Q: 2
You are using Skope IT to analyze and correlate a security incident. You are seeing too many events
generated by API policies. You want to filter for logs generated by the Netskope client only.
Options
Discussion
Option D, Using
access_method neq Client in query mode seems logical since it filters out non-client events, but I think the official guide emphasizes dropdown selection. I saw a similar scenario in practice questions, so maybe double-check with labs.C or A, depends if the question means "generated by the Client" specifically or if tunnel connections via the client count too. If it said "most secure method" instead, maybe D would make sense?
Be respectful. No spam.