Skip to main content

NSK101 Real Exam Questions

Netskope Certified Cloud Security Administrator (NCCSA)

129 questions available · Page 1 of 13

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

You just deployed the Netskope client in Web mode and several users mention that their messenger application is no longer working. Although you have a specific real-time policy that allows this application, upon further investigation you discover that it is using proprietary encryption. You need to permit access to all the users and maintain some visibility.

In this scenario, which configuration change would accomplish this task?

  1. A

    Change the real-time policy to block the messenger application.

  2. B

    Create a new custom cloud application using the custom connector that can be used in the real-time policy.

  3. C

    Add a policy in the SSL decryption section to bypass the messenger domain(s).

  4. D

    Edit the steering configuration and add a steering exception for the messenger application.

Show answer and explanation

Correct answer: C

Question 2 Single choice

Exhibit

Which portion of the interface shown in the exhibit allows an administrator to set severity, assign ownership, track progress, and perform forensic analysis with excerpts of violating content?

  1. A

    Skope IT-> Alerts

  2. B

    Incidents -> DLP

  3. C

    API-enabled Protection -> Inventory

  4. D

    Reports -> New Report

Show answer and explanation

Correct answer: B

Question 3 Single choice

What is the limitation of using a legacy proxy compared to Netskope's solution?

  1. A

    Netskope architecture requires on-premises components.

  2. B

    Legacy solutions offer higher performance and scalability for corporate and remote users.

  3. C

    Legacy on-premises solutions fail to provide protection for traffic from on-premises users.

  4. D

    To enforce policies, traffic needs to traverse back through a customer's on-premises security stack.

Show answer and explanation

Correct answer: D

Question 4 Multiple choice

You have applied a DLP Profile to block all Personally Identifiable Information data uploads to Microsoft 365 OneDrive. DLP Alerts are not displayed and no OneDrive-related activities are displayed in the Skope
IT App Events table.

In this scenario, what are two possible reasons for this issue? (Choose two.)

  1. A

    The Cloud Storage category is in the Steering Configuration as an exception.

  2. B

    The destination domain is excluded from decryption in the decryption policy.

  3. C

    A Netskope POP is not in your local country and therefore DLP policies cannot be applied.

  4. D

    DLP policies do not apply when using IPsec as a steering option.

Show answer and explanation

Correct answers: A, B

Question 5 Multiple choice

Which two statements describe a website categorized as a domain generated algorithm (DGA)? (Choose two.)

  1. A

    The website is used for domain registration.

  2. B

    The domain contains malicious algorithms.

  3. C

    The website is used to hide a command-and-control server.

  4. D

    The domain was created by a program.

Show answer and explanation

Correct answers: C, D

Question 6 Single choice

You are working with a large retail chain and have concerns about their customer data. You want to protect customer credit card data so that it is never exposed in transit or at rest.
In this scenario, which regulatory compliance standard should be used to govern this data?

  1. A

    SOC 3

  2. B

    PCI-DSS

  3. C

    AES-256

  4. D

    ISO 27001

Show answer and explanation

Correct answer: B

Question 7 Single choice

A Netskope administrator wants to create a policy to quarantine files based on sensitive content.

In this scenario, which variable must be included in the policy to achieve this goal?

  1. A

    Organizational Unit

  2. B

    Cloud Confidence Index level

  3. C

    DLP Profile

  4. D

    Threat Protection Profile

Show answer and explanation

Correct answer: C

Question 8 Single choice

Users are connecting to sanctioned cloud applications from public computers, such as from a hotel business center.

Which traffic steering method would work in this scenario?

  1. A

    proxy chaining

  2. B

    IPsec/GRE tunnel

  3. C

    reverse proxy

  4. D

    steering client

Show answer and explanation

Correct answer: C

Question 9 Multiple choice

Click the Exhibit button.

What are two use cases where the parameter shown in the exhibit is required? (Choose two.)

  1. A

    When you create a policy to prevent file transfer between a sanctioned Google Drive and personal Google Drive.

  2. B

    When you share the JoC between a third-party security solution and the Threat Protection Profile.

  3. C

    When you create a policy to prevent binary files larger than 5 MB that are shared publicly on a sanctioned OneDrive.

  4. D

    When you share Incident details about files detected in a DLP incident.

Show answer and explanation

Correct answers: A, C

Question 10 Single choice

An administrator has created a DLP rule to search for text within documents that match a specific pattern.
After creating a Real-time Protection Policy to make use of this DLP rule, the administrator suspects the rule is generating false positives.

Within the Netskope tenant, which feature allows administrators to review the data that was matched by the DLP rule?

  1. A

    Risk Insights

  2. B

    Forensic

  3. C

    Quarantine

  4. D

    Leaal Hold

Show answer and explanation

Correct answer: B