Get Fortinet NSE6_FML-6.4 Dumps Questions Study Exam Guide May 23, 2023 [Q20-Q40]

Share

Get Fortinet NSE6_FML-6.4 Dumps Questions Study Exam Guide May 23, 2023

NSE6_FML-6.4 Premium Exam Engine - Download Free PDF Questions

NEW QUESTION # 20
FortiMail is configured with the protected domain example.com.
Which two envelope addresses will require an access receive rule, to relay for unauthenticated senders? (Choose two.)

Answer: A,D


NEW QUESTION # 21
Refer to the exhibit.

Which configuration change must you make to block an offending IP address temporarily?

  • A. Add the offending IP address to the user block list
  • B. Change the authentication reputation setting status to Enable
  • C. Add the offending IP address to the system block list
  • D. Add the offending IP address to the domain block list

Answer: B


NEW QUESTION # 22
Refer to the exhibit.

Which two message types will trigger this DLP scan rule? (Choose two.)

  • A. An email sent from [email protected] will trigger this scan rule, even without matching any conditions
  • B. An email message with a subject that contains the term "credit card" will trigger this scan rule
  • C. An email message that contains credit card numbers in the body will trigger this scan rule
  • D. An email that contains credit card numbers in the body, attachment, and subject will trigger this scan rule

Answer: C,D


NEW QUESTION # 23
What three configuration steps are required to enable DKIM signing for outbound messages on FortiMail? (Choose three.)

  • A. Publish the public key as a TXT record in a public DNS server
  • B. Generate a public/private key pair in the protected domain configuration
  • C. Enable DKIM check in a matching antispam profile
  • D. Enable DKIM check in a matching session profile
  • E. Enable DKIM signing for outgoing messages in a matching session profile

Answer: A,B,D


NEW QUESTION # 24
Examine the FortiMail DLP scan rule shown in the exhibit; then answer the question below.

Which of the following statements is true regarding this configuration? (Choose two.)

  • A. If an email is sent from [email protected] the action will be applied without matching any conditions
  • B. An email must contain credit card numbers in the body, attachment, and subject to trigger this scan rule
  • C. An email message containing the words "Credit Card" in the subject will trigger this scan rule
  • D. An email message containing credit card numbers in the body will trigger this scan rule

Answer: C,D


NEW QUESTION # 25
Examine the configured routes shown in the exhibit; then answer the question below.

Which interface will FortiMail use to forward an email message destined for 10.1.100.252?

  • A. port3
  • B. port2
  • C. port4
  • D. port1

Answer: B


NEW QUESTION # 26
Which statement about how impersonation analysis identifies spoofed email addresses is correct?

  • A. It uses SPF validation to detect spoofed addresses.
  • B. It maps the display name to the correct recipient email address.
  • C. It uses DMARC validation to detect spoofed addresses.
  • D. It uses behavior analysis to detect spoofed addresses.

Answer: D


NEW QUESTION # 27
Which of the following antispam techniques queries FortiGuard for rating information? (Choose two.)

  • A. SURBL
  • B. URI filter
  • C. IP reputation
  • D. DNSBL

Answer: B,C


NEW QUESTION # 28
Examine the FortiMail recipient-based policy shown in the exhibit; then answer the question below.

After creating the policy, an administrator discovered that clients are able to send unauthenticated email using SMTP. What must be done to ensure clients cannot send unauthenticated email?

  • A. Configure an access delivery rule to enforce authentication
  • B. Configure an access receive rule to verify authentication status
  • C. Configure a matching IP policy with SMTP authentication and exclusive flag enabled
  • D. Move the recipient policy to the top of the list

Answer: A


NEW QUESTION # 29
Refer to the exhibit.

An administrator has enabled the sender reputation feature in the Example_Session profile on FML-1. After a few hours, the deferred queue on the mail server starts filling up with undeliverable email. What two changes must the administrator make to fix this issue? (Choose two.)

  • A. Disable the exclusive flag in IP policy ID 1
  • B. Create an outbound recipient policy to bypass outbound email from session profile inspections
  • C. Apply a session profile with sender reputation disabled on a separate IP policy for outbound sessions
  • D. Clear the sender reputation database using the CLI

Answer: A,C


NEW QUESTION # 30
Refer to the exhibit.



Which of the following statements are true regarding the transparent mode FortiMail's email routing for the example.com domain? (Choose two.)

  • A. FML-1 will use the transparent proxy for incoming sessions
  • B. If incoming email are undeliverable, FML-1 can queue them to retry again later
  • C. If outgoing email messages are undeliverable, FML-1 can queue them to retry later
  • D. FML-1 will use the built-in MTA for outgoing sessions

Answer: A,B


NEW QUESTION # 31
What are the configuration steps to enable DKIM signing for outbound messages on FortiMail? (Choose three.)

  • A. Enable DKIM check in a matching session profile
  • B. Publish the public key as a TXT record in a public DNS server
  • C. Generate a public/private key pair in the protected domain configuration
  • D. Enable DKIM signing for outgoing messages in a matching session profile
  • E. Enable DKIM check in a matching antispam profile

Answer: B,C,D

Explanation:
DKIM Signing for Outbound Email
* To configure DKIM signing for outgoing messages, you must first generate a public and private key pair for the domain
* DKIM signatures are domain specific
* FortiMail generates and stores the private key, and uses it to generate the DKIM signature
- Download the public key and publish to your external DNS server
- Enable sign outgoing messages with a DKIM signature


NEW QUESTION # 32
Refer to the exhibit.

The exhibit shows a FortiMail active-passive setup.
Which three actions are recommended when configuring the primary FortiMail HA interface? (Choose three.)

  • A. In the Virtual IP action drop-down list, select Use
  • B. In the Heartbeat status drop-down list, select Primary
  • C. In the Virtual IP address field, type 172.16.32.55/24
  • D. Disable Enable port monitor
  • E. In the Peer IP address field, type 172.16.32.57

Answer: A,B,D


NEW QUESTION # 33
Examine the message column of a log cross search result of an inbound email shown in the exhibit; then answer the question below

Based on logs, which of the following statements are true? (Choose two.)

  • A. The FortiMail is experiencing issues delivering the email to the back-end mail server
  • B. The FortiMail is experiencing issues accepting the connection from the remote sender
  • C. The logs were generated by a gateway or transparent mode FortiMail
  • D. The logs were generated by a server mode FortiMail

Answer: A,C


NEW QUESTION # 34
Examine the FortiMail session profile and protected domain configuration shown in the exhibit; then answer the question below.


Which size limit will FortiMail apply to outbound email?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: C

Explanation:
domain only applies to inbound. https://kb.fortinet.com/kb/viewContent.do?externalId=FD31006&sliceId=1


NEW QUESTION # 35
Examine the FortiMail antivirus action profile shown in the exhibit; then answer the question below.

What is the expected outcome if FortiMail applies this action profile to an email? (Choose two.)

  • A. The administrator will be notified of the virus detection
  • B. A replacement message will be added to the email
  • C. The sanitized email will be sent to the recipient's personal quarantine
  • D. Virus content will be removed from the email

Answer: B,D


NEW QUESTION # 36
Which firmware upgrade method for an active-passive HA cluster ensures service outage is minimal, and there are no unnecessary failovers?

  • A. Upgrade the active unit, which will upgrade the standby unit automatically
  • B. Upgrade the standby unit, and then upgrade the active unit
  • C. Upgrade both units at the same time
  • D. Break the cluster, upgrade the units independently, and then form the cluster

Answer: C


NEW QUESTION # 37
Which three statements about SMTPS and SMTP over TLS are true? (Choose three.)

  • A. SMTPS encrypts only the body of the email message
  • B. The STARTTLS command is used to initiate SMTP over TLS
  • C. SMTP over TLS connections are entirely encrypted and initiated on port 465
  • D. SMTPS encrypts the identities of both the sender and receiver
  • E. SMTPS connections are initiated on port 465

Answer: B,D,E


NEW QUESTION # 38
Examine the access receive rule shown in the exhibit; then answer the question below.

Which of the following statements are true? (Choose two.)

  • A. Email must originate from an example.com email address to match this rule
  • B. Email from any host in the 10.0.1.0/24 subnet can match this rule
  • C. Email matching this rule will be relayed
  • D. Senders must be authenticated to match this rule

Answer: A,C


NEW QUESTION # 39
Refer to the exhibit.

Which message size limit will FortiMail apply to the outbound email?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: D


NEW QUESTION # 40
......


In order to pass the Fortinet NSE6_FML-6.4 exam, candidates must have a solid understanding of email security concepts and FortiMail features. Candidates must also be familiar with network security concepts and have experience with FortiMail deployment, administration, and troubleshooting. Upon passing the exam, candidates will be awarded the Fortinet NSE 6 - FortiMail 6.4 certification, which demonstrates their expertise in FortiMail and their ability to protect their organization from email-borne threats.

 

Free NSE6_FML-6.4 Exam Braindumps Fortinet  Pratice Exam: https://vcetorrent.examtorrent.com/NSE6_FML-6.4-prep4sure-dumps.html