Pass Fortinet NSE6_FML-6.4 Exam With Practice Test Questions Dumps Bundle
2023 Valid NSE6_FML-6.4 test answers & Fortinet Exam PDF
Fortinet NSE6_FML-6.4 Exam, also known as the Fortinet NSE 6 - FortiMail 6.4 Exam, is a certification exam designed for network security professionals who want to validate their expertise in FortiMail 6.4. FortiMail is a popular email security platform that is used by many organizations to protect their email systems from cyber threats. Passing the NSE6_FML-6.4 Exam demonstrates that a candidate has the knowledge and skills needed to configure, manage, and troubleshoot FortiMail 6.4.
Fortinet NSE6_FML-6.4 Exam is an advanced level certification exam that requires candidates to have a good understanding of email security concepts, protocols, and technologies. NSE6_FML-6.4 exam covers a wide range of topics, including but not limited to, email filtering, anti-spam, anti-virus, DLP, email encryption, and authentication.
NEW QUESTION # 33
Refer to the exhibit.
Which two statements about the access receive rule are true? (Choose two.)
- A. Email must originate from an example.com email address to match this rule
- B. Email matching this rule will be relayed
- C. Senders must be authenticated to match this rule
- D. Email from any host in the 10.0.1.0/24 subnet can match this rule
Answer: A,B
NEW QUESTION # 34
Examine the configured routes shown in the exhibit; then answer the question below.
Which interface will FortiMail use to forward an email message destined for 10.1.100.252?
- A. port2
- B. port3
- C. port1
- D. port4
Answer: A
NEW QUESTION # 35
Which of the following antispam techniques queries FortiGuard for rating information? (Choose two.)
- A. URI filter
- B. SURBL
- C. IP reputation
- D. DNSBL
Answer: A,C
NEW QUESTION # 36
FortiMail is configured with the protected domain example.com.
Which two envelope addresses will require an access receive rule, to relay for unauthenticated senders? (Choose two.)
- A. MAIL FROM: [email protected] RCPT TO: [email protected]
- B. MAIL FROM: [email protected] RCPT TO: [email protected]
- C. MAIL FROM: [email protected] RCPT TO: [email protected]
- D. MAIL FROM: [email protected] RCPT TO: [email protected]
Answer: B,D
NEW QUESTION # 37
What three configuration steps are required to enable DKIM signing for outbound messages on FortiMail? (Choose three.)
- A. Enable DKIM signing for outgoing messages in a matching session profile
- B. Publish the public key as a TXT record in a public DNS server
- C. Enable DKIM check in a matching antispam profile
- D. Enable DKIM check in a matching session profile
- E. Generate a public/private key pair in the protected domain configuration
Answer: B,D,E
NEW QUESTION # 38
A FortiMail is configured with the protected domain example.com.
On this FortiMail, which two envelope addresses are considered incoming? (Choose two.)
- A. MAIL FROM: [email protected] RCPT TO: [email protected]
- B. MAIL FROM: [email protected] RCPT TO: [email protected]
- C. MAIL FROM: [email protected] RCPT TO: [email protected]
- D. MAIL FROM: [email protected] RCPT TO: [email protected]
Answer: C,D
NEW QUESTION # 39
Examine the FortiMail DLP scan rule shown in the exhibit; then answer the question below.
Which of the following statements is true regarding this configuration? (Choose two.)
- A. An email message containing the words "Credit Card" in the subject will trigger this scan rule
- B. An email must contain credit card numbers in the body, attachment, and subject to trigger this scan rule
- C. An email message containing credit card numbers in the body will trigger this scan rule
- D. If an email is sent from [email protected] the action will be applied without matching any conditions
Answer: A,C
NEW QUESTION # 40
While testing outbound MTA functionality, an administrator discovers that all outbound email is being processed using policy IDs 1:2:0.
Which two reasons explain why the last policy ID value is 0? (Choose two.)
- A. IP policy ID 2 has the exclusive flag set
- B. Outbound email is being rejected
- C. There are no access delivery rules configured for outbound email
- D. There are no outgoing recipient policies configured
Answer: C,D
NEW QUESTION # 41
Refer to the exhibit.
An administrator has enabled the sender reputation feature in the Example_Session profile on FML-1. After a few hours, the deferred queue on the mail server starts filling up with undeliverable email. What two changes must the administrator make to fix this issue? (Choose two.)
- A. Clear the sender reputation database using the CLI
- B. Disable the exclusive flag in IP policy ID 1
- C. Apply a session profile with sender reputation disabled on a separate IP policy for outbound sessions
- D. Create an outbound recipient policy to bypass outbound email from session profile inspections
Answer: B,C
NEW QUESTION # 42
Examine the FortiMail user webmail interface shown in the exhibit; then answer the question below.
Which one of the following statements is true regarding this server mode FortiMail's configuration?
- A. The administrator has not made any changes to the default address book access privileges
- B. The protected domain-level service settings have been modified to allow access to the domain address book
- C. The administrator has configured an inbound recipient policy with a customized resource profile
- D. This user's account has a customized access profile applied that allows access to the personal address book
Answer: C
Explanation:
domain address book can be enabled under resource profile which is applied to inbound recipient policy
NEW QUESTION # 43
Refer to the exhibit.
Which two statements about the MTAs of the domain example.com are true? (Choose two.)
- A. The PriNS server should receive all email for the example.com domain
- B. The primary MTA for the example.com domain is mx.hosted.com
- C. The higher preference value is used to load balance more email to the mx.example.com MTA
- D. The external MTAs will send email to mx.example.com only if mx.hosted.com is unreachable
Answer: B,D
NEW QUESTION # 44
Refer to the exhibit.
For the transparent mode FortiMail shown in the exhibit, which two sessions are considered incoming sessions? (Choose two.)
- A. DESTINATION IP: 192.168.54.10 MAIL FROM: [email protected] RCPT TO: [email protected]
- B. DESTINATION IP: 172.16.32.56 MAIL FROM: [email protected] RCPT TO: [email protected]
- C. DESTINATION IP: 172.16.32.56 MAIL FROM: [email protected] RCPT TO: [email protected]
- D. DESTINATION IP: 10.25.32.15 MAIL FROM: [email protected] RCPT TO: [email protected]
Answer: B,D
NEW QUESTION # 45
Refer to the exhibit.
Which two statements about the mail server settings are true? (Choose two.)
- A. FortiMail will support the STARTTLS extension
- B. FortiMail will enforce SMTPS on all outbound sessions
- C. FortiMail will drop any inbound plaintext SMTP connection
- D. FortiMail will accept SMTPS connections
Answer: C,D
NEW QUESTION # 46
A FortiMail administrator is investigating a sudden increase in DSNs being delivered to the protected domain for undeliverable email messages. After searching the logs, the administrator identifies that the DSNs were not generated as a result of any outbound email sent from the protected domain.
Which FortiMail antispam technique can the administrator use to prevent this scenario?
- A. Spam outbreak protection
- B. Bounce address tag validation
- C. FortiGuard IP Reputation
- D. Spoofed header detection
Answer: A
NEW QUESTION # 47
Refer to the exhibit.
It is recommended that you configure which three access receive settings to allow outbound email from the example.com domain on FML-1? (Choose three.)
- A. The Enable check box should be cleared
- B. The Action should be set to Relay
- C. The Sender IP/netmask should be set to 10.29.1.45/32
- D. The Sender pattern should be set to *@example.com
- E. The Recipient pattern should be set to 10.29.1.45/24
Answer: A,B,C
NEW QUESTION # 48
Which FortiMail option removes embedded code components in Microsoft Word, while maintaining the original file format?
- A. Header analysis
- B. Content disarm and reconstruction
- C. Behavior analysis
- D. Impersonation analysis
Answer: B
NEW QUESTION # 49
Refer to the exhibit.
The exhibit shows a FortiMail active-passive setup.
Which three actions are recommended when configuring the primary FortiMail HA interface? (Choose three.)
- A. In the Virtual IP action drop-down list, select Use
- B. In the Virtual IP address field, type 172.16.32.55/24
- C. Disable Enable port monitor
- D. In the Peer IP address field, type 172.16.32.57
- E. In the Heartbeat status drop-down list, select Primary
Answer: A,C,E
NEW QUESTION # 50
Examine the nslookup output shown in the exhibit; then answer the question below.
Identify which of the following statements is true regarding the example.com domain's MTAs. (Choose two.)
- A. The PriNS server should receive all email for the example.com domain
- B. The primary MTA for the example.com domain is mx.hosted.com
- C. The higher preference value is used to load balance more email to the mx.example.com MTA
- D. External MTAs will send email to mx.example.com only if mx.hosted.com is unreachable
Answer: B,D
NEW QUESTION # 51
Which of the following statements are true regarding FortiMail's behavior when using the built-in MTA to process email in transparent mode? (Choose two.)
- A. MUAs need to be configured to connect to the built-in MTA to send email
- B. FortiMail ignores the destination set by the sender and uses its own MX record lookup to deliver email
- C. FortiMail can queue undeliverable messages and generate DSNs
- D. If you disable the built-in MTA, FortiMail will use its transparent proxies to deliver email
Answer: B,C
NEW QUESTION # 52
Examine the FortiMail IBE service configuration shown in the exhibit; then answer the question below.
Which of the following statements describes the User inactivity expiry time of 90 days?
- A. Registered IBE users have 90 days from the time they receive a notification email message to access their IBE email
- B. First time IBE users must register to access their email within 90 days of receiving the notification email message
- C. After initial registration, IBE users can access the secure portal without authenticating again for 90 days
- D. IBE user accounts will expire after 90 days of inactivity, and must register again to access new IBE email message
Answer: D
NEW QUESTION # 53
Examine the FortiMail recipient-based policy shown in the exhibit; then answer the question below.
After creating the policy, an administrator discovered that clients are able to send unauthenticated email using SMTP. What must be done to ensure clients cannot send unauthenticated email?
- A. Configure a matching IP policy with SMTP authentication and exclusive flag enabled
- B. Configure an access delivery rule to enforce authentication
- C. Configure an access receive rule to verify authentication status
- D. Move the recipient policy to the top of the list
Answer: B
NEW QUESTION # 54
......
Top Fortinet NSE6_FML-6.4 Courses Online: https://dumpstorrent.dumpsfree.com/NSE6_FML-6.4-valid-exam.html