Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Netskope Certified Cloud Security Administrator Exam NSK101 Exam Questions

Page: 1 / 13 Total 129 questions

Want more questions? Get Premium Access.

Question 1

Which three technologies describe the primary cloud service models as defined by the National Institute of Standards and Technology (NIST)? (Choose three.)

Correct Answer: C. Platform as a Service (PaaS); D. Software as a Service (SaaS); E. Infrastructure as a Service (laaS)
Explanation:

The three technologies that describe the primary cloud service models as defined by the National Institute of Standards and Technology (NIST) are Platform as a Service (PaaS), Software as a Service (SaaS), and Infrastructure as a Service (IaaS). These service models are based on the type of computing capability that is provided by the cloud provider to the cloud consumer over a network. According to NIST, these service models have the following definitions:

Platform as a Service (PaaS): The capability provided to the consumer is to deploy onto the cloud infrastructure consumer-created or acquired applications created using programming languages, libraries, services, and tools supported by the provider. The consumer does not manage or control the underlying cloud infrastructure including network, servers, operating systems, or storage, but has control over the deployed applications and possibly configuration settings for the application-hosting environment.

Software as a Service (SaaS): The capability provided to the consumer is to use the provider's applications running on a cloud infrastructure. The applications are accessible from various client devices through either a thin client interface, such as a web browser (e.g., web-based email), or a program interface. The consumer does not manage or control the underlying cloud infrastructure including network, servers, operating systems, storage, or even individual application capabilities, with the possible exception of limited user-specific application configuration settings.

Infrastructure as a Service (IaaS): The capability provided to the consumer is to provision processing, storage, networks, and other fundamental computing resources where the consumer is able to deploy and run arbitrary software, which can include operating systems and applications. The consumer does not manage or control the underlying cloud infrastructure but has control over operating systems, storage, and deployed applications; and possibly limited control of select networking components (e.g., host firewalls).


Question 2

Your organization has implemented Netskope Private Access (NPA) for all users. Users from the European region are reporting that they are unable to access many of their applications. You suspect that the publishers for the European data center may be disconnected and you want to verify the Publishers' status.

Which two methods describe how you would accomplish this task? (Choose two.)

Correct Answer: A. Use the Status field on the Publishers page.; C. Use the Netskope Private Access Troubleshooter.
Explanation:

To verify the status of the Publishers in the European data center, the following methods can be used:

Use the Status field on the Publishers page:

Navigate to the Publishers page in the Netskope UI.

Check the Status field to see if any Publishers are disconnected or experiencing issues.

Use the Netskope Private Access Troubleshooter:

Access the Netskope Private Access Troubleshooter tool.

This tool provides detailed diagnostic information and helps identify connectivity issues with Publishers.

These methods provide direct insights into the health and connectivity status of the Publishers, helping to quickly identify and resolve any issues affecting user access.


Netskope Knowledge Portal: Private Access

Netskope Private Access Troubleshooter

Question 3

What are two correct methods to gather logs from the Netskope Client? (Choose two.)

Correct Answer: A. From the Netskope Console in the device detail view, select Collect Log.; B. Right-click on the Netskope task tray icon and click Save Logs...
Explanation:

From the Netskope Console in the device detail view, select Collect Log:

Step 1: Access the Netskope Admin Console.

Step 2: Navigate to the specific device detail view.

Step 3: Locate and select the 'Collect Log' option.


Right-click on the Netskope task tray icon and click Save Logs...:

Step 1: Go to the device running the Netskope Client.

Step 2: Locate the Netskope icon in the task tray.

Step 3: Right-click on the Netskope icon.

Step 4: Select 'Save Logs...' from the context menu.

Netskope Knowledge Portal: Detailed guides on collecting logs via the Netskope Console and client applications.

Question 4

When accessing an encrypted website (HTTPS), what is a reason why you might receive a "certificate not trusted" browser message?

Correct Answer: B. A self-signed certificate is installed on the server.
Explanation:

When accessing an encrypted website (HTTPS), a 'certificate not trusted' message in the browser usually occurs because the certificate presented by the website is not issued by a trusted Certificate Authority (CA). A common scenario for this is when a self-signed certificate is installed on the server. Self-signed certificates are not signed by a CA that is recognized by the browser, so the browser cannot verify the authenticity of the certificate, leading to the 'certificate not trusted' message.


'If the SSL certificate is self-signed, the browser will not trust the certificate because it has not been issued by a trusted CA.'.

Question 5

Which three status indicators does the NPA Troubleshooter Tool provide when run? (Choose three)

Correct Answer: A. Steering configuration; C. Publisher connectivity; E. Reachability of the private app
Explanation:

The NPA (Netskope Private Access) Troubleshooter Tool provides the following status indicators when run:

Steering configuration: This indicates whether the traffic is being correctly steered through the Netskope infrastructure according to the defined policies.

Publisher connectivity: This status shows whether the Netskope Publisher is correctly connected and able to communicate with the Netskope cloud. It ensures that the Publisher, which acts as a gateway, is functioning correctly.

Reachability of the private app: This status verifies if the private application is reachable from the Netskope infrastructure, ensuring that users can access the necessary internal resources.

These indicators help administrators troubleshoot and ensure that the NPA setup is working correctly, providing secure and reliable access to private applications.


Netskope documentation on using the NPA Troubleshooter Tool and the status indicators it provides.

Best practices for troubleshooting NPA connectivity and performance issues.

Question 6

Your organization has recently implemented Netskope Private Access. During an investigation, your security team has asked you to provide a list of all hosts including domains and IP addresses that a user accessed through Netskope Private Access for the past seven days.

Which two locations in the Netskope Web UI would allow you to obtain and export the requested data? (Choose two.)

Correct Answer: A. Private Apps page in SkopeIT; C. Network Events page in SkopeIT
Explanation:

To obtain and export a list of all hosts including domains and IP addresses that a user accessed through Netskope Private Access for the past seven days, you can follow these steps:

Access the Netskope Web UI: Log in to your Netskope admin console.

Navigate to SkopeIT:

Go to the SkopeIT section in the Netskope admin console.

Private Apps page in SkopeIT:

In the SkopeIT section, navigate to the 'Private Apps' page.

Here, you can find detailed information about the private applications accessed by users, including the domains and IP addresses.

Use the filter options to specify the user and the time range (past seven days).

Export the data as needed for your investigation.

Network Events page in SkopeIT:

In the SkopeIT section, navigate to the 'Network Events' page.

This page provides a comprehensive list of network events, including details about the hosts accessed through Netskope Private Access.

Again, use the filter options to specify the user and the time range.

Export the data for reporting purposes.

These two locations within the SkopeIT section of the Netskope Web UI will provide you with the necessary data to meet your security team's requirements.


Netskope Knowledge Portal: Using SkopeIT for Network and Private Apps Analysis.

Question 7

As an administrator, you need to configure the Netskope Admin UI to be accessible by specific IP addresses and to display a custom message after the admin users have been authenticated.

Which two statements are correct in this scenario? (Choose two.)

Correct Answer: A. Add the specific IP addresses on the IP Allow List.; D. Enable and set the User Notification Template to display the custom message.
Explanation:

Add the specific IP addresses on the IP Allow List (A): To restrict access to the Netskope Admin UI to specific IP addresses, administrators need to add these IP addresses to the IP Allow List. This ensures that only connections from these specified IP addresses are allowed access to the Admin UI. This configuration is crucial for enhancing security by limiting access to trusted IP addresses only.

Enable and set the User Notification Template to display the custom message (D): To display a custom message to admin users after they have authenticated, administrators need to enable and configure the User Notification Template. This template allows the customization of messages that are shown to users, including after login. This feature is useful for displaying privacy notices, welcome messages, or other important information to users upon successful authentication.

These steps are verified based on the configuration options available within the Netskope Admin UI settings. For more detailed steps and configuration, you can refer to the respective sections in the Netskope documentation.


Question 8

Which compliance standard should a company consider if both controllers and processors have legal entities in the EU?

Correct Answer: B. GDPR
Explanation:

The General Data Protection Regulation (GDPR) is the compliance standard a company should consider if both controllers and processors have legal entities in the EU. The GDPR applies to any organization that processes personal data of individuals within the EU, regardless of where the organization itself is based. This regulation imposes strict rules on data handling and provides robust protection for personal data.


GDPR is designed to protect data privacy for all individuals within the European Union (EU) and the European Economic Area (EEA). It also addresses the export of personal data outside the EU and EEA areas.

Question 9

According to Netskope. what are two preferred methods to report a URL miscategorization? (Choose two.)

Question 10