View Full Fortinet FCP_FML_AD-7.4 Exam Dumps and Practice Test Dumps.
Q201. What does SPF hard fail normally indicate?
- Sender is fully trusted
- Message must be archived
- Sending host is not authorized
- Recipient does not exist
Correct Answer: 3. Sending host is not authorized
Explanation
An SPF hard fail indicates that the sending IP address is not authorized by the domain owner’s published SPF policy to send email for that domain. FortiMail can use this result during antispam and sender authentication processing. A hard fail is stronger than a soft fail because the domain owner explicitly indicates that unauthorized sources should fail SPF evaluation. Administrators can configure appropriate actions based on SPF results and organizational requirements. SPF results should also be considered with DKIM and DMARC where available. A hard fail does not indicate an invalid recipient or automatically mean that a message must be archived.
Q202. What is the purpose of a DKIM selector?
- Identify the DNS public key record
- Choose the recipient mailbox
- Select an antivirus profile
- Determine queue priority
Correct Answer: 1. Identify the DNS public key record
Explanation
A DKIM selector identifies which public key record receiving systems should retrieve from DNS when verifying a DKIM signature. A domain can use multiple selectors, allowing different keys to be used for different systems or during key rotation. The selector appears in the DKIM signature and helps the receiver locate the correct DNS record containing the public key. This makes key management more flexible and allows organizations to replace keys without changing the entire domain configuration. The selector does not choose recipients or antivirus profiles. Its purpose is identifying the correct DKIM public key used to verify signed email.
Q203. What can a DMARC quarantine policy request?
- Disable SPF
- Delete all mail
- Accept every message
- Treat failed mail as suspicious
Correct Answer: 4. Treat failed mail as suspicious
Explanation
A DMARC quarantine policy tells receiving systems that messages failing DMARC authentication and alignment should be treated as suspicious. Depending on the receiving platform and local policy, this can result in spam handling or quarantine rather than normal delivery. DMARC allows domain owners to publish none, quarantine, or reject policies and to receive reports about authentication results. The receiving system still applies its configured handling behavior. A quarantine policy does not disable SPF or require all messages to be deleted. Its purpose is signaling that failed DMARC messages should receive more restrictive treatment than fully authenticated mail.
Q204. What is a main purpose of SMTP AUTH?
- Archive outbound mail
- Authenticate clients before relay
- Validate antivirus files
- Create DNS records
Correct Answer: 2. Authenticate clients before relay
Explanation
SMTP AUTH allows a client to provide credentials before being granted relay privileges or other protected SMTP access. This helps FortiMail distinguish legitimate users from unauthorized systems attempting to send mail through the appliance. Authentication can use local accounts or supported external identity sources depending on configuration. It is commonly combined with access control rules and policies to prevent open relay behavior. SMTP AUTH does not create DNS records or validate antivirus files. Its purpose is verifying client identity before FortiMail permits mail submission or relay actions that require authenticated access.
Q205. What can a soft fail SPF result mean?
- Recipient is invalid
- TLS is required
- Message is malware
- Sender is probably unauthorized
Correct Answer: 4. Sender is probably unauthorized
Explanation
An SPF soft fail means that the sending IP address is probably not authorized to send mail for the domain, but the domain owner has not published the strongest possible failure instruction. This result is commonly represented differently from a hard fail and may receive less severe handling depending on local policy. FortiMail can include SPF results in spam and authentication decisions. Administrators should consider additional evidence such as DKIM, DMARC, reputation, and message content before choosing an action. A soft fail does not indicate malware or an invalid recipient. It reflects uncertainty about sender authorization.
Q206. What can a message delivery DSN provide?
- Administrator privileges
- Mailbox quota
- Delivery status information
- DKIM private key
Correct Answer: 3. Delivery status information
Explanation
A delivery status notification provides information about the outcome of an email delivery attempt. It can indicate successful delivery, delay, or permanent failure depending on the SMTP result and message processing. FortiMail administrators can review delivery status information when troubleshooting bounced or delayed mail. A notification may contain the recipient, destination, status code, and reason returned by the remote system. This information helps distinguish temporary delivery issues from permanent failures. DSN information does not provide administrator privileges or cryptographic keys. Its purpose is communicating the result of an email delivery attempt.
Q207. What can an LDAP failover server provide?
- Backup directory availability
- Additional archive storage
- More DNS zones
- Antivirus signatures
Correct Answer: 1. Backup directory availability
Explanation
An LDAP failover server provides another directory source that FortiMail can use if the primary LDAP server becomes unavailable. This improves the resilience of authentication, recipient verification, group lookup, and other features that depend on directory information. Administrators should configure connectivity and search settings correctly for both primary and backup servers. A failover directory does not replace proper monitoring because repeated primary failures should still be investigated. It does not provide antivirus signatures or archive storage. Its purpose is maintaining directory dependent FortiMail functions during temporary failure of the preferred LDAP server.
Q208. What can a transparent mode port pair connect?
- Two administrator accounts
- Two network interfaces
- Two archive folders
- Two user mailboxes
Correct Answer: 2. Two network interfaces
Explanation
In transparent deployments, FortiMail can use paired network interfaces to pass SMTP traffic through the appliance while inspecting and controlling the communication. The port pair forms an inline path between network segments so existing mail addressing can remain largely unchanged. Administrators must configure the network design carefully to avoid loops or bypass paths. Transparent mode is useful when FortiMail should protect existing mail servers without acting as the normal routed gateway. A port pair does not connect user mailboxes or administrator accounts. Its purpose is creating the inline network path used for transparent inspection.
Q209. What can a quarantine folder separate?
- Different categories of held messages
- DNS servers
- Network interfaces
- Administrator profiles
Correct Answer: 1. Different categories of held messages
Explanation
Quarantine folders can help organize messages that FortiMail holds for review. Different message categories or quarantine reasons can be separated so administrators and users can understand why mail was withheld and manage it more efficiently. Organized quarantine can simplify review of spam, content violations, or other security related messages. Retention and access permissions should also be configured appropriately. Quarantine folders do not separate DNS servers or network interfaces. Their purpose is organizing held email so quarantine management and message review are easier and more structured.
Q210. What can mandatory TLS require?
- No authentication
- Plain text SMTP only
- Disabled certificates
- Encrypted SMTP transport
Correct Answer: 4. Encrypted SMTP transport
Explanation
Mandatory TLS requires FortiMail to establish encrypted SMTP transport for the applicable mail flow. If the remote system cannot negotiate the required TLS session, message delivery or acceptance can fail according to the configured policy. This is stronger than opportunistic TLS, which attempts encryption but can fall back to unencrypted SMTP when necessary. Mandatory TLS is useful for partners or environments where transport confidentiality is required. It does not require plain text SMTP or disabled certificates. Its purpose is ensuring that selected email traffic travels through an encrypted SMTP connection.
Q211. What can sender verification against LDAP confirm?
- Antivirus version
- Sender identity exists in directory
- Mailbox storage size
- Route priority
Correct Answer: 2. Sender identity exists in directory
Explanation
Sender verification against LDAP allows FortiMail to determine whether the claimed sender address exists in an authorized directory. This can help reduce spoofing or unauthorized use of internal addresses, especially for outbound or internal message flows. FortiMail queries configured directory information and applies policy according to the verification result. Directory accuracy is important because stale or incomplete records can cause legitimate mail to fail verification. LDAP sender verification does not determine antivirus versions or route priority. Its purpose is validating whether the sender identity corresponds to a known directory entry.
Q212. What can a MIME header reveal?
- Administrator password
- Interface speed
- Content type information
- DNS ownership
Correct Answer: 3. Content type information
Explanation
MIME headers describe how email content is structured and identify the type of data contained in message parts and attachments. FortiMail can use MIME information during content filtering, antivirus scanning, and attachment control. Examples include identifying whether a message part is text, an image, a document, or another supported content type. Attackers can sometimes misuse file names or extensions, so MIME analysis provides another source of information about the actual message structure. MIME headers do not contain administrator passwords or interface speed. Their purpose is describing email content format and type.
Q213. What can a null envelope sender indicate?
- A delivery status message
- Administrator login failure
- Antivirus update request
- Archive search
Correct Answer: 1. A delivery status message
Explanation
A null envelope sender is commonly used for delivery status notifications and bounce messages. Using an empty return path prevents delivery failures from generating additional bounce messages back to another failing address, which could create mail loops. FortiMail administrators should recognize that a null sender can be legitimate in SMTP and should not automatically treat it as malicious. Bounce verification and related controls can help distinguish genuine delivery notifications from forged bounce spam. A null envelope sender does not indicate an administrator login failure. It is a normal SMTP mechanism used by certain system generated messages.
Q214. What can an SMTP VRFY command request?
- Antivirus update
- Recipient identity verification
- Certificate renewal
- Archive deletion
Correct Answer: 2. Recipient identity verification
Explanation
The SMTP VRFY command is designed to ask a mail server whether a particular user or mailbox exists. Because this information can help attackers discover valid email addresses, many mail systems restrict or disable useful VRFY responses. FortiMail administrators should understand how recipient verification and SMTP commands interact when designing secure mail services. FortiMail can perform recipient verification through more controlled methods such as LDAP or SMTP server queries. VRFY does not request antivirus updates or certificate renewal. Its purpose is querying whether a specified SMTP recipient identity is recognized by the server.
Q215. What can an email encryption policy protect?
- Message confidentiality
- Interface routing
- Administrator themes
- DNS cache
Correct Answer: 1. Message confidentiality
Explanation
An email encryption policy protects message confidentiality by ensuring that selected messages are delivered using an approved secure method. FortiMail can support encryption technologies such as IBE and S MIME depending on deployment and policy requirements. Encryption can be triggered by recipient policy, content conditions, or other configured criteria. This helps protect sensitive information when email leaves the organization or travels to external recipients. Encryption does not control DNS cache or interface routing. Its purpose is preventing unauthorized parties from reading protected message content while preserving secure delivery to the intended recipient.
Q216. What can SMTP command line length limits reduce?
- Mailbox quota
- Archive storage
- Abusive oversized SMTP commands
- DKIM key rotation
Correct Answer: 3. Abusive oversized SMTP commands
Explanation
SMTP command line length limits help protect FortiMail from clients that send abnormally large protocol commands. Oversized commands can indicate malformed traffic, protocol abuse, or attempts to consume resources. Limiting acceptable command size allows FortiMail to reject abnormal behavior during the SMTP session before full message processing occurs. Administrators should choose values that support legitimate mail systems while blocking unreasonable requests. This setting does not control mailbox quota or DKIM keys. Its purpose is strengthening SMTP session protection against malformed or excessive command input.
Q217. What can an encryption exception allow?
- All users administrator access
- DNS modification
- Antivirus bypass globally
- Selected mail to avoid encryption
Correct Answer: 4. Selected mail to avoid encryption
Explanation
An encryption exception allows selected messages, recipients, or conditions to bypass an otherwise applicable encryption requirement. This can be useful when particular destinations cannot support the configured secure delivery method or when business policy defines approved exceptions. Exceptions should be narrowly scoped and documented because broad exclusions can weaken confidentiality controls. They should also be tested to ensure only intended mail is excluded. Encryption exceptions do not grant administrative access or globally disable antivirus scanning. Their purpose is providing controlled flexibility within an email encryption policy.
Q218. What can a mail header insertion action do?
- Add a custom header field
- Increase disk storage
- Create a DNS record
- Reset a password
Correct Answer: 1. Add a custom header field
Explanation
A header insertion action allows FortiMail to add defined header information to a message during processing. Custom headers can help downstream systems identify how FortiMail classified or handled a message. They may also support routing, monitoring, integration, or internal processing requirements. Administrators should avoid creating headers that conflict with existing standards or expose sensitive information unnecessarily. Header insertion does not create DNS records or increase storage capacity. Its purpose is adding structured metadata to email so other systems or administrators can recognize particular message processing conditions.
Q219. What can an SMTP maximum recipient limit control?
- Certificate lifetime
- Archive size
- Number of recipients in one message
- Administrator sessions
Correct Answer: 3. Number of recipients in one message
Explanation
A maximum recipient limit controls how many recipient addresses an SMTP client can specify for a single message. Limiting recipients can help reduce bulk abuse, spam distribution, and excessive processing caused by messages sent to very large recipient lists. Organizations should select a value that supports legitimate business communication while restricting unreasonable activity. High volume authorized senders may require different handling according to policy. The limit does not control certificate lifetime or administrator sessions. Its purpose is restricting the number of recipients that can be associated with one SMTP message transaction.
Q220. What can a policy fallback action provide?
- Automatic mailbox expansion
- Default handling when specific conditions do not match
- Administrator password recovery
- DNS replication
Correct Answer: 2. Default handling when specific conditions do not match
Explanation
A fallback or default policy action provides predictable handling when email does not meet more specific policy conditions. Administrators commonly design policies from specific rules toward broader rules so unmatched traffic still receives appropriate security processing. A well designed fallback helps prevent email from bypassing necessary controls simply because it failed to match a specialized rule. The fallback should reflect the organization’s baseline antispam, antivirus, content, and authentication requirements. It does not expand mailboxes or replicate DNS. Its purpose is ensuring that otherwise unmatched mail still receives defined and controlled processing.