nerdexam
Netskope

NSK100 · Question #54

You are working with traffic from applications with pinned certificates. In this scenario, which statement is correct?

The correct answer is A. An exception should be added to the steering configuration. When working with traffic from applications with pinned certificates, you should add an exception to the steering configuration to bypass them. Pinned certificates are a security technique that prevents man-in-the-middle attacks by validating the server certificates against a…

Deployment and Configuration of Netskope Components

Question

You are working with traffic from applications with pinned certificates. In this scenario, which statement is correct?

Options

  • AAn exception should be added to the steering configuration.
  • BThe domains used by certificate-pinned applications should be added to the authentication bypass
  • CTraffic with pinned certificates should be blocked.
  • DThe domains used by applications with pinned certificates should be allowed in an inline policy.

How the community answered

(48 responses)
  • A
    83% (40)
  • B
    10% (5)
  • C
    2% (1)
  • D
    4% (2)

Explanation

When working with traffic from applications with pinned certificates, you should add an exception to the steering configuration to bypass them. Pinned certificates are a security technique that prevents man-in-the-middle attacks by validating the server certificates against a hardcoded list of certificates in the application. If you try to intercept or inspect the traffic from such applications, they will reject the connection or display an error message. Therefore, you should add the domains used by certificate-pinned applications as exceptions in your steering configuration, so that they are not steered to Netskope for analysis and enforcement.

Topics

#certificate pinning#SSL inspection#steering configuration#traffic bypass

Community Discussion

No community discussion yet for this question.

Full NSK100 Practice