Skip to content

FCP-FML-AD-7-4 FCP - FortiMail 7.4 Administrator Practice Questions

Prepare for FCP-FML-AD-7-4 with more than an answer.

214 questions in the full set19 sample questionsUpdated Jan 25, 2026
Level
Professional
Valid for
As per Fortinet NSE certification program policies
Domains covered on the exam 5
  1. Initial Deployment and Basic Configuration20%
  2. Email Flow and Authentication20%
  3. Email Security30%
  4. Encryption15%
  5. Server Mode and Transparent Mode15%
  1. 1

    A new administrator is reviewing the policy list on a FortiMail appliance. They see two policies that could potentially match an incoming email:

    1. An IP Policy (ID 5) with Source IP 0.0.0.0/0
    2. A Recipient Policy (ID 2) for the recipient's domain

    The IP Policy has the 'Take precedence over recipient based policy match' option enabled. Which policy will FortiMail apply to the incoming email?

    Show answer details

    Correct answer: B

    By default, FortiMail prefers the more specific recipient-based policy. However, the 'Take precedence over recipient based policy match' option in an IP policy explicitly forces the IP policy to be applied, even if a matching recipient policy exists. Therefore, IP Policy ID 5 will be used.

  2. 2

    A FortiMail administrator is troubleshooting an issue where legitimate emails from a partner are being incorrectly classified as spam. The administrator wants to analyze the antispam logs to see exactly which antispam check is causing the high spam score. What is the best way to view this detailed information?

    Show answer details

    Correct answer: D

    The History log (found under Monitor > Log) provides a detailed record of every processed email. By finding the specific email and viewing its details, an administrator can see a full breakdown of the antispam scan, including which checks were positive (e.g., FortiGuard, SURBL, heuristics) and the score contributed by each, allowing for precise troubleshooting.

  3. 3

    What is the primary purpose of the Sender Rewriting Scheme (SRS) feature on a FortiMail appliance?

    Show answer details

    Correct answer: B

    When an email is forwarded, the new sending server's IP address will not be in the original sender's SPF record, causing SPF checks to fail. SRS addresses this by rewriting the 'MAIL FROM' (envelope sender) address to be from the forwarding domain (e.g., the FortiMail's domain). This makes the forwarded email pass SPF checks, while embedding the original sender's address in a way that allows bounce messages to be returned correctly.

  4. 4

    Case Study

    A mid-sized logistics company, 'GlobalShip', is migrating its email infrastructure. They currently use an on-premise mail server that is outdated and difficult to manage. They have purchased a FortiMail-VM to act as their new secure email gateway and eventual mail server. The migration will happen in two phases.

    Phase 1 Requirements:
    GlobalShip wants to deploy the FortiMail-VM immediately to provide advanced threat protection and spam filtering for their existing mail server. During this phase, they cannot make any changes to their existing mail server's IP address, client configurations, or their public MX records due to a temporary network freeze. The FortiMail appliance must be hidden from both the internal mail server and external senders.

    Phase 2 Requirements:
    After the network freeze is lifted in six months, GlobalShip plans to decommission the old on-premise server. The FortiMail-VM will then become the primary mail server, hosting all user mailboxes and providing webmail access. The solution must support this future transition seamlessly.

    Which FortiMail configuration best satisfies the requirements for both phases?

    Show answer details

    Correct answer: B

    This is the optimal solution. Transparent mode is designed for the exact scenario in Phase 1: it can be inserted into the network to inspect traffic without requiring any changes to DNS (MX records) or mail server configurations. For Phase 2, the operation mode of the FortiMail can be switched to Server Mode. This allows it to take over as the primary mail server, fulfilling all the requirements for the final state of the migration.

  5. 5

    A FortiMail appliance is configured with an authentication reputation profile that is set to block an IP address for 60 minutes after 5 failed login attempts. An administrator observes that a user's home IP address has been blocked. The logs show the user made 6 failed login attempts to the webmail interface. Which action should the administrator take to grant the user immediate access without disabling the security feature?

    Show answer details

    Correct answer: C

    The Authentication Reputation monitor (under Monitor > Reputation) displays a list of currently blocked IP addresses. An administrator can select a specific entry and manually delete it to remove the block immediately. This resolves the user's issue without making permanent changes to the security policy.

  6. 6

    A financial services firm has deployed a FortiMail 2000E cluster in gateway mode. During a routine audit, it was discovered that outbound emails containing customer account numbers are not being properly encrypted using the configured Identity-Based Encryption (IBE) policy. The policy is designed to trigger encryption for any email sent to external domains. A junior administrator confirms the IBE service is running and users are registered. Which of the following is the most likely cause for the IBE policy failure for outbound mail?

    Show answer details

    Correct answer: A

    FortiMail applies IBE encryption through policies. For outbound mail, an outbound recipient policy must be matched, and that policy must have a content profile that specifies the IBE encryption action. If the content profile with the IBE action is not linked to the outbound policy, encryption will not be triggered, even if the IBE service is active.

  7. 7

    A healthcare organization is deploying FortiMail in transparent mode to inspect all inbound and outbound email for their on-premise Microsoft Exchange server. The security architect wants to ensure that if the FortiMail appliance fails or is taken offline for maintenance, email flow is not interrupted. Which two actions should the administrator take to achieve this? (Choose two.)

    Show answer details

    Correct answer: A, D

    Deploying an active-passive HA cluster is the primary method for providing redundancy. If the active unit fails, the passive unit takes over all processing, ensuring continuous email inspection and delivery.

    Fail-to-wire (also known as fail-open or bypass mode) is a hardware feature on certain FortiMail models. If the appliance loses power or fails critically, the ports create a direct physical connection, allowing traffic to pass through uninspected but without interrupting the mail flow. This is a crucial last-resort mechanism for maintaining connectivity.

  8. 8

    True or False: When FortiMail is configured in gateway mode, it is mandatory to change the public MX records of the protected domain to point to the FortiMail's public IP address.

    Show answer details

    Correct answer: A

    In gateway mode, the FortiMail unit acts as an inbound and outbound mail relay. To ensure that all incoming email for the protected domain is first processed by FortiMail, the public Mail Exchanger (MX) DNS records must be updated to point to the FortiMail appliance. This directs all external mail servers to deliver email to FortiMail instead of directly to the organization's mail server.

  9. 9

    An administrator is configuring Bounce Address Tag Validation (BATV) to combat spam in delivery status notifications (DSNs). After enabling BATV, the administrator notices that some legitimate bounce messages from a trusted partner domain are being dropped. What is the most effective way to resolve this issue while keeping BATV active for all other traffic?

    Show answer details

    Correct answer: C

    FortiMail provides a specific exemption list for bounce address tag validation. By adding the trusted partner's domain to this list, their DSNs will be accepted without a valid BATV tag, resolving the issue without disabling the feature globally or creating overly permissive IP whitelists.

Create an account to continue.