100% PASS RATE FCP in Public Cloud Security FCP_FML_AD-7.4 Certified Exam DUMP with 65 Questions [Q24-Q39]

Share

100% PASS RATE FCP in Public Cloud Security FCP_FML_AD-7.4 Certified Exam DUMP with 65 Questions

Updates For the Latest FCP_FML_AD-7.4 Free Exam Study Guide!


Fortinet FCP_FML_AD-7.4 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Initial Deployment and Basic Configuration: This section of the exam measures skills of a Network Security Administrator and covers the foundational setup of FortiMail. It includes understanding SMTP and email flow, performing initial configurations such as selecting operation mode, system settings, and defining protected domains. It also involves deploying FortiMail in high-availability clusters to ensure service continuity.
Topic 2
  • Email Security: This section of the exam measures skills of a Network Security Administrator and deals with implementing security controls to filter and manage email threats. Candidates must configure session-based filtering, spam detection methods, malware protection, APT mitigation, and content filtering. The section also includes email archiving configurations for compliance and storage.
Topic 3
  • Server Mode and Transparent Mode: This section of the exam measures skills of a Network Security Administrator and explains how to deploy and manage FortiMail in different operation modes. It includes configuring server mode to handle mail directly and deploying FortiMail in transparent mode where it acts as a gateway to filter email traffic without altering the existing mail infrastructure.
Topic 4
  • Email Flow and Authentication: This section of the exam measures skills of a Messaging Security Engineer and focuses on configuring FortiMail to handle email flow securely. It includes enabling and matching authentication protocols, setting up secure MTA features, and implementing access control, IP policies, and recipient-based policies to control mail delivery and security.
Topic 5
  • Encryption: This section of the exam measures skills of a Messaging Security Engineer and addresses the implementation of encryption methods in FortiMail. It covers traditional SMTP encryption and identity-based encryption (IBE). Candidates are expected to configure these technologies and manage IBE users for secure email communication.

 

NEW QUESTION # 24
Which two factorsare required for an active-active HA configuration of FortiMail in server mode? (Choose two.)

  • A. A primary must be designated to initially process email.
  • B. Service monitoring must be configured for remote SMTP
  • C. Mail data must be stored on a NAS server.
  • D. Devices must be deployed behind a load balancer.

Answer: C,D


NEW QUESTION # 25
When configuring a FortiMail HA group consisting of different models, which two statements are true?
(Choose two.)

  • A. The most powerful model must be configured as the primary unit.
  • B. Configurations will not synchronize between different model types.
  • C. Group capacity is limited to the least powerful model.
  • D. All units must have the same firmware.

Answer: C,D


NEW QUESTION # 26
In which two ways does a transparent mode FortiMail use the build-it MTA to process email?
(Choose two.)

  • A. MUAs must be configured to connect to the built-in MTAto send email.
  • B. It ignores the destination set by the sender and uses its own MX record lookup.
  • C. The built-in MTA must connect to an external relay host to deliver email.
  • D. It can queue undeliverable messages and generate DSNs.

Answer: B,D

Explanation:
It ignores the destination set by the sender and uses its own MX record lookup.
In transparent mode FortiMail intercepts mail and then its built-in MTA performs an MX lookup on the recipient domain rather than trusting the original destination hop.
It can queue undeliverable messages and generate DSNs.
The built-in MTA maintains delivery queues and produces Delivery Status Notifications when downstream delivery fails.


NEW QUESTION # 27
Refer to the exhibits, which shows a DLP scan profile configuration (DLP Scan Rule 1 and DLP Scan Rule 2) from a FortiMail device.


Which two message types will trigger this DLP scan rule? (Choose two.)

  • A. An email sent from [email protected] trigger this scan rule, even without matching any conditions.
  • B. An email message with a subject that contains the term "credit card" will trigger this scan rule.
  • C. An email that contains credit card numbers in the body, attachment, and subject will trigger this scan rule.
  • D. An email message that contains credit card numbers in the body will trigger this scan rule.

Answer: B,D

Explanation:
Any message whose subject line contains the phrase "credit card" meets one of the "Match any condition" criteria, so it triggers the rule.
Any message whose body contains a detected credit-card number likewise meets a condition and triggers the rule.


NEW QUESTION # 28
Which SMTP command lists the supported SMTP service extensions of the recipient MTA?

  • A. DATA
  • B. EHLO
  • C. HELO
  • D. VRFY

Answer: B

Explanation:
The EHLO command (Extended HELO) prompts the recipient MTA to respond with a list of all supported SMTP service extensions, enabling the sender to use features like SMTP authentication, pipelining, and STARTTLS.


NEW QUESTION # 29
Refer to the exhibits. The exhibits display a topology diagram of a FortiMail cluster (Topology) and the primary HA interface configuration of the Primary FortiMail (HA Interface Configuration).
Which three actions are recommended when configuring the primary FortiMail HA interface?
(Choose three.)

  • A. In the Peer IP address field, type 172.16.32.57
  • B. In the Heartbeat status drop-down list, select Primary
  • C. Disable Enable port monitor
  • D. In the Virtual IP address field, type 172.16.32.55/24
  • E. In the Virtual IP action drop-down list, select Use.

Answer: A,D,E

Explanation:
Here are the three settings you should change on the Primary's HA port1 interface:
- Set Virtual IP action to Use
- Enter 172.16.32.55/24 as the Virtual IP address
- Enter 172.16.32.57 as the Peer IP address
With those in place, the Primary will advertise and answer on the cluster VIP (172.16.32.55) and know how to reach its Secondary peer (172.16.32.57).


NEW QUESTION # 30
Which license must you apply to a FortiMail device to enable the HA centralized monitoring features?

  • A. Advanced Management and MSSP license
  • B. Office 365 protection license
  • C. Cloud gateway license
  • D. Enterprise license

Answer: A

Explanation:
The HA Centralized Monitor feature is only available when the Advanced Management & MSSP license is applied to the FortiMail unit.


NEW QUESTION # 31
In which two places can the maximum email size be overridden on FortiMail? (Choose two.)

  • A. Protected Domain configuration
  • B. Session Profile configuration
  • C. Resource Profile configuration
  • D. IP Policy configuration

Answer: A,C


NEW QUESTION # 32
Refer to the exhibit, which shows a few lines of FortiMail logs.

Based on these log entries, which two statements describe the operational status of this FortiMail device?
(Choose two.)

  • A. The FortiMail device is in gateway or transparent mode.
  • B. FortiMail is experiencing issues delivering the email to the internal. lab MTA.
  • C. FortiMail is experiencing issues accepting the connection from the external. lab MTA.
  • D. The FortiMail device is in server mode.

Answer: A,B


NEW QUESTION # 33
Refer to the exhibit, which shows the IBE Encryption page of a FortiMail device.

Which user account behavior can you expect from these IBE settings?

  • A. After initial registration, IBE users can access the secure portal without authenticating again for
    90 days.
  • B. IBE user accounts will expire after 90 days of inactivity and must register again to access new IBE email message.
  • C. First time IBE users must register to access their email within 90 days of receiving the notification email message.
  • D. Registered IBE users have 90 days from the time they receive a notification email message to access their IBE email.

Answer: B

Explanation:
With "Activation is required for account registration" enabled and an Account inactivity expiry time of 90 days, any IBE account that isn't used (i.e. that goes 90 days without a secure-portal login) will expire, requiring the user to re-register before they can access any new encrypted messages.


NEW QUESTION # 34
Refer to the exhibit which shows a command prompt output of a telnet command.

Which configuration change must you make to prevent the banner from displaying the FortiMail serial number?

  • A. Change the host name
  • B. Configure a local domain name
  • C. Change the operation mode
  • D. Add a protected domain

Answer: A


NEW QUESTION # 35
Refer to the exhibit which shows annslookupoutput of MX records of theexample.comdomain.

Which two MTA selection behaviors for theexample.comdomain are correct? (Choose two.)

  • A. The external MTAs will send email to mx.example.com only if mx.hosted.com is unreachable.
  • B. The primary MTA for the example.com domain is mx.hosted.com.
  • C. The PriNS server should receive all email for the example.com domain.
  • D. mx.example.com will receive approximately twice the number of email as mx.hosted.com because of its preference value.

Answer: A,B


NEW QUESTION # 36
Refer to the exhibit, which shows a partial antispam profile configuration.

What will happen to an email that triggers Spam outbreak protection?

  • A. The email is logged.
  • B. The email is rejected.
  • C. The email is held in a deferred queue for a period of time.
  • D. The email is marked as clean and released to the recipient.

Answer: A


NEW QUESTION # 37
A FortiMail administrator is concerned about cyber criminals attempting to get sensitive information from employees using whaling phishing attacks. What option can the administrator configure to prevent these types of attacks?

  • A. Dictionary profile with predefined smart identifiers
  • B. Impersonation analysis
  • C. Content disarm and reconstruction
  • D. Bounce tag verification

Answer: B


NEW QUESTION # 38
While reviewing logs, an administrator discovers that an incoming email was processed using policy IDs0:4:9:
INTERNAL.
Which two statements describe what this policy ID means? (Choose two.)

  • A. The email was processed using IP-based policy ID 4.
  • B. FortiMail is applying the default behavior for relaying inbound email.
  • C. The FortiMail configuration is missing an access delivery rule.
  • D. Access control policy number 9 was used.

Answer: A,B


NEW QUESTION # 39
......

Best FCP_FML_AD-7.4 Exam Preparation Material with New Dumps Questions https://www.pass4leader.com/Fortinet/FCP_FML_AD-7.4-exam.html

Fast Exam Updates FCP_FML_AD-7.4 dumps with PDF Test Engine Practice https://drive.google.com/open?id=1Fk7H-Vi1tHcGB0UHX0WXWt0CMjDU8DZ6