Question 1
Multiple answersA financial services company is implementing Netskope Private Access (NPA) to provide Zero Trust access to internal applications. They have a requirement that access to their core banking API, hosted in an AWS VPC, must be restricted to only corporate-issued devices that have the latest security patches. Which two components are essential to enforce this device posture-based access control? (Select TWO)
Answer and explanation
Correct answers: A, C
Netskope Cloud Exchange is required to share risk signals and device posture information from third-party systems like UEM or EDR solutions (e.g., CrowdStrike, VMware Carbon Black) with the Netskope Security Cloud.
The Private Access policy is where the enforcement happens. It uses the Device Classification tags (populated by Cloud Exchange from the UEM/EDR) as a condition to grant or deny access to the specific private application.