Refer to the Exhibit:

Based on the FortiEDR status output shown in the exhibit, what are two reasons for the degraded state? (Choose two answers)
The correct answers are B and C.
The exhibit shows:
FortiEDR Service: Up FortiEDR Driver: Up FortiEDR Status: Degraded (no configuration)
This means the local Collector service and driver are running, but the Collector has not received valid configuration. In FortiEDR, a Collector must register and communicate with the FortiEDR Aggregator to receive its configuration. The guide states that the Collector initially sends registration information to the FortiEDR Aggregator using SSL, sends ongoing health/status/security-event information, and receives its configuration from the Aggregator.
During installation, a non-customized Windows Collector requires the correct Aggregator address, Aggregator port 8081, and registration password. The guide explicitly states that the Aggregator port should be specified as 8081, and that the registration password must be entered during installation.
Therefore, an incorrect registration password or incorrect port number can prevent proper registration/configuration retrieval, resulting in a degraded/no-configuration state.
Option A is not the best answer because Windows Firewall being enabled by itself does not automatically cause this FortiEDR status; only if it blocks required FortiEDR communication would it matter, and the option is too generic. Option D is also not correct as written because the Collector receives configuration from the Aggregator, not directly from the Central Manager. The guide describes Collector-to-Aggregator communication for registration and configuration.
=========
Currently there are no comments in this discussion, be the first to comment!