WorksheetsFORTIMAIL 7.2
Total questions: 52
Worksheet time: 33mins
Identify the role that Fortisandbox plays when it is integrated with Fortimail for ATP
Analyze the message body contents for viruses
Hold a copy of the email while Fortimail does spam analysis
Trap the attacking Ip address in a sandbox to prevent spam
Analyze the file and URL objects
What are the two scan modes Fortimail Uses to submit files to FortiSandbox?
submit only
Submit and wait for result
Active scan
Passive scan
The Content monitor and filtering feature performs which function?
Detects offensive images in the email body
examines the email header and body for specific words or patterns
examines the mail header and body for offensive images
Detects specific words and patterns in the email body
URL click protection is available for which type of content?
Microsoft office
HTML
VIDEOS
Why is the DLP feature disable on entry-level Fortimail models?
DLP configuration is disable if you do not have at least two interface
It is disable because of performance considerations
There is no lincense available on entry-level models
Entry-level Fortimail models do not support gateway mode, which is required for DLP
what is a method for creating fingerprints on fortimail for DLP ?
Upload files manually
Upload hash values of files
Point to an SSH server to upload and create fingerprints
Specify a Fortiguard DLP server
In which two locations can you store Fortimail archives ? (choose two)
local disk
fortiloud storage
SFTP server
CFS file share
Which management inteface do you use to access archived email on Fortimail?
Webmail GUI
Management CLI
Webmail CLI
Managemente GUI
Which statement about IBE is true?
IBE use public key cryptography as the encryption architecture
Recipients can access their IBE emal without authentication, if they have the sender's public key
Users need to install OpenPGP to read Email.
IBE can be used only when all MTAs are Fortimail
How is the encryption key generated for IBE ?
It is generated using a key generator
It is generated using random mouse movements when the email is sent
It is generated from identity elements, such as email addresses
It is generated from biometric data
Which statement accurately describes the pull delivery method used by IBE ?
Fortimail encrypts the confidential data and delivers it as an HTML email message
The client pulls the encrypted message from Fortimail and decrypts it.
Fortimail pulls the encrypted message from the sending MTA
Fortimail generates a notification emal message with an embedded HTTPS URL
Which is a true statement about the storage of an encrypted message when IBE uses the push delivery method[?
The encrypted message is stored in the recipient's mailbox
The encrypted message is stored on Fortimail
The encrypted message is stored on the sending MTA
The encrypted message is stored in all above locations
Which Fortimail feature is available only in server mode ?
Webmail interface
Calendar resource management
Spam email detection
DLP
There should be at least one routed interface to allow fortimail to process non-SMTP traffic
Automatically proxies non-SMTP traffic according to firewall rules
Non-SMTP traffic is bridge through without any inspection
Drops all non-SMTP traffic
Why is it recommended that you run reports during low traffic volumen?
You do this to avoid inaccuracies in the report
Running reports cause the system to reboot
Running reports can be resource intensive
Reports cannot be generated when CPU usage is over 50%
Which feature causes high false positive rates, when not configured properly?
Fortiguard
Greylisting
Heuristics
Access Control Rules
Sender policy framework (SPF) provides protection from forged email identities by performing which action?
comparing the ip address of the senders MTA with a list of Fortiguard-approved IP addresses in the sender domain DNS records
comparing the IP address of the sender MTA with a list of approved IP address in the sender domain DNS records
What is the propose of access delivery control ?
It applies rates to limit excessive incoming emails
It applies rates to limit outgoing email delivery at the system level
What cannot be restricted using with sender address rate control?
spammers that overwhelm your Fortimail sessions
Emails with too many recipients
The amount of data sent through the Fortimail device
An MTA that is sending too many emails
Refer to the exhibits showing SMTP limits (Session Profile — SMTP Limits), and domain settings (Domain Settings, and Domain Settings — Other) of a FortiMail device.
Which message size limit in KB will the FortiMail apply to outbound email?
204800
There is no message size limit for outbound email from a protected domain.
10240
51200
A FortiMail device is configured with the protected domain example.com.
If none of the senders is authenticated, which two envelope addresses will require an access receive rule? (Choose two.)
MAIL FROM: support@example.org RCPT TO: marketing@example.com
MAIL FROM: mis@hosted.net RCPT TO: noc@example.com
MAIL FROM: accounts@example.com RCPT TO: sales@biz.example.com
MAIL FROM: training@example.com RCPT TO: students@external.org
Refer to the exhibit, which shows a topology diagram of two separate email domains.
Which two statements correctly describe how an email message is delivered from User A to User B? (Choose two.)
mx.example1.org will forward the email message to the MX record that has the lowest preference.
User B will retrieve the email message using either POP3 or IMAP.
User A’s MUA will perform a DNS MX record lookup to send the email message.
The DNS server will act as an intermediary MTA.
Refer to the exhibit which shows the output of an email transmission using a telnet session.
What are two correct observations about this SMTP session? (Choose two.)
The SMTP envelope addresses are different from the message header addresses.
The "250 Message accepted for delivery" message is part of the message body.
The "Subject" is part of the message header.
The "220 mx.internal.lab ESMTP Smtpd" message is part of the SMTP banner.
Accurate date and time values are critical to which two features on FortiMail? (Choose two.)
TLS transactions
Route selection
DNS queries
Log timestamps
Which statement describes the heuristics antispam technique?
It analyzes email using characteristics of known spam samples recently caught by FortiMail.
It analyzes characteristics of images using depth of color, grey level, space, and color change.
The header and body of email messages are scanned against a set of PCRE rules.
URIs in the email message body are extracted and sent to third-party rating servers.
What are two benefits of having authentication reputation tracking enabled on FortiMail? (Choose two.)
Tracks offending IP addresses attempting brute force attacks
Temporarily locks out an attacker
Enforces SMTP authentication
Detects spoofed SMTP header addresses
Refer to the exhibit, which shows a transparent mode FortiMail deployment.
Which connection pickup configurations allow FML-1 to scan bidirectional traffic? (Choose two.)
Port2 Incoming connections: Proxy; Port2 Outgoing connections: Proxy
Port2 Incoming connections: Pass through; Port2 Outgoing connections: Proxy
Port1 Incoming connections: Proxy; Port1 Outgoing connections: Pass through
Port1 Incoming connections: Proxy; Port1 Outgoing connections: Proxy
Which are FortiMail operating modes? (Choose three.)
Transparent mode
NAT/Route mode
Proxy mode
Server mode
Gateway mode
Which three features are available only in server mode? (Choose three.)
Address book management
Resource profiles
Webmail interface
User preference management
Calendar resource management
Which two statements about domain keys identified mail (DKIM) on FortiMail are true? (Choose two.)
The DKIM public key contains a list of authorized MTAs.
A private key is used to generate a DKIM signature, which is inserted into the message headers of outbound email.
The private key should be shared with any remote MTAs that will participate in DKIM.
DNS is queried for the sending domain TXT records, which contain the DKIM public key.
What are three authentication type options available for configuring server mode FortiMail users? (Choose three.)
LDAP
RADIUS
Local
IMAP
POP3
Which troubleshooting step should you take when investigating FortiGuard antispam and antivirus update issues?
Use the execute smtptest command to verify email flow.
Use the execute ping command to check connectivity with service.fortiguard.net.
Use one of the alternate service ports, such as 8888 or 8889.
Confirm that FortiMail can establish outbound connections on port 443.
An administrator wants to configure disk quotas for all the users of a specific protected domain on a FortiMail device that is operating in server mode.
In which two ways can an administrator meet this requirement? (Choose two.)
Define the disk quota value in a resource profile, and apply it to an incoming recipient policy.
Define the disk quota value in an access profile, and apply it to the affected user accounts.
Define the disk quota value for each user in their respective account settings.
Define the disk quota value in the protected domain-level service setting.
When the domain keys identified mail (DKIM) feature is used, where is the public key stored?
The public key is distributed during the SMTP session establishment.
The public key is stored in a DNS server as a TXT record.
The public key is stored in a DNS server as a PTR record.
The public key is stored in the local FortiMail flash memory.
Refer to the exhibit.
Which three statements about the SMTP session shown in the exhibit are true? (Choose three.)
The server accepted the email message for delivery.
The server FQDN is mx.internal.lab.
mx.internal.lab FQDN resolves to 10.0.1.10.
The client did not authenticate.
The session is encrypted using TLS.
By default, a transparent mode FortiMail does not hide its presence.
Which parts of an email transmission will have evidence of a transparent mode FortiMail in the SMTP path? (Choose three.)
XMAILER: header
Source IP of sessions
Return-Path: header
EHLO/HELO greeting
Received: header
Which two statements describe the push delivery method used by IBE? (Choose two.)
Select one or more:
The recipient accesses the HTTPS link and logs in to the FortiMail secure message portal.
FortiMail encrypts the email and adds it to a notification email as an HTML attachment.
Decrypted email is displayed using the HTTPS webmail interface.
FortiMail generates a notification email message with an embedded HTTPS URL.
Access receive rule selection criteria provide control, based on which two parts of an email message? (Choose two.)
Message headers
Sender IP
SMTP envelope header
Message body
Which three actions does FortiSandbox perform when it is integrated with FortiMail for advanced threat protection (ATP)? (Choose three.)
It assigns and returns a rating for analyzed objects.
It updates FortiGuard databases.
It analyzes file and URI objects.
It submits objects for sandbox scanning.
It queues email during analysis.
Which two statements about how FortiMail behaves when using transparent proxies to process email in transparent mode, are true? (Choose two.)
The outbound proxy supports DSNs, but not message queuing.
If you disable the transparent proxies, FortiMail will use its built-in MTA to process email.
FortiMail ignores the destination set by the sender, and uses its own MX record lookup to deliver email.
The inbound proxy supports message queuing and DSNs
How does FortiMail process SMTP sessions, if no access receive rules are configured?
If the destination IP matches the MAIL FROM domain’s MX record, the email will be relayed.
If the source IP matches the RCPT TO domain’s MX record, the email will be relayed.
If the MAIL FROM domain matches the protected domain, the email will be relayed.
If the RCPT TO domain matches the protected domain, the email will be relayed.
Which two types of remote authentication are supported for FortiMail administrator accounts? (Choose two.)
Kerberos
Single Sign-on
RADIUS
TACACS
What is one advantage of creating domain associations?
It disables FortiMail default relay behavior.
It allows the creation of protected, domain-specific administrator accounts.
It eliminates the need for different recipient-based policies for different protected domains.
It eliminates the need for different DNS MX records for different protected domains.
Which FortiMail feature combats spammers who try to hide spam content in delivery status notifications (DSN) messages?
Heuristic
Bounce address tag validation (BATV)
Header analysis
Behavior analysis
What are two benefits of enabling the header manipulation feature? (Choose two.)
It hides internal network information.
It detects spoofed SMTP header addresses.
It reduces overall message size by removing header content.
It detects common spamming techniques.
Refer to the exhibit, which shows a TLS profile.
Which two TLS levels allow an administrator to enforce TLS?
Secure
Preferred
None
What are two methods of creating fingerprint documents on FortiMail? (Choose two.)
Create a fingerprint source that FortiMail can use to generate fingerprints
Upload the MD5 checksum value of each file to FortiMail
Manually upload hash files of documents to FortiMail
Manually upload files to FortiMail
Refer to the exhibit, which shows the HA configuration of a FortiMail device.
Which two steps are the minimum configuration steps required to configure an active-passive cluster? (Choose two.)
In the Shared password field, type the same password that is used for all of the clustered devices.
In the HA mode drop-down list, select Primary.
Add the IP addresses of the secondary devices that will be members of the cluster.
In the HA base port field, change the value to 22000.
What is a mail user agent (MUA)?
Software that end users interact with to retrieve and send email messages
A protocol used to authenticate users for email retrieval
The destination server where user mailboxes are stored
Any SMTP server that processes and forwards email messages, but does not store them
Why should you select the FortiMail operation mode early in the setup process?
If users are configured, the operation mode can be changed only after a factory reset.
The operation mode can be set only by using the quick start wizard.
When the operation mode is changed, most settings revert to their factory defaults.
If a protected domain is configured, the operation mode will be locked at its present value.
Refer to the exhibit, which shows the HA configuration of a FortiMail device.What are the minimum configuration changes required to deploy this FortiMail device as a config-secondary in a config-only cluster? (Choose two.)
In the Shared password field, type the same password as the one configured on the config-primary FortiMail.
In the Primary IP address field, type the config-primary FortiMail IP address.
In the HA base port field, change the value to 8890.
In the HA mode drop-down list, select Secondary.
Refer to the exhibit, which shows the service ports used by FortiMail for FortiGuard connectivity.
Which two statements about the service ports used by FortiMail for FortiGuard connectivity are true? (Choose two.)
UDP 53/8888/8889 is used for FortiGuard firmware updates.
TCP 443 is used for antispam sample submission.
UDP 53/8888/8889 is used for FortiGuard rating queries.
TCP 443 is used for FortiGuard antivirus and antispam updates.
