Refer to the exhibit.

Which configuration change must you make to block an offending IP address temporarily?
A. Add the offending IP address to the system block list
B. Add the offending IP address to the user block list
C. Add the offending IP address to the domain block list
D. Change the authentication reputation setting status to Enable
Refer to the exhibit.

Which statement describes the pre-registered status of the IBE user extuser2@external.lab?
A. The user has received an IBE notification email, but has not accessed the HTTPS URL or attachment yet.
B. The user account has been de-activated, and the user must register again the next time they receive an IBE email.
C. The user was registered by an administrator in anticipation of IBE participation.
D. The user has completed the IBE registration process, but has not yet accessed their IBE email.
Refer to the exhibit.

MTA-1 is delivering an email intended for User 1 to MTA-2.
Which two statements about protocol usage between the devices are true? (Choose two.)
A. User 1 will use IMAP to download the email message from MTA-2
B. MTA-2 will use IMAP to receive the email message from MTA-1
C. MTA-1 will use POP3 to deliver the email message to User 1 directly
D. MTA-1 will use SMTP to deliver the email message to MTA-2
FortiMail is configured with the protected domain example.com.
Which two envelope addresses will require an access receive rule, to relay for unauthenticated senders? (Choose two.)
A. MAIL FROM: accounts@example.com RCPT TO: sales@external.org
B. MAIL FROM: support@example.com RCPT TO: marketing@example.com
C. MAIL FROM: training@external.org RCPT TO: students@external.org
D. MAIL FROM: mis@hosted.net RCPT TO: noc@example.com
Which three statements about SMTPS and SMTP over TLS are true? (Choose three.)
A. SMTP over TLS connections are entirely encrypted and initiated on port 465
B. SMTPS encrypts the identities of both the sender and receiver
C. The STARTTLS command is used to initiate SMTP over TLS
D. SMTPS encrypts only the body of the email message
E. SMTPS connections are initiated on port 465
If you are using the built-in MTA to process email in transparent mode, which two statements about FortiMail behavior are true? (Choose two.)
A. MUAs need to be configured to connect to the built-in MTA to send email
B. If you disable the built-in MTA, FortiMail will use its transparent proxies to deliver email
C. FortiMail can queue undeliverable messages and generate DSNs
D. FortiMail ignores the destination set by the sender, and uses its own MX record lookup to deliver email
A FortiMail is configured with the protected domain example.com.
On this FortiMail, which two envelope addresses are considered incoming? (Choose two.)
A. MAIL FROM: accounts@example.com RCPT TO: sales@external.org
B. MAIL FROM: support@example.com RCPT TO: marketing@example.com
C. MAIL FROM: training@external.org RCPT TO: students@external.org
D. MAIL FROM: mis@hosted.net RCPT TO: noc@example.com
Refer to the exhibit.

What two archiving actions will FortiMail take when email messages match these archive policies? (Choose two.)
A. FortiMail will save archived email in the journal account
B. FortiMail will allow only the marketing@example.com account to access the archived email
C. FortiMail will exempt spam email from archiving
D. FortiMail will archive email sent from marketing@example.com
While reviewing logs, an administrator discovers that an incoming email was processed using policy IDs
0:4:9.
Which two scenarios will generate this policy ID? (Choose two.)
A. Email was processed using IP policy ID 4
B. Incoming recipient policy ID 9 has the exclusive flag set
C. FortiMail applies the default behavior for relaying inbound email
D. FortiMail configuration is missing an access delivery rule
Refer to the exhibit.

An administrator must enforce authentication on FML-1 for all outbound email from the example.com domain.
Which two settings should be used to configure the access receive rule? (Choose two.)
A. The Recipient pattern should be set to *@example.com
B. The Authentication status should be set to Authenticated
C. The Sender IP/netmask should be set to 10.29.1.0/24
D. The Action should be set to Reject