Fortinet NSE6_FML-6.2 Test Engine Dumps Training With 52 Questions
NSE6_FML-6.2 Questions Pass on Your First Attempt Dumps for NSE 6 Network Security Specialist Certified
NEW QUESTION 31
Examine the nslookup output shown in the exhibit; then answer the question below.
Identify which of the following statements is true regarding the example.com domain's MTAs. (Choose two.)
- A. External MTAs will send email to mx.example.com only if mx.hosted.com is unreachable
- B. The higher preference value is used to load balance more email to the mx.example.com MTA
- C. The PriNS server should receive all email for the example.com domain
- D. The primary MTA for the example.com domain is mx.hosted.com
Answer: A,D
NEW QUESTION 32
Refer to the exhibit.
An administrator must enforce authentication on FML-1 for all outbound email from the example.com domain.
Which two settings should be used to configure the access receive rule? (Choose two.)
- A. The Recipient pattern should be set to *@example.com
- B. The Sender IP/netmask should be set to 10.29.1.0/24
- C. The Authentication status should be set to Authenticated
- D. The Action should be set to Reject
Answer: B,C
Explanation:
Explanation/Reference:
NEW QUESTION 33
Refer to the exhibit.
Which two statements about the access receive rule are true? (Choose two.)
- A. Email from any host in the 10.0.1.0/24subnet can match this rule
- B. Senders must be authenticated to match this rule
- C. Email matching this rule will be relayed
- D. Email must originate from an example.comemail address to match this rule
Answer: C,D
NEW QUESTION 34
Refer to the exhibit.
Which two statements about the access receive rule are true? (Choose two.)
- A. Email from any host in the 10.0.1.0/24 subnet can match this rule
- B. Senders must be authenticated to match this rule
- C. Email matching this rule will be relayed
- D. Email must originate from an example.com email address to match this rule
Answer: C,D
NEW QUESTION 35
FortiMail is configured with the protected domain example.com.
Which two envelope addresses will require an access receive rule, to relay for unauthenticated senders?
(Choose two.)
- A. MAIL FROM: [email protected] RCPT TO: [email protected]
- B. MAIL FROM: [email protected] RCPT TO: [email protected]
- C. MAIL FROM: [email protected] RCPT TO: [email protected]
- D. MAIL FROM: [email protected] RCPT TO: [email protected]
Answer: A,B
NEW QUESTION 36
Refer to the exhibit.
The exhibit shows a FortiMail active-passive setup.
Which three actions are recommended when configuring the primary FortiMail HA interface? (Choose three.)
- A. In the Peer IP address field, type 172.16.32.57
- B. Disable Enable port monitor
- C. In the Heartbeat status drop-down list, select Primary
- D. In the Virtual IP address field, type 172.16.32.55/24
- E. In the Virtual IP action drop-down list, select Use
Answer: B,C,E
NEW QUESTION 37
Refer to the exhibit.
It is recommended that you configure which three access receive settings to allow outbound email from the example.comdomain on FML-1? (Choose three.)
- A. The Enable check box should be cleared
- B. The Sender pattern should be set to *@example.com
- C. The Sender IP/netmask should be set to 10.29.1.45/32
- D. The Recipient pattern should be set to 10.29.1.45/24
- E. The Action should be set to Relay
Answer: A,C,E
NEW QUESTION 38
Refer to the exhibit.
It is recommended that you configure which three access receive settings to allow outbound email from the example.com domain on FML-1? (Choose three.)
- A. The Enable check box should be cleared
- B. The Sender pattern should be set to *@example.com
- C. The Sender IP/netmask should be set to 10.29.1.45/32
- D. The Recipient pattern should be set to 10.29.1.45/24
- E. The Action should be set to Relay
Answer: A,C,E
NEW QUESTION 39 
What IP address should the DNS MX record for this deployment resolve to?
- A. 172.16.32.55
- B. 172.16.32.57
- C. 172.16.32.56
- D. 172.16.32.1
Answer: A
NEW QUESTION 40
Examine the FortiMail session profile and protected domain configuration shown in the exhibit; then answer the question below.

Which size limit will FortiMail apply to outbound email?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: A
NEW QUESTION 41
A FortiMail is configured with the protected domain example.com.
On this FortiMail, which two envelope addresses are considered incoming? (Choose two.)
- A. MAIL FROM: [email protected] RCPT TO: [email protected]
- B. MAIL FROM: [email protected] RCPT TO: [email protected]
- C. MAIL FROM: [email protected] RCPT TO: [email protected]
- D. MAIL FROM: [email protected] RCPT TO: [email protected]
Answer: A,C
Explanation:
Explanation/Reference: https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/9aa62d26-858d-11ea-
9384-00505692583a/FortiMail-6.4.0-Administration_Guide.pdf (30)
NEW QUESTION 42
What are the configuration steps to enable DKIM signing for outbound messages on FortiMail? (Choose three.)
- A. Publish the public key as a TXT record in a public DNS server
- B. Enable DKIM check in a matching session profile
- C. Enable DKIM check in a matching antispam profile
- D. Enable DKIM signing for outgoing messages in a matching session profile
- E. Generate a public/private key pair in the protected domain configuration
Answer: A,D,E
NEW QUESTION 43
Refer to the exhibit.
An administrator has enabled the sender reputation feature in the Example_Session profile on FML-1. After a few hours, the deferred queue on the mail server starts filling up with undeliverable email. What two changes must the administrator make to fix this issue? (Choose two.)
- A. Disable the exclusive flag in IP policy ID 1
- B. Apply a session profile with sender reputation disabled on a separate IP policy for outbound sessions
- C. Clear the sender reputation database using the CLI
- D. Create an outbound recipient policy to bypass outbound email from session profile inspections
Answer: A,B
NEW QUESTION 44
Refer to the exhibit.
Which message size limit will FortiMail apply to the outbound email?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: A
NEW QUESTION 45
Examine the FortiMail IBE users shown in the exhibit; then answer the question below
Which one of the following statements describes the Pre-registered status of the IBE user [email protected]?
- A. The user has received an IBE notification email, but has not accessed the HTTPS URL or attachment yet
- B. The user has completed the IBE registration process but has not yet accessed their IBE email
- C. The user was registered by an administrator in anticipation of IBE participation
- D. The user account has been de-activated, and the user must register again the next time they receive an IBE email
Answer: A
NEW QUESTION 46
While testing outbound MTA functionality, an administrator discovers that all outbound email is being processed using policy IDs 1:2:0.
Which two reasons explain why the last policy ID value is 0? (Choose two.)
- A. There are no outgoing recipient policies configured
- B. IP policy ID 2 has the exclusive flag set
- C. Outbound email is being rejected
- D. There are no access delivery rules configured for outbound email
Answer: A,D
NEW QUESTION 47
Refer to the exhibit.
Which configuration change must you make to block an offending IP address temporarily?
- A. Add the offending IP address to the system block list
- B. Add the offending IP address to the domain block list
- C. Change the authentication reputation setting status to Enable
- D. Add the offending IP address to the user block list
Answer: C
Explanation:
Explanation/Reference: https://help.fortinet.com/fweb/550/Content/FortiWeb/fortiweb-admin/blacklisting.htm
NEW QUESTION 48
What three configuration steps are required to enable DKIM signing for outbound messages on FortiMail?
(Choose three.)
- A. Publish the public key as a TXT record in a public DNS server
- B. Enable DKIM check in a matching session profile
- C. Enable DKIM check in a matching antispam profile
- D. Enable DKIM signing for outgoing messages in a matching session profile
- E. Generate a public/private key pair in the protected domain configuration
Answer: A,B,E
NEW QUESTION 49
Examine the FortiMail recipient-based policy shown in the exhibit; then answer the question below.
After creating the policy, an administrator discovered that clients are able to send unauthenticated email using SMTP. What must be done to ensure clients cannot send unauthenticated email?
- A. Configure a matching IP policy with SMTP authentication and exclusive flag enabled
- B. Configure an access receive rule to verify authentication status
- C. Move the recipient policy to the top of the list
- D. Configure an access delivery rule to enforce authentication
Answer: A
NEW QUESTION 50
......
NSE6_FML-6.2 Practice Test Pdf Exam Material: https://www.dumpstillvalid.com/NSE6_FML-6.2-prep4sure-review.html
