Courseiva

NSE7 Advanced Threat Protection Practice Question

Which technology uses DMARC reports to help administrators identify unauthorized use of their email domain?

⚠ Common exam trap

Many candidates confuse DMARC's reporting and policy enforcement features with the underlying authentication mechanisms (SPF and DKIM), thinking those protocols alone provide visibility into unauthorized use, when in fact only DMARC defines the reporting format and feedback loop.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DMARC

DMARC (Domain-based Message Authentication, Reporting, and Conformance) is the correct answer because it specifically uses aggregate and forensic reports (DMARC reports) to provide administrators with visibility into how their email domain is being used, including unauthorized or spoofed emails. These reports are generated by receiving mail servers and sent back to the domain owner, detailing authentication results from SPF and DKIM checks, which helps identify and mitigate domain abuse.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SPF

    Why it's wrong here

    SPF publishes which hosts may send for a domain and is checked against the envelope sender, but it does not consume DMARC aggregate or forensic reports. It is tempting as the foundational email-authentication record, yet DMARC reporting itself is the mechanism that surfaces unauthorised domain use.

  • ✗

    DKIM

    Why it's wrong here

    DKIM cryptographically signs outbound messages so receivers can verify authenticity, but it generates no aggregate or forensic reporting back to the domain owner. DMARC is the layer that consumes those reports to expose unauthorised senders. DKIM alone would be the right choice when the requirement is proving a message genuinely originated from your domain.

  • ✗

    FortiMail

    Why it's wrong here

    FortiMail is a mail security gateway that can process and display DMARC aggregate reports it receives, but it does not itself publish the DMARC policy or generate the reports identifying unauthorised senders. It would be the correct selection if the question asked which appliance can enforce DMARC checks on inbound mail.

  • ✓

    DMARC

    Why this is correct

    DMARC consumes aggregate and forensic reports from receiving mail servers, letting administrators see which sources send mail claiming their domain. This satisfies the requirement to identify unauthorised use of the domain by revealing failing alignment and authentication results.

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.