FCP in Public Cloud Security FCP_FML_AD-7.4 Exam Dumps and Certification Test Engine [Q12-Q37]

Share

(PDF) FCP in Public Cloud Security FCP_FML_AD-7.4 Exam and Certification Test Engine

Use FCP_FML_AD-7.4 Exam Dumps (2026 PDF Dumps) To Have Reliable FCP_FML_AD-7.4 Test Engine


Fortinet FCP_FML_AD-7.4 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Encryption: This section of the exam measures skills of a Messaging Security Engineer and addresses the implementation of encryption methods in FortiMail. It covers traditional SMTP encryption and identity-based encryption (IBE). Candidates are expected to configure these technologies and manage IBE users for secure email communication.
Topic 2
  • Initial Deployment and Basic Configuration: This section of the exam measures skills of a Network Security Administrator and covers the foundational setup of FortiMail. It includes understanding SMTP and email flow, performing initial configurations such as selecting operation mode, system settings, and defining protected domains. It also involves deploying FortiMail in high-availability clusters to ensure service continuity.
Topic 3
  • Server Mode and Transparent Mode: This section of the exam measures skills of a Network Security Administrator and explains how to deploy and manage FortiMail in different operation modes. It includes configuring server mode to handle mail directly and deploying FortiMail in transparent mode where it acts as a gateway to filter email traffic without altering the existing mail infrastructure.
Topic 4
  • Email Security: This section of the exam measures skills of a Network Security Administrator and deals with implementing security controls to filter and manage email threats. Candidates must configure session-based filtering, spam detection methods, malware protection, APT mitigation, and content filtering. The section also includes email archiving configurations for compliance and storage.
Topic 5
  • Email Flow and Authentication: This section of the exam measures skills of a Messaging Security Engineer and focuses on configuring FortiMail to handle email flow securely. It includes enabling and matching authentication protocols, setting up secure MTA features, and implementing access control, IP policies, and recipient-based policies to control mail delivery and security.

 

NEW QUESTION # 12
Refer to the exhibit which shows a detailed history log view.

Which two actions did FortiMail take on this email message? (Choose two.)

  • A. FortiMail forwarded the email to User 1 without scanning.
  • B. FortJMail replaced the virus content with a message
  • C. FortiMail sent the email message to User 1's personal quarantine.
  • D. FortiMail modified the subject of the email message.

Answer: B,D


NEW QUESTION # 13
An organization has different groups of users with different needs in email functionality, such as address book access, mobile device access, email retention periods, and disk quotas. Which FortiMail feature specific to server mode can be used to accomplish this?

  • A. Email group profiles
  • B. Domain-level service settings
  • C. Access profiles
  • D. Resource profiles.

Answer: D


NEW QUESTION # 14
Which FortiMail feature combats spammers who try to hide spam content in delivery status notifications (DSN) messages?

  • A. Behavior analysis
  • B. Heuristic
  • C. Bounce address tag validation (BATV)
  • D. Header analysis

Answer: C

Explanation:
BATV verifies the validity of bounce messages and prevents attackers from embedding spam content inside fake DSN messages.


NEW QUESTION # 15
Which are FortiMail operating modes? (Choose three.)

  • A. Server mode
  • B. Proxy mode
  • C. Transparent mode
  • D. Gateway mode
  • E. NAT/Route mode

Answer: A,C,D

Explanation:
FortiMail supports Transparent, Server, and Gateway modes. Proxy and NAT/Route are not valid FortiMail operating modes.


NEW QUESTION # 16
Refer to the exhibit, which shows a topology diagram of two MTAs.

MTA-1 is delivering an email intended for User 1 to MTA-2. User 1 uses Outlook as an email client. Which two statements about protocol usage between these devices are correct? (Choose two.)

  • A. User 1 will use IMAP or POP3 to download the email message from MTA-2.
  • B. MTA-1 will use SMTP to deliver the email message to MTA-2.
  • C. MTA-2 will use IMAP to download the email message from MTA-1.
  • D. MTA-1 will use POP3 to deliver the email message to User 1 directly.

Answer: A,B


NEW QUESTION # 17
Refer to the exhibit, which displays the domain configuration of a FortiMail device running in transparent mode.

Based on the exhibit, which two sessions are considered incoming sessions? (Choose two.) DESTINATION IP: 192.168.54.10 MAIL FROM: [email protected] RCPT TO:

Answer: A,B

Explanation:
The sessions that originate from SMTP clients connecting into FortiMail are:
- A client connecting to 192.168.54.10 and sending mail from [email protected] to [email protected].
- A client connecting to 10.25.32.15 and submitting mail from [email protected] to [email protected].
Both of these represent inbound SMTP traffic terminating on the FortiMail device. The other sessions are FortiMail itself relaying messages onward to the configured back-end server, so they are considered outgoing.


NEW QUESTION # 18
Refer to the exhibit, which shows an inbound recipient policy.

After creating the policy, an administrator discovers that clients can send Inbound Recipient Policy unauthenticated emails using SMTP.
What must the administrator do to enforce authentication?

  • A. Configure a matching IP policy with the exclusive flag enabled.
  • B. Configure an outbound recipient policy for LDAP authentication.
  • C. Configure an access receive rule to verify authentication status.
  • D. Configure an access delivery rule to enforce authentication.

Answer: C

Explanation:
You need to create an Access Receive Rule that matches your incoming mail and sets Authentication status to "Authenticated." That rule will block any SMTP session that isn't authenticated before it ever reaches the recipient policy.


NEW QUESTION # 19
What are two benefits of enabling the header manipulation feature? (Choose two.)

  • A. It detects common spamming techniques
  • B. It detects spoofed SMTP header addresses
  • C. It hides internal network information
  • D. It reduces overall message size by removing header content

Answer: C,D

Explanation:
Header manipulation can remove or rewrite sensitive headers, hiding internal infrastructure details and reducing message size.


NEW QUESTION # 20


Refer to the exhibits, which show a topology diagram (Topology) and a configurationelement (Access Control Rule.) An administrator wants to configure an access receive rule to matchauthentication status on FML-1 for all outbound email from the example. co- domain.
Which two access receive rule settings must the administrator configure? (Choose two.)

  • A. The Authentication status must be set to Authenticated
  • B. A TLS profile must be configured and applied.
  • C. The Recipient pattern must be set to *@example. com.
  • D. The Sender IP/netmask must be set to 10.29.1.0/24.

Answer: A,C


NEW QUESTION # 21
Refer to the exhibits, which show an email archiving configuration (Email Archiving 1 and Email Archiving 2) from a FortiMail device.


What two archiving actions will FortiMail take when email messages match these archive policies? (Choose two.)

  • A. FortiMail will exempt spam email from archiving.
  • B. FortiMail will save archived email in the journal account.
  • C. FortiMail will archive email sent from [email protected].
  • D. FortiMail Will allow only the [email protected] account to access the archived email.

Answer: A,B

Explanation:
FortiMail will exempt spam email from archiving.
The Email Archiving Exempt Policy is set to "Spam Email," so any messages identified as spam are skipped.
FortiMail will save archived email in the journal account.
Both policies target the same "journal" account, so all non-exempt matching messages go into that mailbox.


NEW QUESTION # 22
Refer to the exhibit which displays a topology diagram.

Which two statements describe the built-in bridge functionality on a transparent mode FortiMail? (Choose two.)

  • A. Any bridge member interface can be removed from the bridge and configured as a routed interface.
  • B. If port1. is required to process SMTP traffic, it must be configured as a routed interface.
  • C. The management IP is permanently tied to port1, and port1 cannot be removed from the bridge.
  • D. All bridge member interfaces belong to the same subnet as the management IP.

Answer: C,D


NEW QUESTION # 23
Refer to the exhibits. The exhibits display a topology diagram of a FortiMail cluster (Topology) and the primary HA interface configuration of the Primary FortiMail (HA Interface Configuration).
Which three actions are recommended when configuring the primary FortiMail HA interface?
(Choose three.)

  • A. Disable Enable port monitor
  • B. In the Virtual IP action drop-down list, select Use.
  • C. In the Heartbeat status drop-down list, select Primary
  • D. In the Peer IP address field, type 172.16.32.57
  • E. In the Virtual IP address field, type 172.16.32.55/24

Answer: B,D,E

Explanation:
Here are the three settings you should change on the Primary's HA port1 interface:
- Set Virtual IP action to Use
- Enter 172.16.32.55/24 as the Virtual IP address
- Enter 172.16.32.57 as the Peer IP address
With those in place, the Primary will advertise and answer on the cluster VIP (172.16.32.55) and know how to reach its Secondary peer (172.16.32.57).


NEW QUESTION # 24
In which two places can the maximum email size be overridden on FortiMail? (Choose two.)

  • A. Protected Domain configuration
  • B. IP Policy configuration
  • C. Resource Profile configuration
  • D. Session Profile configuration

Answer: A,C


NEW QUESTION # 25
Which three configuration steps must you set to enable DKIM signing for outbound messages on FortiMail? (Choose three.)

  • A. Enable DKIM signing for outgoing messages in a matching session profile.
  • B. Generate a public/private key pair in the protected domain configuration.
  • C. Enable the DKIM checker in a matching antispam profile.
  • D. Enable the DKIM checker in a matching session profile.
  • E. Publish the public key as a TXT record in a public DNS server.

Answer: A,B,E

Explanation:
You must enable DKIM signing for outgoing messages in the session profile (or IP policy) that handles your outbound flow.
After generating your key pair, you publish the public key as a DNS TXT record so receivers can verify signatures.
In the protected-domain settings you generate a DKIM key pair (private key for signing and public key for DNS).


NEW QUESTION # 26
Exhibit.

Refer to the exhibits, which show an email archiving configuration (Email Archiving 1 and Email Archiving
2) from a FortiMail device.
What two archiving actions will FortiMail take when email messages match these archive policies? (Choose two.)

  • A. FortiMail will exempt spam email from archiving.
  • B. FortiMail will allow only the marketingeexample.com account to access the archived email.
  • C. FortiMail will save archived email in the journal account.
  • D. FortiMail will archive email sent from marketingexample. com.

Answer: A,C


NEW QUESTION # 27
Which two antispam techniques query FortiGuard for rating information? (Choose two.)

  • A. IP reputation
  • B. URL filter
  • C. SURBL
  • D. DNSBL

Answer: A,B


NEW QUESTION # 28
Which SMTP command lists the supported SMTP service extensions of the recipient MTA?

  • A. VRFY
  • B. HELO
  • C. DATA
  • D. EHLO

Answer: D

Explanation:
The EHLO command (Extended HELO) prompts the recipient MTA to respond with a list of all supported SMTP service extensions, enabling the sender to use features like SMTP authentication, pipelining, and STARTTLS.


NEW QUESTION # 29
Refer to the exhibit, which shows the mail server settings of a FortiMail device:

What are two ways this FortiMail device will handle connections? (Choose two.)

  • A. FortiMail will support the STARTTLS extension.
  • B. FortiMail will drop any inbound plaintext SMTP connection.
  • C. FortiMail will enforce SMTPS on all outbound sessions.
  • D. FortiMail will accept SMTPS connections.

Answer: A,D

Explanation:
FortiMail will accept SMTPS connections.
The SMTPS port (465) is enabled and "SMTPS" authentication is turned on, so it will listen for and accept implicit-SSL SMTP on port 465.
FortiMail will support the STARTTLS extension.
With "SMTP over SSL/TLS" enabled on port 25, the server advertises and accepts STARTTLS for opportunistic TLS upgrades on plaintext SMTP sessions.


NEW QUESTION # 30
What are two disadvantages of configuring the dictionary and DLP scan rule aggressiveness too high? (Choose two.)

  • A. High aggressiveness scan settings do not support executable file types.
  • B. It is more resource intensive
  • C. FortiMail requires more disk space for the additional rules.
  • D. More false positives could be detected.

Answer: B,D


NEW QUESTION # 31
A FortiMail device is configured with the protected domain example.com.
If senders are not authenticated, which two envelope addresses will require an access receive rule? (Choose two.)

Answer: C,D

Explanation:
MAIL FROM: [email protected] RCPT TO: [email protected]
This is an unauthenticated internal-to-external flow, so you must have a receive rule allowing your internal senders to relay outbound mail.
MAIL FROM: [email protected] RCPT TO: [email protected]
This is an unauthenticated external-to-internal flow (the recipient is in your protected domain), so it also needs an explicit access receive rule.


NEW QUESTION # 32
Which two factors are required for an active-active HA configuration of FortiMail in server mode?
(Choose two.)

  • A. A primary must be designated to initially process email.
  • B. Service monitoring must be configured for remote SMTP.
  • C. Devices must be deployed behind a load balancer.
  • D. Mail data must be stored on a NAS server.

Answer: C,D

Explanation:
FortiMail in server-mode active-active requires a shared mail store (e.g. NAS) so both units see the same data, and an external load-balancer (or DNS round-robin) to distribute SMTP sessions across the pair.


NEW QUESTION # 33
Refer to the exhibit, which shows an antivirus action profile.

What are two expected outcomes if FortiMail applies this antivirus action profile to an email?
(Choose two.)

  • A. A replacement message will be added to the email.
  • B. The original email will be sent to the system quarantine.
  • C. Virus content will be removed from the email.
  • D. The sanitized email will be sent to the recipient's personal quarantine.

Answer: A,B,C

Explanation:
A replacement message will be added to the email.
Because the "Replace infected/suspicious body or attachment" action is enabled, any detected virus object is stripped out and replaced with a stub or notice.
Virus content will be removed from the email.
FortiMail strips the infected parts of the message as part of that replacement action.


NEW QUESTION # 34
Refer to the exhibit, which shows a topology diagram of a FortiMail cluster deployment.

Which IP address must the DNS MX record for this organization resolve to?

  • A. 1172 16 32 57
  • B. 172.16.32.56
  • C. 172.16.32.55
  • D. 172.16.32.1

Answer: C


NEW QUESTION # 35
Refer to the exhibits, which display a topology diagram (Topology) and two FortiMail device configurations (FML1 ConfigurationandFML2 Configuration).



What is the expected outcome of SMTP sessions sourced from FML1 and destined for FML2?

  • A. FML1 will attempt to establish an SMTPS session with FML2. but fail and revert to standard SMTP.
  • B. FML1 will fail to establish any connection with FML2.
  • C. FML1 will successfully establish an SMTPS session with FML2.
  • D. FML1 will send the STARTTLS command in the SMTP session, which will be rejected by FML2.

Answer: C


NEW QUESTION # 36
A FortiMail administrator is investigating a sudden increase in DSNs being delivered to their protected domain. After searching the logs, the administrator identifies that the DSNs were not generated because of any outbound email sent from their organization.
Which FortiMail antispam technique can the administrator enable to prevent this scenario?

  • A. FortiGuard IP Reputation
  • B. Spam outbreak protection
  • C. Bounce address tag validation
  • D. Spoofed header detection

Answer: C

Explanation:
Enabling Bounce Address Tag Validation prevents FortiMail from accepting forged bounce messages (backscatter) for mail it never actually sent, stopping those unsolicited DSNs from reaching your users.


NEW QUESTION # 37
......

FCP_FML_AD-7.4 Dumps Full Questions with Free PDF Questions to Pass: https://testinsides.vcedumps.com/FCP_FML_AD-7.4-examcollection.html