Q: 7
You are deploying a Netskope client in your corporate office network. You are aware of firewall or
proxy rules that need to be modified to allow traffic.
Which two statements are true in this scenario? (Choose two.)
Options
Discussion
Definitely C and D. The Netskope client always relies on TCP 443 for the tunnel to the cloud, and UDP 443 (DTLS) is just highly recommended for performance but not absolutely required. Never needed to set up SSL decryption (B) unless you have a specific inspection policy in place. Let me know if I missed something here.
Nah, it's not B. C and D are right here. UDP 443 lets DTLS work for better performance and TCP 443 is required for the client tunnel. B is a common trap since SSL decryption isn't usually needed for the tunnel itself. Seen this in similar practice sets.
Its C and D. Netskope client always needs TCP 443 open for the main tunnel, and DTLS (UDP 443) is recommended for performance. That's straight from the official Netskope deployment guides. Pretty sure SSL decryption isn't required in this scenario, but open to correction.
Probably B and D. If SSL decryption isn't enabled on the proxy, I don't think the traffic can be properly inspected, which could break visibility, especially with tunneling. UDP port 443 isn't always required unless you're specifically using DTLS features. Am I missing a corner case here?
Be respectful. No spam.