PDF問題(2026年最新)実際のNetskope NSK100日本語試験問題 [Q19-Q37]

Share

PDF問題(2026年最新)実際のNetskope NSK100日本語試験問題

問題集返金保証付きのNSK100日本語問題集には90%オフされます

質問 # 19
NetskopeのNewEdge Securityクラウドネットワークインフラストラクチャについて、正しい記述を3つ選びなさい。
(3つ選択してください。)

  • A. Google Cloud Platform 上にセキュリティサービスをデプロイすることで、パブリッククラウドを活用しています。
  • B. すべてのデータセンターで、Microsoft および Google との直接ピアリングが含まれます。
  • C. これは、過剰にプロビジョニングされ、非常に柔軟性があり、拡張性を考慮して構築されたプライベートセキュリティクラウドネットワークです。
  • D. 追加料金やパブリッククラウドインフラストラクチャ、仮想PoPへの依存なしに、単一の統合ネットワークを提供します。
  • E. 事前定義された可用性ゾーンへのアクセスを制限することで、管理者の作業を簡素化します。

正解:B、C、D

解説:
Netskope's NewEdge Security Cloud Network Infrastructure is a global network that powers the Netskope Security Cloud, providing real-time inline and out-of-band API-driven services for cloud and web security.
Three statements that are correct about Netskope's NewEdge Security Cloud Network Infrastructure are:
It includes direct peering with Microsoft and Google in every data center. This means that Netskope has established high-speed, low-latency connections with these major cloud service providers, ensuring optimal performance and user experience for their customers. Direct peering also reduces the risk of network congestion, packet loss, or routing issues that may affect the quality of service.
It is a private security cloud network that is massively over provisioned, highly elastic, and built for scale. This means that Netskope owns and operates its own network infrastructure, without relying on third-party providers or public cloud platforms. Netskope has invested over $150 million to build the world's largest and fastest security private cloud, with data centers in more than 65 regions and growing.
Netskope can dynamically scale its network capacity and resources to meet the growing demand and traffic volume of its customers, without compromising on security or performance.
It delivers a single, unified network with no surcharges or reliance on public cloud infrastructure or virtual PoPs. This means that Netskope provides a consistent and transparent network service to its customers, regardless of their location or device. Netskope does not charge any additional fees or hidden costs for accessing its network services, unlike some other providers that may impose surcharges based on geography or bandwidth usage. Netskope also does not use virtual points of presence (PoPs) that are hosted on public cloud platforms, which may introduce latency, complexity, or security risks.
References: Netskope NewEdgeNetskope NewEdge Data SheetNetskope SASE


質問 # 20
Netskopeのセキュアアクセスサービスエッジ(SASE)アーキテクチャの主な利点は2つあります。

  • A. ベイズ型スパムフィルタリング
  • B. 単一管理コンソール
  • C. ポリシー適用にオンプレミスのハードウェアは不要です
  • D. エンドポイント検出および対応 (EDR)

正解:B、C

解説:
Two primary advantages of Netskope's Secure Access Service Edge (SASE) architecture are: no on-premises hardware required for policy enforcement and single management console. Netskope's SASE architecture delivers network and security services as cloud-based services that can be accessed from any location and device. This eliminates the need for on-premises hardware appliances such as firewalls, proxies, VPNs, etc., that are costly to maintain and scale. Netskope's SASE architecture also provides a single management console that allows administrators to configure and monitor all the network and security services from one place. This simplifies IT operations and reduces complexity and overhead. References: Netskope SASEWhat is SASE?


質問 # 21
Netskope Cloudプラットフォームが提供するセキュリティ制御機能はどれですか?(3つ選択してください。)

  • A. アイデンティティライフサイクル管理
  • B. 脅威からの保護
  • C. エンドポイントのマルウェア対策
  • D. SMTP のデータ損失防止
  • E. クラウドセキュリティ態勢管理

正解:B、D、E

解説:
Three security controls that are offered by the Netskope Cloud platform are: C. cloud security posture management, E. threat protection, and B. data loss prevention for SMTP.
Cloud security posture management is a service that provides continuous assessment and remediation of public cloud deployments for risks, threats, and compliance issues. Netskope CSPM leverages the APIs available from cloud service providers such as AWS, Azure, and GCP to scan the cloud infrastructure for misconfigurations, such as insecure permissions, open ports, unencrypted data, etc. Netskope CSPM also provides security posture policies, profiles, and rules that can be customized to match the security standards and best practices of the organization or industry.
Threat protection is a capability to detect and block malware, ransomware, phishing, and other cyber threats that may compromise cloud data or users. Netskope threat protection uses advanced techniques such as machine learning, sandboxing, threat intelligence, and behavioral analysis to identify and prevent malicious activities in real time.Netskope threat protection also integrates with third-party solutions such as antivirus engines, firewalls, SIEMs, etc., to provide comprehensive defense across the cloud and web1.
Data loss prevention for SMTP is a feature that allows you to protect sensitive data that is sent or received via email. Netskope DLP for SMTP can scan email messages and attachments for predefined or custom data patterns, such as credit card numbers, social security numbers, health records, etc., and apply appropriate actions, such as block, quarantine, encrypt, notify, etc., based on the DLP policies.Netskope DLP for SMTP can also support multiple email domains and routing rules for different groups of users2.


質問 # 22
Skope ITアプリケーションページの下に、リスクの高いシャドウITクラウドアプリケーションのみを表示するクイックビューを提供する必要があります。
このシナリオでは、このタスクを達成するためにどの2つのフィルターの組み合わせを使用しますか?(2つ選択してください。)

  • A. 承認済み = いいえ
  • B. ユーザーデバイスの種類 = Windowsデバイス
  • C. CCL = 高。研究中。
  • D. CCL = 中程度。低、不良

正解:A、D

解説:
To provide a quick view under the Skope IT Applications page showing only risky shadow IT cloud applications being used, you can use two filter combinations: Sanctioned = No and CCL = Medium, Low, Poor. The Sanctioned filter allows you to select whether you want to see only sanctioned or unsanctioned apps in your organization. Sanctioned apps are those that are approved and managed by your IT department, while unsanctioned apps are those that are used without authorization or oversight by your employees. Shadow IT refers to the use ofunsanctioned apps that may pose security or compliance risks for your organization. The CCL filter allows you to select the Cloud Confidence Level (CCL) ratings of the apps you want to see. The CCL rating is a measure of how enterprise-ready a cloud app is based on various criteria such as security, auditability, business continuity, etc. The CCL rating ranges from Excellent to Poor, with Excellent being the most secure and compliant and Poor being the least. Risky cloud apps are those that have a low CCL rating, such as Medium, Low, or Poor. By applying these two filters, you can narrow down the list of apps to only those that are unsanctioned and have a low CCL rating, which indicates that they are risky shadow IT cloud applications being used in your organization. References: SkopeIT ApplicationsNetskope Cloud Confidence Index


質問 # 23
あなたは大手小売チェーンと取引しており、その顧客データに関して懸念を抱いています。顧客のクレジットカードデータが転送中や保存中に決して漏洩しないよう保護したいと考えています。このような場合、どの規制遵守基準を適用してこのデータを管理すべきでしょうか?

  • A. AES-256
  • B. SOC 3
  • C. ISO 27001
  • D. PCI-DSS

正解:D

解説:
PCI-DSS stands for Payment Card Industry Data Security Standard, which is a set of security requirements for organizations that handle credit card data. It aims to protect cardholder data from unauthorized access, disclosure, or theft, both in transit and at rest. PCI-DSS covers various aspects of security, such as encryption, authentication, firewall, logging, monitoring, andincident response. If you are working with a large retail chain and have concerns about their customer data, you should use PCI-DSS as the regulatory compliance standard to govern this data. SOC 3, AES-256, and ISO 27001 are not specific to credit card data protection, although they may have some relevance to general security practices. References: [PCI-DSS], [SOC 3], [AES-256],
[ISO 27001].


質問 # 24
NetskopeクライアントをWebモードで展開したところ、複数のユーザーからメッセンジャーアプリケーションが動作しなくなったとの報告がありました。このアプリケーションを許可するリアルタイムポリシーは設定済みですが、さらに調査したところ、独自の暗号化方式を使用していることが判明しました。すべてのユーザーにアクセスを許可しつつ、ある程度の可視性を維持する必要があります。
このシナリオでは、どの設定変更を行うことでこのタスクを達成できますか?

  • A. リアルタイムポリシーを変更して、メッセンジャーアプリケーションをブロックします。
  • B. リアルタイム ポリシーで使用できるカスタム コネクタを使用して、新しいカスタム クラウド アプリケーションを作成します。
  • C. SSL復号化セクションにポリシーを追加して、メッセンジャードメインをバイパスします。
  • D. ステアリング設定を編集し、メッセンジャーアプリケーションのステアリング例外を追加します。

正解:C

解説:
In this scenario, you have deployed the Netskope client in Web mode, which is a feature that allows you to steer your users' web traffic to Netskope for inspection and policy enforcement. However, some users report that their messenger application is no longer working, even though you have a specific real-time policy that allows this application. Upon further investigation, you discover that the messenger application is using proprietary encryption, which means that Netskope cannot decrypt or inspect the traffic from this application.
To resolve this issue, you need to permit access to all the users and maintain some visibility. The configuration change that would accomplish this task is to add a policy in the SSL decryption section to bypass the messenger domain(s). This will allow Netskope to skip the decryption process for the traffic from the messenger application and pass it through without any modification. However, Netskope will still be able to log some basic information about the traffic, such as source, destination, bytes, etc., for visibility purposes.
Changing the real-time policy to block the messenger application, creating a new custom cloud application using the custom connector, or editing the steering configuration and adding a steering exception for the messenger application are not configuration changes that would accomplish this task, as they would either prevent access to the application, require additional steps or resources, or reduce visibility. References: [Netskope Client], Netskope Security Cloud Operation & Administration (NSCO&A) - Classroom Course, Module 4: Decryption Policy.


質問 # 25
Netskopeクライアントがテナントに接続する際に問題が発生しています。
このシナリオでは、クライアントマシンからログを収集する方法を2つ挙げてください。(2つ選択してください。)

  • A. NetskopeクライアントのUl「概要」ページより
  • B. Netskopeクライアントのシステムトレイアイコンから
  • C. nsdiagコマンドを使用してコマンドラインから
  • D. NetskopeクライアントのUI設定ページから

正解:A、C

解説:
To collect the logs from the client machine when you have an issue with the Netskope client connecting to the tenant, two ways that you can use are: from the Netskope client UI About page and from the command line using the nsdiag command. From the Netskope client UI About page, you can click on the "Collect Logs" button to generate a zip file containing all the relevant logs and configuration files from the client machine.
You can then send this zip file to Netskope support for troubleshooting. From the command line, you can use the nsdiag command with various options to collect different types of logs and diagnostic information from the client machine. For example, you can use nsdiag -l to collect all logs, nsdiag -c to collect configuration files, nsdiag -t to collect traffic statistics, etc. You can also use nsdiag -h to see all available options and usage instructions. You can then send the output files to Netskope support for troubleshooting. References: Netskope Client Configuration overviewInstall and Test the Client - Netskope Knowledge Portal


質問 # 26
ある企業がGREトンネルを使用してNetskopeへのトラフィック誘導を試みている。初期設定後、ユーザーがブラウザから外部ウェブサイトにアクセスできなくなることに気づいた。
この問題の考えられる原因を3つ挙げてください。(3つ選択してください。)

  • A. Netskopeプラットフォームで設定されているGREピアが正しくありません。
  • B. GREトンネルの事前共有キーが間違っています。
  • C. ルートマップが間違ったルーターインターフェースに適用されました。
  • D. Netskope は GRE トンネルをサポートしていません。
  • E. 企業のファイアウォールがGREトラフィックをブロックしている可能性があります。

正解:A、C、E

解説:
In this scenario, there are three probable causes for the issue of users not being able to access external websites from their browsers after attempting to steer traffic to Netskope using GRE tunnels. One cause is that the configured GRE peer in the Netskope platform is incorrect, which means that the Netskope POP that is supposed to receive the GRE traffic from the customer's network is not matching the IP address of the customer's router that is sending the GRE traffic. This will result in a failure to establish a GRE tunnel between the customer and Netskope. Another cause is that the corporate firewall might be blocking GRE traffic, which means that the firewall rules are not allowing the GRE protocol (IP protocol number 47) or the UDP port 4789 (for VXLAN encapsulation) to pass through. This will result in a failure to send or receive GRE packets between the customer and Netskope. A third cause is that the route map was applied to the wrong router interface, which means that the configuration that specifies which traffic should be steered to Netskope using GRE tunnels was not applied to the correct interface on the customer's router. This will result in a failure to steer the desired traffic to Netskope. The pre-shared key for the GRE tunnel is incorrect is not a probable cause for this issue, as GRE tunnelsdo not use pre-shared keys for authentication or encryption.
Netskope does support GRE tunnels, so this is not a cause for this issue either. References: [Netskope Secure Forwarder], Netskope Security Cloud Operation & Administration (NSCO&A) - Classroom Course, Module
3: Steering Configuration, Lesson 3: Secure Forwarder.


質問 # 27
承認済みのクラウドサービスで帯域外API接続を使用する場合、管理者が利用できる2つの機能は何ですか?(2つ選択してください。)

  • A. リアルタイムアクセスを許可する
  • B. マルウェアを隔離する
  • C. センシティブなコンテンツを見つける
  • D. アップロードをブロックする

正解:B、C

解説:
When using an out-of-band API connection with your sanctioned cloud service, two capabilities available to the administrator are: to quarantine malware and to find sensitive content. An out-of-band API connection is a method of integrating Netskope with your cloud service provider using the APIs exposed by the cloud service.
This allows Netskope to access the data that is already stored in the cloud service and perform retrospective inspection and enforcement ofpolicies. One capability that the administrator can use with an out-of-band API connection is to quarantine malware. This means that Netskope can scan the files in the cloud service for malware, ransomware, phishing, and other threats, and move them to a quarantine folder or delete them if they are found to be malicious. Another capability that the administrator can use with an out-of-band API connection is to find sensitive content. This means that Netskope can scan the files in the cloud service for sensitive data, such as personal information, intellectual property, or regulated data, and apply data loss prevention (DLP) policies to protect them. For example, Netskope can encrypt, redact, or watermark the files that contain sensitive content, or notify the administrator or the file owner about the exposure. References: Netskope API ProtectionReal-time Control and Data Protection via Out-of-Band API


質問 # 28
承認済みの Google ドライブ インスタンス内のファイルで DLP 違反が発生しました。ファイルは削除済み状態です。Netskope を使用して、この DLP 違反に関する情報を特定する必要があります。このシナリオでは、次のうちどの記述が正しいですか?

  • A. インシデントを作成するために、フォレンジックプロファイルを作成する必要があります。
  • B. ファイルが削除されると、そのファイルに関する DLP インシデントは表示されません。
  • C. DLP違反はインシデントダッシュボードで確認できます。
  • D. DLP違反はフォレンジックプロファイルで確認できます。

正解:C

解説:
To locate information pertaining to a DLP violation on a file in your sanctioned Google Drive instance, you can use the Incidents dashboard in Netskope. The Incidents dashboard provides a comprehensive view of all the incidents that have occurred in your cloud environment, such as DLP violations, malware infections, anomalous activities, etc. You can filter the incidents by various criteria, such as app name, incident type, severity, user name, etc. You can also drill down into each incident to see more details, such as file name, file path, file owner, file size, file type, etc. The Incidents dashboard can show DLP violations for files that are in a deleted state, as long as they are still recoverable from the trash bin of the app. If the file is permanently deleted from the app, then the incident will not be visible in the dashboard. References: Netskope Incidents Dashboard


質問 # 29
顧客から、複数のリアルタイムポリシーを作成するよう依頼されました。ポリシーAは、ユーザーがクラウドストレージアプリケーション上でファイルをダウンロード、アップロード、または共有した際にアラートを生成します。ポリシーBは、ユーザーがMacまたはWindows以外のオペレーティングシステム(OS)からクラウドストレージにファイルをダウンロードすることをブロックします。この場合、ポリシーAが最も制限が緩く、ポリシーBが最も制限が厳しいと言えます。
この状況において、正しい記述はどれですか?

  • A. ポリシーAはポリシーBより先に実行されます。
  • B. この2つの政策は実際には一緒に機能しません。
  • C. ポリシーの順序は重要ではありません。ポリシーは互いに独立しています。
  • D. ポリシーBはポリシーAより先に実行されます。

正解:D

解説:
In this scenario, policy B is more restrictive than policy A, as it blocks users from downloading files from any OS other than Mac or Windows for cloud storage, while policy A only generates alerts when any user downloads, uploads, or shares files on a cloud storage application. Therefore, policy B should be implemented before policy A, as the policy order determines the order of evaluation and enforcement of the policies. If policy A is implemented before policy B, then policy B will never be triggered, as policy A will match all the download activities for cloud storage and generate alerts. The policy order is important; policies are not independent of each other, as they may have overlapping or conflicting conditions and actions. These two policies would actually work together, as long as they are ordered correctly. References: Netskope Security Cloud Operation & Administration (NSCO&A) - Classroom Course, Module 5: Real-Time Policies, Lesson 3:
Policy Order.


質問 # 30
Netskopeのソリューションと比較して、従来のプロキシを使用する場合の制限は何ですか?

  • A. Netskopeアーキテクチャにはオンプレミスコンポーネントが必要です。
  • B. 従来のソリューションは、企業ユーザーとリモートユーザーに対して、より高いパフォーマンスと拡張性を提供します。
  • C. ポリシーを適用するには、トラフィックが顧客のオンプレミスセキュリティスタックを経由する必要があります。
  • D. 従来のオンプレミスソリューションでは、オンプレミスユーザーからのトラフィックを保護することができません。

正解:C

解説:
A limitation of using a legacy proxy compared to Netskope's solution is that to enforce policies, traffic needs to traverse back through a customer's on-premises security stack. This creates latency, bandwidth, and scalability issues for remote users and cloud applications. Netskope's solution, on the other hand, leverages a cloud-native architecture that provides high-performance and scalable inspection of traffic from any location and device. References: [Netskope Architecture Overview]


質問 # 31
顧客がCCIスコアリングをデフォルトの客観的スコアから別のスコアに変更しました。このシナリオにおいて、変更を行う正当な理由は何でしょうか?

  • A. 顧客は、CCIデータベースでまだ評価されていない新しいSaaSアプリケーションを発見しました。
  • B. 顧客の組織は、自社のデータの所有権を主張するベンダーに対して、より高いビジネスリスクの重み付けをします。
  • C. 顧客は、劣悪な顧客サービスを提供したアプリケーションベンダーを罰したいと考えています。
  • D. 顧客の組織は、現在「調査中」とされているSaaSアプリケーションを使用しています。

正解:B

解説:
The CCI scoring is a way to measure the security posture of cloud applications based on a set of criteria and weights. The default objective score is calculated by Netskope using industry best practices and standards.
However, customers can change the CCI scoring to suit their own business needs and risk appetite. For example, a customer may want to place a higher business risk weight on vendors that claim ownership of their data, as this may affect their data sovereignty and privacy rights. Changing the CCI scoring for this reason would be valid, as it reflects the customer's own security requirements and preferences. Changing the CCI scoring for other reasons, such as discovering a new SaaS application, punishing an application vendor, or using an application under research, would not be valid, as they do not align with the purpose and methodology of the CCI scoring. References: Netskope Security Cloud Operation & Administration (NSCO&A) - Classroom Course, Module 7: Cloud Confidence Index (CCI), Lesson 1: CCI Overview and Lesson 2: CCI Scoring.


質問 # 32
NetskopeクライアントUIを使用して、クライアント関連の問題についてサービスリクエストチケットを作成する必要があります。このシナリオでは、システムトレイアイコンを右クリックして、クライアントログを生成します。

  • A. ヘルプ
  • B. 設定
  • C. トラブルシューティング
  • D. ログを保存する

正解:C

解説:
To create a service request ticket for a client-related issue using the Netskope client UI, you need to generate the client logs by right-clicking on the system tray icon and choosing Troubleshoot. This will open a window where you can select the option to Save Logs, which will create a zip file containing the client logs. You can then attach this file to your service request ticket and provide any relevant details about the issue. Choosing Save logs, Configuration, or Help will not generate the client logs, as they perform different functions, such as saving the current configuration, opening the settings menu, or opening the help page. References: [Netskope Client Troubleshooting].


質問 # 33
組織内におけるシャドウITの例として、どの2つのユースケースが挙げられますか?(2つ選択してください。)

  • A. 企業ユーザーが機密データを共有するために使用している、承認済みのWetransfer
  • B. 請負業者が機密性の低いデータをアップロードするために使用する、承認済みのSalesforceアカウント
  • C. 企業ユーザーが機密性の低いデータをアップロードするために使用する、承認されていないGoogleドライブアカウント
  • D. 企業ユーザーが機密データをアップロードするために使用している、承認されていない Microsoft 365 OneDrive アカウント

正解:C、D

解説:
Shadow IT is the term for the unauthorized use of IT resources and functions by employees within an organization. It can include cloud services, software, and hardware that are not approved or managed by the IT department. Two use cases that would be considered examples of shadow IT within an organization are: an unsanctioned Microsoft 365 OneDrive account being used by a corporate user to upload sensitive data and an unsanctioned Google Drive account used by a corporate user to upload non-sensitive data. In both cases, the corporate user is using a personal cloud storage service that is not sanctioned by the organization to store work-related data. This can introduce security risks, such as data leakage, data loss, compliance violations, malware infections, etc. The IT department may not have visibility or control over these cloud services or the data stored in them. References: What is shadow IT? | CloudflareWhat is Shadow IT? | IBM


質問 # 34
マルウェア感染の疑いのある事案を調査し、それが誤報であったことを確認した。

  • A. ハッシュをファイルフィルタに追加します。
  • B. ファイルを隔離します。VirusTotalのWebサイトでハッシュ値を調べます。
  • C. パケットキャプチャをpcapファイルにエクスポートします。
  • D. このシナリオでは、同じファイルが別のインシデントを引き起こすのをどのように防ぎますか?

正解:A

解説:
A file filter is a list of file hashes that you can use to exclude files from inspection by Netskope. By adding the hash of the file that triggered a false alarm to the file filter, you can prevent it from being scanned again by Netskope and avoid generating another incident. Quarantining the file, exporting the packet capture, or looking up the hash at VirusTotal are not effective ways to prevent the same file from triggering another incident, as they do not affect how Netskope handles the file. References: Netskope Security Cloud Operation & Administration (NSCO&A) - Classroom Course, Module 6: Data Loss Prevention, Lesson 2: File Filters.


質問 # 35
リスクの高いコラボレーションアプリケーションへのデータファイルのアップロードをすべてのユーザーがブロックできるようにする必要があります。このタスクを実行するには、NetskopeのCASB内でどの要素を設定する必要がありますか?

  • A. リアルタイムポリシー
  • B. DLPルール
  • C. DLPプロファイル
  • D. ブロック通知

正解:A

解説:
A real-time policy is a type of policy in Netskope's CASB that allows you to control the actions that users can perform on cloud applications in real time. You can use a real-time policy to block all users from uploading data files into risky collaboration applications by specifying the following elements: the application category (such as Collaboration), the activity (such as Upload), the file type (such as Data), the risk level (such as High or Very High), and the action (such as Block). A DLP rule, a DLP profile, and a block notification are not sufficient to accomplish this task, as they are either sub-components or outcomes of a real-time policy. References: Netskope Security Cloud Operation & Administration (NSCO&A) - Classroom Course, Module 5: Real-Time Policies, Lesson 1: Real-Time Policy Overview and Lesson 2: Real-Time Policy Configuration.


質問 # 36
展示する

展示されているインターフェースのどの部分で、管理者は違反の深刻度を設定したり、所有者を割り当てたり、進捗状況を追跡したり、違反コンテンツの抜粋を用いてフォレンジック分析を実行したりできますか?

  • A. レポート -> 新規レポート
  • B. インシデント -> DLP
  • C. Skope IT-> アラート
  • D. API対応保護 -> インベントリ

正解:B

解説:
The portion of the interface shown in the exhibit that allows an administrator to set severity, assign ownership, track progress, and perform forensic analysis with excerpts of violating content is Incidents -> DLP. The Incidents dashboard provides a comprehensive view of all the incidents that have occurred in your cloud environment, such as DLP violations, malware infections, anomalous activities, etc. You can filter the incidents by various criteria, such as app name, incident type, severity, user name, etc. You can also drill down into each incident to see more details, such as file name, file path, file owner, file size, file type, etc. You can also assign an owner to an incident, change its status and severity, add notes or comments, and view the excerpts of the violating content that triggered the DLP policy. References: Netskope Incidents Dashboard


質問 # 37
......

更新された2026年09月合格させるNSK100日本語試験リアル練習テスト問題:https://www.passtest.jp/Netskope/NSK100-JPN-shiken.html