Fortinet Certified Professional - FortiMail 7.4 Administrator Free Sample Questions

19 free sample questions214 in the full practice test

Try simulator

FCP-FML-AD-7-4 Sample Questions

  1. Question 1

    A financial services firm has deployed a FortiMail 2000E cluster in gateway mode. During a routine audit, it was discovered that outbound emails containing customer account numbers are not being properly encrypted using the configured Identity-Based Encryption (IBE) policy. The policy is designed to trigger encryption for any email sent to external domains. A junior administrator confirms the IBE service is running and users are registered. Which of the following is the most likely cause for the IBE policy failure for outbound mail?

    Answer and explanation

    Correct answer: A

    FortiMail applies IBE encryption through policies. For outbound mail, an outbound recipient policy must be matched, and that policy must have a content profile that specifies the IBE encryption action. If the content profile with the IBE action is not linked to the outbound policy, encryption will not be triggered, even if the IBE service is active.

  2. Question 2

    Multiple answers

    A healthcare organization is deploying FortiMail in transparent mode to inspect all inbound and outbound email for their on-premise Microsoft Exchange server. The security architect wants to ensure that if the FortiMail appliance fails or is taken offline for maintenance, email flow is not interrupted. Which two actions should the administrator take to achieve this? (Choose two.)

    Answer and explanation

    Correct answers: A, D

    Deploying an active-passive HA cluster is the primary method for providing redundancy. If the active unit fails, the passive unit takes over all processing, ensuring continuous email inspection and delivery.

    Fail-to-wire (also known as fail-open or bypass mode) is a hardware feature on certain FortiMail models. If the appliance loses power or fails critically, the ports create a direct physical connection, allowing traffic to pass through uninspected but without interrupting the mail flow. This is a crucial last-resort mechanism for maintaining connectivity.

  3. Question 3

    True or False: When FortiMail is configured in gateway mode, it is mandatory to change the public MX records of the protected domain to point to the FortiMail's public IP address.

    Answer and explanation

    Correct answer: A

    In gateway mode, the FortiMail unit acts as an inbound and outbound mail relay. To ensure that all incoming email for the protected domain is first processed by FortiMail, the public Mail Exchanger (MX) DNS records must be updated to point to the FortiMail appliance. This directs all external mail servers to deliver email to FortiMail instead of directly to the organization's mail server.

  4. Question 4

    An administrator is configuring Bounce Address Tag Validation (BATV) to combat spam in delivery status notifications (DSNs). After enabling BATV, the administrator notices that some legitimate bounce messages from a trusted partner domain are being dropped. What is the most effective way to resolve this issue while keeping BATV active for all other traffic?

    Answer and explanation

    Correct answer: C

    FortiMail provides a specific exemption list for bounce address tag validation. By adding the trusted partner's domain to this list, their DSNs will be accepted without a valid BATV tag, resolving the issue without disabling the feature globally or creating overly permissive IP whitelists.

  5. Question 5

    A system administrator is configuring an LDAP profile to authenticate users for a protected domain. The LDAP server is a standard Microsoft Active Directory. The administrator needs to ensure that FortiMail can query for user group membership to apply group-based policies. Which LDAP attribute should be used in the 'Group member attribute' field for a typical Active Directory schema?

    Answer and explanation

    Correct answer: A

    In Microsoft Active Directory, the 'memberOf' attribute is a multi-valued attribute on a user object that lists the distinguished names of the groups to which the user belongs. FortiMail uses this attribute to determine group membership for policy matching.

  6. Question 6

    A retail company is using FortiMail in Server Mode as its primary mail server for the 'example.com' domain. An administrator needs to configure a 'catch-all' address, so that any email sent to a non-existent user at 'example.com' is delivered to the '[email protected]' mailbox instead of being rejected. How should this be configured?

    Answer and explanation

    Correct answer: B

    In FortiMail's server mode, a wildcard user alias (*) can be created to act as a catch-all. When recipient verification fails to find a specific user, it checks for a matching alias. The wildcard alias will match any non-existent user in the domain and redirect the email to the specified destination, in this case, '[email protected]'.

  7. Question 7

    Multiple answers

    A consultant is reviewing a FortiMail configuration and observes a high number of deferred messages in the mail queue from a specific sending IP address. The logs show the reason for deferral is 'Greylisting'. Which three statements about this situation are correct? (Choose three.)

    Answer and explanation

    Correct answers: A, C, E

    Greylisting works by temporarily rejecting an email from an unknown combination of IP/sender/recipient. A compliant Mail Transfer Agent (MTA) will attempt to redeliver the email after a short period. If the sending server does not retry, the message will remain deferred and eventually time out.

    Greylisting is a feature configured within a session profile. That profile must then be applied to a policy (either IP-based or recipient-based) that matches the incoming email session for the greylisting action to be triggered.

    Once the initial greylist period has passed, FortiMail will recognize the retried attempt from the same IP/sender/recipient tuple and accept the connection, delivering the email. The tuple is then whitelisted for a configurable period.

  8. Question 8

    An administrator wants to configure DomainKeys Identified Mail (DKIM) signing for an outbound domain, 'corp-internal.com'. Where must the administrator store the public key so that receiving mail servers can verify the DKIM signature applied by the FortiMail appliance?

    graph TD subgraph FortiMail A[Private Key] --> B(Email Signing) end B --> C{Receiving MTA} subgraph PublicDNS D[Public Key in TXT Record] --> E(Verification) end C --> E

    Answer and explanation

    Correct answer: B

    The DKIM standard specifies that the public key must be published in the public DNS system as a TXT record. The record is located at a specific subdomain indicated by the selector in the DKIM signature header. Receiving servers query this DNS record to retrieve the public key and verify the signature's authenticity.

  9. Question 9

    A manufacturing company is setting up a new FortiMail appliance. The IT director has mandated that two separate teams, 'Network Ops' and 'Security Ops', should have administrative access, but with different permissions. The Network Ops team should only be able to manage system settings, network configurations, and HA. The Security Ops team should only manage policies and security profiles. Which FortiMail feature should be used to enforce this separation of duties?

    Answer and explanation

    Correct answer: B

    Administrator access profiles are used to create custom, role-based access control (RBAC) policies. An administrator can create a profile for each team, granting read/write or read-only access to specific areas of the GUI and CLI. These profiles are then assigned to the respective administrator accounts.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 214 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon