100% Pass Your NSE6_FML-6.2 Exam Dumps at First Attempt with BootcampPDF
Penetration testers simulate NSE6_FML-6.2 exam PDF
NEW QUESTION 19
Examine the FortMail mail server settings shown in the exhibit; then answer the question below.
Which of the following statements are true? (Choose two.)
- A. mx.example.com will display STARTTLS as one of the supported commands in SMTP sessions
- B. mx.example.com will accept SMTPS connections
- C. mx.example.com will enforce SMTPS on all outbound sessions
- D. mx.example.com will drop any inbound plaintext SMTP connection
Answer: A,B
NEW QUESTION 20
Refer to the exhibit.
An administrator must enforce authentication on FML-1 for all outbound email from the example.com domain. Which two settings should be used to configure the access receive rule? (Choose two.)
- A. The Sender IP/netmask should be set to 10.29.1.0/24
- B. The Recipient pattern should be set to *@example.com
- C. The Action should be set to Reject
- D. The Authentication status should be set to Authenticated
Answer: A,D
NEW QUESTION 21
Refer to the exhibit.
Which two statements about the mail server settings are true? (Choose two.)
- A. FortiMail will support the STARTTLS extension
- B. FortiMail will enforce SMTPS on all outbound sessions
- C. FortiMail will accept SMTPS connections
- D. FortiMail will drop any inbound plaintext SMTP connection
Answer: C,D
NEW QUESTION 22
Refer to the exhibit.
What are two expected outcomes if FortiMail applies this antivirus action profile to an email? (Choose two.)
- A. The administrator will be notified of the virus detection
- B. Virus content will be removed from the email
- C. The sanitized email will be sent to the recipient's personal quarantine
- D. A replacement message will be added to the email
Answer: C,D
NEW QUESTION 23
What three configuration steps are required to enable DKIM signing for outbound messages on FortiMail?
(Choose three.)
- A. Enable DKIM check in a matching session profile
- B. Publish the public key as a TXT record in a public DNS server
- C. Enable DKIM check in a matching antispam profile
- D. Generate a public/private key pair in the protected domain configuration
- E. Enable DKIM signing for outgoing messages in a matching session profile
Answer: A,B,D
NEW QUESTION 24
A FortiMail administrator is investigating a sudden increase in DSNs being delivered to the protected domain for undeliverable email messages. After searching the logs, the administrator identifies that the DSNs were not generated as a result of any outbound email sent from the protected domain.
Which FortiMail antispam technique can the administrator use to prevent this scenario?
- A. FortiGuard IP Reputation
- B. Spam outbreak protection
- C. Spoofed header detection
- D. Bounce address tag validation
Answer: B
NEW QUESTION 25
Refer to the exhibit.
Which message size limit will FortiMail apply to the outbound email?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: C
Explanation:
Explanation
NEW QUESTION 26
Which three statements about SMTPS and SMTP over TLS are true? (Choose three.)
- A. SMTPS encrypts the identities of both the sender and receiver
- B. SMTP over TLS connections are entirely encrypted and initiated on port 465
- C. SMTPS encrypts only the body of the email message
- D. The STARTTLS command is used to initiate SMTP over TLS
- E. SMTPS connections are initiated on port 465
Answer: A,D,E
Explanation:
Explanation/Reference: https://docs.fortinet.com/document/fortimail/6.2.0/administration-guide/807960/fortimail- support-of-tls-ssl
NEW QUESTION 27 


Which of the following statements are true regarding the transparent mode FortiMail's email routing for the example.com domain? (Choose two.)
- A. FML-1 will use the transparent proxy for incoming sessions
- B. If outgoing email messages are undeliverable, FML-1 can queue them to retry later
- C. If incoming email are undeliverable, FML-1 can queue them to retry again later
- D. FML-1 will use the built-in MTA for outgoing sessions
Answer: A,C
NEW QUESTION 28
Refer to the exhibit.
What two archiving actions will FortiMail take when email messages match these archive policies? (Choose two.)
- A. FortiMail will allow only the [email protected] account to access the archived email
- B. FortiMail will archive email sent from [email protected]
- C. FortiMail will exempt spam email from archiving
- D. FortiMail will save archived email in the journal account
Answer: A,D
NEW QUESTION 29
Refer to the exhibit.
Which statement describes the pre-registered status of the IBE user [email protected]?
- A. The user account has been de-activated, and the user must register again the next time they receive an IBE email.
- B. The user has completed the IBE registration process, but has not yet accessed their IBE email.
- C. The user has received an IBE notification email, but has not accessed the HTTPS URL or attachment yet.
- D. The user was registered by an administrator in anticipation of IBE participation.
Answer: B
NEW QUESTION 30
Examine the FortiMail user webmail interface shown in the exhibit; then answer the question below.
Which one of the following statements is true regarding this server mode FortiMail's configuration?
- A. The protected domain-level service settings have been modified to allow access to the domain address book
- B. The administrator has configured an inbound recipient policy with a customized resource profile
- C. This user's account has a customized access profile applied that allows access to the personal address book
- D. The administrator has not made any changes to the default address book access privileges
Answer: A
NEW QUESTION 31
If you are using the built-in MTA to process email in transparent mode, which two statements about FortiMail behavior are true? (Choose two.)
- A. FortiMail ignores the destination set by the sender, and uses its own MX record lookup to deliver email
- B. MUAs need to be configured to connect to the built-in MTA to send email
- C. FortiMail can queue undeliverable messages and generate DSNs
- D. If you disable the built-in MTA, FortiMail will use its transparent proxies to deliver email
Answer: A,C
NEW QUESTION 32
Refer to the exhibit.
Which two statements about the access receive rule are true? (Choose two.)
- A. Senders must be authenticated to match this rule
- B. Email matching this rule will be relayed
- C. Email must originate from an example.comemail address to match this rule
- D. Email from any host in the 10.0.1.0/24subnet can match this rule
Answer: B,C
NEW QUESTION 33
Which of the following statements are true regarding the transparent mode FortiMail's email routing for the example.com domain? (Choose two.)
- A. FML-1 will use the transparent proxy for incoming sessions
- B. If outgoing email messages are undeliverable, FML-1 can queue them to retry later
- C. If incoming email are undeliverable, FML-1 can queue them to retry again later
- D. FML-1 will use the built-in MTA for outgoing sessions
Answer: A,C
NEW QUESTION 34
Which firmware upgrade method for an active-passive HA cluster ensures service outage is minimal, and there are no unnecessary failovers?
- A. Break the cluster, upgrade the units independently, and then form the cluster
- B. Upgrade the standby unit, and then upgrade the active unit
- C. Upgrade the active unit, which will upgrade the standby unit automatically
- D. Upgrade both units at the same time
Answer: D
NEW QUESTION 35
Refer to the exhibit.
Which two statements about how the transparent mode FortiMail device routes email for the example.com domain are true? (Choose two.)
- A. FML-1 will use the transparent proxy for incoming sessions
- B. If outgoing email messages are undeliverable, FM-1 can queue them to retry later
- C. FML-1 will use the built-in MTA for outgoing sessions
- D. If incoming email messages are undeliverable, FML-1 can queue them to retry later
Answer: A,B
NEW QUESTION 36
Refer to the exhibit.
Which configuration change must you make to block an offending IP address temporarily?
- A. Add the offending IP address to the user block list
- B. Change the authentication reputation setting status to Enable
- C. Add the offending IP address to the domain block list
- D. Add the offending IP address to the system block list
Answer: B
Explanation:
Reference: https://help.fortinet.com/fweb/550/Content/FortiWeb/fortiweb-admin/blacklisting.htm
NEW QUESTION 37
Refer to the exhibit.
What are two expected outcomes if FortiMail applies this antivirus action profile to an email? (Choose two.)
- A. The administrator will be notified of the virus detection
- B. Virus content will be removed from the email
- C. The sanitized email will be sent to the recipient's personal quarantine
- D. A replacement message will be added to the email
Answer: C,D
NEW QUESTION 38
Examine the FortiMail DLP scan rule shown in the exhibit; then answer the question below.
Which of the following statements is true regarding this configuration? (Choose two.)
- A. An email message containing the words "Credit Card" in the subject will trigger this scan rule
- B. An email message containing credit card numbers in the body will trigger this scan rule
- C. If an email is sent from [email protected] the action will be applied without matching any conditions
- D. An email must contain credit card numbers in the body, attachment, and subject to trigger this scan rule
Answer: A,B
NEW QUESTION 39
Refer to the exhibit.
Which configuration change must you make to block an offending IP address temporarily?
- A. Add the offending IP address to the user block list
- B. Change the authentication reputation setting status to Enable
- C. Add the offending IP address to the domain block list
- D. Add the offending IP address to the system block list
Answer: B
NEW QUESTION 40
......
All NSE6_FML-6.2 Dumps and Training Courses: https://www.bootcamppdf.com/NSE6_FML-6.2_exam-dumps.html