{"id":23852,"date":"2026-09-28T10:50:46","date_gmt":"2026-09-28T10:50:46","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=23852"},"modified":"2026-09-28T10:50:46","modified_gmt":"2026-09-28T10:50:46","slug":"fortinet-fcp_fml_ad-7-4-practice-test-questions-and-exam-dumps-part4-q61-80","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/fortinet-fcp_fml_ad-7-4-practice-test-questions-and-exam-dumps-part4-q61-80\/","title":{"rendered":"Fortinet FCP_FML_AD-7.4 Practice Test Questions and Exam Dumps Part4 Q61-80"},"content":{"rendered":"<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/fcp-fml-ad-7-4-exam-dumps\"><b>Fortinet FCP_FML_AD-7.4 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/p>\n<p><b><br \/>\n<\/b><b>Q61. What does a FortiMail system certificate primarily support?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Spam scoring<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Mailbox creation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Secure encrypted connections<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Message archiving<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Secure encrypted connections<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A system certificate provides identity information that FortiMail can use when establishing secure encrypted connections. Certificates are commonly involved in TLS communication, secure administrative access, and other services that require cryptographic authentication. A valid certificate helps remote systems or users verify the identity of the FortiMail appliance and protects information transmitted across encrypted sessions. Administrators should ensure certificates are valid, trusted where required, and renewed before expiration. System certificates do not determine spam scores, create mailboxes, or decide which messages are archived. Their main role is supporting secure authenticated communication between FortiMail and other systems or users.<\/span><\/p>\n<p><b>Q62. Why can reverse DNS checking be useful?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It checks whether an IP resolves to a host name<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It encrypts message bodies<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It creates local users<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It increases mailbox storage<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. It checks whether an IP resolves to a host name<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Reverse DNS checking helps FortiMail evaluate whether the connecting IP address has a corresponding host name in DNS. Legitimate mail servers commonly maintain appropriate DNS information, while poorly configured or abusive systems may lack meaningful reverse records. FortiMail can use this information as one factor during SMTP and antispam processing. A failed reverse lookup does not always prove that a sender is malicious, so administrators should consider legitimate mail server behavior before applying strict actions. Reverse DNS checking does not encrypt messages, create users, or increase mailbox storage. Its purpose is helping assess the credibility of SMTP sources.<\/span><\/p>\n<p><b>Q63. What can an LDAP group be used for in policy matching?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Updating FortiGuard signatures<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Configuring interfaces<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Managing RAID storage<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Applying policies to selected users<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Applying policies to selected users<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">LDAP groups can help FortiMail apply policies to defined sets of users without requiring every recipient to be configured individually. For example, administrators can apply different security profiles to executives, finance staff, or other organizational groups stored in a directory. This simplifies administration and keeps FortiMail policy assignments aligned with existing identity management. Accurate LDAP searches and group membership information are important for reliable matching. LDAP groups are not used to update FortiGuard signatures, configure network interfaces, or manage storage. Their primary value is allowing directory based user groups to participate in authentication and email policy decisions.<\/span><\/p>\n<p><b>Q64. What can attachment filtering control?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS server selection<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> File types allowed in email<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Administrator login time<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Mail route priority<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. File types allowed in email<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Attachment filtering allows FortiMail to control which file types can be sent or received through the protected mail environment. Administrators can identify files by extension, type, or other supported characteristics and apply actions when restricted attachments are detected. This can reduce the risk of dangerous executable files, prohibited content, or unsupported attachment formats reaching users. Attachment filtering should normally complement antivirus scanning rather than replace it because even permitted file types can contain malicious content. DNS selection and administrator login settings are unrelated. Its purpose is controlling email attachments according to organizational security and acceptable use requirements.<\/span><\/p>\n<p><b>Q65. What does URI filtering examine in an email?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Web links contained in the message<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Mailbox quota values<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Administrator roles<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Interface addresses<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Web links contained in the message<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">URI filtering examines web addresses or links contained within email messages. Malicious or spam messages frequently include links directing recipients to phishing sites, fraudulent pages, or other harmful destinations. FortiMail can use reputation and filtering information to evaluate these links as part of antispam and security processing. Link analysis adds another protection layer because a message may contain no malicious attachment while still directing the recipient to a dangerous website. URI filtering does not inspect mailbox quotas or administrator permissions. Its primary purpose is evaluating links found inside email and helping identify messages containing suspicious or unwanted web destinations.<\/span><\/p>\n<p><b>Q66. Why is scanning compressed attachments important?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It improves DNS resolution<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It creates aliases<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Malware can be hidden inside archives<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It increases archive storage<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Malware can be hidden inside archives<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Attackers can place malicious files inside compressed archives in an attempt to avoid simple attachment inspection. FortiMail can inspect supported compressed files so antivirus and content controls can examine the files contained within them. This improves protection against malware delivered inside archive formats. Administrators should configure appropriate limits because very deeply nested or extremely large compressed files can consume significant processing resources. Compressed file inspection does not improve DNS resolution or create mail aliases. Its purpose is helping security engines inspect content that might otherwise remain hidden inside an attached archive before the message reaches the recipient.<\/span><\/p>\n<p><b>Q67. What can FortiGuard outbreak protection help identify?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> User password reuse<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Emerging email threats<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disk partition errors<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Local mailbox aliases<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Emerging email threats<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiGuard outbreak protection can help detect rapidly emerging malicious email campaigns before traditional detection methods fully catch up. New malware or spam outbreaks can spread quickly, making timely threat intelligence important. FortiMail can use FortiGuard information alongside antivirus, antispam, and other security controls to strengthen protection against new campaigns. Outbreak related information can help reduce the window during which recently emerging threats might otherwise pass normal checks. The feature does not evaluate password reuse or mailbox aliases. Its primary purpose is improving response to new email threats by using updated intelligence from Fortinet security services.<\/span><\/p>\n<p><b>Q68. What can personal quarantine access allow a user to do?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Change FortiMail firmware<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Modify global routes<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Create administrator accounts<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Review held messages<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Review held messages<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Personal quarantine access allows end users to review messages that FortiMail has placed into their individual quarantine. Depending on configuration and permissions, users may be able to release legitimate messages, delete unwanted messages, or manage selected sender preferences. This reduces the need for administrators to handle every false positive manually. Appropriate controls should remain in place so users cannot bypass protections that require administrator authority. Personal quarantine access does not allow users to change firmware, modify global mail routes, or create administrators. Its purpose is giving recipients controlled access to messages held for their own account.<\/span><\/p>\n<p><b>Q69. What can a mailbox quota control in server mode?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Interface bandwidth<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> SMTP route priority<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Amount of mailbox storage<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Antivirus update frequency<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Amount of mailbox storage<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">In server mode, FortiMail can host user mailboxes, and mailbox quotas can limit how much storage individual users are allowed to consume. Quotas help prevent one mailbox from using excessive disk capacity and provide administrators with a predictable way to manage storage resources. When users approach or exceed configured limits, mail handling can be affected according to system behavior and policy. Administrators should size storage and quotas according to organizational needs. Mailbox quotas do not control interface bandwidth, route priority, or antivirus update schedules. Their purpose is managing storage consumption for hosted user mailboxes.<\/span><\/p>\n<p><b>Q70. What does a domain association help define in server mode?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Which email domain a user belongs to<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Which antivirus engine is used<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Which interface is primary<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Which archive disk is active<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Which email domain a user belongs to<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">In server mode, user accounts and mailboxes are associated with email domains so FortiMail knows the complete addresses used for local message delivery. Domain association helps organize users and determines how local recipient addresses are interpreted. This is especially important when FortiMail hosts multiple email domains. Correct domain configuration ensures that messages are delivered to the intended local mailbox. Domain association does not select an antivirus engine or determine the active network interface. Its primary purpose is linking local users and mailboxes with the email domain under which they send and receive messages.<\/span><\/p>\n<p><b>Q71. What can webmail provide in server mode?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS management<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> RAID configuration<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Cluster heartbeat control<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Browser based mailbox access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Browser based mailbox access<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Webmail can provide users with browser based access to mailboxes hosted by FortiMail in server mode. This allows users to read, send, organize, and manage email without relying only on a separate desktop mail client. Access normally requires user authentication and should be protected through appropriate secure connection settings. Server mode webmail is different from administrative access because it is intended for mailbox users rather than FortiMail administrators. Webmail does not manage DNS, storage RAID, or high availability heartbeat settings. Its purpose is providing convenient user access to hosted email through a web interface.<\/span><\/p>\n<p><b>Q72. What normally happens after a deferred message exceeds its retry lifetime?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It becomes an administrator account<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It is treated as a permanent delivery failure<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It becomes a protected domain<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It disables TLS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. It is treated as a permanent delivery failure<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A deferred message remains queued while FortiMail repeatedly attempts delivery after temporary failures. If delivery continues to fail until the configured retry or expiration period is exhausted, the system treats the problem as a permanent delivery failure. A delivery status notification may then be generated according to normal mail handling behavior. Retry settings should provide destination systems enough time to recover while preventing messages from remaining queued indefinitely. Deferred messages do not become administrator accounts or protected domains. Queue expiration provides a controlled endpoint when temporary delivery problems cannot be resolved within the permitted period.<\/span><\/p>\n<p><b>Q73. Where is a DKIM public key normally published?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The message body<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The user quarantine<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The SMTP queue<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. DNS<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DKIM uses public key cryptography to verify email signatures. The sending system signs selected message information using a private key, while the corresponding public key is published in DNS. Receiving systems retrieve the public key and use it to verify the DKIM signature. This helps confirm that the message was signed by the associated domain and that signed content was not modified after signing. The public key is not stored in the message body or quarantine. Correct DNS publication is therefore essential for recipients to validate DKIM signed email successfully.<\/span><\/p>\n<p><b>Q74. What does DMARC alignment compare?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Attachment names and MIME types<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Sender IP and recipient IP<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Visible From domain with authenticated domains<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Mailbox quota and message size<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Visible From domain with authenticated domains<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DMARC alignment examines whether the domain shown in the visible From address aligns appropriately with the domain authenticated by SPF or DKIM. This helps prevent attackers from using a trusted looking From address while authentication succeeds for an unrelated domain. DMARC combines authentication results with domain alignment and the policy published by the sender&#8217;s domain. Alignment can be evaluated according to the policy requirements in use. It does not compare mailbox quotas or attachment names. The main purpose is ensuring that the identity visible to the recipient is meaningfully connected to an authenticated sending domain.<\/span><\/p>\n<p><b>Q75. What is the purpose of trusted CA certificates on FortiMail?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Increase spam scores<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Validate certificate trust<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Create mail routes<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Configure quarantine quotas<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Validate certificate trust<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Trusted certificate authority certificates allow FortiMail to determine whether another certificate chains back to a trusted issuer. This is important during secure TLS communication and other certificate based services. When FortiMail validates a peer certificate, trusted CA information helps establish whether the certificate should be considered legitimate. Administrators should maintain appropriate trusted authorities and remove certificates that are no longer required. Trusted CA certificates do not create mail routes or influence quarantine quotas. Their main purpose is supporting certificate validation and helping FortiMail establish trusted encrypted communication with external or internal systems.<\/span><\/p>\n<p><b>Q76. What can a safe sender list help reduce?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Interface errors<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Mailbox size<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> False positive spam handling<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS query volume<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. False positive spam handling<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A safe sender list identifies senders that a user or administrator considers trusted. Depending on configuration, this information can influence antispam handling so legitimate messages from known senders are less likely to be treated as unwanted mail. Safe lists should be used carefully because compromised trusted accounts can still send malicious content. Antivirus and other security scanning should therefore remain important even when a sender is trusted. Safe sender lists do not reduce mailbox size or DNS query volume. Their main purpose is reducing unnecessary spam treatment for known legitimate sender addresses.<\/span><\/p>\n<p><b>Q77. What can a blocked attachment rule prevent?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Delivery of prohibited file types<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS resolution<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> SMTP authentication<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Administrator login<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Delivery of prohibited file types<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A blocked attachment rule can prevent messages containing prohibited file types from being delivered normally. Organizations may restrict executable files, scripts, or other formats that create security or compliance concerns. FortiMail can inspect attachment characteristics and apply configured actions when blocked types are detected. Attachment controls complement antivirus scanning because a file can be prohibited by policy even if no malware signature is detected. These rules do not prevent DNS resolution or administrator login. Their purpose is enforcing organizational restrictions on the kinds of files users are allowed to send or receive through email.<\/span><\/p>\n<p><b>Q78. What can a certificate expiration warning help prevent?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Spam outbreaks<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Unexpected TLS trust problems<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Mailbox duplication<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Archive search failures<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Unexpected TLS trust problems<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Certificate expiration warnings help administrators renew or replace certificates before they become invalid. An expired certificate can cause browsers, mail systems, or other clients to reject or distrust secure connections. Monitoring certificate validity therefore reduces the risk of unexpected service disruption or TLS trust warnings. Administrators should maintain an appropriate renewal process and confirm that replacement certificates are installed correctly. Certificate expiration does not directly cause spam outbreaks or mailbox duplication. The main purpose of expiration monitoring is preserving trusted encrypted communication and avoiding outages caused by certificates reaching the end of their validity period.<\/span><\/p>\n<p><b>Q79. What can an outbound content rule help protect?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disk health<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Interface speed<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Sensitive information leaving the organization<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Administrator themes<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Sensitive information leaving the organization<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Outbound content rules can inspect messages leaving protected users or domains and identify sensitive information according to configured patterns or policies. Organizations can use these controls to prevent or protect transmission of confidential information such as financial data, internal records, or other regulated content. Actions can include blocking, quarantining, notifying, or encrypting messages depending on the configured policy. Outbound content inspection is an important data protection capability. It does not monitor disk health or interface speed. Its purpose is controlling sensitive content before email leaves the protected environment.<\/span><\/p>\n<p><b>Q80. What can a certificate based TLS policy require?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Message archiving<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Spam quarantine<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Mailbox creation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Trusted encrypted SMTP communication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Trusted encrypted SMTP communication<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A certificate based TLS policy can require secure SMTP communication that uses certificates to establish encryption and, where configured, verify the identity of the communicating mail system. This can be useful when sensitive organizations or partner domains require stronger transport security than opportunistic TLS provides. Administrators must configure certificates, trust relationships, and policy settings correctly on both sides. If required security conditions cannot be established, mail delivery may fail according to policy. Certificate based TLS does not create mailboxes or determine quarantine behavior. Its main purpose is enforcing trusted encrypted transport between SMTP systems.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Fortinet FCP_FML_AD-7.4 Exam Dumps and Practice Test Dumps. Q61. What does a FortiMail system certificate primarily support? Spam scoring Mailbox creation Secure encrypted connections Message archiving Correct Answer: 3. Secure encrypted connections Explanation A system certificate provides identity information that FortiMail can use when establishing secure encrypted connections. Certificates are commonly involved in [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23852"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=23852"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23852\/revisions"}],"predecessor-version":[{"id":23853,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23852\/revisions\/23853"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=23852"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=23852"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=23852"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}