Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet NSE6_EDR_AD-7.0 Exam - Topic 4 Question 1 Discussion

Refer to the Exhibit:Based on the FortiEDR status output shown in the exhibit, what are two reasons for the degraded state? (Choose two answers)
B) The collector is installed with an incorrect registration password. and C) The collector is installed with an incorrect port number.
A) The endpoint has windows firewall enabled.
D) The endpoint cannot reach the central manager.

Fortinet NSE6_EDR_AD-7.0 Exam - Topic 4 Question 1 Discussion

Actual exam question for Fortinet's NSE6_EDR_AD-7.0 exam
Question #: 1
Topic #: 4
[All NSE6_EDR_AD-7.0 Questions]

Refer to the Exhibit:

Based on the FortiEDR status output shown in the exhibit, what are two reasons for the degraded state? (Choose two answers)

Show Suggested Answer Hide Answer
Suggested Answer: B, C

The correct answers are B and C.

The exhibit shows:

FortiEDR Service: Up FortiEDR Driver: Up FortiEDR Status: Degraded (no configuration)

This means the local Collector service and driver are running, but the Collector has not received valid configuration. In FortiEDR, a Collector must register and communicate with the FortiEDR Aggregator to receive its configuration. The guide states that the Collector initially sends registration information to the FortiEDR Aggregator using SSL, sends ongoing health/status/security-event information, and receives its configuration from the Aggregator.

During installation, a non-customized Windows Collector requires the correct Aggregator address, Aggregator port 8081, and registration password. The guide explicitly states that the Aggregator port should be specified as 8081, and that the registration password must be entered during installation.

Therefore, an incorrect registration password or incorrect port number can prevent proper registration/configuration retrieval, resulting in a degraded/no-configuration state.

Option A is not the best answer because Windows Firewall being enabled by itself does not automatically cause this FortiEDR status; only if it blocks required FortiEDR communication would it matter, and the option is too generic. Option D is also not correct as written because the Collector receives configuration from the Aggregator, not directly from the Central Manager. The guide describes Collector-to-Aggregator communication for registration and configuration.

=========


Contribute your Thoughts:

0/2000 characters
Emogene
3 days ago
C is definitely a possibility, I've seen that happen before.
upvoted 0 times
...
Krissy
8 days ago
Surprised that a wrong password can mess things up so much.
upvoted 0 times
...
Hollis
13 days ago
No way, the firewall shouldn't cause degradation like that!
upvoted 0 times
...
Javier
18 days ago
I think A could also be a factor, but not sure.
upvoted 0 times
...
Rutha
24 days ago
Definitely B and D, those are common issues.
upvoted 0 times
...
Ben
29 days ago
I thought having the Windows firewall enabled was usually okay, but I guess it could interfere with communication. Not sure if A is relevant here.
upvoted 0 times
...
Domonique
1 month ago
I practiced a similar question where the port number was a factor, so I wonder if C could also be a reason here.
upvoted 0 times
...
Marva
1 month ago
I'm not entirely sure, but I think if the endpoint can't reach the central manager, that could definitely cause a degraded state. So maybe D?
upvoted 0 times
...
Galen
1 month ago
I remember something about the collector needing the correct registration password, so B might be one of the answers.
upvoted 0 times
...

Save Cancel