nerdexam
Fortinet

FCP_FML_AD-7.4 · Question #19

Refer to the exhibit, which shows the Authentication Reputation list on a FortiMail device running in gateway mode. Why was the IP address blocked?

The correct answer is D. The IP address had consecutive SMTPS login failures to FortiMail. Because the device's Authentication Reputation list shows a "Mail" violation and is blocking mail access (along with CLI and Web), it indicates repeated failures of the mail-protocol login. In gateway mode FortiMail only tracks SMTP (SMTPS) authentication failures under the…

Antispam

Question

Refer to the exhibit, which shows the Authentication Reputation list on a FortiMail device running in gateway mode. Why was the IP address blocked?

Exhibit

FCP_FML_AD-7.4 question #19 exhibit

Options

  • AThe IP address had consecutive administrative password failures to FortiMail.
  • BThe IP address had consecutive SSH login failures to FortiMail.
  • CThe IP address had consecutive IMAP login failures to FortiMail.
  • DThe IP address had consecutive SMTPS login failures to FortiMail.

How the community answered

(30 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    13% (4)
  • D
    80% (24)

Explanation

Because the device's Authentication Reputation list shows a "Mail" violation and is blocking mail access (along with CLI and Web), it indicates repeated failures of the mail-protocol login. In gateway mode FortiMail only tracks SMTP (SMTPS) authentication failures under the "Mail" category, not IMAP, so consecutive SMTPS login failures triggered the block.

Topics

#authentication reputation#SMTPS login failures#IP blocking#brute force protection

Community Discussion

No community discussion yet for this question.

Full FCP_FML_AD-7.4 Practice