Which GUI menu is primarily used for monitoring real-time activity?
The Monitor menu displays real-time activity.
Why this answer
The Dashboard and Monitor sections show live traffic and status indicators.
75 of 76 questions · Page 1/2 · Nse6 Fortimail Secure Email Gateway · Answers revealed
Which GUI menu is primarily used for monitoring real-time activity?
The Monitor menu displays real-time activity.
Why this answer
The Dashboard and Monitor sections show live traffic and status indicators.
An administrator needs to enforce DMARC 'reject' policy for incoming mail. Where is this enforced in FortiMail?
DMARC enforcement is a feature of the AntiSpam profile.
Why this answer
DMARC settings are managed within the 'AntiSpam' profile under 'Domain settings' or specific DMARC control configurations.
Where do you configure the global whitelist to ensure specific email addresses are never blocked by AntiSpam?
The whitelist is a core component of the AntiSpam profile.
Why this answer
The global whitelist is found within the AntiSpam profile settings to ensure that senders are always allowed.
You need to ensure that the FortiMail doesn't relay spam to external addresses. Which feature should be configured?
This restricts what can leave the network.
Why this answer
Setting up strict relaying/access control rules and AntiSpam profiles on outbound traffic is necessary to prevent relaying spam.
Which feature is essential for protecting against password-based malware in attachments?
This blocks the delivery of unscannable archives.
Why this answer
Since malware in password-protected ZIPs cannot be scanned, blocking these archives is a standard security practice in the AV profile.
When configuring an Antivirus profile, which option is best to handle password-protected ZIP files?
Blocking/quarantining is the standard security practice for encrypted archives.
Why this answer
You can configure the AV profile to either block, quarantine, or scan if possible; blocking is often safer for encrypted archives.
Which THREE items are included in a standard email header for DMARC validation?
DKIM is one of two pillars.
Why this answer
DMARC checks the From domain, SPF/DKIM alignment, and policy flags.
What is the primary function of the 'Sender Reputation' service?
Reputation is based on history.
Why this answer
The reputation service uses real-time data to block senders who are known to be malicious, saving system resources.
Which feature allows FortiMail to perform automatic cleanup of old messages in the quarantine?
Maintenance settings allow defining the TTL for quarantined items.
Why this answer
The Quarantine maintenance settings allow for the automatic purging of messages after a set number of days to conserve disk space.
What is the purpose of the 'Relay Host' setting in FortiMail?
Relay host is the next destination.
Why this answer
The relay host defines the next hop for outgoing mail, usually the ISP's server or another MTA.
You are experiencing delays in mail delivery. Where is the best place to check for queued messages?
The queue monitoring tool shows specific messages.
Why this answer
The 'Mail Queue' monitoring page shows all messages currently awaiting delivery or retry.
When configuring a Recipient Policy, what does the 'Action' field determine?
The action defines the disposition of the message.
Why this answer
The 'Action' field in a policy determines if the email is accepted, rejected, relayed, or quarantined based on matching criteria.
Which TWO of the following are valid options for FortiMail deployment?
Valid deployment mode.
Why this answer
FortiMail supports Gateway, Transparent, and Server modes.
Which of the following is a symptom of a full quarantine storage?
Lack of space prevents new writes.
Why this answer
When storage is full, the system may stop accepting new quarantined items or fail to save new mail.
Which protocol is used for communication between the FortiMail and a remote LDAP server for user authentication?
LDAP is used for directory integration.
Why this answer
LDAP (Lightweight Directory Access Protocol) is the standard for directory-based user authentication.
What is the purpose of the 'Session Limit' setting in an Access Control Rule?
Session limits protect the gateway from connection-based attacks.
Why this answer
Session limits prevent resource exhaustion by limiting the number of concurrent connections from a single IP.
Which TWO methods can be used to authenticate users for access to the FortiMail quarantine portal?
LDAP is a standard external auth method.
Why this answer
FortiMail supports internal authentication and external services like LDAP or RADIUS.
Which protocol is most secure for retrieving email from the FortiMail server?
IMAPS includes SSL encryption.
Why this answer
IMAPS (IMAP over SSL) provides encryption for the retrieval process, making it the most secure choice.
What is the benefit of using 'FortiGuard' services with FortiMail?
FortiGuard is a threat intelligence service.
Why this answer
FortiGuard provides real-time updates for spam and virus signatures, keeping the appliance protected against new threats.
How can you ensure that only encrypted traffic is allowed for webmail access?
This enforces encryption.
Why this answer
Configuring the system to only listen on HTTPS (443) and redirecting HTTP (80) requests enforces encryption.
When an email is encrypted using FortiMail's Identity-Based Encryption (IBE), what does the recipient receive?
The portal is used to decrypt and view the message.
Why this answer
With IBE, the recipient gets a notification email with a link to a secure portal where they can read the encrypted message.
In which configuration area are 'Content Profiles' created and modified?
Content profiles are defined in the profiles section.
Why this answer
Content profiles are managed under the 'Policy' or 'Profile' sections depending on the firmware version, focusing on content inspection.
Which THREE settings are required for successful DKIM signing on outgoing mail?
The domain must be identified for signing.
Why this answer
DKIM signing requires a key, a selector, and the configuration of the signing domain.
Where do you check the current status of the FortiMail services?
The dashboard provides a real-time status summary.
Why this answer
The dashboard provides an overview of system status and active services.
In Gateway mode, what is the default behavior when FortiMail receives an email for an unknown recipient?
FortiMail typically rejects unknown recipients during the SMTP conversation to prevent backscatter.
Why this answer
By default, FortiMail acts as a relay. If it doesn't recognize the recipient, it may reject the connection or try to relay it based on relay policies.
Which TWO types of logs can be generated by FortiMail?
Logs specific to mail filtering.
Why this answer
FortiMail generates various logs including Event and Spam logs.
Which configuration file format is used for importing user lists?
CSV is the standard format for user lists.
Why this answer
FortiMail typically supports CSV files for the bulk import of user addresses.
Which THREE actions are available in the 'DLP' section of a policy?
Discarding is a common action for policy violations.
Why this answer
DLP allows for logging, quarantining, and rejecting content.
Which FortiMail feature helps to prevent 'backscatter' when dealing with spam?
This prevents the creation of NDRs.
Why this answer
Backscatter occurs when the server sends NDRs (non-delivery reports) for spam that was spoofed; rejecting at the SMTP stage prevents this.
You are configuring DKIM signing on FortiMail. The administrator has generated the public/private key pair. Where must the public key be published to ensure the receiving MTA validates the email correctly?
Receiving servers query DNS to verify the signature using the published public key.
Why this answer
DKIM verification relies on the public key being published as a TXT record in the DNS zone of the sending domain.
How can you restrict management access to the FortiMail GUI to only specific IP addresses?
Trusted hosts restrict access by IP.
Why this answer
Access control can be restricted in the 'Access' or 'Admin' profile settings by defining allowed source IPs.
Which TWO settings are configurable in a 'Recipient Policy'?
Profiles are assigned via policy.
Why this answer
Recipient policies control relaying and the AntiSpam/AV profiles applied to messages.
Which TWO of the following are components of the FortiMail AntiSpam framework?
Heuristic scanning is a core component.
Why this answer
Heuristic scanning and Bayesian analysis are both key components of the AntiSpam engine.
Which THREE actions can be taken by a DLP filter when a match is found?
Encryption can be triggered by DLP policy.
Why this answer
DLP filters can be configured to log, quarantine, or block/reject messages based on the rule.
When using FortiMail in Server Mode, how does the appliance handle incoming mail?
Server Mode makes FortiMail the primary mail server.
Why this answer
In Server Mode, FortiMail acts as the actual mail server (providing POP3/IMAP/Webmail services), so it receives mail directly for local domains.
Which THREE items are checked by the AntiSpam profile during email processing?
SPF is a part of AntiSpam/Authentication checks.
Why this answer
AntiSpam profiles utilize various techniques including RBLs, SPF/DKIM validation, and heuristics.
When configuring DMARC on FortiMail, which THREE components are required to successfully implement a 'reject' policy?
DKIM is a prerequisite for DMARC alignment.
Why this answer
DMARC relies on SPF and DKIM for alignment, and the DMARC record in DNS dictates the policy.
An administrator wants to prevent email spoofing by verifying the sender's domain. Which policy should be configured to check the DNS TXT record of the sending domain?
SPF checks the DNS TXT record for authorized sending IPs.
Why this answer
SPF (Sender Policy Framework) is used to verify that the sending IP is authorized by checking the sender domain's DNS TXT records.
Which TWO actions occur during the FortiMail inspection process before an email is delivered?
AntiSpam filtering is a core inspection step.
Why this answer
Inspection involves AV scanning and AntiSpam filtering.
What should you do to ensure that an encrypted email sent via IBE reaches the recipient correctly?
IBE requires these to function.
Why this answer
You must ensure that the recipient has a valid email address and that the FortiMail can reach the internet to send the notification.
How can you disable the 'Greylisting' feature for a specific, trusted sender?
Whitelisting bypasses AntiSpam checks, including greylisting.
Why this answer
You can add the sender to a whitelist in the AntiSpam profile or use an exception list to bypass greylisting.
Which interface mode is best suited for high-availability setups where you need to minimize configuration changes on existing infrastructure?
Transparent mode requires no infrastructure changes.
Why this answer
Transparent mode sits in-line and requires no IP changes, making it ideal for seamless integration.
How can you view the current number of emails in the quarantine?
Dashboard shows usage statistics.
Why this answer
The dashboard displays statistics about the quarantine, including count.
What is the primary role of the 'Administrator' profile?
The admin profile defines what a manager can do.
Why this answer
The admin profile manages access rights and permissions for different user accounts managing the FortiMail.
You notice that the FortiMail system time is incorrect, causing issues with SSL/TLS certificate validation. How do you correct this?
NTP keeps the clock synchronized.
Why this answer
System time is managed through NTP configuration to ensure synchronization with a reliable time server.
You are deploying FortiMail in Transparent Mode. Which network configuration requirement is mandatory for this deployment?
Bridge pairs are required to bridge the internal and external segments in Transparent mode.
Why this answer
Transparent mode operates at Layer 2; the FortiMail must have a bridge pair configured to inspect traffic without requiring changes to the mail server IP addressing.
Where do you configure the expiration period for messages in the quarantine?
These settings control the TTL for quarantined items.
Why this answer
Quarantine maintenance settings allow defining how many days a message is kept before being purged.
What is the purpose of the 'License' section in the FortiMail menu?
License management is the specific function.
Why this answer
The license section allows you to manage and verify the status of your product licenses.
Which of these is a legitimate reason to place a sender on the 'Block' list in the AntiSpam profile?
Blocking known spam sources improves filtering efficiency.
Why this answer
The block list allows for the manual rejection of known malicious senders, bypassing further analysis.
You are configuring DLP to block emails containing credit card numbers. Which component must be configured to define the pattern matching for the card numbers?
DLP dictionaries define the patterns or keywords to scan for.
Why this answer
Dictionary-based scanning allows for the definition of patterns (using regex or built-in types) to match sensitive data like credit card numbers.
You are deploying FortiMail in Transparent mode. Which configuration step is mandatory to ensure traffic is inspected without modifying the IP headers of the email packets?
In transparent mode, you must bridge two interfaces so that traffic flows through the FortiMail without IP layer changes.
Why this answer
Transparent mode operates at Layer 2. You must define the Bridge pair interfaces and ensure the FortiMail acts as a transparent bridge.
Which TWO actions can be performed on items currently residing in the FortiMail global quarantine?
Administrators can purge messages from the quarantine.
Why this answer
Global quarantine management allows administrators to release or delete messages, and potentially download them for forensic analysis.
Which DNS record must be published in the public DNS to enable DKIM signing for outgoing mail?
The public key is published as a DNS TXT record.
Why this answer
DKIM uses a public key published in a DNS TXT record so that receiving servers can verify the signature added to the email header.
Which command allows you to verify if the FortiMail can reach a remote mail server on port 25?
Telnet tests the TCP port connection.
Why this answer
The telnet command from the CLI is the standard way to test network-level connectivity to a specific port.
Which THREE factors are used by the FortiMail sender reputation service to evaluate an IP address?
High spam volume lowers reputation.
Why this answer
Reputation is calculated based on historical activity, spam history, and known blacklists.
Which configuration is required to allow external users to access the Webmail portal?
Access rules permit the traffic.
Why this answer
You must configure an Access Control rule to allow traffic to the Webmail service on the appropriate interface.
Which component manages the 'Daily Report' schedule?
Reporting is where schedules are defined.
Why this answer
Report settings allow for the scheduling and delivery of summaries regarding system and email activity.
What is the primary function of the FortiMail 'Quarantine' feature?
Quarantine is specifically for holding flagged messages.
Why this answer
The quarantine stores suspicious emails that have been flagged by filters, allowing administrators or users to review them rather than automatically deleting them.
An administrator sees a large volume of '451 4.7.1' errors in the logs. What does this indicate?
Greylisting uses 451 to defer delivery.
Why this answer
451 errors are typical of greylisting, where the mail server is temporarily deferring the email for verification.
Which type of scan should be enabled to detect known malware in email attachments?
AV is for malware.
Why this answer
Antivirus scanning is specifically designed to detect known malware signatures in attachments.
What does the 'Heuristic' score measure in the AntiSpam engine?
Heuristics look for spam characteristics.
Why this answer
Heuristic scores are generated by evaluating the structure and content of an email for common spam patterns.
A customer is experiencing false positives with the FortiMail Antispam engine. Which feature should be configured to allow trusted sender domains while still performing virus scanning?
ACL policies allow granular control to bypass specific modules without disabling virus scanning.
Why this answer
The Access Control List (ACL) allows you to define policies based on sender IP/domain to bypass antispam scanning while maintaining other security layers.
Which TWO of the following protocols does FortiMail support for mail retrieval?
Standard protocol for retrieving mail.
Why this answer
FortiMail supports POP3 and IMAP for accessing mailboxes.
A user reports that legitimate emails are being quarantined due to a high spam score. You want to add the sender's email address to a whitelist. Where should this be configured to be effective for the specific user?
The user-level Safe List is the correct place to whitelist senders for individual accounts.
Why this answer
The Personal Address Book or the per-user Safe List in the user's quarantine portal allows for individual whitelisting.
What is the default port for SMTP communication?
25 is the standard SMTP port.
Why this answer
SMTP standard communication occurs on port 25.
Which TWO features in FortiMail help prevent email spoofing?
DKIM verifies the signature integrity.
Why this answer
SPF and DKIM are the primary mechanisms for verifying sender identity and preventing spoofing.
What happens if a message matches multiple policies?
Policies are processed in sequential order.
Why this answer
FortiMail evaluates policies in order; the first match determines the action.
How does FortiMail identify the policy to apply to an incoming email?
Policies are matched based on these criteria.
Why this answer
FortiMail evaluates the incoming connection and recipient information against the configured Access Control and Recipient policies.
What is the primary function of the 'AntiSpam' profile?
Blocking spam is the core function.
Why this answer
The AntiSpam profile is used to aggregate and configure multiple spam filtering techniques to protect users.
Which TWO methods can be used to perform 'Greylisting' in FortiMail?
Address-based greylisting is supported.
Why this answer
Greylisting can be configured based on the sender's IP or the sender's email address.
What is the primary difference between a Gateway and a Server mode deployment?
This is the primary distinction.
Why this answer
Gateway mode acts as an MTA for existing servers, while Server mode acts as the mail server itself.
Which of these is a benefit of 'Transparent' mode?
Ease of deployment is a key benefit.
Why this answer
Transparent mode allows for installation without reconfiguring mail servers, providing ease of deployment.
What is the primary benefit of deploying FortiMail in a cluster?
Clustering ensures redundancy and service uptime.
Why this answer
Clustering provides high availability and load balancing to ensure mail service continuity.
What is the main advantage of using the FortiMail 'Quarantine' portal for end-users?
User self-service is the main benefit.
Why this answer
The portal empowers users to manage their own spam, reducing the load on IT administrators.
An administrator wants to ensure that all outgoing emails are archived to a secondary server. Where is this configured?
The archiving policy handles the duplication of mail for storage.
Why this answer
Archiving policies are configured to define the source and destination for email archival.
Ready to test yourself?
Try a timed practice session using only Nse6 Fortimail Secure Email Gateway questions.