Fortinet FCP_FML_AD-7.4 Practice Test Questions and Exam Dumps Part4 Q61-80

View Full Fortinet FCP_FML_AD-7.4 Exam Dumps and Practice Test Dumps.


Q61. What does a FortiMail system certificate primarily support?

  1. Spam scoring
  2. Mailbox creation
  3. Secure encrypted connections
  4. Message archiving

Correct Answer: 3. Secure encrypted connections

Explanation

A system certificate provides identity information that FortiMail can use when establishing secure encrypted connections. Certificates are commonly involved in TLS communication, secure administrative access, and other services that require cryptographic authentication. A valid certificate helps remote systems or users verify the identity of the FortiMail appliance and protects information transmitted across encrypted sessions. Administrators should ensure certificates are valid, trusted where required, and renewed before expiration. System certificates do not determine spam scores, create mailboxes, or decide which messages are archived. Their main role is supporting secure authenticated communication between FortiMail and other systems or users.

Q62. Why can reverse DNS checking be useful?

  1. It checks whether an IP resolves to a host name
  2. It encrypts message bodies
  3. It creates local users
  4. It increases mailbox storage

Correct Answer: 1. It checks whether an IP resolves to a host name

Explanation

Reverse DNS checking helps FortiMail evaluate whether the connecting IP address has a corresponding host name in DNS. Legitimate mail servers commonly maintain appropriate DNS information, while poorly configured or abusive systems may lack meaningful reverse records. FortiMail can use this information as one factor during SMTP and antispam processing. A failed reverse lookup does not always prove that a sender is malicious, so administrators should consider legitimate mail server behavior before applying strict actions. Reverse DNS checking does not encrypt messages, create users, or increase mailbox storage. Its purpose is helping assess the credibility of SMTP sources.

Q63. What can an LDAP group be used for in policy matching?

  1. Updating FortiGuard signatures
  2. Configuring interfaces
  3. Managing RAID storage
  4. Applying policies to selected users

Correct Answer: 4. Applying policies to selected users

Explanation

LDAP groups can help FortiMail apply policies to defined sets of users without requiring every recipient to be configured individually. For example, administrators can apply different security profiles to executives, finance staff, or other organizational groups stored in a directory. This simplifies administration and keeps FortiMail policy assignments aligned with existing identity management. Accurate LDAP searches and group membership information are important for reliable matching. LDAP groups are not used to update FortiGuard signatures, configure network interfaces, or manage storage. Their primary value is allowing directory based user groups to participate in authentication and email policy decisions.

Q64. What can attachment filtering control?

  1. DNS server selection
  2. File types allowed in email
  3. Administrator login time
  4. Mail route priority

Correct Answer: 2. File types allowed in email

Explanation

Attachment filtering allows FortiMail to control which file types can be sent or received through the protected mail environment. Administrators can identify files by extension, type, or other supported characteristics and apply actions when restricted attachments are detected. This can reduce the risk of dangerous executable files, prohibited content, or unsupported attachment formats reaching users. Attachment filtering should normally complement antivirus scanning rather than replace it because even permitted file types can contain malicious content. DNS selection and administrator login settings are unrelated. Its purpose is controlling email attachments according to organizational security and acceptable use requirements.

Q65. What does URI filtering examine in an email?

  1. Web links contained in the message
  2. Mailbox quota values
  3. Administrator roles
  4. Interface addresses

Correct Answer: 1. Web links contained in the message

Explanation

URI filtering examines web addresses or links contained within email messages. Malicious or spam messages frequently include links directing recipients to phishing sites, fraudulent pages, or other harmful destinations. FortiMail can use reputation and filtering information to evaluate these links as part of antispam and security processing. Link analysis adds another protection layer because a message may contain no malicious attachment while still directing the recipient to a dangerous website. URI filtering does not inspect mailbox quotas or administrator permissions. Its primary purpose is evaluating links found inside email and helping identify messages containing suspicious or unwanted web destinations.

Q66. Why is scanning compressed attachments important?

  1. It improves DNS resolution
  2. It creates aliases
  3. Malware can be hidden inside archives
  4. It increases archive storage

Correct Answer: 3. Malware can be hidden inside archives

Explanation

Attackers can place malicious files inside compressed archives in an attempt to avoid simple attachment inspection. FortiMail can inspect supported compressed files so antivirus and content controls can examine the files contained within them. This improves protection against malware delivered inside archive formats. Administrators should configure appropriate limits because very deeply nested or extremely large compressed files can consume significant processing resources. Compressed file inspection does not improve DNS resolution or create mail aliases. Its purpose is helping security engines inspect content that might otherwise remain hidden inside an attached archive before the message reaches the recipient.

Q67. What can FortiGuard outbreak protection help identify?

  1. User password reuse
  2. Emerging email threats
  3. Disk partition errors
  4. Local mailbox aliases

Correct Answer: 2. Emerging email threats

Explanation

FortiGuard outbreak protection can help detect rapidly emerging malicious email campaigns before traditional detection methods fully catch up. New malware or spam outbreaks can spread quickly, making timely threat intelligence important. FortiMail can use FortiGuard information alongside antivirus, antispam, and other security controls to strengthen protection against new campaigns. Outbreak related information can help reduce the window during which recently emerging threats might otherwise pass normal checks. The feature does not evaluate password reuse or mailbox aliases. Its primary purpose is improving response to new email threats by using updated intelligence from Fortinet security services.

Q68. What can personal quarantine access allow a user to do?

  1. Change FortiMail firmware
  2. Modify global routes
  3. Create administrator accounts
  4. Review held messages

Correct Answer: 4. Review held messages

Explanation

Personal quarantine access allows end users to review messages that FortiMail has placed into their individual quarantine. Depending on configuration and permissions, users may be able to release legitimate messages, delete unwanted messages, or manage selected sender preferences. This reduces the need for administrators to handle every false positive manually. Appropriate controls should remain in place so users cannot bypass protections that require administrator authority. Personal quarantine access does not allow users to change firmware, modify global mail routes, or create administrators. Its purpose is giving recipients controlled access to messages held for their own account.

Q69. What can a mailbox quota control in server mode?

  1. Interface bandwidth
  2. SMTP route priority
  3. Amount of mailbox storage
  4. Antivirus update frequency

Correct Answer: 3. Amount of mailbox storage

Explanation

In server mode, FortiMail can host user mailboxes, and mailbox quotas can limit how much storage individual users are allowed to consume. Quotas help prevent one mailbox from using excessive disk capacity and provide administrators with a predictable way to manage storage resources. When users approach or exceed configured limits, mail handling can be affected according to system behavior and policy. Administrators should size storage and quotas according to organizational needs. Mailbox quotas do not control interface bandwidth, route priority, or antivirus update schedules. Their purpose is managing storage consumption for hosted user mailboxes.

Q70. What does a domain association help define in server mode?

  1. Which email domain a user belongs to
  2. Which antivirus engine is used
  3. Which interface is primary
  4. Which archive disk is active

Correct Answer: 1. Which email domain a user belongs to

Explanation

In server mode, user accounts and mailboxes are associated with email domains so FortiMail knows the complete addresses used for local message delivery. Domain association helps organize users and determines how local recipient addresses are interpreted. This is especially important when FortiMail hosts multiple email domains. Correct domain configuration ensures that messages are delivered to the intended local mailbox. Domain association does not select an antivirus engine or determine the active network interface. Its primary purpose is linking local users and mailboxes with the email domain under which they send and receive messages.

Q71. What can webmail provide in server mode?

  1. DNS management
  2. RAID configuration
  3. Cluster heartbeat control
  4. Browser based mailbox access

Correct Answer: 4. Browser based mailbox access

Explanation

Webmail can provide users with browser based access to mailboxes hosted by FortiMail in server mode. This allows users to read, send, organize, and manage email without relying only on a separate desktop mail client. Access normally requires user authentication and should be protected through appropriate secure connection settings. Server mode webmail is different from administrative access because it is intended for mailbox users rather than FortiMail administrators. Webmail does not manage DNS, storage RAID, or high availability heartbeat settings. Its purpose is providing convenient user access to hosted email through a web interface.

Q72. What normally happens after a deferred message exceeds its retry lifetime?

  1. It becomes an administrator account
  2. It is treated as a permanent delivery failure
  3. It becomes a protected domain
  4. It disables TLS

Correct Answer: 2. It is treated as a permanent delivery failure

Explanation

A deferred message remains queued while FortiMail repeatedly attempts delivery after temporary failures. If delivery continues to fail until the configured retry or expiration period is exhausted, the system treats the problem as a permanent delivery failure. A delivery status notification may then be generated according to normal mail handling behavior. Retry settings should provide destination systems enough time to recover while preventing messages from remaining queued indefinitely. Deferred messages do not become administrator accounts or protected domains. Queue expiration provides a controlled endpoint when temporary delivery problems cannot be resolved within the permitted period.

Q73. Where is a DKIM public key normally published?

  1. DNS
  2. The message body
  3. The user quarantine
  4. The SMTP queue

Correct Answer: 1. DNS

Explanation

DKIM uses public key cryptography to verify email signatures. The sending system signs selected message information using a private key, while the corresponding public key is published in DNS. Receiving systems retrieve the public key and use it to verify the DKIM signature. This helps confirm that the message was signed by the associated domain and that signed content was not modified after signing. The public key is not stored in the message body or quarantine. Correct DNS publication is therefore essential for recipients to validate DKIM signed email successfully.

Q74. What does DMARC alignment compare?

  1. Attachment names and MIME types
  2. Sender IP and recipient IP
  3. Visible From domain with authenticated domains
  4. Mailbox quota and message size

Correct Answer: 3. Visible From domain with authenticated domains

Explanation

DMARC alignment examines whether the domain shown in the visible From address aligns appropriately with the domain authenticated by SPF or DKIM. This helps prevent attackers from using a trusted looking From address while authentication succeeds for an unrelated domain. DMARC combines authentication results with domain alignment and the policy published by the sender’s domain. Alignment can be evaluated according to the policy requirements in use. It does not compare mailbox quotas or attachment names. The main purpose is ensuring that the identity visible to the recipient is meaningfully connected to an authenticated sending domain.

Q75. What is the purpose of trusted CA certificates on FortiMail?

  1. Increase spam scores
  2. Validate certificate trust
  3. Create mail routes
  4. Configure quarantine quotas

Correct Answer: 2. Validate certificate trust

Explanation

Trusted certificate authority certificates allow FortiMail to determine whether another certificate chains back to a trusted issuer. This is important during secure TLS communication and other certificate based services. When FortiMail validates a peer certificate, trusted CA information helps establish whether the certificate should be considered legitimate. Administrators should maintain appropriate trusted authorities and remove certificates that are no longer required. Trusted CA certificates do not create mail routes or influence quarantine quotas. Their main purpose is supporting certificate validation and helping FortiMail establish trusted encrypted communication with external or internal systems.

Q76. What can a safe sender list help reduce?

  1. Interface errors
  2. Mailbox size
  3. False positive spam handling
  4. DNS query volume

Correct Answer: 3. False positive spam handling

Explanation

A safe sender list identifies senders that a user or administrator considers trusted. Depending on configuration, this information can influence antispam handling so legitimate messages from known senders are less likely to be treated as unwanted mail. Safe lists should be used carefully because compromised trusted accounts can still send malicious content. Antivirus and other security scanning should therefore remain important even when a sender is trusted. Safe sender lists do not reduce mailbox size or DNS query volume. Their main purpose is reducing unnecessary spam treatment for known legitimate sender addresses.

Q77. What can a blocked attachment rule prevent?

  1. Delivery of prohibited file types
  2. DNS resolution
  3. SMTP authentication
  4. Administrator login

Correct Answer: 1. Delivery of prohibited file types

Explanation

A blocked attachment rule can prevent messages containing prohibited file types from being delivered normally. Organizations may restrict executable files, scripts, or other formats that create security or compliance concerns. FortiMail can inspect attachment characteristics and apply configured actions when blocked types are detected. Attachment controls complement antivirus scanning because a file can be prohibited by policy even if no malware signature is detected. These rules do not prevent DNS resolution or administrator login. Their purpose is enforcing organizational restrictions on the kinds of files users are allowed to send or receive through email.

Q78. What can a certificate expiration warning help prevent?

  1. Spam outbreaks
  2. Unexpected TLS trust problems
  3. Mailbox duplication
  4. Archive search failures

Correct Answer: 2. Unexpected TLS trust problems

Explanation

Certificate expiration warnings help administrators renew or replace certificates before they become invalid. An expired certificate can cause browsers, mail systems, or other clients to reject or distrust secure connections. Monitoring certificate validity therefore reduces the risk of unexpected service disruption or TLS trust warnings. Administrators should maintain an appropriate renewal process and confirm that replacement certificates are installed correctly. Certificate expiration does not directly cause spam outbreaks or mailbox duplication. The main purpose of expiration monitoring is preserving trusted encrypted communication and avoiding outages caused by certificates reaching the end of their validity period.

Q79. What can an outbound content rule help protect?

  1. Disk health
  2. Interface speed
  3. Sensitive information leaving the organization
  4. Administrator themes

Correct Answer: 3. Sensitive information leaving the organization

Explanation

Outbound content rules can inspect messages leaving protected users or domains and identify sensitive information according to configured patterns or policies. Organizations can use these controls to prevent or protect transmission of confidential information such as financial data, internal records, or other regulated content. Actions can include blocking, quarantining, notifying, or encrypting messages depending on the configured policy. Outbound content inspection is an important data protection capability. It does not monitor disk health or interface speed. Its purpose is controlling sensitive content before email leaves the protected environment.

Q80. What can a certificate based TLS policy require?

  1. Message archiving
  2. Spam quarantine
  3. Mailbox creation
  4. Trusted encrypted SMTP communication

Correct Answer: 4. Trusted encrypted SMTP communication

Explanation

A certificate based TLS policy can require secure SMTP communication that uses certificates to establish encryption and, where configured, verify the identity of the communicating mail system. This can be useful when sensitive organizations or partner domains require stronger transport security than opportunistic TLS provides. Administrators must configure certificates, trust relationships, and policy settings correctly on both sides. If required security conditions cannot be established, mail delivery may fail according to policy. Certificate based TLS does not create mailboxes or determine quarantine behavior. Its main purpose is enforcing trusted encrypted transport between SMTP systems.