Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

FORTIMAIL 7.2

Total questions: 52

Worksheet time: 33mins

Name
Class
Date
1.

Identify the role that Fortisandbox plays when it is integrated with Fortimail for ATP

a)

Analyze the message body contents for viruses

b)

Hold a copy of the email while Fortimail does spam analysis

c)

Trap the attacking Ip address in a sandbox to prevent spam

d)

Analyze the file and URL objects

2.

What are the two scan modes Fortimail Uses to submit files to FortiSandbox?

a)

submit only

b)

Submit and wait for result

c)

Active scan

d)

Passive scan

3.

The Content monitor and filtering feature performs which function?

a)

Detects offensive images in the email body

b)

examines the email header and body for specific words or patterns

c)

examines the mail header and body for offensive images

d)

Detects specific words and patterns in the email body

4.

URL click protection is available for which type of content?

a)

Microsoft office

b)

PDF

c)

HTML

d)

VIDEOS

5.

Why is the DLP feature disable on entry-level Fortimail models?

a)

DLP configuration is disable if you do not have at least two interface

b)

It is disable because of performance considerations

c)

There is no lincense available on entry-level models

d)

Entry-level Fortimail models do not support gateway mode, which is required for DLP

6.

what is a method for creating fingerprints on fortimail for DLP ?

a)

Upload files manually

b)

Upload hash values of files

c)

Point to an SSH server to upload and create fingerprints

d)

Specify a Fortiguard DLP server

7.

In which two locations can you store Fortimail archives ? (choose two)

a)

local disk

b)

fortiloud storage

c)

SFTP server

d)

CFS file share

8.

Which management inteface do you use to access archived email on Fortimail?

a)

Webmail GUI

b)

Management CLI

c)

Webmail CLI

d)

Managemente GUI

9.

Which statement about IBE is true?

a)

IBE use public key cryptography as the encryption architecture

b)

Recipients can access their IBE emal without authentication, if they have the sender's public key

c)

Users need to install OpenPGP to read Email.

d)

IBE can be used only when all MTAs are Fortimail

10.

How is the encryption key generated for IBE ?

a)

It is generated using a key generator

b)

It is generated using random mouse movements when the email is sent

c)

It is generated from identity elements, such as email addresses

d)

It is generated from biometric data

11.

Which statement accurately describes the pull delivery method used by IBE ?

a)

Fortimail encrypts the confidential data and delivers it as an HTML email message

b)

The client pulls the encrypted message from Fortimail and decrypts it.

c)

Fortimail pulls the encrypted message from the sending MTA

d)

Fortimail generates a notification emal message with an embedded HTTPS URL

12.

Which is a true statement about the storage of an encrypted message when IBE uses the push delivery method[?

a)

The encrypted message is stored in the recipient's mailbox

b)

The encrypted message is stored on Fortimail

c)

The encrypted message is stored on the sending MTA

d)

The encrypted message is stored in all above locations

13.

Which Fortimail feature is available only in server mode ?

a)

Webmail interface

b)

Calendar resource management

c)

Spam email detection

d)

DLP

14.
a)

There should be at least one routed interface to allow fortimail to process non-SMTP traffic

b)

Automatically proxies non-SMTP traffic according to firewall rules

c)

Non-SMTP traffic is bridge through without any inspection

d)

Drops all non-SMTP traffic

15.

Why is it recommended that you run reports during low traffic volumen?

a)

You do this to avoid inaccuracies in the report

b)

Running reports cause the system to reboot

c)

Running reports can be resource intensive

d)

Reports cannot be generated when CPU usage is over 50%

16.

Which feature causes high false positive rates, when not configured properly?

a)

Fortiguard

b)

Greylisting

c)

Heuristics

d)

Access Control Rules

17.

Sender policy framework (SPF) provides protection from forged email identities by performing which action?

a)

comparing the ip address of the senders MTA with a list of Fortiguard-approved IP addresses in the sender domain DNS records

b)

comparing the IP address of the sender MTA with a list of approved IP address in the sender domain DNS records

18.

What is the propose of access delivery control ?

a)

It applies rates to limit excessive incoming emails

b)

It applies rates to limit outgoing email delivery at the system level

19.

What cannot be restricted using with sender address rate control?

a)

spammers that overwhelm your Fortimail sessions

b)

Emails with too many recipients

c)

The amount of data sent through the Fortimail device

d)

An MTA that is sending too many emails

20.

Refer to the exhibits showing SMTP limits (Session Profile — SMTP Limits), and domain settings (Domain Settings, and Domain Settings — Other) of a FortiMail device.

Which message size limit in KB will the FortiMail apply to outbound email?

a)

204800

b)

There is no message size limit for outbound email from a protected domain.

c)

10240

d)

51200

21.

A FortiMail device is configured with the protected domain example.com.
If none of the senders is authenticated, which two envelope addresses will require an access receive rule? (Choose two.)

22.

Refer to the exhibit, which shows a topology diagram of two separate email domains.

Which two statements correctly describe how an email message is delivered from User A to User B? (Choose two.)

a)

mx.example1.org will forward the email message to the MX record that has the lowest preference.

b)

User B will retrieve the email message using either POP3 or IMAP.

c)

User A’s MUA will perform a DNS MX record lookup to send the email message.

d)

The DNS server will act as an intermediary MTA.

23.

Refer to the exhibit which shows the output of an email transmission using a telnet session.

What are two correct observations about this SMTP session? (Choose two.)

a)

The SMTP envelope addresses are different from the message header addresses.

b)

The "250 Message accepted for delivery" message is part of the message body.

c)

The "Subject" is part of the message header.

d)

The "220 mx.internal.lab ESMTP Smtpd" message is part of the SMTP banner.

24.

Accurate date and time values are critical to which two features on FortiMail? (Choose two.)

a)

TLS transactions

b)

Route selection

c)

DNS queries

d)

Log timestamps

25.

Which statement describes the heuristics antispam technique?

a)

It analyzes email using characteristics of known spam samples recently caught by FortiMail.

b)

It analyzes characteristics of images using depth of color, grey level, space, and color change.

c)

The header and body of email messages are scanned against a set of PCRE rules.

d)

URIs in the email message body are extracted and sent to third-party rating servers.

26.

What are two benefits of having authentication reputation tracking enabled on FortiMail? (Choose two.)

a)

Tracks offending IP addresses attempting brute force attacks

b)


Temporarily locks out an attacker

c)

Enforces SMTP authentication

d)

Detects spoofed SMTP header addresses

27.

Refer to the exhibit, which shows a transparent mode FortiMail deployment.

Which connection pickup configurations allow FML-1 to scan bidirectional traffic? (Choose two.)

a)

Port2 Incoming connections: Proxy; Port2 Outgoing connections: Proxy

b)

Port2 Incoming connections: Pass through; Port2 Outgoing connections: Proxy

c)


Port1 Incoming connections: Proxy; Port1 Outgoing connections: Pass through

d)


Port1 Incoming connections: Proxy; Port1 Outgoing connections: Proxy

28.

Which are FortiMail operating modes? (Choose three.)

a)

Transparent mode

b)

NAT/Route mode

c)

Proxy mode

d)

Server mode

e)


Gateway mode

29.

Which three features are available only in server mode? (Choose three.)

a)

Address book management

b)

Resource profiles

c)

Webmail interface

d)

User preference management

e)

Calendar resource management

30.

Which two statements about domain keys identified mail (DKIM) on FortiMail are true? (Choose two.)

a)

The DKIM public key contains a list of authorized MTAs.

b)

A private key is used to generate a DKIM signature, which is inserted into the message headers of outbound email.

c)

The private key should be shared with any remote MTAs that will participate in DKIM.

d)

DNS is queried for the sending domain TXT records, which contain the DKIM public key.

31.

What are three authentication type options available for configuring server mode FortiMail users? (Choose three.)

a)

LDAP

b)

RADIUS

c)

Local

d)

IMAP

e)

POP3

32.

Which troubleshooting step should you take when investigating FortiGuard antispam and antivirus update issues?

a)

Use the execute smtptest command to verify email flow.

b)


Use the execute ping command to check connectivity with service.fortiguard.net.

c)

Use one of the alternate service ports, such as 8888 or 8889.

d)

Confirm that FortiMail can establish outbound connections on port 443.

33.

An administrator wants to configure disk quotas for all the users of a specific protected domain on a FortiMail device that is operating in server mode.

In which two ways can an administrator meet this requirement? (Choose two.)

a)

Define the disk quota value in a resource profile, and apply it to an incoming recipient policy.

b)

Define the disk quota value in an access profile, and apply it to the affected user accounts.

c)

Define the disk quota value for each user in their respective account settings.

d)

Define the disk quota value in the protected domain-level service setting.

34.

When the domain keys identified mail (DKIM) feature is used, where is the public key stored?

a)


The public key is distributed during the SMTP session establishment.

b)


The public key is stored in a DNS server as a TXT record.

c)

The public key is stored in a DNS server as a PTR record.

d)


The public key is stored in the local FortiMail flash memory.

35.

Refer to the exhibit.

Which three statements about the SMTP session shown in the exhibit are true? (Choose three.)

a)

The server accepted the email message for delivery.

b)

The server FQDN is mx.internal.lab.

c)

mx.internal.lab FQDN resolves to 10.0.1.10.

d)

The client did not authenticate.

e)


The session is encrypted using TLS.

36.

By default, a transparent mode FortiMail does not hide its presence.

Which parts of an email transmission will have evidence of a transparent mode FortiMail in the SMTP path? (Choose three.)

a)

XMAILER: header

b)


Source IP of sessions

c)

Return-Path: header

d)

EHLO/HELO greeting

e)

Received: header

37.

Which two statements describe the push delivery method used by IBE? (Choose two.)

Select one or more:

a)

The recipient accesses the HTTPS link and logs in to the FortiMail secure message portal.

b)

FortiMail encrypts the email and adds it to a notification email as an HTML attachment.

c)

Decrypted email is displayed using the HTTPS webmail interface.

d)


FortiMail generates a notification email message with an embedded HTTPS URL. 

38.

Access receive rule selection criteria provide control, based on which two parts of an email message? (Choose two.)

a)

Message headers

b)

Sender IP

c)


SMTP envelope header

d)

Message body

39.

Which three actions does FortiSandbox perform when it is integrated with FortiMail for advanced threat protection (ATP)? (Choose three.)

a)

It assigns and returns a rating for analyzed objects.

b)


It updates FortiGuard databases.

c)

It analyzes file and URI objects.

d)

It submits objects for sandbox scanning.

e)

It queues email during analysis.

40.

Which two statements about how FortiMail behaves when using transparent proxies to process email in transparent mode, are true? (Choose two.)

a)


The outbound proxy supports DSNs, but not message queuing.

b)

If you disable the transparent proxies, FortiMail will use its built-in MTA to process email.

c)

FortiMail ignores the destination set by the sender, and uses its own MX record lookup to deliver email.

d)


The inbound proxy supports message queuing and DSNs

41.

How does FortiMail process SMTP sessions, if no access receive rules are configured?

a)


If the destination IP matches the MAIL FROM domain’s MX record, the email will be relayed.

b)


If the source IP matches the RCPT TO domain’s MX record, the email will be relayed.

c)


If the MAIL FROM domain matches the protected domain, the email will be relayed.

d)


If the RCPT TO domain matches the protected domain, the email will be relayed.

42.

Which two types of remote authentication are supported for FortiMail administrator accounts? (Choose two.)

a)


Kerberos

b)

Single Sign-on

c)


RADIUS

d)


TACACS

43.

What is one advantage of creating domain associations?

a)

It disables FortiMail default relay behavior.

b)

It allows the creation of protected, domain-specific administrator accounts.

c)


It eliminates the need for different recipient-based policies for different protected domains.

d)

It eliminates the need for different DNS MX records for different protected domains.

44.

Which FortiMail feature combats spammers who try to hide spam content in delivery status notifications (DSN) messages?

a)

Heuristic

b)

Bounce address tag validation (BATV)

c)

Header analysis

d)

Behavior analysis

45.

What are two benefits of enabling the header manipulation feature? (Choose two.)

a)


It hides internal network information.

b)

It detects spoofed SMTP header addresses.

c)


It reduces overall message size by removing header content.

d)

It detects common spamming techniques.

46.

Refer to the exhibit, which shows a TLS profile.

Which two TLS levels allow an administrator to enforce TLS?

a)

Secure

b)

Preferred

c)


None

47.

What are two methods of creating fingerprint documents on FortiMail? (Choose two.)

a)

Create a fingerprint source that FortiMail can use to generate fingerprints

b)

Upload the MD5 checksum value of each file to FortiMail

c)


Manually upload hash files of documents to FortiMail

d)

Manually upload files to FortiMail

48.

Refer to the exhibit, which shows the HA configuration of a FortiMail device.

Which two steps are the minimum configuration steps required to configure an active-passive cluster? (Choose two.)

a)


In the Shared password field, type the same password that is used for all of the clustered devices.

b)


In the HA mode drop-down list, select Primary.

c)

Add the IP addresses of the secondary devices that will be members of the cluster.

d)

In the HA base port field, change the value to 22000.

49.

What is a mail user agent (MUA)?

a)

Software that end users interact with to retrieve and send email messages

b)

A protocol used to authenticate users for email retrieval

c)


The destination server where user mailboxes are stored

d)


Any SMTP server that processes and forwards email messages, but does not store them

50.

Why should you select the FortiMail operation mode early in the setup process?

a)

If users are configured, the operation mode can be changed only after a factory reset.


b)

The operation mode can be set only by using the quick start wizard.

c)

When the operation mode is changed, most settings revert to their factory defaults.

d)

If a protected domain is configured, the operation mode will be locked at its present value.

51.

Refer to the exhibit, which shows the HA configuration of a FortiMail device.What are the minimum configuration changes required to deploy this FortiMail device as a config-secondary in a config-only cluster? (Choose two.)

a)


In the Shared password field, type the same password as the one configured on the config-primary FortiMail.

b)


In the Primary IP address field, type the config-primary FortiMail IP address.

c)


In the HA base port field, change the value to 8890.

d)


In the HA mode drop-down list, select Secondary.

52.

Refer to the exhibit, which shows the service ports used by FortiMail for FortiGuard connectivity.

Which two statements about the service ports used by FortiMail for FortiGuard connectivity are true? (Choose two.)

a)

UDP 53/8888/8889 is used for FortiGuard firmware updates.

b)

TCP 443 is used for antispam sample submission.

c)

UDP 53/8888/8889 is used for FortiGuard rating queries.

d)


TCP 443 is used for FortiGuard antivirus and antispam updates.