Fortinet FCP_FML_AD-7.4 Practice Test Questions and Exam Dumps Part20 Q381-400

View Full Fortinet FCP_FML_AD-7.4 Exam Dumps and Practice Test Dumps.


Q381. What can an ARC signature help preserve?

  1. Mailbox quota information
  2. Authentication results across forwarding
  3. Administrator permissions
  4. Archive retention settings

Correct Answer: 2. Authentication results across forwarding

Explanation

Authenticated Received Chain helps preserve email authentication information when a message passes through intermediary systems such as mailing lists or forwarding services. Normal forwarding can sometimes cause SPF or DKIM results to change because the delivery path or message content is modified. ARC records authentication information from earlier stages so later receiving systems can consider that history when evaluating the message. ARC does not guarantee that a message is trustworthy, but it provides additional context for authentication decisions. It does not manage mailbox quotas or administrator permissions. Its purpose is preserving useful authentication information across intermediary email handling.

Q382. What can bounce verification protect against?

  1. Valid outbound mail
  2. Mailbox quota errors
  3. DNS caching
  4. Forged delivery failure messages

Correct Answer: 4. Forged delivery failure messages

Explanation

Bounce verification helps FortiMail distinguish legitimate delivery failure notifications from forged bounce messages. Attackers can send fake nondelivery reports in an attempt to bypass normal spam filtering because bounce messages often appear to come from trusted mail systems. FortiMail can verify whether a bounce corresponds to a message that previously passed through the appliance. Messages that do not match expected delivery history can receive more restrictive treatment. Bounce verification does not control mailbox quota or DNS caching. Its purpose is reducing backscatter and forged bounce spam by confirming that delivery failure messages are associated with real outbound email activity.

Q383. What can an IBE message expiration setting control?

  1. How long secured mail remains available
  2. SMTP connection speed
  3. Administrator password complexity
  4. DNS lookup order

Correct Answer: 1. How long secured mail remains available

Explanation

Identity Based Encryption can make protected messages available to recipients through a secure access process. An expiration setting determines how long the secured message remains accessible before the configured period ends. This helps organizations avoid keeping sensitive encrypted content available indefinitely. Administrators should select an expiration period that provides recipients enough time to retrieve the message while meeting security and retention requirements. Message expiration does not control SMTP connection speed or administrator passwords. Its purpose is limiting the period during which an IBE protected message can be accessed through the FortiMail secure message environment.

Q384. What can an S MIME signing action provide?

  1. Larger mailbox capacity
  2. Faster routing
  3. Proof of sender authenticity and integrity
  4. Additional DNS servers

Correct Answer: 3. Proof of sender authenticity and integrity

Explanation

S MIME digital signing allows a message to carry a cryptographic signature created with the sender’s certificate and private key. Recipients can use the signature to verify that the message was signed by the expected identity and that its protected content was not modified after signing. Signing differs from encryption because it primarily provides authenticity and integrity rather than confidentiality. FortiMail can apply S MIME security according to configured policies and certificate availability. It does not increase mailbox capacity or routing speed. Its purpose is helping recipients verify the origin and integrity of an email message.

Q385. What can a disclaimer profile add to outgoing email?

  1. Standard organizational text
  2. Antivirus signatures
  3. New administrator accounts
  4. Network routes

Correct Answer: 1. Standard organizational text

Explanation

A disclaimer profile can add predefined organizational text to messages processed by FortiMail. Common uses include legal notices, confidentiality statements, regulatory information, or corporate contact details. Disclaimers can be applied according to policy so only selected mail flows receive the additional text. Administrators should test formatting carefully because message structure and rich text content can affect how a disclaimer appears to recipients. A disclaimer profile does not create administrator accounts or network routes. Its purpose is adding consistent organizational information to email messages without requiring individual users to insert the same text manually.

Q386. What can LDAP recipient routing help determine?

  1. Administrator access level
  2. Antivirus update schedule
  3. Archive password
  4. Destination information for a recipient

Correct Answer: 4. Destination information for a recipient

Explanation

LDAP information can be used by FortiMail to obtain recipient related routing data when an organization stores mail delivery attributes in a directory. This allows delivery decisions to be based on centrally maintained user information instead of requiring every destination to be configured separately on the appliance. Directory based routing is especially useful in larger environments where recipients are distributed across different mail systems. Correct LDAP attributes and search settings are essential for reliable results. This function does not manage administrator access or antivirus schedules. Its purpose is helping FortiMail determine where email for a specific recipient should be delivered.

Q387. What can a recipient verification timeout prevent?

  1. Archive growth
  2. Excessive waiting for verification results
  3. DKIM signing
  4. Mailbox alias creation

Correct Answer: 2. Excessive waiting for verification results

Explanation

Recipient verification can require FortiMail to query LDAP or another mail server before accepting a recipient. A verification timeout prevents FortiMail from waiting indefinitely when the external verification source is slow or unavailable. Without an appropriate timeout, SMTP sessions could remain open for excessive periods and consume system resources. Administrators should choose a value that allows normal directory or server response times while still protecting the appliance from prolonged delays. The timeout does not affect archive growth or DKIM signing. Its purpose is limiting how long FortiMail waits for recipient validation to complete.

Q388. What can a mail route preference value influence?

  1. Antivirus scan depth
  2. Administrator role
  3. Which route is preferred
  4. Quarantine folder name

Correct Answer: 3. Which route is preferred

Explanation

When multiple mail routes can deliver messages to the same destination, a route preference value can help determine which configured path FortiMail should use first. Administrators can define preferred and alternate routes so delivery continues through another path if the primary route is unavailable. Correct preference design improves reliability and avoids unpredictable routing behavior. Route preference should be coordinated with destination availability and network architecture. It does not control antivirus scanning or quarantine names. Its purpose is helping FortiMail choose the preferred delivery route when more than one valid route is available.

Q389. What can an IBE recipient authenticate with?

  1. Only an administrator certificate
  2. Only a network interface
  3. Only a DNS record
  4. Credentials for secure message access

Correct Answer: 4. Credentials for secure message access

Explanation

Identity Based Encryption allows recipients to access protected email through an authentication process rather than requiring every recipient to possess a preinstalled encryption certificate. The recipient uses supported credentials or registration information to prove identity before viewing the secured message. This makes encrypted delivery practical for external recipients who do not participate in the sender’s certificate infrastructure. Administrators should configure access and expiration policies according to security requirements. IBE authentication does not depend on network interfaces or DNS records alone. Its purpose is ensuring that only the intended recipient can open the protected email.

Q390. What can a recipient verification cache reduce?

  1. Repeated external verification requests
  2. DKIM key strength
  3. Archive retention
  4. Administrator sessions

Correct Answer: 2. Repeated external verification requests

Explanation

Recipient verification cache stores recently obtained validation results so FortiMail does not need to query LDAP or another mail server every time the same recipient is checked. This can reduce network traffic, decrease verification latency, and lower the processing load on external directory or mail systems. Cache duration should be selected carefully because recipient information can change. Very long caching may preserve outdated results, while very short caching provides fewer performance benefits. The cache does not change DKIM strength or archive retention. Its purpose is reducing repeated verification requests for recipient addresses whose status was recently determined.

Q391. What can personal safelist entries do?

  1. Reduce spam treatment for trusted senders
  2. Create administrator accounts
  3. Change network routes
  4. Increase disk capacity

Correct Answer: 1. Reduce spam treatment for trusted senders

Explanation

A personal safelist allows a user to identify senders whose messages should receive more trusted antispam treatment. This can reduce false positives for contacts whose legitimate email is repeatedly classified as spam. Personal safelists should still be used carefully because sender addresses can sometimes be forged. Stronger authentication controls remain important when security is critical. User level safelists are different from global administrative trust settings because they apply to individual recipient preferences. They do not change network routing or storage capacity. Their purpose is allowing users to reduce unnecessary spam handling for selected trusted senders.

Q392. What can a personal block list do?

  1. Increase TLS strength
  2. Change DKIM selectors
  3. Identify unwanted senders for a user
  4. Create mail routes

Correct Answer: 3. Identify unwanted senders for a user

Explanation

A personal block list allows an email user to identify senders whose messages should be treated as unwanted according to available FortiMail user preferences. This gives users some control over repetitive unwanted mail that may not meet global spam thresholds. Personal block lists are narrower than system wide block rules because they apply to the individual recipient’s preferences. Administrators should still use broader antispam and reputation controls for organization wide threats. Personal block lists do not modify DKIM selectors or mail routes. Their purpose is giving individual users a way to restrict messages from selected unwanted senders.

Q393. What can a mail route fallback server provide?

  1. Additional mailbox aliases
  2. Alternate delivery destination
  3. New administrator password
  4. Antivirus signature storage

Correct Answer: 2. Alternate delivery destination

Explanation

A fallback or alternate mail server provides another delivery destination when the preferred server cannot accept mail. This improves resilience because FortiMail can attempt delivery through another configured route rather than relying on a single unavailable destination. Administrators should verify that the alternate server is authorized to receive the relevant domain and that routing does not create loops. Fallback routing complements normal queue retry behavior and can improve message availability during backend outages. It does not create mailbox aliases or store antivirus signatures. Its purpose is providing another valid SMTP destination when the preferred mail server is unavailable.

Q394. What can secure email portal access provide?

  1. DNS management
  2. Archive deletion
  3. Antivirus updates
  4. Browser based access to protected messages

Correct Answer: 4. Browser based access to protected messages

Explanation

A secure email portal allows authorized recipients to open protected messages through a web browser after completing the required authentication. This is commonly associated with identity based encryption and is useful for external recipients who do not have compatible local encryption software or certificates. The portal provides controlled access to sensitive messages while keeping protected content within the secure FortiMail workflow. Access should be governed by strong authentication and appropriate message expiration. The portal does not manage DNS or antivirus updates. Its purpose is providing a convenient browser based method for viewing encrypted email securely.

Q395. What can an LDAP group search support?

  1. Group based policy matching
  2. Disk partition creation
  3. DNS registration
  4. Antivirus update delivery

Correct Answer: 1. Group based policy matching

Explanation

FortiMail can query LDAP group membership and use the returned information when applying user or policy based settings. This allows administrators to create controls for departments, roles, or other directory defined groups rather than maintaining long lists of individual addresses. Group searches can simplify administration and keep FortiMail policies aligned with centrally managed directory membership. Correct base distinguished names, filters, and attributes are required for accurate results. LDAP group searches do not create disk partitions or deliver antivirus updates. Their purpose is enabling policy decisions based on directory maintained user group membership.

Q396. What can a message hold action provide?

  1. New DNS records
  2. Administrator authentication
  3. Temporary retention before final handling
  4. Additional interfaces

Correct Answer: 3. Temporary retention before final handling

Explanation

A message hold action keeps email temporarily instead of immediately delivering or permanently rejecting it. Holding can be useful when FortiMail needs additional analysis, administrator review, or another delayed decision before final message handling. Security services such as advanced threat analysis can require a message to remain under FortiMail control until a result is available. Administrators should monitor held messages and ensure retention settings prevent indefinite accumulation. A hold action does not create DNS records or network interfaces. Its purpose is temporarily retaining email while FortiMail waits for further processing or a final security decision.

Q397. What can an IBE registration process establish?

  1. Recipient identity for secure access
  2. Archive indexing
  3. SMTP route priority
  4. Antivirus exclusions

Correct Answer: 4. Recipient identity for secure access

Explanation

IBE registration establishes the recipient information needed to access encrypted messages securely. A recipient who does not already have an appropriate identity record may be asked to complete a registration process before viewing protected content. This provides FortiMail with a way to associate secure access credentials with the intended email address. Registration should be protected so unauthorized users cannot take control of another recipient’s identity. It does not configure archive indexing or SMTP routing. Its purpose is establishing a verified recipient identity that can be used for future access to messages protected with identity based encryption.

Q398. What can a content profile scan attachment names for?

  1. Administrator roles
  2. Defined filename patterns
  3. DNS ownership
  4. Mailbox quotas

Correct Answer: 1. Defined filename patterns

Explanation

A content profile can examine attachment file names and compare them with configured patterns or rules. This allows organizations to identify files whose names indicate prohibited, sensitive, or unusual content even before considering the file body. Filename inspection can be combined with file type, size, antivirus, and content analysis for broader attachment protection. Administrators should avoid overly broad patterns because legitimate files could be matched unintentionally. Filename scanning does not evaluate administrator roles or mailbox quotas. Its purpose is allowing FortiMail to apply security actions when attachment names match defined policy criteria.

Q399. What can a secure message notification contain?

  1. Disk formatting instructions
  2. Antivirus database files
  3. Instructions for accessing protected email
  4. Administrator private keys

Correct Answer: 3. Instructions for accessing protected email

Explanation

A secure message notification informs the recipient that protected content is available and provides the information required to begin the secure access process. Depending on the configuration, the notification can include a link to the secure portal and instructions for authentication or registration. The notification itself should not expose the confidential message content that encryption is intended to protect. Clear instructions improve recipient usability while preserving security. Secure message notifications do not contain administrator private keys or antivirus databases. Their purpose is guiding the intended recipient toward the approved method for accessing an encrypted email.

Q400. What can profile based policy design improve?

  1. Hardware fan speed
  2. Reuse and consistency of security settings
  3. DNS ownership
  4. Mailbox folder creation

Correct Answer: 2. Reuse and consistency of security settings

Explanation

FortiMail uses reusable profiles for many security functions such as antispam, antivirus, sessions, authentication, content inspection, encryption, and TLS. Policies reference these profiles instead of requiring every setting to be created separately in each policy. This design reduces duplication and helps administrators apply consistent security controls across multiple mail flows. Changes to a shared profile can also simplify maintenance when several policies need the same updated settings. Administrators should still confirm that shared profiles are appropriate for every referenced policy. Profile based design does not control hardware fan speed. Its purpose is improving configuration consistency and administrative efficiency.