NSK200 Sample Questions & Answers
CASB architecture, DLP policy configuration and threat protection with the secure web gateway tie for the top weight, alongside user activity monitoring and analytics, third-party integrations and deployment methods, and platform administration.
Launch the full NSK200 simulator →Showing 10 of 20 free samples.
- Question 1Beginner
Integration and Deployment · Steering Configuration
A system administrator is reviewing the Netskope steering configuration for a new deployment. The goal is to ensure all web traffic from managed endpoints is inspected, regardless of whether the user is in the office or remote. The office network is 192.168.1.0/24. Which configuration mode for the Netskope client would be most appropriate?
Show answer & explanation
Correct answer: B
'All Traffic' mode is the simplest and most effective way to ensure all web traffic from the client is steered to the Netskope cloud for inspection, regardless of the user's location. While 'On-Premises Detection' could be used, it adds unnecessary complexity if the goal is to inspect all traffic universally. 'All Traffic' mode ensures consistent policy enforcement for both on-premises and remote users.
- Question 2Intermediate
Platform Management and Operations · Cloud Security Posture Management (CSPM)
During a security audit, an analyst discovers that several users have been granted excessive permissions within the company's AWS environment, violating the principle of least privilege. The company wants to use Netskope to continuously monitor for and alert on IAM users who have administrative-level permissions. Which Netskope feature should be used to accomplish this?
Show answer & explanation
Correct answer: B
Cloud Security Posture Management (CSPM) is the Netskope feature designed specifically to assess the configuration and security posture of IaaS environments like AWS. CSPM policies can be configured to check for specific misconfigurations, such as IAM users with administrative privileges, and generate alerts based on predefined or custom compliance rules.
- Question 3Beginner
User Activity Monitoring and Analytics · User and Entity Behavior Analytics (UEBA)
A security team is investigating an alert from Netskope Advanced Analytics indicating an unusually high volume of data has been downloaded from a sanctioned cloud application by a user. This activity is anomalous compared to the user's established baseline. What is the name of the feature within Netskope that provides this type of behavior-based threat detection?
Show answer & explanation
Correct answer: C
User and Entity Behavior Analytics (UEBA) is the core feature that establishes baseline behaviors for users and entities and then detects deviations or anomalies from those baselines. An unusually large download is a classic example of an anomaly that UEBA is designed to identify as a potential threat.
- Question 4Beginner
Data Loss Prevention (DLP) · DLP Profile Configuration
An administrator needs to create a DLP policy to prevent the upload of source code files to any cloud application. The policy should identify files with extensions like .py, .java, and .cpp. What is the most direct way to define the data to be protected in the DLP profile?
Show answer & explanation
Correct answer: C
While regex or dictionaries could potentially identify source code by content, the most direct and efficient method to target specific file types based on their extension is to use a File Profile. The administrator can create a File Profile that lists the extensions (.py, .java, .cpp) and then associate this profile with the DLP rule.
- Question 5Intermediate
Platform Management and Operations · Remote Browser Isolation (RBI)
A company is using Netskope Remote Browser Isolation (RBI) to protect users browsing high-risk websites. A user reports that they are unable to copy and paste text from an isolated website into a local application. What RBI policy setting most likely needs to be adjusted to allow this functionality?
Show answer & explanation
Correct answer: C
Netskope RBI policies include specific 'Data protection controls' that govern user interactions within an isolated session. These controls include options to allow or disallow copy/paste, printing, and file uploads/downloads. To enable copy and paste, the administrator must explicitly enable it within the data protection settings of the applicable RBI policy.
- Question 6IntermediateSelect 2
Netskope Security Cloud Fundamentals · SSL Decryption Configuration
A security engineer needs to configure Netskope to decrypt SSL/TLS traffic for inspection. However, they must ensure that traffic destined for healthcare and financial applications is never decrypted to comply with privacy regulations. Which TWO actions should the engineer take? (Select TWO)
Show answer & explanation
Correct answers: A, C
- Question 7Intermediate
Data Loss Prevention (DLP) · API Data Protection Remediation
When configuring an API Data Protection policy for a SaaS application like Box, what does the 'Remediation Action' of 'Make Private' typically do?
Show answer & explanation
Correct answer: C
The 'Make Private' remediation action leverages the SaaS application's native API to modify the sharing settings of a file. It is designed to remove permissions for external users or disable public links, effectively reverting the file's access level to be private to the owner or restricted to internal collaborators, thus mitigating exposure.
- Question 8Advanced
Netskope Security Cloud Fundamentals · SSL Decryption Troubleshooting
A user is attempting to access a web application through Netskope, but the page fails to load correctly. The Netskope client logs show errors related to 'Certificate Pinned Application'. What does this error indicate?
Show answer & explanation
Correct answer: B
Certificate pinning is a security mechanism where an application is designed to only accept a specific, pre-defined server certificate or public key. When Netskope performs SSL decryption, it presents its own certificate to the client. A pinned application will detect this mismatch, reject the connection, and cause the application to fail. The solution is to create an exception to not decrypt traffic for this application.
- Question 9Beginner
Threat Protection · Cloud Threat Exchange (CTE) Architecture
True or False: The Netskope Cloud Exchange (CTE) platform requires a dedicated physical appliance to be installed in the customer's data center to function.
Show answer & explanation
Correct answer: B
This statement is false. The Netskope Cloud Exchange (CTE) is a software-based solution that is deployed as a virtual machine (VM) within the customer's environment (e.g., VMware, AWS, Azure, GCP). It does not require a physical appliance.
- Question 10Intermediate
Threat Protection · Remote Browser Isolation (RBI) Use Case
A university wants to provide students with access to a specific online research database but is concerned about potential malware on the database's website. They want to allow full access to the content while ensuring no malicious code can reach the students' devices. Which Netskope policy action provides the best solution?
Show answer & explanation
Correct answer: A
The 'Isolate' action invokes Netskope's Remote Browser Isolation (RBI). This renders the website in a disposable container in the Netskope cloud and streams a safe, interactive visual feed to the user's browser. It allows the user to interact with the site's content fully, but no active code from the website ever reaches the endpoint, providing robust protection against web-based malware.
Ready for the real thing?
The full NSK200 simulator has every exam-style question, timed mode, and instant scoring.