Q: 7
You are deploying a Netskope client in your corporate office network. You are aware of firewall or
proxy rules that need to be modified to allow traffic.
Which two statements are true in this scenario? (Choose two.)
Options
Discussion
C/D tbh. The question is about firewall/proxy *allow* rules, not inspection, so B's a red herring. A looks like a legacy TLS trap. TCP 443 for basic tunnel, UDP 443 for DTLS performance-both needed for most deployments. Disagree?
Definitely C and D. The Netskope client always relies on TCP 443 for the tunnel to the cloud, and UDP 443 (DTLS) is just highly recommended for performance but not absolutely required. Never needed to set up SSL decryption (B) unless you have a specific inspection policy in place. Let me know if I missed something here.
Nah, it's not B. C and D are right here. UDP 443 lets DTLS work for better performance and TCP 443 is required for the client tunnel. B is a common trap since SSL decryption isn't usually needed for the tunnel itself. Seen this in similar practice sets.
C and D imo, saw similar question on a practice exam and it asked about connectivity only, not inspection.
Maybe B and D
C/D? Official guide and some lab practice exams say these are the key ports but B comes up sometimes too.
C/D for this one. Option B trips up a lot of folks since SSL decryption isn't required for the Netskope client to connect, just need to allow TCP and (ideally) UDP 443 through the firewall to Netskope ranges. A is just outdated protocol stuff. Pretty sure C and D are right here, but open if someone has a different view.
C/D tbh, since those are the actual ports you need to open for Netskope client traffic.
B and D. I picked B since SSL decryption sometimes gets flagged as required for traffic security, but pretty sure it trips people up here. D's obvious for tunnel connectivity. C is probably better than B tbh, but not 100%.
Its C and D. You need TCP 443 open to Netskope for the tunnel, and allowing UDP 443 is best practice for DTLS performance. Nothing about SSL inspection or needing old TLS. Makes sense to me, but correct me if I missed something.
Be respectful. No spam.