NSE6_FML-6.4 Dumps with Free 365 Days Update Fast Exam Updates
Verified NSE6_FML-6.4 dumps Q&As - 2022 Latest NSE6_FML-6.4 Download
NEW QUESTION 10
Refer to the exhibit.
An administrator has enabled the sender reputation feature in the Example_Session profile on FML-1. After a few hours, the deferred queue on the mail server starts filling up with undeliverable email. What two changes must the administrator make to fix this issue? (Choose two.)
- A. Disable the exclusive flag in IP policy ID 1
- B. Apply a session profile with sender reputation disabled on a separate IP policy for outbound sessions
- C. Create an outbound recipient policy to bypass outbound email from session profile inspections
- D. Clear the sender reputation database using the CLI
Answer: A,B
NEW QUESTION 11
Examine the FortiMail active-passive cluster shown in the exhibit; then answer the question below.

Which of the following parameters are recommended for the Primary FortiMail's HA interface configuration? (Choose three.)
- A. Heartbeat status: Primary
- B. Peer IP address: 172.16.32.57
- C. Virtual IP action: Use
- D. Virtual IP address: 172.16.32.55/24
- E. Enable port monitor: disable
Answer: A,C,D
NEW QUESTION 12
Examine the FortiMail recipient-based policy shown in the exhibit; then answer the question below.
After creating the policy, an administrator discovered that clients are able to send unauthenticated email using SMTP. What must be done to ensure clients cannot send unauthenticated email?
- A. Configure a matching IP policy with SMTP authentication and exclusive flag enabled
- B. Configure an access delivery rule to enforce authentication
- C. Move the recipient policy to the top of the list
- D. Configure an access receive rule to verify authentication status
Answer: B
NEW QUESTION 13
If you are using the built-in MTA to process email in transparent mode, which two statements about FortiMail behavior are true? (Choose two.)
- A. FortiMail ignores the destination set by the sender, and uses its own MX record lookup to deliver email
- B. FortiMail can queue undeliverable messages and generate DSNs
- C. MUAs need to be configured to connect to the built-in MTA to send email
- D. If you disable the built-in MTA, FortiMail will use its transparent proxies to deliver email
Answer: A,B
NEW QUESTION 14
Examine the nslookup output shown in the exhibit; then answer the question below.
Identify which of the following statements is true regarding the example.com domain's MTAs. (Choose two.)
- A. The higher preference value is used to load balance more email to the mx.example.com MTA
- B. External MTAs will send email to mx.example.com only if mx.hosted.com is unreachable
- C. The PriNS server should receive all email for the example.com domain
- D. The primary MTA for the example.com domain is mx.hosted.com
Answer: B,D
NEW QUESTION 15
Which FortiMail option removes embedded code components in Microsoft Word, while maintaining the original file format?
- A. Header analysis
- B. Behavior analysis
- C. Impersonation analysis
- D. Content disarm and reconstruction
Answer: D
NEW QUESTION 16
Which of the following statements are true regarding FortiMail's behavior when using the built-in MTA to process email in transparent mode? (Choose two.)
- A. FortiMail can queue undeliverable messages and generate DSNs
- B. MUAs need to be configured to connect to the built-in MTA to send email
- C. FortiMail ignores the destination set by the sender and uses its own MX record lookup to deliver email
- D. If you disable the built-in MTA, FortiMail will use its transparent proxies to deliver email
Answer: A,C
NEW QUESTION 17
Refer to the exhibit.
Which statement describes the pre-registered status of the IBE user [email protected]?
- A. The user was registered by an administrator in anticipation of IBE participation.
- B. The user has completed the IBE registration process, but has not yet accessed their IBE email.
- C. The user has received an IBE notification email, but has not accessed the HTTPS URL or attachment yet.
- D. The user account has been de-activated, and the user must register again the next time they receive an IBE email.
Answer: B
NEW QUESTION 18
What three configuration steps are required to enable DKIM signing for outbound messages on FortiMail? (Choose three.)
- A. Publish the public key as a TXT record in a public DNS server
- B. Generate a public/private key pair in the protected domain configuration
- C. Enable DKIM check in a matching session profile
- D. Enable DKIM check in a matching antispam profile
- E. Enable DKIM signing for outgoing messages in a matching session profile
Answer: A,B,C
NEW QUESTION 19
Refer to the exhibit.
Which message size limit will FortiMail apply to the outbound email?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: A
NEW QUESTION 20
Examine the FortiMail DLP scan rule shown in the exhibit; then answer the question below.
Which of the following statements is true regarding this configuration? (Choose two.)
- A. If an email is sent from [email protected] the action will be applied without matching any conditions
- B. An email message containing credit card numbers in the body will trigger this scan rule
- C. An email must contain credit card numbers in the body, attachment, and subject to trigger this scan rule
- D. An email message containing the words "Credit Card" in the subject will trigger this scan rule
Answer: B,D
NEW QUESTION 21
A FortiMail administrator is concerned about cyber criminals attempting to get sensitive information from employees using whaling phishing attacks.
What option can the administrator configure to prevent these types of attacks?
- A. Dictionary profile with predefined smart identifiers
- B. Content disarm and reconstruction
- C. Bounce tag verification
- D. Impersonation analysis
Answer: D
NEW QUESTION 22
A FortiMail administrator is investigating a sudden increase in DSNs being delivered to the protected domain for undeliverable email messages. After searching the logs, the administrator identifies that the DSNs were not generated as a result of any outbound email sent from the protected domain.
Which FortiMail antispam technique can the administrator use to prevent this scenario?
- A. Spoofed header detection
- B. Spam outbreak protection
- C. FortiGuard IP Reputation
- D. Bounce address tag validation
Answer: B
NEW QUESTION 23
Which statement about how impersonation analysis identifies spoofed email addresses is correct?
- A. It uses DMARC validation to detect spoofed addresses.
- B. It uses behavior analysis to detect spoofed addresses.
- C. It maps the display name to the correct recipient email address.
- D. It uses SPF validation to detect spoofed addresses.
Answer: B
NEW QUESTION 24
Which three statements about SMTPS and SMTP over TLS are true? (Choose three.)
- A. The STARTTLS command is used to initiate SMTP over TLS
- B. SMTP over TLS connections are entirely encrypted and initiated on port 465
- C. SMTPS encrypts the identities of both the sender and receiver
- D. SMTPS encrypts only the body of the email message
- E. SMTPS connections are initiated on port 465
Answer: A,C,E
NEW QUESTION 25
......
Updated Fortinet Study Guide NSE6_FML-6.4 Dumps Questions: https://torrentpdf.exam4tests.com/NSE6_FML-6.4-pdf-braindumps.html