Fortinet FCP_FML_AD-7.4 Practice Test Questions and Exam Dumps Part10 Q181-200

View Full Fortinet FCP_FML_AD-7.4 Exam Dumps and Practice Test Dumps.


Q181. What is the purpose of a Bayesian control account?

  1. Configure mail routes
  2. Receive spam training messages
  3. Manage certificates
  4. Create protected domains

Correct Answer: 2. Receive spam training messages

Explanation

A Bayesian control account receives messages that users or administrators forward for training purposes. Messages can be submitted as examples of spam or legitimate email so the Bayesian database learns which words and patterns are associated with each category. Proper training improves the usefulness of Bayesian spam detection and should continue over time because message characteristics change. FortiMail must also be configured to accept training messages through the relevant antispam profile and recipient policy. The control account does not configure routing or certificates. Its purpose is providing an email based method for training Bayesian spam databases.

Q182. Which Bayesian database is used for outgoing email?

  1. Recipient database
  2. Quarantine database
  3. Archive database
  4. Global Bayesian database

Correct Answer: 4. Global Bayesian database

Explanation

FortiMail uses the global Bayesian database when scanning outgoing email with Bayesian antispam analysis. Incoming email can use either the global database or a protected domain specific Bayesian database depending on configuration. Bayesian databases need sufficient training to distinguish probable spam from legitimate mail accurately. Poorly trained databases can produce false positive and false negative results. Administrators should therefore maintain training data rather than treating Bayesian filtering as a configuration that never needs attention. The outgoing scan does not use quarantine or archive databases. Its Bayesian analysis relies on the global training database.

Q183. What does a SURBL scan evaluate?

  1. URLs associated with spam
  2. Mailbox quotas
  3. Administrator roles
  4. Interface addresses

Correct Answer: 1. URLs associated with spam

Explanation

SURBL scanning checks web addresses found in email against configured SURBL services. These services maintain information about domains or URLs associated with spam campaigns and unwanted messages. FortiMail can query SURBL servers as part of an antispam profile and apply an antispam action when a match indicates suspicious content. This method is useful because many spam messages rely on links even when the message text itself appears harmless. SURBL does not inspect mailbox quotas or administrator privileges. Its purpose is helping identify spam through reputation information associated with URLs contained inside messages.

Q184. What happens when a safelist word matches?

  1. The message is deleted
  2. The message is archived
  3. The message is treated as not spam
  4. The SMTP session closes

Correct Answer: 3. The message is treated as not spam

Explanation

A safelist word can be configured in an antispam profile to identify words or phrases that indicate a message should not be classified as spam. FortiMail can inspect the subject line, message body, or both for configured safelist words. If a safelist word matches, the message is considered not spam for that scan. Wildcards can be used for safelist words, but regular expressions are not supported by this particular feature. Safelist words should be selected carefully because overly broad entries could allow unwanted mail to bypass spam classification.

Q185. Which matching method can banned words use?

  1. Wildcards
  2. Only IP addresses
  3. Only certificates
  4. Only DNS records

Correct Answer: 1. Wildcards

Explanation

FortiMail banned word scanning can use wildcards when administrators define prohibited words or phrases. The scan can inspect the email subject, message body, or both depending on configuration. Unlike dictionary scans, banned word scanning does not support regular expressions. When a configured banned word is detected, FortiMail can treat the message as spam and apply the selected antispam action profile. This feature provides a straightforward way to flag messages containing prohibited terms. It does not depend on certificate or IP matching. Administrators should choose banned words carefully to avoid unnecessary false positive detections.

Q186. What does Deliver to alternate host do?

  1. Deletes the message
  2. Changes the administrator
  3. Expands quarantine storage
  4. Sends mail to a specified SMTP server

Correct Answer: 4. Sends mail to a specified SMTP server

Explanation

The Deliver to alternate host action routes matching email to a specified SMTP server or relay instead of following the normal delivery destination. Administrators can configure the destination using an IP address or fully qualified domain name. This action can be useful when selected messages need special processing, monitoring, archiving, or delivery through another system. When alternate host delivery applies, it can override normal relay host behavior for those matching messages. The feature does not change administrators or quarantine capacity. Its purpose is redirecting selected email to a specifically configured SMTP destination.

Q187. What does modified copy selection control?

  1. DNS lookup method
  2. Which version of altered email is delivered
  3. Administrator authentication
  4. Mailbox quota

Correct Answer: 2. Which version of altered email is delivered

Explanation

FortiMail can sometimes modify a message during content processing by changing HTML, inserting information, removing content, or performing another configured action. Delivery and quarantine preferences can determine whether the modified version or the original unmodified version is used for certain actions. This gives administrators greater control over what copy is delivered to an alternate host, original host, or quarantine. The selection does not determine DNS lookup behavior or administrator authentication. Its purpose is controlling whether FortiMail uses the processed message or the original message when carrying out selected content actions.

Q188. What can authentication cache provide during an LDAP outage?

  1. New DNS records
  2. More archive storage
  3. Continued user authentication
  4. New antivirus signatures

Correct Answer: 3. Continued user authentication

Explanation

Authentication cache allows FortiMail to temporarily use cached user credentials when the configured LDAP server becomes unavailable. This can help users continue authenticating during a temporary directory outage instead of immediately losing access to services that depend on LDAP. Administrators can enable the authentication cache and configure how long cached authentication information remains valid. The feature should be managed carefully because authentication data is security sensitive. It does not create DNS records or antivirus signatures. Its purpose is improving authentication continuity when FortiMail cannot communicate successfully with the normal LDAP authentication source.

Q189. What should be included in a complete pre upgrade backup?

  1. Only administrator names
  2. Configuration and related security data
  3. Only message subjects
  4. Only DNS records

Correct Answer: 2. Configuration and related security data

Explanation

Before changing FortiMail firmware, Fortinet recommends performing a complete backup. This includes the main configuration file and related information such as Bayesian databases, dictionaries, and block and safe lists. Keeping these items available provides stronger recovery options if the upgrade fails or if the administrator needs to restore important security information afterward. A backup should be stored securely because configuration and security data can contain sensitive information. Backing up only administrator names or DNS information would be incomplete. The goal is preserving the configuration and supporting data required to recover the FortiMail environment.

Q190. What must FortiMail reach to receive FortiGuard updates?

  1. FortiGuard Distribution Network
  2. User quarantine
  3. Local mailbox
  4. Archive server only

Correct Answer: 1. FortiGuard Distribution Network

Explanation

FortiMail must be able to connect to the FortiGuard Distribution Network to receive supported FortiGuard antivirus and antispam updates. Administrators should verify that required network access, DNS resolution, and licensing are working correctly when updates fail. Current FortiGuard information is important because email threats and spam campaigns change continuously. Firewalls between FortiMail and the internet must allow the required FortiGuard communication. The user quarantine and local mailboxes are not update sources. The FortiGuard Distribution Network provides the services and update information required for FortiMail security features to remain current.

Q191. What is the main purpose of CDR?

  1. Increase mailbox storage
  2. Change DNS settings
  3. Create administrator accounts
  4. Sanitize potentially dangerous content

Correct Answer: 4. Sanitize potentially dangerous content

Explanation

Content Disarm and Reconstruction helps reduce risk by sanitizing email content that may contain dangerous active elements. FortiMail can remove or modify items such as scripts and hyperlinks and can process supported attachments so users receive safer content. This approach differs from simply detecting known malware because it attempts to remove potentially dangerous elements from otherwise usable documents. CDR can work together with other security controls including FortiSandbox. It does not manage mailbox storage or administrator accounts. Its purpose is reducing the risk associated with active or potentially harmful content contained in email and attachments.

Q192. Which attachments can CDR process?

  1. Only image files
  2. Only text files
  3. Microsoft Office and PDF files
  4. Only mailbox files

Correct Answer: 3. Microsoft Office and PDF files

Explanation

FortiMail CDR can be configured to process supported Microsoft Office and PDF attachments. The goal is to sanitize content by removing or reconstructing elements that could create security risk. Depending on configuration, supported compressed files containing these documents can also be processed. CDR can complement antivirus scanning because malicious activity may rely on active document content rather than a traditional known malware signature. Administrators should select CDR settings that balance security with document usability. The feature is not limited to plain text or mailbox files. It specifically supports common business document formats including Office and PDF content.

Q193. What does URL Click Protection rewrite?

  1. Links inside email
  2. Administrator passwords
  3. Mailbox quotas
  4. Network routes

Correct Answer: 1. Links inside email

Explanation

URL Click Protection can rewrite links found in email so the user is directed through FortiMail security processing when the link is clicked. FortiMail can then evaluate the destination using services such as FortiGuard URL filtering and FortiSandbox before allowing or blocking access. This provides protection at click time because a website can become malicious after the original message was delivered. The feature does not rewrite administrator passwords or network routes. Its purpose is protecting users from phishing, malicious websites, and other dangerous destinations linked from email messages.

Q194. What does FortiIsolator provide?

  1. Larger message queues
  2. Remote browser isolation
  3. More administrator roles
  4. DNS redundancy

Correct Answer: 2. Remote browser isolation

Explanation

FortiIsolator provides browser isolation by running web content in a remote disposable environment rather than directly in the user’s browser environment. FortiMail can redirect selected URLs through FortiIsolator when configured with content protection features. This creates separation between potentially dangerous websites and the user’s endpoint. If malicious code exists on the destination site, isolation reduces the chance that the code will execute directly on the user’s device. FortiIsolator does not expand message queues or create administrator roles. Its purpose is protecting users when they follow web links that could contain phishing or malicious web content.

Q195. What does intra domain protection enable?

  1. Only archive processing
  2. Only antivirus updates
  3. Only administrator access
  4. Both inbound and outbound policies between protected domains

Correct Answer: 4. Both inbound and outbound policies between protected domains

Explanation

Intra domain protection controls policy processing when email moves between two protected domains. When this feature is enabled, FortiMail can apply both the relevant inbound and outbound policies instead of applying only inbound treatment. This can be important in environments where protected domains belong to separate customers or tenants and traffic between them should still receive outbound controls such as DLP. When the feature is disabled, only the matching inbound policy is applied in this situation. The setting does not control administrator access or FortiGuard updates. Its purpose is strengthening policy enforcement between protected domains.

Q196. Which policy normally has precedence when both policy types match?

  1. Archive policy
  2. IP policy
  3. Recipient policy
  4. Report policy

Correct Answer: 3. Recipient policy

Explanation

When an email matches both a recipient based policy and an IP based policy, the recipient based policy normally takes precedence. This allows FortiMail administrators to apply more specific controls according to sender and recipient addresses even when a broader IP policy also matches the SMTP connection. There is an exception when the IP policy is explicitly configured to take precedence over recipient policy matches. Understanding this order is important when troubleshooting why an expected profile was not applied. Archive and report policies are not involved in this precedence decision.

Q197. What can make an IP policy override a recipient policy?

  1. Larger attachment size
  2. Take precedence setting
  3. Different mailbox quota
  4. Archive retention

Correct Answer: 2. Take precedence setting

Explanation

FortiMail normally gives recipient based policies precedence when both recipient and IP policies match the same email. An IP based policy can override this behavior when the Take precedence over recipient based policy match option is enabled. This setting should be used carefully because it changes the normal policy hierarchy and can cause IP based profiles to replace more specific recipient settings. Administrators troubleshooting policy behavior should verify this option when expected recipient profiles are not applied. Attachment size and mailbox quota do not control policy precedence. The explicit precedence setting determines whether the matching IP policy overrides the recipient policy.

Q198. Where should a specific policy normally be placed?

  1. Above a general policy
  2. Below every general policy
  3. In the archive only
  4. After all disabled policies

Correct Answer: 1. Above a general policy

Explanation

FortiMail policies should normally be ordered with more specific rules above more general rules. Policy evaluation proceeds according to the configured order, and once a matching policy is found, later policies may not be considered. If a broad rule is placed first, it can match traffic that administrators intended a more specific policy to handle. This can produce unexpected antispam, antivirus, content, or authentication behavior. Administrators should therefore design policy order from specific conditions toward broad catch all conditions. Placement is not determined by archive configuration. Correct ordering makes policy matching predictable and easier to troubleshoot.

Q199. How are multiple recipients normally handled by recipient policies?

  1. All recipients are ignored
  2. Only the sender policy is used
  3. Each recipient can be evaluated separately
  4. The message is always rejected

Correct Answer: 3. Each recipient can be evaluated separately

Explanation

For most recipient based policy processing, FortiMail treats a message with multiple recipients as though separate messages existed for each recipient. This allows different recipient based policies to apply to different people on the same original email. As a result, a message could be allowed for one recipient while receiving different treatment for another. This provides fine control when users have different security requirements. Antivirus processing is an important exception to this normal behavior. The message is not automatically rejected simply because several recipients are present. Recipient based evaluation can occur separately for each destination.

Q200. How does antivirus policy selection differ for multiple recipients?

  1. Every recipient receives every antivirus profile
  2. Antivirus scanning is disabled
  3. Only the IP address is checked
  4. The first matching recipient policy is used

Correct Answer: 4. The first matching recipient policy is used

Explanation

Antivirus processing is an exception to the normal per recipient policy behavior for messages with several recipients. FortiMail treats the message as one email for antivirus profile selection. Beginning with the first recipient, it looks for a matching recipient based policy and applies the antivirus profile from the first matching policy. Later recipients are not evaluated for additional antivirus profiles. If no recipient policy matches, FortiMail can use the antivirus profile from the matching IP based policy. This behavior prevents the same message from requiring separate antivirus scans for every recipient while still allowing policy based antivirus selection.