Fortinet • NSE6-FML
Validates the skills and knowledge required to deploy, configure, administer, and troubleshoot FortiMail devices to protect small to enterprise email networks from email-borne threats. Covers email security, spam detection, malware mitigation, encryption, and advanced FortiMail administration.
Questions
600
Duration
65 minutes
Passing Score
Pass/Fail
Difficulty
ProfessionalLast Updated
May 2026
The Fortinet NSE 6 - FortiMail 7.4 Administrator certification (also designated FCP_FML_AD-7.4 under Fortinet's Fortinet Certified Professional track) validates the skills and knowledge required to deploy, configure, administer, and troubleshoot FortiMail appliances protecting small to enterprise-scale email networks from email-borne threats. The exam tests competency across the full FortiMail feature set, including initial system deployment, email flow management, MTA security, spam detection, malware and advanced persistent threat (APT) mitigation, Identity-Based Encryption (IBE), and high availability configurations running FortiMail 7.4.
This certification sits within the Fortinet Certified Professional (FCP) certification framework and is recognized as an elective exam for the FCP in Network Security or Public Cloud Security tracks. Candidates who earn this credential demonstrate the ability to manage day-to-day FortiMail operations and resolve complex email security issues in both server mode and transparent mode deployment scenarios. The exam is available in English and Japanese and is delivered through Pearson VUE.
This certification is designed for network security engineers, email security administrators, and systems administrators who are responsible for deploying and managing FortiMail solutions within their organizations. It is particularly relevant for professionals working in enterprise IT environments, managed security service providers (MSSPs), and Fortinet partners who implement FortiMail as part of a broader Fortinet Security Fabric deployment.
Candidates typically come from roles such as Security Engineer, Network Administrator, Email Security Analyst, or Cloud Security Specialist. Those preparing to add an elective to their Fortinet Certified Professional (FCP) credential will also find this exam directly applicable to their certification pathway.
Fortinet does not enforce mandatory prerequisites for registering for this exam, but strongly recommends that candidates bring substantial practical experience before attempting it. Specifically, Fortinet advises a minimum of three years of general networking experience to understand underlying email infrastructure concepts, one year of network security experience to grasp the security framework in which FortiMail operates, and at least six months of hands-on experience working directly with FortiMail devices.
Candidates should be comfortable with core email protocols (SMTP, IMAP, POP3), DNS concepts relevant to email (MX records, SPF, DKIM, DMARC), and fundamental network security principles. Completing the official FortiMail 7.4 Administrator course offered through the Fortinet Training Institute, which includes approximately 10 hours of lecture and 10 hours of guided lab work, is strongly encouraged as preparation before sitting the exam.
The Fortinet NSE 6 - FortiMail 7.4 Administrator exam consists of 30 to 40 questions and is allotted 65 minutes for completion. Questions are presented in single-selection and multiple-selection multiple-choice formats, including both knowledge-based items and scenario-driven questions that simulate real-world FortiMail deployment and troubleshooting situations. The exam is delivered online through Pearson VUE, and candidates can access their score report via their Pearson VUE account after completion.
The exam is scored on a pass/fail basis; no partial credit is awarded, and there are no penalties for incorrect answers. Candidates must answer all selected responses correctly on multi-select items to receive credit for those questions. After passing, the associated digital badge is applied to the candidate's Fortinet Training Institute account within five business days. The exam is available in English and Japanese.
Earning the Fortinet NSE 6 - FortiMail 7.4 Administrator certification demonstrates specialized expertise in enterprise email security, a discipline in high demand as phishing, business email compromise (BEC), and ransomware delivered via email continue to be among the most prevalent threat vectors facing organizations. Certified professionals are well-positioned for roles including Email Security Engineer, Security Operations Analyst, Network Security Engineer, and Fortinet-focused Security Architect, particularly within organizations that have standardized on the Fortinet Security Fabric.
This certification functions as an elective within the Fortinet Certified Professional (FCP) framework, enabling holders to progress toward higher-tier Fortinet credentials such as Fortinet Certified Solution Expert (FCSE). For Fortinet partners and MSSPs, holding this certification supports partner program competency requirements. Professionals with Fortinet NSE 6-level specializations typically command salaries in the range of $85,000–$120,000 USD annually in North American markets, depending on experience and the breadth of their overall Fortinet certification portfolio.
5 sample questions with correct answers and explanations. Start a practice session to test yourself across all 600 questions.
1. Adatum Corp. has a security policy requiring that all inbound Microsoft Office documents and PDF files must have active content including macros, JavaScript, and embedded OLE objects removed before delivery. Users must still be able to open and read the document text and data after it is delivered. Which FortiMail feature meets this requirement? (Select one!)
Explanation
Content Disarm and Reconstruction strips potentially malicious active content including macros, VBA scripts, JavaScript in PDFs, ActiveX objects, OLE embeddings, and external references from supported Office and PDF files while preserving the readable text and data. A sanitized, reconstructed version is delivered to the recipient. The attachment filter blocks entire file types and prevents delivery entirely, meaning users cannot receive the document content at all. The antivirus heuristic engine detects malware and quarantines infected files but does not sanitize or reconstruct documents. FortiSandbox in inspect-only mode analyzes files for threats and provides verdicts but does not modify or strip active content before delivery.
2. Northwind Traders' FortiGuard Antivirus subscription expired 20 days ago and renewal is still pending. The security team asks whether email is still being scanned for viruses during this period. Which two statements accurately describe FortiMail's behavior during this 20-day post-expiry window? (Select two!)
Multiple correct answersExplanation
FortiMail provides a 30-day grace period after subscription expiry during which FortiGuard antivirus services continue functioning using the last downloaded signature database. At 20 days post-expiry, the subscription is still within this grace period. The antivirus engine therefore continues scanning all messages against the cached signatures, so email is still being inspected for known threats. However, no new signature updates are downloaded from FortiGuard during this period, meaning the detection database is not being refreshed and the ability to detect threats discovered after the last successful update degrades over time. FortiMail does not immediately stop scanning upon license expiry. Heuristic scanning does not automatically replace signature scanning. After the 30-day grace period ends, FortiGuard queries stop returning updated signature data entirely and the system falls back to stale local signatures and heuristics only.
3. An administrator at Tailspin Toys has generated a new 2048-bit RSA DKIM key pair with selector fml2025 for the tailspintoys.com domain. The new selector DNS TXT record is published, and FortiMail is now signing outbound mail with fml2025. The administrator wants to remove the old fml2024 DNS TXT record immediately. Which action must be completed before safely removing the old DNS selector record to avoid authentication failures? (Select one!)
Explanation
Messages signed with the old fml2024 selector may still be in transit when the key rotation occurs — sitting in deferred queues on remote sending MTAs awaiting retry, traveling between mail hops, or awaiting scanning at receiving systems. Recipient MTAs query DNS for the fml2024 selector when verifying these in-flight signatures. If the DNS TXT record is removed immediately, all such in-flight messages fail DKIM verification, negatively impacting DMARC results for those messages. Waiting approximately one week provides sufficient time for all messages signed under the old selector to complete delivery and pass verification. DKIM private keys do not support formal revocation like X.509 CRL or OCSP; stopping their use is achieved by replacing them with new keys and removing the signing reference. DMARC aggregate reports reflect past signing patterns and are not a transition readiness indicator. Recipient administrators do not manually manage DKIM DNS caches; verification is automated through standard DNS TTL expiration.
4. Which statement correctly describes the default FortiMail session profile behavior when a connecting SMTP client repeatedly issues invalid or unexpected protocol commands during a single session? (Select one!)
Explanation
The default FortiMail session profile allows five SMTP protocol errors within a single session before terminating the TCP connection to the client. This threshold balances tolerance for legitimate but imperfect MTA implementations against protection from clients that systematically probe server capabilities with invalid commands, which is a common behavior of spam bots and attackers. Dropping the connection on the first error would cause excessive false positives with real but slightly non-compliant senders. Imposing no limit would allow attackers to probe the server indefinitely. Deferral to the deferred queue is used for temporary delivery failures indicated by 4xx responses from the receiving system, not for protocol errors within an active SMTP session.
5. Fabrikam Inc.'s compliance policy requires that all outbound email from FortiMail to the partner domain banking-partner.com must always be encrypted in transit via TLS. If the partner MTA does not support STARTTLS, delivery must fail rather than fall back to plaintext. Certificate validation is not required. Which outbound TLS setting should the administrator configure in the delivery profile for banking-partner.com? (Select one!)
Explanation
Required TLS (starttls-enforce) mandates that STARTTLS must be offered and successfully negotiated before any message data is transmitted. If the partner MTA does not advertise STARTTLS support, FortiMail defers delivery rather than sending in plaintext. This enforces encryption in transit without adding certificate validation requirements. Opportunistic TLS offers STARTTLS but transparently falls back to cleartext delivery when the partner does not support it, violating the compliance requirement. Mandatory TLS with certificate verification also enforces STARTTLS but additionally validates the peer certificate against a CA trust store, which exceeds the stated requirements and could cause unnecessary delivery failures if the partner uses a private CA or self-signed certificate. Preferred TLS attempts STARTTLS but falls back on cipher negotiation failure, providing insufficient enforcement of the encryption requirement.
One-time access to this exam