View Full Fortinet FCP_FML_AD-7.4 Exam Dumps and Practice Test Dumps.
Q301. What can SMTP session concurrency control limit?
- Archive search results
- DKIM selector length
- Simultaneous SMTP sessions
- Mailbox aliases
Correct Answer: 3. Simultaneous SMTP sessions
Explanation
SMTP session concurrency control limits how many SMTP sessions a client can maintain with FortiMail at the same time. This helps protect appliance resources from excessive connection activity caused by spam systems, compromised hosts, or incorrectly configured mail servers. Administrators should select limits that accommodate legitimate high volume senders while restricting abnormal behavior. Concurrency controls work with other session profile settings such as connection rates and message limits. They do not control mailbox aliases or DKIM selectors. Their primary purpose is preventing individual SMTP sources from consuming an unreasonable number of simultaneous FortiMail connections.
Q302. What can an LDAP query filter narrow?
- Directory search results
- Antivirus signatures
- Archive capacity
- SMTP queue size
Correct Answer: 1. Directory search results
Explanation
An LDAP query filter defines which directory objects FortiMail should consider when searching an LDAP server. Filters can restrict searches to specific users, groups, attributes, or other directory conditions. This improves efficiency and helps ensure FortiMail retrieves only information relevant to authentication, recipient verification, address books, or policy matching. An incorrect filter can prevent valid users from being found, so administrators should test LDAP searches carefully. Query filters do not control antivirus signatures or message queues. Their purpose is narrowing directory results so FortiMail receives the appropriate identity information from the configured LDAP service.
Q303. What can an SMTP client certificate verify?
- Mailbox quota
- Archive ownership
- Spam dictionary
- Identity of a connecting mail system
Correct Answer: 4. Identity of a connecting mail system
Explanation
An SMTP client certificate can provide cryptographic identity information during a TLS connection. FortiMail can use certificate validation when a mail partner or trusted system is required to present a certificate issued by an accepted certificate authority. This strengthens authentication beyond simply relying on an IP address or domain name. Certificate validation requires correct trust configuration and valid certificate dates. An SMTP client certificate does not determine mailbox quotas or spam dictionaries. Its purpose is helping FortiMail verify the identity of a connecting SMTP system during secure transport establishment.
Q304. What can a message size session limit prevent?
- Administrator logins
- Oversized email acceptance
- DNS queries
- DKIM signing
Correct Answer: 2. Oversized email acceptance
Explanation
A message size limit controls the maximum email size FortiMail will accept during SMTP processing. Large messages can consume significant memory, storage, scanning time, and network bandwidth. Setting an appropriate limit protects resources while ensuring legitimate business attachments remain deliverable. When a message exceeds the configured value, FortiMail can reject it according to SMTP processing behavior. Administrators should coordinate size limits with protected mail servers and user requirements. The setting does not affect administrator authentication or DKIM signing. Its purpose is preventing excessively large email from consuming unnecessary FortiMail resources.
Q305. What can certificate chain validation confirm?
- Mailbox availability
- Spam reputation
- Archive indexing
- Trust through certificate authorities
Correct Answer: 4. Trust through certificate authorities
Explanation
Certificate chain validation checks whether a certificate can be linked through one or more intermediate certificate authorities to a trusted root authority. FortiMail can use this process when validating certificates presented during TLS communication or management access. A valid chain helps confirm that the certificate was issued through an accepted trust structure. Validation also considers factors such as certificate dates and trust configuration. Certificate chain checking does not determine spam reputation or mailbox availability. Its purpose is confirming that a presented certificate belongs to a trusted certification path recognized by the FortiMail system.
Q306. What can LDAP bind credentials provide?
- Access for directory queries
- Additional mail routes
- Antivirus updates
- Quarantine storage
Correct Answer: 1. Access for directory queries
Explanation
LDAP bind credentials allow FortiMail to authenticate to an LDAP server before performing directory searches. Some directory environments permit anonymous searches, while others require a dedicated account with permission to read required user and group attributes. The bind account should have only the permissions necessary for FortiMail functions and its password should be protected carefully. Incorrect credentials can cause authentication, recipient verification, or group lookup failures. LDAP bind credentials do not provide antivirus updates or additional routing. Their purpose is giving FortiMail authorized access to directory information required for configured LDAP functions.
Q307. What can an SMTP command timeout control?
- Archive retention
- Waiting time for client commands
- Mailbox alias creation
- DKIM key length
Correct Answer: 2. Waiting time for client commands
Explanation
An SMTP command timeout determines how long FortiMail waits for a client to continue the SMTP conversation before considering the session inactive or abnormal. Without suitable timeouts, slow or malicious clients could leave many connections open and consume system resources. Values should allow normal network delays without permitting excessively idle sessions. Command timeouts complement connection limits and other session security controls. They do not determine archive retention or DKIM key length. Their purpose is controlling how long FortiMail tolerates inactivity while waiting for the next expected SMTP command from a connected client.
Q308. What can a policy status setting do?
- Change DNS ownership
- Expand storage
- Enable or disable policy enforcement
- Create certificates
Correct Answer: 3. Enable or disable policy enforcement
Explanation
A policy status setting allows administrators to enable or disable a policy without necessarily deleting its configuration. This can be useful during testing, troubleshooting, staged deployment, or temporary changes in mail flow requirements. A disabled policy remains configured but does not participate normally in matching and enforcement until it is enabled again. Administrators should verify policy order after reactivation because position can affect which rule matches traffic. Policy status does not create certificates or expand disk storage. Its purpose is giving administrators operational control over whether a configured policy is currently active.
Q309. What can a local certificate contain?
- Private key information
- Mailbox messages
- Archive indexes
- Spam reports
Correct Answer: 1. Private key information
Explanation
A local certificate installed or generated on FortiMail can include the certificate together with the corresponding private key required for cryptographic operations. FortiMail may use local certificates for secure management, SMTP TLS, signing, or other supported functions. The private key must remain protected because anyone obtaining it could potentially impersonate the certificate holder. Administrators should monitor certificate expiration and use appropriate key strengths. Local certificates do not contain mailbox messages or archive indexes. Their purpose is providing FortiMail with the cryptographic identity and key material required for secure communication and authentication.
Q310. What can a content profile attachment count rule detect?
- Administrator accounts
- DNS failures
- Messages with many attachments
- Mailbox passwords
Correct Answer: 3. Messages with many attachments
Explanation
An attachment count condition allows FortiMail to identify messages containing more attachments than a configured threshold. This can support security, resource control, or organizational email policies. Messages with unusually large numbers of attachments may consume additional scanning resources or indicate automated distribution behavior. Administrators can combine attachment count conditions with file type, size, content, or other rules for more precise handling. Attachment count rules do not detect administrator accounts or DNS failures. Their purpose is controlling or identifying messages based on the number of attached files included in the email.
Q311. What can a trusted certificate authority validate?
- Mail route preference
- Mailbox capacity
- Archive retention
- Certificates issued under its trust
Correct Answer: 4. Certificates issued under its trust
Explanation
A trusted certificate authority provides a trust anchor FortiMail can use when validating certificates presented by other systems or users. If a certificate chains successfully to a configured trusted authority and satisfies other validation requirements, FortiMail can treat the certificate as trusted for the relevant operation. Administrators should install only certificate authorities that are genuinely trusted by the organization. Removing obsolete or untrusted authorities reduces unnecessary trust exposure. Certificate authorities do not control mailbox capacity or mail routing. Their purpose is establishing which certificate issuers FortiMail accepts when verifying cryptographic identities.
Q312. What can SMTP authentication encryption protect?
- Archive searches
- Login credentials in transit
- DNS records
- Mailbox quotas
Correct Answer: 2. Login credentials in transit
Explanation
When SMTP authentication occurs over an encrypted TLS connection, user credentials are protected from being transmitted across the network in easily readable form. This is important because authentication information could otherwise be intercepted by an attacker with access to network traffic. Administrators should require secure transport where possible when clients authenticate to FortiMail. Authentication encryption does not protect archive searches or change mailbox quotas. Its purpose is maintaining confidentiality of authentication exchanges between SMTP clients and FortiMail while users or systems prove their identity before receiving relay or submission privileges.
Q313. What can an access rule source address match?
- Connecting client IP information
- Antivirus signature version
- Attachment content
- Archive folder
Correct Answer: 1. Connecting client IP information
Explanation
A source address condition in an SMTP access control rule can match the IP address or configured address group associated with the client connecting to FortiMail. This allows administrators to apply different access behavior to trusted servers, internal networks, partners, or unknown internet sources. Source address matching can be combined with authentication and sender or recipient criteria for more precise control. It does not examine attachment content or antivirus versions. Its purpose is using network source information as one of the conditions that determines how FortiMail handles an incoming SMTP connection.
Q314. What can an antivirus scan exclusion do?
- Delete all attachments
- Disable SMTP completely
- Create a DNS server
- Skip selected content from scanning
Correct Answer: 4. Skip selected content from scanning
Explanation
An antivirus scan exclusion allows selected content or conditions to bypass antivirus inspection when there is a specific operational reason to do so. Exclusions should be used cautiously because bypassed content does not receive the same malware protection as normally scanned email. Administrators should keep exclusions narrow and document why they are required. Broad exclusions can create a significant security weakness. Antivirus exclusions do not disable SMTP or create DNS services. Their purpose is providing controlled exceptions where particular trusted content does not need standard antivirus scanning according to organizational requirements.
Q315. What can a recipient policy sender condition help distinguish?
- Disk types
- Messages from different senders
- Administrator themes
- Interface speeds
Correct Answer: 2. Messages from different senders
Explanation
Recipient policies can include sender related conditions so FortiMail can apply different security profiles depending on who sends a message and who receives it. This allows an organization to treat internal, partner, trusted, or unknown senders differently for the same recipient population. More specific policies should be placed appropriately in the policy order to ensure expected matches. Sender conditions do not evaluate disk types or network interface speed. Their purpose is providing granular security control by allowing recipient based policy decisions to consider the identity of the message sender.
Q316. What can FortiMail configuration restore do?
- Recover settings from a backup
- Create spam automatically
- Replace all certificates permanently
- Increase network bandwidth
Correct Answer: 1. Recover settings from a backup
Explanation
Configuration restore allows administrators to load previously saved FortiMail settings from a backup file. This can be valuable after configuration errors, hardware replacement, disaster recovery, or other situations where a known working configuration must be recovered. Administrators should verify firmware compatibility and restoration requirements before applying a backup. Backup files should also be protected because they can contain sensitive configuration information. Configuration restore does not increase network bandwidth or create spam. Its purpose is returning FortiMail settings to a previously saved state when recovery or migration is required.
Q317. What can OCSP help determine?
- Message attachment count
- Mailbox quota status
- Current certificate revocation status
- Sender reputation history
Correct Answer: 3. Current certificate revocation status
Explanation
Online certificate status protocol allows a system to query certificate status information and determine whether a certificate has been revoked by its issuing authority. This provides a more current validation method than relying only on certificate expiration dates. A certificate may still be within its validity period but should no longer be trusted if it has been revoked. FortiMail can use revocation related checking where supported and configured. OCSP does not determine attachment counts or sender reputation. Its purpose is helping verify whether a presented certificate remains valid from the issuing authority’s trust perspective.
Q318. What can certificate hostname validation compare?
- Archive retention and disk size
- Certificate identity and expected host
- Sender reputation and spam score
- Mailbox quota and alias
Correct Answer: 2. Certificate identity and expected host
Explanation
Hostname validation compares the identity contained in a certificate with the host name that FortiMail expects to communicate with. A mismatch can indicate an incorrectly configured certificate or a possible attempt to impersonate another system. Certificate trust alone is not enough if the certificate belongs to a different host. Hostname validation is therefore an important part of secure TLS verification. Administrators should ensure remote mail systems use certificates containing the appropriate names. This process does not compare spam scores or mailbox quotas. Its purpose is confirming that a trusted certificate actually represents the intended remote host.
Q319. What can an IP based policy source match identify?
- Mailbox folder
- DKIM selector
- SMTP client network source
- Archive account
Correct Answer: 3. SMTP client network source
Explanation
An IP based policy can use source IP information to determine which security settings should apply to an SMTP connection. This is useful for distinguishing internal servers, trusted partners, relay systems, and unknown internet hosts. The matching policy can then reference profiles for session control, antispam, antivirus, authentication, and other supported functions. Administrators should order IP policies carefully so specific network sources are evaluated before broad ranges where appropriate. The source match does not identify mailbox folders or archive accounts. Its purpose is classifying SMTP traffic according to the network location of the connecting client.
Q320. What can a configuration checksum help verify?
- User password strength
- Message delivery status
- Antivirus reputation
- Configuration integrity
Correct Answer: 1. Configuration integrity
Explanation
A configuration checksum can help verify whether configuration data has remained consistent or changed between two points in time. Checksums provide a compact value based on the underlying data, so differences can indicate that the configuration content is no longer identical. This can support backup validation, administrative review, or troubleshooting after changes. A checksum does not explain which specific setting changed unless other comparison information is available. It also does not measure password strength or message delivery. Its purpose is providing an integrity indicator that helps administrators determine whether configuration data matches an expected state.