nerdexam
Netskope

NSK100 · Question #11

A customer changes CCI scoring from the default objective score to another score. In this scenario, what would be a valid reason for making this change?

The correct answer is B. The customer's organization places a higher business risk weight on vendors that claim ownership. The CCI scoring is a way to measure the security posture of cloud applications based on a set of criteria and weights. The default objective score is calculated by Netskope using industry best practices and standards. However, customers can change the CCI scoring to suit their…

Cloud Security and SD-WAN

Question

A customer changes CCI scoring from the default objective score to another score. In this scenario, what would be a valid reason for making this change?

Options

  • AThe customer has discovered a new SaaS application that is not yet rated in the CCI database.
  • BThe customer's organization places a higher business risk weight on vendors that claim ownership
  • CThe customer wants to punish an application vendor for providing poor customer service.
  • DThe customer's organization uses a SaaS application that is currently listed as "under research".

How the community answered

(47 responses)
  • A
    2% (1)
  • B
    83% (39)
  • C
    11% (5)
  • D
    4% (2)

Explanation

The CCI scoring is a way to measure the security posture of cloud applications based on a set of criteria and weights. The default objective score is calculated by Netskope using industry best practices and standards. However, customers can change the CCI scoring to suit their own business needs and risk appetite. For example, a customer may want to place a higher business risk weight on vendors that claim ownership of their data, as this may affect their data sovereignty and privacy rights. Changing the CCI scoring for this reason would be valid, as it reflects the customer's own security requirements and preferences. Changing the CCI scoring for other reasons, such as discovering a new SaaS application, punishing an application vendor, or using an application under research, would not be valid, as they do not align with the purpose and methodology of the CCI scoring.

Topics

#CCI scoring#cloud confidence index#SaaS risk weighting#Netskope

Community Discussion

No community discussion yet for this question.

Full NSK100 Practice