FCP-FML-AD-7-4 Sample Questions & Answers
Email security work like session-based filtering, spam filtering, and malware detection gets the heaviest weighting, built on SMTP flow basics and high availability, authentication and access policies, SMTP and identity-based encryption, and transparent mode.
Launch the full FCP-FML-AD-7-4 simulator →Showing 9 of 19 free samples.
- Question 1Intermediate
Email Flow and Authentication · LDAP Integration
A system administrator is configuring an LDAP profile to authenticate users for a protected domain. The LDAP server is a standard Microsoft Active Directory. The administrator needs to ensure that FortiMail can query for user group membership to apply group-based policies. Which LDAP attribute should be used in the 'Group member attribute' field for a typical Active Directory schema?
Show answer & explanation
Correct answer: A
In Microsoft Active Directory, the 'memberOf' attribute is a multi-valued attribute on a user object that lists the distinguished names of the groups to which the user belongs. FortiMail uses this attribute to determine group membership for policy matching.
- Question 2Intermediate
Server Mode and Transparent Mode · Server Mode User Management
A retail company is using FortiMail in Server Mode as its primary mail server for the 'example.com' domain. An administrator needs to configure a 'catch-all' address, so that any email sent to a non-existent user at 'example.com' is delivered to the '[email protected]' mailbox instead of being rejected. How should this be configured?
Show answer & explanation
Correct answer: B
In FortiMail's server mode, a wildcard user alias (
*) can be created to act as a catch-all. When recipient verification fails to find a specific user, it checks for a matching alias. The wildcard alias will match any non-existent user in the domain and redirect the email to the specified destination, in this case, '[email protected]'. - Question 3IntermediateSelect 3
Email Security · Greylisting
A consultant is reviewing a FortiMail configuration and observes a high number of deferred messages in the mail queue from a specific sending IP address. The logs show the reason for deferral is 'Greylisting'. Which three statements about this situation are correct? (Choose three.)
Show answer & explanation
Correct answers: A, C, E
Greylisting works by temporarily rejecting an email from an unknown combination of IP/sender/recipient. A compliant Mail Transfer Agent (MTA) will attempt to redeliver the email after a short period. If the sending server does not retry, the message will remain deferred and eventually time out.
Greylisting is a feature configured within a session profile. That profile must then be applied to a policy (either IP-based or recipient-based) that matches the incoming email session for the greylisting action to be triggered.
Once the initial greylist period has passed, FortiMail will recognize the retried attempt from the same IP/sender/recipient tuple and accept the connection, delivering the email. The tuple is then whitelisted for a configurable period.
- Question 4Beginner
Encryption · DomainKeys Identified Mail (DKIM)
An administrator wants to configure DomainKeys Identified Mail (DKIM) signing for an outbound domain, 'corp-internal.com'. Where must the administrator store the public key so that receiving mail servers can verify the DKIM signature applied by the FortiMail appliance?
graph TD subgraph FortiMail A[Private Key] --> B(Email Signing) end B --> C{Receiving MTA} subgraph PublicDNS D[Public Key in TXT Record] --> E(Verification) end C --> EShow answer & explanation
Correct answer: B
The DKIM standard specifies that the public key must be published in the public DNS system as a TXT record. The record is located at a specific subdomain indicated by the selector in the DKIM signature header. Receiving servers query this DNS record to retrieve the public key and verify the signature's authenticity.
- Question 5Beginner
Initial Deployment and Basic Configuration · Administrator Accounts and Access Profiles
A manufacturing company is setting up a new FortiMail appliance. The IT director has mandated that two separate teams, 'Network Ops' and 'Security Ops', should have administrative access, but with different permissions. The Network Ops team should only be able to manage system settings, network configurations, and HA. The Security Ops team should only manage policies and security profiles. Which FortiMail feature should be used to enforce this separation of duties?
Show answer & explanation
Correct answer: B
Administrator access profiles are used to create custom, role-based access control (RBAC) policies. An administrator can create a profile for each team, granting read/write or read-only access to specific areas of the GUI and CLI. These profiles are then assigned to the respective administrator accounts.
- Question 6AdvancedSelect 2
Email Security · Antispam and Impersonation Protection
During a security audit, a FortiMail administrator is asked to demonstrate how the company prevents spear-phishing attacks that use forged sender display names to impersonate executives. Which two FortiMail features are most effective for this purpose? (Choose two.)
Show answer & explanation
Correct answers: B, D
The Impersonation Analysis feature within an antispam profile is specifically designed to detect these attacks. It can be configured with a list of key individuals (e.g., executives) and will flag emails from external sources that use their display names.
While Impersonation Analysis is the primary tool, a content profile using a dictionary of executive names can serve as a supplementary control. The rule could be configured to trigger an action (like adding a warning header) if an executive's name appears in the 'From' header of an email originating from an external IP address. This provides a customizable layer of defense.
- Question 7Intermediate
Email Flow and Authentication · Policy Configuration in Transparent Mode
A company has deployed FortiMail in transparent mode. An administrator needs to configure a policy that applies a specific antivirus profile only to emails sent from the internal marketing team ([email protected]) to external recipients. How can this be achieved?
Show answer & explanation
Correct answer: C
Recipient policies can be configured as inbound or outbound. To target this specific flow, an outbound recipient policy is required. The policy would be configured with a sender pattern matching '[email protected]' and a recipient pattern matching '*' (wildcard for any external domain), and the desired antivirus profile would be attached to it.
- Question 8Beginner
Initial Deployment and Basic Configuration · High Availability (HA) Modes
An administrator is configuring a new FortiMail 1000F appliance and needs to set up a high availability (HA) cluster with a second, identical unit. The primary goal is redundancy, with a secondary goal of load balancing traffic if possible. Which HA mode should be selected to meet these requirements?
Show answer & explanation
Correct answer: C
Active-Active HA mode meets both requirements. It provides redundancy by allowing a secondary unit to take over if the primary fails. It also provides load balancing by distributing the processing of email traffic across all active members of the cluster, increasing overall throughput.
- Question 9Beginner
Encryption · IBE Delivery Methods
True or False: In FortiMail's IBE pull mode, the encrypted email content is delivered to the recipient as an HTML attachment within a notification email.
Show answer & explanation
Correct answer: B
This statement describes IBE push mode. In IBE pull mode, the recipient receives a notification email containing a URL. The recipient clicks the URL, authenticates to the FortiMail secure message portal, and views the decrypted email content within the web interface. The email content itself is not attached to the notification email.
Ready for the real thing?
The full FCP-FML-AD-7-4 simulator has every exam-style question, timed mode, and instant scoring.