A Fully Updated 2026 FCP_FML_AD-7.4 Exam Dumps - PDF Questions and Testing Engine
Easy Success Fortinet FCP_FML_AD-7.4 Exam in First Try
NEW QUESTION # 39
A FortiMail is configured with the protected domain example.com.
On this FortiMail, which two envelope addresses are considered incoming? (Choose two.)
- A. MAIL FROM: [email protected] RCPT TO: [email protected]
- B. MAIL FROM: [email protected] RCPT TO: [email protected]
- C. MAIL FROM: [email protected] RCPT TO: [email protected]
- D. MAIL FROM: [email protected] RCPT TO: [email protected]
Answer: A,B
NEW QUESTION # 40
Refer to the exhibit, which shows the output of an email transmission using a telnet session.
What are two correct observations about this SMTP session? (Choose two.)
- A. The SMTP envelope addresses are different from the message header addresses.
- B. The "250 Message accepted for delivery" message is part of the message body.
- C. The "Subject" is part of the message header.
- D. The "220 mx.internal.lab ESMTP Smtpd" message is part of the SMTP banner.
Answer: C,D
Explanation:
The line 220 mx.internal.lab ESMTP Smtpd is the server's SMTP banner sent immediately upon connection.
The Subject: field appears in the message header, not the SMTP envelope or body.
NEW QUESTION # 41
In which two places can the maximum email size be overridden on FortiMail? (Choose two.)
- A. Session Profile configuration
- B. Protected Domain configuration
- C. IP Policy configuration
- D. Resource Profile configuration
Answer: B,D
NEW QUESTION # 42
Refer to the exhibit which shows a topology diagram of a FortiMail cluster deployment.
Which IP address must the DNS MX record for this organization resolve to?
- A. 1172 16 32 57
- B. 172.16.32.56
- C. 172.16.32.55
- D. 172.16.32.1
Answer: C
NEW QUESTION # 43
In which two ways does a transparent mode FortiMail use the build-it MTA to process email?
(Choose two.)
- A. It can queue undeliverable messages and generate DSNs.
- B. The built-in MTA must connect to an external relay host to deliver email.
- C. MUAs must be configured to connect to the built-in MTAto send email.
- D. It ignores the destination set by the sender and uses its own MX record lookup.
Answer: A,D
Explanation:
It ignores the destination set by the sender and uses its own MX record lookup.
In transparent mode FortiMail intercepts mail and then its built-in MTA performs an MX lookup on the recipient domain rather than trusting the original destination hop.
It can queue undeliverable messages and generate DSNs.
The built-in MTA maintains delivery queues and produces Delivery Status Notifications when downstream delivery fails.
NEW QUESTION # 44
Refer to the exhibit, which shows the Authentication Reputation list on a FortiMail device running in gateway mode.
Why was the IP address blocked?
- A. The IP address had consecutive SSH login failures to FortiMail.
- B. The IP address had consecutive administrative password failures to FortiMail.
- C. The IP address had consecutive IMAP login failures to FortiMail.
- D. The IP address had consecutive SMTPS login failures to FortiMail..
Answer: D
NEW QUESTION # 45
Refer to the exhibits, which show an email archiving configuration (Email Archiving 1 and Email Archiving 2) from a FortiMail device.

What two archiving actions will FortiMail take when email messages match these archive policies? (Choose two.)
- A. FortiMail will save archived email in the journal account.
- B. FortiMail Will allow only the [email protected] account to access the archived email.
- C. FortiMail will exempt spam email from archiving.
- D. FortiMail will archive email sent from [email protected].
Answer: A,C
Explanation:
FortiMail will exempt spam email from archiving.
The Email Archiving Exempt Policy is set to "Spam Email," so any messages identified as spam are skipped.
FortiMail will save archived email in the journal account.
Both policies target the same "journal" account, so all non-exempt matching messages go into that mailbox.
NEW QUESTION # 46
A FortiMail is configured with the protected domain example.com.
On this FortiMail, which two envelope addresses are considered incoming? (Choose two.)
- A. MAIL FROM: supporteexample.com RCPT TO: [email protected]
- B. EMAIL FROM: nisGhosted.r.et RCPT 70: noceexampIe.com
- C. MAIL FROM: training&external.crg RCPT TO: student30extersal.org
- D. MAIL FROM: accountsGexample.ccm RCPT TO: [email protected]
Answer: A,D
NEW QUESTION # 47
Refer to the exhibit, which shows an antivirus action profile.
What are two expected outcomes if FortiMail applies this antivirus action profile to an email?
(Choose two.)
- A. The original email will be sent to the system quarantine.
- B. A replacement message will be added to the email.
- C. The sanitized email will be sent to the recipient's personal quarantine.
- D. Virus content will be removed from the email.
Answer: A,B,D
Explanation:
A replacement message will be added to the email.
Because the "Replace infected/suspicious body or attachment" action is enabled, any detected virus object is stripped out and replaced with a stub or notice.
Virus content will be removed from the email.
FortiMail strips the infected parts of the message as part of that replacement action.
NEW QUESTION # 48
Refer to the exhibit, which shows a detailed history log view.
Which two actions did FortiMail take on this email message? (Choose two.)
- A. FortiMail sent the email message to User 1's personal quarantine.
- B. FortJMail replaced the virus content with a message
- C. FortiMail forwarded the email to User 1 without scanning.
- D. FortiMail modified the subject of the email message.
Answer: B,D
NEW QUESTION # 49
In which two ways does a transparent mode FortiMail use the build-it MTA to process email? (Choose two.)
- A. The built-in MTA must connect to an external relay host to deliver email.
- B. MUAs must be configured to connect to the built-in MTA to send email.
- C. It can queue undeliverable messages and generate DSNs.
- D. It ignores the destination set by the sender and uses its own MX record lookup.
Answer: B,D
NEW QUESTION # 50
Refer to the exhibit, which shows a topology diagram of two MTAs.
MTA-1 is delivering an email intended for User 1 to MTA-2. User 1 uses Outlook as an email client.
Which two statements about protocol usage between these devices are correct? (Choose two.)
- A. MTA-1 will use SMTP to deliver the email message to MTA-2.
- B. User 1 will use IMAP or POP3 to download the email message from MTA-2.
- C. MTA-1 will use POP3 to deliver the email message to User 1 directly.
- D. MTA-2 will use IMAP to download the email message from MTA-1.
Answer: A,B
Explanation:
MTA-1 uses SMTP to hand off the message to MTA-2 over the Internet.
User 1 then retrieves mail from MTA-2 using either IMAP or POP3 with Outlook.
NEW QUESTION # 51
Which two antispam techniques query FortiGuard for rating information? (Choose two.)
- A. SURBL
- B. DNSBL
- C. URL filter
- D. IP reputation
Answer: C,D
NEW QUESTION # 52
What are two benefits of having authentication reputation tracking enabled on FortiMail? (Choose two.)
- A. Tracks offending IP addresses attempting brute force attacks
- B. Enforces SMTP authentication
- C. Temporarily locks out an attacker
- D. Detects spoofed SMTP header addresses
Answer: A,C
Explanation:
Authentication reputation tracking monitors repeated authentication failures and can track malicious IPs and temporarily block attackers.
NEW QUESTION # 53
A mail user wants the ability to subscribe or publish to and from their FortiMail calendar using Thunderbird as their mail user agent (MUA). What information does this mail user need from their webmail User Preferences section?
- A. Message tags
- B. Free busy URL
- C. Service URLs
- D. Secondary account configurations
Answer: D
NEW QUESTION # 54
When configuring a FortiMail HA group consisting of different models, which two statements are true?
(Choose two.)
- A. Group capacity is limited to the least powerful model.
- B. All units must have the same firmware.
- C. The most powerful model must be configured as the primary unit.
- D. Configurations will not synchronize between different model types.
Answer: A,B
NEW QUESTION # 55
Refer to the exhibit, which displays an access control rule. What are two expected behaviors for this access control rule? (Choose two.)
- A. Email matching this rule will be relayed.
- B. Senders must be authenticated to match this rule.
- C. Email must originate from an example.comemail address.
- D. Emails must be sent from the 10.0.1.0/24subnet.
Answer: A,C
Explanation:
Email matching this rule will be relayed.
The rule's Action is set to Relay, so any message that matches the rule is forwarded onward.
Email must originate from an example.com email address.
The Sender field is "*@example.com," so only envelopes with a MAIL FROM in that domain match.
NEW QUESTION # 56
A FortiMail administrator is investigating a sudden increase in DSNs being delivered to their protected domain. After searching the logs, the administrator identifies that the DSNs were not generated because of any outbound email sent from their organization.
Which FortiMail antispam technique can the administrator enable to prevent this scenario?
- A. Bounce address tag validation
- B. Spam outbreak protection
- C. Spoofed header detection
- D. FortiGuard IP Reputation
Answer: A
Explanation:
Enabling Bounce Address Tag Validation prevents FortiMail from accepting forged bounce messages (backscatter) for mail it never actually sent, stopping those unsolicited DSNs from reaching your users.
NEW QUESTION # 57
Exhibit.
Refer to the exhibit, which shows the mail server settings of a FortiMail device. What are two ways this FortiMail device will handle connections? (Choose two.)
- A. FortiMail will enforce SMTPS on all outbound sessions.
- B. FortiMail will drop any inbound plaintext SMTP connection.
- C. FortiMail will support the STARTTLS extension.
- D. FortiMail will accept SMTPS connections.
Answer: C,D
NEW QUESTION # 58
A FortiMail administrator is investigating a sudden increase in DSNs being delivered to their protected domain. After searching the logs, the administrator identities that the DSNs were not generated because of any outbound email sent from their organization.
Which FortiMail antispam technique can the administrator enable to prevent this scenario?
- A. Bounce address tag validation
- B. Spoofed header detection
- C. FortiGuard IP Reputation
- D. Spam outbreak protection.
Answer: A
NEW QUESTION # 59
While reviewing logs, an administrator discovers that an incoming email was processed using policy IDs0:4:9:
INTERNAL.
Which two statements describe what this policy ID means? (Choose two.)
- A. Access control policy number 9 was used.
- B. FortiMail is applying the default behavior for relaying inbound email.
- C. The email was processed using IP-based policy ID 4.
- D. The FortiMail configuration is missing an access delivery rule.
Answer: B,C
NEW QUESTION # 60
Which two types of remote authentication are supported for FortiMail administrator accounts?
(Choose two.)
- A. TACACS
- B. Single Sign-on
- C. RADIUS
- D. Kerberos
Answer: B,C
Explanation:
FortiMail supports RADIUS and SSO-based authentication for administrator access.
NEW QUESTION # 61
......
FCP_FML_AD-7.4 Study Material, Preparation Guide and PDF Download: https://www.actual4dumps.com/FCP_FML_AD-7.4-study-material.html
Best FCP_FML_AD-7.4 Exam Dumps for the Preparation of Latest Exam Questions: https://drive.google.com/open?id=17p-oo--_08XLwngMwi-hfmcPWX6LFu7U