You are asked to prevent Netskope from inspecting Google traffic while maintaining visibility. According to Netskope, what is the recommended way to accomplish this task?
A.
Create a real-time policy to block Google traffic.
B.
Create a steering exception.
C.
Add a trusted CA to allow Netskope to trust the traffic source.
D.
Create a Do Not Decrypt SSL policy for the Google traffic.
The correct method is to create a Do Not Decrypt SSL policy for the Google traffic. This satisfies both parts of the requirement: Netskope does not perform SSL inspection on the selected Google traffic, but the traffic is still sent to the Netskope Cloud, preserving visibility and policy awareness. A steering exception would bypass Netskope entirely at the device level, which means the traffic would not reach the Netskope Cloud and visibility would be reduced or lost. A real-time block policy would deny the traffic, not merely prevent inspection. Adding a trusted CA only addresses certificate trust and does not define an inspection bypass. Netskope specifically distinguishes SSL decryption bypasses from steering bypasses and recommends SSL bypasses when visibility should be preserved.
================
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit