2026 Realistic Verified FCP_FML_AD-7.4 exam dumps Q&As - FCP_FML_AD-7.4 Free Update
Use Real FCP_FML_AD-7.4 Dumps - 100% Free FCP_FML_AD-7.4 Exam Dumps
NEW QUESTION # 17
Which two features are available when you enable HA centralized monitoring on FortiMail?
(Choose two.)
- A. Firmware update of all cluster members from the primary device
- B. Policy configuration changes of all cluster members from the primary device.
- C. Cross-device log searches across all cluster members from the primary device.
- D. Mail statistics of all cluster members on the primary device.
Answer: C,D
NEW QUESTION # 18
Refer to the exhibits, which display a topology diagram (Topology) and two FortiMail device configurations (FML1 ConfigurationandFML2 Configuration).


What is the expected outcome of SMTP sessions sourced from FML1 and destined for FML2?
- A. FML1 will send the STARTTLS command in the SMTP session, which will be rejected by FML2.
- B. FML1 will attempt to establish an SMTPS session with FML2. but fail and revert to standard SMTP.
- C. FML1 will fail to establish any connection with FML2.
- D. FML1 will successfully establish an SMTPS session with FML2.
Answer: D
NEW QUESTION # 19
Refer to the exhibit, which shows the Authentication Reputation list on a FortiMail device running in gateway mode.
Why was the IP address blocked?
- A. The IP address had consecutive SMTPS login failures to FortiMail.
- B. The IP address had consecutive administrative password failures to FortiMail.
- C. The IP address had consecutive SSH login failures to FortiMail.
- D. The IP address had consecutive IMAP login failures to FortiMail.
Answer: A
Explanation:
Because the device's Authentication Reputation list shows a "Mail" violation and is blocking mail access (along with CLI and Web), it indicates repeated failures of the mail-protocol login. In gateway mode FortiMail only tracks SMTP (SMTPS) authentication failures under the "Mail" category, not IMAP, so consecutive SMTPS login failures triggered the block.
NEW QUESTION # 20 

Refer to the exhibits, which show a topology diagram (Topology) and a configurationelement (Access Control Rule.) An administrator wants to configure an access receive rule to matchauthentication status on FML-1 for all outbound email from the example. co- domain.
Which two access receive rule settings must the administrator configure? (Choose two.)
- A. The Authentication status must be set to Authenticated
- B. A TLS profile must be configured and applied.
- C. The Sender IP/netmask must be set to 10.29.1.0/24.
- D. The Recipient pattern must be set to *@example. com.
Answer: A,D
NEW QUESTION # 21
Refer to the exhibit, which displays an access control rule.
What are two expected behaviors for this access control rule? (Choose two.)
- A. Senders must be authenticated to match this rule.
- B. Email must originate from an example. com email address.
- C. Email matching this rule will be relayed.
- D. Emails must be sent from the 10.0.1.0/24 subnet.
Answer: A,B
NEW QUESTION # 22
Which two features are available when you enable HA centralized monitoring on FortiMail? (Choose two.)
- A. Firmware update of all cluster members from the primary device
- B. Policy configuration changes of all cluster members from the primary device.
- C. Cross-device log searches across all cluster members from the primary device.
- D. Mail statistics of all cluster members on the primary device.
Answer: C,D
NEW QUESTION # 23
Refer to the exhibit which displays a topology diagram.
Which two statements describe the built-in bridge functionality on a transparent mode FortiMail? (Choose two.)
- A. If port1. is required to process SMTP traffic, it must be configured as a routed interface.
- B. The management IP is permanently tied to port1, and port1 cannot be removed from the bridge.
- C. All bridge member interfaces belong to the same subnet as the management IP.
- D. Any bridge member interface can be removed from the bridge and configured as a routed interface.
Answer: B,C
NEW QUESTION # 24
Which two types of remote authentication are supported for FortiMail administrator accounts?
(Choose two.)
- A. Single Sign-on
- B. RADIUS
- C. Kerberos
- D. TACACS
Answer: A,B
Explanation:
FortiMail supports RADIUS and SSO-based authentication for administrator access.
NEW QUESTION # 25
What are two benefits of enabling the header manipulation feature? (Choose two.)
- A. It detects common spamming techniques
- B. It hides internal network information
- C. It reduces overall message size by removing header content
- D. It detects spoofed SMTP header addresses
Answer: B,C
Explanation:
Header manipulation can remove or rewrite sensitive headers, hiding internal infrastructure details and reducing message size.
NEW QUESTION # 26
In which two ways does a transparent mode FortiMail use the build-it MTA to process email?
(Choose two.)
- A. It ignores the destination set by the sender and uses its own MX record lookup.
- B. MUAs must be configured to connect to the built-in MTAto send email.
- C. It can queue undeliverable messages and generate DSNs.
- D. The built-in MTA must connect to an external relay host to deliver email.
Answer: A,C
Explanation:
It ignores the destination set by the sender and uses its own MX record lookup.
In transparent mode FortiMail intercepts mail and then its built-in MTA performs an MX lookup on the recipient domain rather than trusting the original destination hop.
It can queue undeliverable messages and generate DSNs.
The built-in MTA maintains delivery queues and produces Delivery Status Notifications when downstream delivery fails.
NEW QUESTION # 27
An organization has different groups of users with different needs in email functionality, such as address book access, mobile device access, email retention periods, and disk quotas.
Which FortiMail feature specific to server mode can be used to accomplish this?
- A. Resource profiles
- B. Email group profiles
- C. Access profiles
- D. Domain-level service settings
Answer: A
Explanation:
In FortiMail's server mode, Resource Profiles let you group mailboxes by things like disk-quota limits and message-retention periods, while corresponding Access Profiles control services such as address-book and mobile (ActiveSync) access. By defining different resource profiles for each user class, you can give each group its own quota and retention settings (and pair them with matching access profiles for service access).
NEW QUESTION # 28
Refer to the exhibits. The exhibits display a topology diagram of a FortiMail cluster (Topology) and the primary HA interface configuration of the Primary FortiMail (HA Interface Configuration).
Which three actions are recommended when configuring the primary FortiMail HA interface?
(Choose three.)

- A. In the Virtual IP action drop-down list, select Use.
- B. In the Virtual IP address field, type 172.16.32.55/24
- C. In the Heartbeat status drop-down list, select Primary
- D. Disable Enable port monitor
- E. In the Peer IP address field, type 172.16.32.57
Answer: A,B,E
Explanation:
Here are the three settings you should change on the Primary's HA port1 interface:
- Set Virtual IP action to Use
- Enter 172.16.32.55/24 as the Virtual IP address
- Enter 172.16.32.57 as the Peer IP address
With those in place, the Primary will advertise and answer on the cluster VIP (172.16.32.55) and know how to reach its Secondary peer (172.16.32.57).
NEW QUESTION # 29
Refer to the exhibit, which displays an encryption profile configuration.
What happens if the attachment size of an IBE email exceeds 1024 KB?
- A. AES 256 will be used.
- B. Pull delivery will be used.
- C. OTLS will be used.
- D. The email message will not be delivered.
Answer: B
NEW QUESTION # 30
Which three actions does FortiSandbox perform when it is integrated with FortiMail for advanced threat protection (ATP)? (Choose three.)
- A. It analyzes file and URI objects
- B. It submits objects for sandbox scanning
- C. It queues email during analysis
- D. It updates FortiGuard databases
- E. It assigns and returns a rating for analyzed objects
Answer: A,D,E
Explanation:
FortiSandbox analyzes files and URLs, rates them, and shares intelligence through FortiGuard.
Email queuing and submission are handled by FortiMail.
NEW QUESTION # 31
Refer to the exhibit, which shows an inbound recipient policy.
After creating the policy, an administrator discovers that clients can send Inbound Recipient Policy unauthenticated emails using SMTP.
What must the administrator do to enforce authentication?
- A. Configure an outbound recipient policy for LDAP authentication.
- B. Configure a matching IP policy with the exclusive flag enabled.
- C. Configure an access delivery rule to enforce authentication.
- D. Configure an access receive rule to verify authentication status.
Answer: D
Explanation:
You need to create an Access Receive Rule that matches your incoming mail and sets Authentication status to "Authenticated." That rule will block any SMTP session that isn't authenticated before it ever reaches the recipient policy.
NEW QUESTION # 32
Which FortiMail feature combats spammers who try to hide spam content in delivery status notifications (DSN) messages?
- A. Header analysis
- B. Behavior analysis
- C. Bounce address tag validation (BATV)
- D. Heuristic
Answer: C
Explanation:
BATV verifies the validity of bounce messages and prevents attackers from embedding spam content inside fake DSN messages.
NEW QUESTION # 33
Refer to the exhibit, which shows the output of an email transmission using a telnet session.
What are two correct observations about this SMTP session? (Choose two.)
- A. The SMTP envelope addresses are different from the message header addresses.
- B. The "250Message accepted for delivery" message is part ofthe message body.
- C. The "Subject" is part of the message header.
- D. The"220 mx. internal, lab ESMTPSmtpd" message is part of the SMTP banner.
Answer: C,D
NEW QUESTION # 34
While testing outbound MTA functionality, an administrator discovers that all outbound email is being processed using policy ID l: 2:0: SYSTEM. What are two possible reasons why the third policy ID value is o?
(Choose two.)
- A. IP policy ID 2 has the exclusive flag set.
- B. Outbound email is being rejected.
- C. There are no outgoing recipient policies configured.
- D. There are no access delivery rules configured for outbound email.
Answer: A,C
NEW QUESTION # 35
Reter to the exhibits.
The exhibits display a topologydiagram of a FortiMail cluster (Topology) and the primary HA interface configuration of the Primary FortiMail (HA Interface Configuration) Which three actions are recommended when configuring the primary FortiMail HA interface? (Choose three.)
- A. In the Virtual IP address field, type 172.16.32.55/24
- B. In the Heartbeat status drop-down list, select Primary
- C. Disable Enable port monitor
- D. In the Virtual IP action drop-down list, select Use
- E. In the Peer IP address field, type 172.16.32.57
Answer: A,D,E
NEW QUESTION # 36
......
Pass FCP_FML_AD-7.4 exam Updated 65 Questions: https://actualanswers.pass4surequiz.com/FCP_FML_AD-7.4-exam-quiz.html