View Full Fortinet FCP_FML_AD-7.4 Exam Dumps and Practice Test Dumps.
Q241. What does endpoint reputation primarily track?
- Mailbox storage
- Reputation of carrier endpoints
- Administrator permissions
- Archive retention
Correct Answer: 2. Reputation of carrier endpoints
Explanation
Endpoint reputation allows FortiMail to maintain reputation information for carrier endpoints identified during email processing. The system can use endpoint behavior to determine whether future delivery attempts should receive normal treatment or a restrictive action. This provides another reputation based control in addition to ordinary sender reputation. Endpoint reputation is especially useful where a carrier infrastructure represents multiple sending endpoints. It does not manage mailbox storage or administrator permissions. Its purpose is to build behavioral information about identified endpoints and use that information when FortiMail evaluates later SMTP activity from those sources.
Q242. What can authentication reputation monitor?
- Attachment sizes
- Mail routes
- Archive searches
- Login access behavior
Correct Answer: 4. Login access behavior
Explanation
Authentication reputation tracks behavior associated with login access attempts to FortiMail. Repeated unsuccessful or suspicious authentication activity can contribute to reputation based protection against abusive sources. This helps protect services that require user authentication from repeated malicious login attempts. Authentication reputation is different from sender reputation because sender reputation evaluates SMTP client behavior related to email delivery. It does not measure attachment size or determine message routing. Its purpose is providing additional protection around authentication activity by identifying sources whose login behavior indicates a higher risk of abuse or unauthorized access.
Q243. What happens when FortiGuard block IP identifies a client?
- The email is rejected
- The mailbox is enlarged
- The message is archived
- The user is created
Correct Answer: 1. The email is rejected
Explanation
FortiGuard block IP checking evaluates the SMTP client IP address against FortiGuard reputation information. When the connecting IP is identified as blocked, FortiMail can reject the email before later stages of message processing. Early rejection reduces unnecessary use of resources because unwanted traffic is stopped before antivirus, content, or other deeper inspections occur. This feature works as part of the early SMTP processing sequence. It does not increase mailbox size or automatically archive the message. Its purpose is blocking traffic from IP addresses that FortiGuard identifies as unsuitable email sources.
Q244. What does a lower sender reputation score indicate?
- Larger messages
- More invalid recipients
- Better sender reputation
- Higher mailbox usage
Correct Answer: 3. Better sender reputation
Explanation
FortiMail sender reputation uses a numeric score to represent the behavior of an SMTP client. A lower score represents a more acceptable sender, while a higher score indicates poorer reputation. The score is affected by the ratio of good and bad email observed from the client. FortiMail can compare the score with thresholds configured in the session profile and take different actions according to the result. Sender reputation is unrelated to mailbox storage. Its purpose is using historical sender behavior to influence how future SMTP connections from that client are treated.
Q245. Which activity can worsen sender reputation?
- Sending virus infected email
- Using a valid recipient
- Sending normal business mail
- Using a valid DKIM signature
Correct Answer: 1. Sending virus infected email
Explanation
FortiMail can treat virus infected email as bad activity when calculating sender reputation. Other negative events can include spam, messages to unknown recipients, invalid DKIM signatures, and failed SPF checks. A sender producing a high proportion of bad email can develop a poorer reputation score and eventually receive more restrictive SMTP treatment. Valid DKIM and legitimate email behavior do not contribute negatively in the same way. Sender reputation therefore provides an adaptive mechanism that changes according to observed behavior instead of relying only on a static list of blocked addresses.
Q246. Where are sender reputation thresholds configured?
- Archive account
- DNS zone
- Mailbox profile
- Session profile
Correct Answer: 4. Session profile
Explanation
Sender reputation thresholds are configured through the session profile. FortiMail compares the current reputation score of an SMTP client with those thresholds to decide whether the client should be allowed normally, throttled, temporarily rejected, or otherwise restricted according to the configured settings. This allows reputation information to influence SMTP behavior before full message processing occurs. Thresholds should be selected carefully because overly aggressive values can affect legitimate senders. They are not configured in mailbox or archive settings. The session profile is the appropriate location because sender reputation affects the SMTP connection stage.
Q247. What does sender rate control help limit?
- Archive retention
- Excessive sender activity
- Administrator roles
- DKIM key size
Correct Answer: 2. Excessive sender activity
Explanation
Sender rate control limits excessive SMTP activity associated with a connecting client. FortiMail can apply rate controls during different stages of SMTP processing to prevent a sender from consuming excessive resources or sending unusually large amounts of mail. This is useful against compromised systems, spam sources, and automated abuse. Rate limits should still allow legitimate high volume mail where required. The controls are configured through session related settings rather than archive or administrator profiles. Their purpose is protecting FortiMail and downstream mail systems by controlling unusually aggressive sending behavior during SMTP sessions.
Q248. Which value is used for sender rate control identification?
- Attachment name
- Mailbox quota
- SMTP client IP address
- Administrator username
Correct Answer: 3. SMTP client IP address
Explanation
FortiMail sender rate control uses the SMTP client IP address as an important identifier when applying connection and message related limits. This allows the appliance to recognize a source that is creating excessive SMTP activity and apply configured restrictions. The controls operate during SMTP processing before the complete message reaches later inspection stages. Using the client address provides a network based method of controlling abusive behavior. Attachment names and administrator usernames do not identify SMTP senders for this function. The client IP address represents the source whose sending activity is being measured and controlled.
Q249. What can sender domain checking reject?
- Invalid sender domains
- Valid administrator accounts
- Local quarantine reports
- System backups
Correct Answer: 1. Invalid sender domains
Explanation
Sender domain checking evaluates domain information in the SMTP envelope sender. If the configured domain checks fail, FortiMail can return an error to the SMTP client before the message proceeds through later security processing. This helps reduce mail that uses nonexistent or otherwise invalid sender domain information. Rejecting clearly invalid senders early can conserve processing resources and improve protection against spam. Sender domain checking is configured as part of session security rather than backup or administrator settings. Its purpose is validating sender domain information during the SMTP transaction before FortiMail fully accepts the email.
Q250. What distinguishes receiving from delivery access control?
- Message size
- Who initiates the SMTP session
- Antivirus engine
- Archive location
Correct Answer: 2. Who initiates the SMTP session
Explanation
FortiMail separates receiving and delivery access control according to whether FortiMail is receiving an SMTP connection or initiating one. Receiving rules apply when another SMTP client connects to FortiMail. Delivery rules apply when FortiMail initiates an SMTP session toward another mail server. This distinction is more important than simply labeling traffic inbound or outbound. Administrators should choose the correct rule type based on which system initiates the SMTP connection. Message size and archive location do not determine the access control category. The connection initiator defines whether receiving or delivery access control applies.
Q251. When do SMTP access control rules take effect?
- After the network connection reaches the application layer
- Before any IP connection exists
- Only after archiving
- Only after antivirus scanning
Correct Answer: 1. After the network connection reaches the application layer
Explanation
FortiMail SMTP access control rules operate after the underlying IP and TCP connection has been established and communication reaches the application layer. At that point, FortiMail can evaluate information associated with the SMTP session and decide whether to permit, reject, discard, or relay traffic according to the matching rule. This differs from lower level network controls that may block a connection before SMTP processing begins. Access control rules therefore do not depend on antivirus scanning or message archiving. Their purpose is controlling SMTP application behavior once a client has established connectivity with FortiMail.
Q252. What can authentication reputation help block?
- Normal DNS responses
- Valid DKIM signatures
- Repeated abusive login sources
- Archived messages
Correct Answer: 3. Repeated abusive login sources
Explanation
Authentication reputation helps FortiMail identify sources that repeatedly demonstrate suspicious login behavior. A source associated with repeated failed or abusive authentication attempts can develop a poor authentication reputation and receive restrictive treatment. This helps protect user and administrative access services from automated password attacks and similar abuse. Authentication reputation is separate from email sender reputation because it focuses on login access behavior rather than the quality of messages sent by an SMTP client. It does not block valid DKIM signatures or ordinary DNS responses. Its goal is reducing repeated authentication abuse.
Q253. What information identifies an endpoint reputation entry?
- Endpoint ID
- Mailbox quota
- Archive folder
- DKIM selector
Correct Answer: 1. Endpoint ID
Explanation
Endpoint reputation uses endpoint identification information to track the behavior of carrier endpoints associated with email delivery. FortiMail can maintain reputation information for these endpoints and use the result when evaluating future activity. This is different from normal sender reputation, which primarily tracks SMTP clients according to source IP address. Endpoint reputation can be useful in environments where carrier related messaging infrastructure requires a distinct reputation mechanism. Mailbox quotas and archive folders are unrelated. The endpoint ID provides the reference FortiMail uses when associating reputation information with a particular endpoint.
Q254. Why should protected domains not be broadly safelisted?
- They cannot receive email
- They disable TLS
- They remove DKIM keys
- Sender addresses can be spoofed
Correct Answer: 4. Sender addresses can be spoofed
Explanation
Broadly safelisting a protected domain can create a security weakness because sender email addresses can be forged. An attacker could claim to send from the organization’s own domain and potentially bypass antispam checks that a safelist would otherwise suppress. Fortinet recommends using stronger evidence such as client IP based access controls or sender authentication mechanisms including SPF and DKIM instead of trusting a sender address alone. Safelists should therefore be configured narrowly and carefully. The issue is not that protected domains cannot receive email. The risk comes from the ease with which sender addresses can be spoofed.
Q255. What can cause antispam scanning to be bypassed unintentionally?
- Proper MX records
- Overly broad safe list entries
- Valid recipient verification
- Current antivirus signatures
Correct Answer: 2. Overly broad safe list entries
Explanation
Overly broad safe list entries can allow unwanted messages to bypass antispam checks. For example, trusting a large address pattern or entire domain can create an easy path for attackers who forge sender information. Safe lists should therefore be used carefully and only where necessary. Fortinet recommends stronger mechanisms such as authenticated sender information or trusted client IP addresses when possible. Valid recipient verification and current antivirus signatures do not create the same bypass condition. The risk comes from granting too much trust to sender information that can be manipulated by an attacker.
Q256. What should gateway mode public MX records normally point to?
- Every internal workstation
- The LDAP server
- The FortiMail unit
- The archive mailbox
Correct Answer: 3. The FortiMail unit
Explanation
In gateway mode, public MX records should normally direct inbound email to the FortiMail unit so traffic receives the intended security inspection before reaching the protected mail server. If external senders can deliver directly to the backend server, they may bypass FortiMail antispam, antivirus, authentication, and content controls. Administrators should also ensure that routers and firewalls do not provide unintended alternate SMTP paths around FortiMail. LDAP and archive systems are not intended MX destinations for normal inbound mail. Correct MX design ensures that external email flows through the FortiMail security gateway.
Q257. Why should all SMTP traffic be directed through FortiMail?
- To prevent security scanning bypass
- To increase mailbox quotas
- To reduce administrator accounts
- To remove DNS records
Correct Answer: 1. To prevent security scanning bypass
Explanation
If SMTP traffic can reach a protected mail server without passing through FortiMail, attackers may bypass the security controls configured on the appliance. Routing policies, firewalls, public DNS, and internal mail architecture should therefore be designed so relevant SMTP traffic flows through FortiMail. This ensures that antispam, antivirus, authentication, content inspection, and policy controls are applied consistently. A bypass path can make otherwise strong FortiMail configuration ineffective. Directing traffic through the appliance is not intended to increase mailbox quotas or remove DNS records. The objective is ensuring that required email security inspection cannot be avoided.
Q258. Why should additional antispam features be enabled gradually?
- To increase spam volume
- To avoid unnecessary performance impact
- To remove recipient policies
- To disable FortiGuard
Correct Answer: 2. To avoid unnecessary performance impact
Explanation
FortiMail offers multiple antispam techniques, but enabling every available scan without considering need can consume additional system resources and reduce performance. Fortinet recommends enabling adaptive features gradually and evaluating the resulting spam detection rate before adding more checks. Once detection is satisfactory, additional scanning may provide little benefit while increasing processing overhead. Administrators should balance security accuracy, false positives, and appliance performance. Gradual deployment also makes it easier to identify which feature caused an unexpected result. The purpose is not to weaken protection but to avoid unnecessary antispam processing.
Q259. What effect can an invalid DKIM signature have on sender reputation?
- It always improves the score
- It deletes the sender
- It disables SPF
- It can worsen the reputation score
Correct Answer: 4. It can worsen the reputation score
Explanation
When FortiMail performs DKIM verification and finds an invalid signature, the result can negatively affect the SMTP client’s sender reputation score. Invalid DKIM is one of the behaviors FortiMail can classify as bad email activity when calculating sender reputation. A worsening score can eventually cause more restrictive session handling if configured reputation thresholds are reached. Valid DKIM produces the opposite reputation effect. DKIM failure does not disable SPF because the two mechanisms are evaluated separately. The reputation impact allows FortiMail to incorporate authentication quality into its adaptive assessment of sender behavior.
Q260. Which sender reputation information has the greatest influence?
- Oldest statistics only
- Archived message age
- Administrator login history
- More recent sender statistics
Correct Answer: 4. More recent sender statistics
Explanation
FortiMail calculates sender reputation using recent historical information, with newer activity having greater influence than older activity. This allows the reputation score to adapt when sender behavior changes. A previously legitimate source that begins sending spam can deteriorate in reputation, while a sender that stops producing bad mail can improve over time. FortiMail does not rely only on the oldest statistics because that would make the score slow to reflect current behavior. Archive age and administrator login history are unrelated. The emphasis on recent activity makes sender reputation responsive to changes in SMTP client behavior.