Netskope NSK300 - Netskope Certified Cloud Security Architect Exam

Question #6 (Topic: Exam A)
You want to integrate with a third-party DLP engine that requires ICAP.
In this scenario, which Netskope platform component must be configured?
A. On-Premises Log Parser (OPLP) B. Secure Forwarder C. Netskope Cloud Exchange D. Netskope Adapter
Answer: B
Question #7 (Topic: Exam A)
You just deployed and registered an NPA publisher for your first private application and need to provide access to this application for the Human Resources (HR) users group only.
How would you accomplish this task?
A. 1. Enable private app steering in the Steering Configuration assigned to the HR group.<br /> 2. Create a new Private App.<br /> 3. Create a new Real-time Protection policy as follows:<br /> Source = HR user group<br /> Destination = Private App<br /> Action = Allow B. 1. Create a new private app and assign it to the HR user group.<br /> 2. Create a new Real-time Protection policy as follows:<br /> Source = HR user group<br /> Destination = Private App<br /> Action = Allow. C. 1. Enable private app steering in Tenant Steering Configuration.<br /> 2. Create a new private app and assign it to the HR user group. D. 1. Enable private app steering in the Steering Configuration assigned to the HR group.<br /> 2. Create a new private app and assign it to the HR user group.<br /> 3. Create a new Real-time Protection policy as follows:<br /> Source = HR user group<br /> Destination = Private App<br /> Action = Allow
Answer: D
Question #8 (Topic: Exam A)
Users at your company’s branch office in San Francisco report that their clients are connecting, but websites and SaaS applications are slow. When troubleshooting, you notice that the users are connected to a Netskope data plane in New York where your company’s headquarters is located.
What is a valid reason for this behavior?
A. The Netskope Client’s on-premises detection check failed. B. The Netskope Client’s default DNS over HTTPS call is failing. C. The closest Netskope data plane to San Francisco is unavailable. D. The Netskope Client’s DNS call to Secure Forwarder is failing.
Answer: C
Question #9 (Topic: Exam A)
Review the exhibit.

AcmeCorp has recently begun using Microsoft 365. The organization is concerned that employees will start using third-party non-AcmeCorp OneDrive instances to store company data. The CISO asks you to use Netskope to create a policy that ensures that no data is being uploaded to non-AcmeCorp instances of OneDrive.
Referring to the exhibit, which two policies would accomplish this posture? (Choose two.)
A. 4 B. 3 C. 2 D. 1
Answer: D
Question #10 (Topic: Exam A)
A company has deployed Explicit Proxy over Tunnel (EPoT) for their VDI users. They have configured Forward Proxy authentication using Okta Universal Directory. They have also configured a number of Real-time Protection policies that block access to different Web categories for different AD groups so, for example, marketing users are blocked from accessing gambling sites. During User Acceptance Testing, they see inconsistent results where sometimes marketing users are able to access gambling sites and sometimes they are blocked as expected. They are seeing this inconsistency based on who logs into the VDI server first.
What is causing this behavior?
A. Forward Proxy is not configured to use the Cookie Surrogate. B. Forward Proxy is not configured to use the IP Surrogate. C. Forward Proxy authentication is configured but not enabled. D. Forward Proxy is configured to use the Cookie Surrogate.
Answer: B
Download Exam
Page: 2 / 12
Total 60 questions