allowed to perform certain relay activities. This helps prevent unauthorized systems from using FortiMail to send email to external domains. Without appropriate relay controls, an email system can become an open relay and be abused for spam distribution. FortiMail can combine authentication with receiving access rules and policies to control legitimate outbound mail flow. SMTP authentication is not used to perform DNS resolution or antivirus updates. Its purpose is to establish trusted sender identity before granting permitted SMTP relay privileges.
Q53. What can a sender reputation check influence?
- Spam handling decisions
- Interface addressing
- Administrator permissions
- Disk formatting
Correct Answer: 1. Spam handling decisions
Explanation
Sender reputation evaluates whether an SMTP source has a history associated with legitimate or unwanted email activity. FortiMail can use reputation information as part of antispam processing to help determine the likelihood that a message or connection is abusive. Reputation should generally be combined with other techniques because sender behavior and infrastructure can change. Strong reputation based controls can reduce spam before resource intensive message scanning occurs. Sender reputation does not determine administrator permissions, disk formatting, or interface addressing. Its main role is contributing information that helps FortiMail make more accurate spam filtering decisions.
Q54. What can an outbound policy apply to?
- Only incoming mail
- Only DNS queries
- Only archived logs
- Messages leaving protected users or domains
Correct Answer: 4. Messages leaving protected users or domains
Explanation
Outbound policies apply security controls to messages that originate from protected users or domains and are being sent toward unprotected destinations. Administrators can use outbound processing to apply antivirus scanning, content filtering, authentication, archiving, encryption, and other controls as appropriate. This is useful for preventing sensitive information from leaving the organization or stopping compromised accounts from distributing malicious email. Direction is determined through protected domain and policy context. Outbound policies are not intended for DNS queries or archived logs. Their purpose is protecting and controlling email as it leaves the protected environment.
Q55. What can a quarantine report provide to users?
- Interface statistics
- Summary of quarantined messages
- DNS configuration
- Administrator audit logs
Correct Answer: 2. Summary of quarantined messages
Explanation
A quarantine report can notify users about messages that have been placed into their quarantine. This allows recipients to review information about suspected spam or other held messages without requiring direct administrator involvement for every case. Depending on configuration and permissions, users may be able to release or manage selected messages. Quarantine reports help balance security with usability by giving recipients visibility into potentially legitimate mail that FortiMail did not deliver normally. They do not provide interface statistics, DNS settings, or administrator logs. Their focus is summarized information about quarantined email relevant to the recipient.
Q56. What is a benefit of FortiMail high availability synchronization?
- It creates spam automatically
- It disables policies
- It helps maintain cluster configuration consistency
- It removes protected domains
Correct Answer: 3. It helps maintain cluster configuration consistency
Explanation
High availability synchronization helps FortiMail units in a supported cluster maintain appropriate shared configuration and operational information. This is important because another unit may need to continue email security processing if a cluster member becomes unavailable. Consistent configuration reduces the risk that failover produces different policy behavior or security settings. Administrators should understand which data and settings synchronize in the selected high availability design. High availability does not disable policies or remove protected domains. Its purpose is improving service resilience while maintaining appropriate consistency among participating FortiMail units.
Q57. What can sender address verification help detect?
- Forged or invalid sender information
- Disk fragmentation
- Administrator inactivity
- Mailbox quota usage
Correct Answer: 1. Forged or invalid sender information
Explanation
Sender address verification can help identify messages that claim sender information that cannot be validated according to configured checks. Invalid or forged sender addresses are commonly associated with spam and malicious email. FortiMail can perform sender related checks during the SMTP session or message security process to reduce unwanted traffic. Administrators should balance strict verification with legitimate email behavior because some systems can use unusual addressing practices. Sender verification is not used to monitor disks or mailbox quotas. Its purpose is improving trust in message sender information and reducing abuse of invalid addresses.
Q58. What can FortiMail message logs record?
- Only hardware temperatures
- Message processing and delivery information
- Only DNS cache data
- Only administrator themes
Correct Answer: 2. Message processing and delivery information
Explanation
Message logs record information that helps administrators understand how FortiMail processed email. Details can include sender, recipient, message identifiers, policy actions, security results, and delivery status. These logs are valuable when investigating missing messages, spam detections, quarantine decisions, or delayed delivery. Administrators can correlate log entries with user reports and SMTP behavior to identify the cause of a mail flow problem. Message logs are not limited to hardware temperatures or DNS cache information. Their primary purpose is providing operational and security visibility into how email was handled by FortiMail.
Q59. What can an email archive search help locate?
- Interface errors
- Password reset requests
- Retained historical messages
- Routing loops only
Correct Answer: 3. Retained historical messages
Explanation
An archive search allows authorized personnel to locate email that FortiMail retained according to archiving policy. Searches can support compliance investigations, legal requests, internal reviews, and historical message retrieval. The usefulness of archive search depends on proper archiving configuration and retention of searchable message data. Archived messages are different from temporary quarantined or deferred messages because the archive is intended for record retention. Interface errors and password requests are unrelated. The primary purpose is finding historical email copies that were preserved by FortiMail for later review.
Q60. What can a secure MTA feature help protect?
- Administrator themes
- Disk partitions
- Mailbox names
- SMTP transport and mail exchange behavior
Correct Answer: 4. SMTP transport and mail exchange behavior
Explanation
Secure mail transfer agent features help protect SMTP communication and improve the trust and security of message exchange between mail systems. These controls can include transport encryption, authentication, sender validation, relay restrictions, and related protections. Proper configuration reduces the risk of unauthorized relay, impersonation, or unprotected SMTP transmission. Secure MTA behavior forms an important part of FortiMail email flow and authentication objectives. It does not manage graphical themes, disk partitions, or mailbox naming. Its focus is making message transfer between SMTP systems more controlled, authenticated, and secure.