Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet NSE6_EDR_AD-7.0 Exam - Topic 4 Question 1 Discussion

Refer to the Exhibit:Based on the FortiEDR status output shown in the exhibit, what are two reasons for the degraded state? (Choose two answers)
B) The collector is installed with an incorrect registration password. and C) The collector is installed with an incorrect port number.
A) The endpoint has windows firewall enabled.
D) The endpoint cannot reach the central manager.

Fortinet NSE6_EDR_AD-7.0 Exam - Topic 4 Question 1 Discussion

Actual exam question for Fortinet's NSE6_EDR_AD-7.0 exam
Question #: 1
Topic #: 4
[All NSE6_EDR_AD-7.0 Questions]

Refer to the Exhibit:

Based on the FortiEDR status output shown in the exhibit, what are two reasons for the degraded state? (Choose two answers)

Show Suggested Answer Hide Answer
Suggested Answer: B, C

The correct answers are B and C.

The exhibit shows:

FortiEDR Service: Up FortiEDR Driver: Up FortiEDR Status: Degraded (no configuration)

This means the local Collector service and driver are running, but the Collector has not received valid configuration. In FortiEDR, a Collector must register and communicate with the FortiEDR Aggregator to receive its configuration. The guide states that the Collector initially sends registration information to the FortiEDR Aggregator using SSL, sends ongoing health/status/security-event information, and receives its configuration from the Aggregator.

During installation, a non-customized Windows Collector requires the correct Aggregator address, Aggregator port 8081, and registration password. The guide explicitly states that the Aggregator port should be specified as 8081, and that the registration password must be entered during installation.

Therefore, an incorrect registration password or incorrect port number can prevent proper registration/configuration retrieval, resulting in a degraded/no-configuration state.

Option A is not the best answer because Windows Firewall being enabled by itself does not automatically cause this FortiEDR status; only if it blocks required FortiEDR communication would it matter, and the option is too generic. Option D is also not correct as written because the Collector receives configuration from the Aggregator, not directly from the Central Manager. The guide describes Collector-to-Aggregator communication for registration and configuration.

=========


Contribute your Thoughts:

0/2000 characters

Currently there are no comments in this discussion, be the first to comment!


Save Cancel