Summer Sale Discount Flat 70% Offer - Ends in 0d 00h 00m 00s - Coupon code: 70diswrap

Zscaler ZDTA Dumps

Page: 1 / 27
Total 273 questions

Zscaler Digital Transformation Administrator Questions and Answers

Question 1

Logs indicate traffic to an internal hostname was permitted and not inspected, despite a posture-based access policy that should have blocked the session.

Which statement best explains this outcome?

Options:

A.

Inspection policy overrode access controls because of protocol heuristics.

B.

SAML attribute mapping suppressed posture checks during reauthentication.

C.

A Client Forwarding Policy bypass matched first, preventing the access policy from evaluating the session.

D.

Connector selection failed closed and defaulted to passthrough to reduce latency.

Question 2

Which of the following is a unified management console for internet and SaaS applications, private applications, digital experience monitoring and endpoint agents?

Options:

A.

identity Admin Portal

B.

Mobile Admin Portal

C.

Experience Center

D.

One API

Question 3

During the authentication process while accessing a private web application, how is the SAML assertion delivered to the service provider?

Options:

A.

HTTP Redirect on the browser

B.

API request/response sequence

C.

Through the client connector

D.

Form POST via the browser

Question 4

Zscaler forwards the server SSL/TLS certificate directly to the user ' s browser session in which situation?

Options:

A.

When traffic contains a known threat signature.

B.

When web traffic is on custom TCP ports.

C.

When traffic is exempted in SSL Inspection policy rules.

D.

When user has connected to server in the past.

Question 5

A team needs to validate who changed an entitlement and whether the change succeeded, and then correlate the activity with broader events.

Which audit source best supports this review before adding SIEM context?

Options:

A.

DLP event dashboards, because data-movement visualizations can uncover configuration edits through exposure trend shifts

B.

Firewall Insights, because network-layer telemetry can expose configuration changes through connection-state deviations

C.

Web Insights, because application traffic views can infer administrative behavior through session lineage and path analysis

D.

ZIdentity or Administrator Management audit logs, because they record administrator actions with the actor, timestamp, target, and outcome for direct attribution

Question 6

An operations team creates a Contractor ZPA Users group to provide least-privileged access to private applications and allow Zscaler policies to evaluate the group accurately.

What is the next step required to align the group with the intended authorization model?

Options:

A.

Create equivalent local user records to avoid delays in identity-provider group propagation

B.

Reduce the administrator sign-on session lifetime so contractors must refresh their credentials more frequently

C.

Add the group to device-posture requirements so posture checks compensate for missing service permissions

D.

Assign the Private Access service entitlement to the group so its members can consume ZPA subject to Access Policy controls

Question 7

A security team suspects that data exfiltration is occurring through encrypted channels to attackers.

To assess the company’s posture before tuning controls, which next step should be taken to validate whether existing protections cover this behavior?

Options:

A.

Raise the severity of egress firewall rules across segments to constrain outbound flows that might be exploited

B.

Review ZIA DLP outbound logs for anomalous uploads to unsanctioned SaaS applications and newly registered domains to gauge detection coverage

C.

Correlate ZIA threat insights with ZPA analytics to identify anomalous outbound patterns and unusual private-application access, and then verify that DLP and botnet controls apply to TLS-decrypted traffic

D.

Trigger broad Cloud Sandbox reanalysis of recent endpoint downloads to look for latent payloads that could facilitate exfiltration

Question 8

An administrator would like users to be able to use the corporate instance of a SaaS application. Which of the following allows an administrator to make that distinction?

Options:

A.

Out-of-band CASB

B.

Cloud application control

C.

URL filtering with SSL inspection

D.

Endpoint DLP

Question 9

Which of the following are types of device posture?

Options:

A.

Detect Crowdstrike, Crowdstrike ZTA score, First name

B.

Certificate Trust, File Path, Full Disk Encryption

C.

Domain Joined, Process Check, Deception Check

D.

Unauthorized Modification, OS Version, License Key

Question 10

An administrator must apply file-type controls to a subset of users while ensuring evasion-resistant detection.

Which configuration most directly maps a file-type policy to a user group and role-based security requirements?

Options:

A.

Define a global File Type Control rule that blocks risky formats and rely on identity-based reporting to address group-level differences later

B.

Enable MIME-type validation in a baseline content policy and expect extension mismatches to be handled through application restrictions

C.

Create a File Type Control rule using magic-byte, MIME-type, and file-extension checks; scope it to the target SCIM group and device posture; and place it above broader catch-all rules

D.

Create a URL Filtering rule scoped to the department and reference a custom URL category that lists file extensions for the restricted formats

Question 11

Audit logs show configuration changes performed by members of a group outside its intended administrative area.

Which step reduces this exposure while preserving required functionality?

Options:

A.

Adjust department classifications to redefine reporting lines for the group

B.

Switch to just-in-time provisioning only so that attributes are reapplied during every session

C.

Revise the group’s administrative entitlements and role assignments to constrain its scope according to least privilege

D.

Relax sign-on policies to reduce failed authentication events across locations

Question 12

An organization wants to reduce implicit trust while preserving user access to both internet and private applications.

Which configuration approach best aligns with a least-privilege design that also reduces the attack surface?

Options:

A.

Apply URL Filtering and Cloud App Control for outbound access, and enforce ZPA application segmentation with inside-out connectivity to restrict private-application reachability

B.

Adopt SD-WAN hairpinning for SaaS access and use VLAN-based controls to partition legacy environments while policies converge

C.

Standardize on shared subnets and rely on internal firewalls to control access, while using broad URL categories to shape outbound traffic

D.

Increase TLS decryption coverage for all destinations and rely on VPN access control lists to constrain private-network discovery during coexistence

Question 13

A new Zscaler Client Connector version causes intermittent tunnel drops for macOS devices in one region during a controlled rollout.

Which action enables broader deployment with minimal disruption while addressing the instability?

Options:

A.

Delay updates in every region until vendor remediation is available, accepting prolonged exposure to vulnerabilities fixed in the new version

B.

Revert the affected segment to the previous version and continue pilots in unaffected cohorts, monitoring the Zscaler Client Connector dashboard and logs for recurrence

C.

Reassign every group to an earlier stable version regardless of local stability, sacrificing rollout progress and increasing coordination overhead

D.

Push diagnostic packet-capture collection to the entire user base, accepting a performance impact for unaffected cohorts

Question 14

Zscaler Client Connector checks for software updates automatically at which interval?

Options:

A.

Every 6 hours

B.

Every 12 hours

C.

Every 2 hours

D.

Every 24 hours

Question 15

A threat actor’s command-and-control infrastructure uses hard-coded IP addresses and several domains resolved through DNS. An organization wants Zscaler to block callback attempts with minimal dependence on endpoint agents and to enforce the decision consistently for roaming users.

Which configuration best aligns with ZIA policy enforcement and the zero-trust model?

Options:

A.

Enable Browser Isolation for the suspected destinations so sessions are rendered remotely even when callbacks reach the external hosts

B.

Add the domains to a URL-category override and depend on TLS inspection to identify the traffic after connection

C.

Create a high-risk URL Filtering rule that reduces the Advanced Threat Protection risk threshold and relies on page scoring to suppress suspicious domains

D.

Create a Cloud Firewall destination group containing the indicator IP addresses and apply a high-priority Drop rule, while adding the domains to a globally blocked custom URL category

Question 16

The security exceptions allow list for Advanced Threat Protection apply to which of the following Policies?

Options:

A.

Sandbox

B.

URL Filtering

C.

File Type Control

D.

IPS Control

Question 17

What is the purpose of the Zscaler Client Connector providing the authentication token to the Zscaler Client Connector Portal after it is received from Zscaler Internet Access?

Options:

A.

To bypass multifactor authentication (MFA) during the enrollment process

B.

To immediately grant the user access to Zscaler Private Access resources

C.

To enable the portal to register the user’s device and pass the registration to Zscaler Internet Access

D.

To share the authentication token with the SAML IdP to validate the user session

Question 18

An investigation requires reviewing administrator entitlement changes from nine months ago to confirm suspected privilege escalation.

ZIdentity’s default portal retention period has already elapsed.

Which approach helps preserve and access the required audit trail for governance and forensic analysis?

Options:

A.

Export audit logs to CSV on a scheduled cadence and integrate supported audit streams with a SIEM through NSS or LSS to maintain an extended history

B.

Rely on recent sign-on policy evaluations and extrapolate prior administrator actions from current configurations

C.

Focus on bandwidth trends in Firewall Insights and infer administrative timelines from rule-utilization patterns

D.

Depend on implicit caching in the Experience Center and query historical entries during off-peak hours

Question 19

Which list of protocols is supported by Zscaler for Privileged Remote Access?

Options:

A.

RDP, VNC and SSH

B.

RDP, SSH and DHCP

C.

SSH, DNS and DHCP

D.

RDP, DNS and VNC

Question 20

To design an update-governance process that reduces disruption and supports reporting, which practice aligns with continuous improvement and defensible decision-making?

Options:

A.

Isolate security operations from IT to control messaging around updates, accepting coordination gaps during rollout

B.

Limit telemetry integration to reduce operational overhead, accepting reduced evidence for trend analysis and planning

C.

Establish regular risk-review cycles using Risk360 dashboards and MTTR metrics, tying ticket routing and wave scheduling to observed trends and remediation progress

D.

Trigger update waves on an ad hoc basis in response to incidents, accepting inconsistent visibility and reactive coordination

Question 21

A branch location must connect to Zscaler for web inspection. The underlay is trusted, the site requires a static egress IP mapped to the location, expected throughput is 700 Mbps, and high availability is not required.

Which tunnel approach and count meet these requirements with the least overhead?

Options:

A.

Configure one IPSec tunnel to the regional Service Edge and declare the bandwidth expectation to match the site profile

B.

Configure one GRE tunnel to a regional Service Edge and bind the location to a static IP to meet the throughput target

C.

Provision two GRE tunnels to separate Service Edges and balance traffic through policy-based routing

D.

Establish two IPSec peers with conservative IKE lifetimes to reduce rekey churn and configure the location’s static IP

Question 22

A log review shows requests to a sanctioned application being allowed despite a later rule intended to restrict access by time of day.

The rule set is:

    Allow the sanctioned application for All Employees

    Block the sanctioned application outside business hours for All Employees

    Log restricted-access hits

Which cause and risk are most consistent with this behavior?

Options:

A.

The time-of-day block inherits timing from device posture, which desynchronizes evaluation and produces inconsistent enforcement

B.

The initial allow rule matches first and stops further evaluation, so the time-of-day block never applies and access remains available after business hours

C.

The logging rule takes precedence because of its action type, preventing the block from being reached

D.

The sanctioned application category becomes invalid during SSL inspection, sending the request to a default allow path that bypasses time restrictions

Question 23

An administrator is provisioning new App Connectors in Microsoft Azure. A new egress policy enforces TLS inspection for outbound traffic from the workload subnets.

Which action should the ZPA administrator take to prevent App Connector registration failures?

Options:

A.

Request static NAT gateway pinning for App Connector egress so ZPA anchors microtunnels to fixed public IP addresses across virtual networks

B.

Explain that App Connector egress traffic to ZPA Service Edges must bypass TLS interception

C.

Recommend disabling App Connector health checks during application-mobility windows to prevent premature failover

D.

Advise the cloud team to delay virtual-machine scale-set events until DNS TTLs expire to minimize App Connector group changes

Question 24

How is the relationship between App Connector Groups and Server Groups created?

Options:

A.

The relationship between App Connector Groups and Server Groups is established dynamically in the Zero Trust Exchange as users try to access Applications

B.

When a new Server Group is created it points to the App Connector Groups that provide visibility to this Server Group

C.

Both App Connector Groups and Server Groups are linked together via the Data Center element

D.

When you create a new App Connector Group you must select the list of Server Groups to which it provides visibility

Question 25

What does Zscaler Advanced Firewall support that Zscaler Standard Firewall does not?

Options:

A.

Destination NAT

B.

FQDN Filtering with wildcard

C.

DNS Dashboards, Insights and Logs

D.

DNS Tunnel and DNS Application Control

Question 26

According to the Zero Trust Exchange Functional Services Diagram, which services does Antivirus belong to?

Options:

A.

Platform Services

B.

Access Control Services

C.

Security Services

D.

Advanced Threat Prevention Services

Question 27

When users are authenticated using SAML, what are the two most efficient ways of provisioning the users?

Options:

A.

Hosted User Database and Directory Server Synchronization

B.

SAML and Hosted User Database

C.

SCIM and Directory Server Synchronization

D.

SCIM and SAML Autoprovisioning

Question 28

Which of the following scenarios would generate a “Patient 0” alert?

Options:

A.

Zscaler ' s AI/ML based Smart Browser Isolation was triggered due to a users accessing a newly-registered domain.

B.

A new malicious file was detected by the sandbox due to an “allow and scan” First-Time Action in the sandbox policy.

C.

A new malicious file was detected by the sandbox due to an “quarantine” First-Time Action in the sandbox policy.

D.

Zscaler detected a HIPAA violation with in-band Data Protection scanning.

Question 29

Architecture reviews reveal trusted network bypass is configured for headquarters, while roaming users route through the service edge. The goal is stricter controls for accessing SaaS application when off-network traffic.

What policy ensures the best coverage for this scenario?

Options:

A.

ZPA App Segment policies that constrain ports for legacy private applications accessed by remote users

B.

Leverage conditional access policies to ensure client sessions only come from known location or via the Zero Trust Exchange

C.

CASB app governance policies that rely on user risk scores to restrict cloud activities across all locations

D.

Data center firewall tiers that mirror internal VLANs and apply deny rules for roaming identities

Question 30

When configuring a ZDX custom application and choosing Type: ' Network ' and completing the configuration by defining the necessary probe(s), which performance metrics will an administrator NOT get for users after enabling the application?

Options:

A.

Server Response Time

B.

ZDX Score

C.

Client Gateway IP Address

D.

Disk I/O

Question 31

A company observes risky uploads from unmanaged devices connecting over public Wi-Fi to cloud storage. The devices intermittently fail posture checks, and logs show inconsistent category enforcement.

Which action places the stricter control where it will be applied consistently to off-network traffic?

Options:

A.

Attach tenant-restriction profiles to a limited set of users in CASB and rely on inherited group mappings to constrain cloud activity

B.

Add connector-level ZPA policies that restrict FQDNs for storage endpoints and deny remote TCP ports used by synchronization clients

C.

Create a ZIA rule set scoped to roaming users and unauthenticated sessions, positioned early in the policy order to enforce stronger Cloud App Control and URL Filtering

D.

Deploy branch bandwidth classes that shape storage traffic in sublocations to reduce large upload attempts from remote users

Question 32

Which Zscaler feature detects whether an intruder is accessing your internal resources?

Options:

A.

SandBox

B.

SSL Decryption Bypass

C.

Browser Isolation

D.

Deception

Question 33

A branch office uses a trusted-network bypass that routes traffic directly to the internet. Incident reviews show that unmanaged laptops at the branch are reaching SaaS applications without device-posture evaluation.

Which action should the administrator take next to ensure that devices are compliant before receiving access?

Options:

A.

Amend the trusted-network bypass and enforce posture-based access through Zscaler Client Connector for branch traffic

B.

Expand application segments to redefine which subnets are considered internal for discovery

C.

Add Caution actions to web policies to prompt users about risks on popular collaboration platforms

D.

Lower bandwidth quotas for the branch to discourage access spikes from unmanaged devices

Question 34

How can we protect the Zscaler Client Connector from unauthorized alterations to its files and registry settings?

Options:

A.

StrictEnforcement CLI Parameter of ZCC installation file

B.

TamperProofing options in Forwarding Profile

C.

AntiTampering CLI Parameter of ZCC installation file

D.

DisableTampering options in Forwarding Profile

Question 35

Which command-line parameter is used to activate tamper proofing during the installation of Zscaler Client Connector?

Options:

A.

--secureInstall

B.

--antiTamper

C.

--disableTampering

D.

--enableAntiTampering

Question 36

Which of the following is a benefit of tunneling?

Options:

A.

Increased latency.

B.

Enhanced data security.

C.

Support for only TCP/IP traffic.

D.

Increased header size.

Question 37

Which field within a URL filtering rule must be defined for Browser Isolation to work?

Options:

A.

Groups

B.

User Agent

C.

Departments

D.

Device Trust

Question 38

What does Zscaler Cloud Sandbox protect from?

Options:

A.

It protects sensitive data from leaving through external channels.

B.

It protects from potential zero-day threats and advanced persistent threats.

C.

It protects cloud workloads from lateral movement.

D.

It protects users from known malicious files and attacks.

Question 39

An administrator needs to refine a custom URL category so that low-risk sites in that category are allowed while high-risk or uncertain sites are isolated or blocked, without weakening overall protection.

Which configuration approach aligns with this goal?

Options:

A.

Defer behavior to Cloud App Control so that URL Filtering is bypassed for known applications that match the category criteria

B.

Consolidate controls under a broad global allow rule and depend on bandwidth shaping to constrain risky traffic within the category

C.

Retain parent-category membership and reference the custom category in a higher-priority rule that applies Allow or Isolate actions as needed

D.

Replace parent-category assignments with a custom list to reduce overlap and simplify rule evaluation

Question 40

What is the purpose of a Microtunnel (M-Tunnel) in Zscaler?

Options:

A.

To provide an end-to-end communication channel between ZCC clients

B.

To provide an end-to-end communication channel to Microsoft Applications such as M365

C.

To create an end-to-end communication channel to Azure AD for authentication

D.

To create an end-to-end communication channel to internal applications

Question 41

The Security Alerts section of the Alerts dashboard has a graph showing what information?

Options:

A.

Top 5 Malware Programs Detected

B.

Top 5 Viruses by Region

C.

Top 5 Threats by Systems Impacted

D.

Top 5 Unified Threat Yara Options

Question 42

Which of the following methods can be used to notify an end-user of a potential DLP violation in Zscaler’s Workflow Automation solution?

Options:

A.

Notifications in MS Teams / Slack

B.

SMS text message.

C.

Automated phone call.

D.

Twitter post with custom hashtag

Question 43

Which of the following is a common use case for adopting Zscaler’s Data Protection?

Options:

A.

Reduce your Internet Attack Surface

B.

Prevent download of Malicious Files

C.

Prevent loss to Internet and Cloud Apps

D.

Securely connect users to Private Applications

Question 44

Security teams are vetting approaches to private application access across two merging organizations to reduce post-acquisition lateral movement.

Which approach best constrains internal discovery and probing while preserving required connectivity?

Options:

A.

Adopt ZPA user-to-app segmentation with inside-out connectivity so users reach defined applications and cannot traverse broader IP ranges.

B.

Centralize VPN concentrators and restrict subnet access by department to contain exploratory traffic during initial entitlement mapping.

C.

Extend shared VLANs across the combined data centers and use access control lists to discourage host-to-host enumeration during audits.

D.

Apply IDS signatures at core routing layers to flag port scans and perform rate limiting until both environments complete segmentation.

Question 45

A regional data center hosts a payroll web application that communicates with a database over TCP port 1433. Recent telemetry shows attempted lateral movement from the compromised payroll web server to unrelated internal services. Contractors also have ZPA access to a separate internal wiki that resides in the same segment as the payroll application.

Which action should the administrator take to refine microsegmentation and reduce risk?

Options:

A.

Apply service-to-service policies tied to server identity so that the payroll application can reach the database on the required port, and deny other application servers from initiating flows to the database

B.

Consolidate both applications into one broad segment and add IPS signatures to suppress suspicious traffic between servers

C.

Configure a trusted-network condition that prioritizes corporate subnets so contractor sessions default to restricted routing policies

D.

Increase the global user risk-score threshold before allowing access to the wiki segment to gate contractor sessions

Question 46

What does Advanced Threat Protection defend users from?

Options:

A.

Vulnerable JavaScripts

B.

Large iFrames

C.

Malicious active content

D.

Command injection attacks

Question 47

A campaign alert identifies affected users and devices across multiple sites.

Which action should the SOC lead take to strengthen response performance and reduce repetitive manual tasks?

Options:

A.

Trigger a SOAR playbook through platform APIs to create tickets, block domains in ZIA, and isolate affected endpoints

B.

Assign manual triage to each site and postpone enforcement changes until endpoint teams confirm independent findings

C.

Disable automated notifications to collaboration tools to reduce noise while analysts evaluate logs for each user separately

D.

Increase the alert-severity classification so future campaign alerts appear higher in queues despite limited context enrichment

Question 48

An organization mandates strict BYOD controls and does not permit endpoint agents on personal devices. Which Zscaler deployment approach aligns with this requirement while maintaining data protection for access to corporate applications?

Options:

A.

Adopt agentless access by combining Browser Isolation for SaaS applications and clientless ZPA for private applications

B.

Require self-enrollment in Zscaler Client Connector across personal endpoints to enforce forwarding profiles

C.

Depend on location-based rules and user agents to shape traffic from home and public networks

D.

Use per-application Zscaler Client Connector tunnels for unmanaged devices to segment private application access

Question 49

Which Zscaler Client Connector configuration setting allows administrators to assign a hosted PAC file to individual users?

Options:

A.

Traffic Steering in the App Profile

B.

Forwarding Profile Action in the Forwarding Profile

C.

Global Settings in the App Profile

D.

Global Settings in the Forwarding Profile

Question 50

What are the two types of Probe supported in ZDX?

Options:

A.

Web Probes and Cloud Path Probes

B.

Application Probes and Network Probes

C.

Page Speed Probes and Connection Speed Probes

D.

SaaS Probes and Router Probes

Question 51

Which of the following are correct request methods when configuring a URL filtering rule with a Caution action?

Options:

A.

Connect, Get, Head

B.

Options, Delete, Put

C.

Get, Delete, Trace

D.

Connect, Post, Put

Question 52

When the Zscaler Client Connector launches, which portal does it initially interact with to understand the user ' s domain and identity provider (IdP)?

Options:

A.

Zscaler Private Access (ZPA) Portal

B.

Zscaler Central Authority

C.

Zscaler Internet Access (ZIA) Portal

D.

Zscaler Client Connector Portal

Question 53

What is the recommended default rule for the cloud-gen firewall configuration when deploying a new ZIA tenant?

Options:

A.

Block all traffic

B.

Permit all traffic

C.

Disable the firewall

D.

Allow only web traffic (ports 80/443)

Question 54

A new customer has just purchased Zscaler for Users.

Which of the following Zscaler service entitlements is enabled by default?

Options:

A.

ZPA

B.

Deception

C.

ZIA

D.

ZDX

Question 55

A company must enforce least-privileged access to private applications when contractors connect from varying locations using devices with inconsistent security posture. The security team wants decisions to use identity and per-session context instead of broad network assumptions.

Which approach best meets the requirement?

Options:

A.

Build ZPA Access Policy rules around a SCIM-synchronized contractor group, apply device-posture conditions to sensitive application segments, and retain a final catch-all deny rule

B.

Prioritize ZIA URL Filtering rules that use department attributes to shape contractor access, and leave ZPA unchanged

C.

Use location groups to provide contractors with tiered access to most internal services and defer device evaluation to downstream controls

D.

Require session MFA for contractor authentication and use SAML attributes to relax private-application access broadly

Question 56

Which of the following enables the discovery of newly observed domains within three minutes of the domain coming online?

Options:

A.

IP Chicken

B.

MXToolbox

C.

Farsight Feed

D.

Dig

Question 57

Which of the following statements most accurately describes Zero Trust Connections?

Options:

A.

They require that SSH inspection be enabled.

B.

They are dependent on a fixed / static network environment.

C.

They are independent of any network for control or trust.

D.

They require IPv6.

Question 58

An administrator needs to SSL inspect all traffic but one specific URL category. The administrator decides to create two policies, one to inspect all traffic and another one to bypass the specific category. What is the logical sequence in which they have to appear in the list?

Options:

A.

Both policies are incompatible, so it is not possible to have them together.

B.

First the policy for the exception Category, then further down the list the policy for the generic " inspect all. "

C.

First the policy for the generic " inspect all " , then further down the list the policy for the exception Category.

D.

All policies both generic and specific will be evaluated so no specific order is required.

Question 59

When configuring Applications to be monitored, what probe types can be created?

Options:

A.

Page Fetch Time Probe and Cloud Path Probe

B.

Web Probe and Page Fetch Time Probe

C.

Page Fetch Time Probe and Server Response time Probe

D.

Web Probe and Cloud Path Probe

Question 60

Administrators report that a content-inspection rule is blocking source-code uploads to a sanctioned repository, although uploads should be permitted only for that application and the engineering group.

Which action and policy ownership are most appropriate for addressing the issue?

Options:

A.

Engage the DLP policy owners to refine the rule context, scope the exception to the approved application and engineering group, and retain enforcement everywhere else

B.

Ask SIEM analysts to suppress correlated alerts for source-code uploads to reduce operational noise

C.

Direct the firewall team to relax deep packet inspection on developer ports to prevent inspection-related disruptions

D.

Ask the identity team to remap group attributes so engineers inherit a less restrictive baseline and bypass the data-protection rule

Question 61

A firewall policy set evaluates rules from top to bottom and stops at the first match. Rule 1 allows Marketing users outbound TCP 80/443 to any destination. Rule 2 blocks the Anonymizers network-application category globally. Rule 3 blocks all traffic to 203.0.113.0/24.

What outcome and risk are most likely when a Marketing user accesses an anonymizer over HTTPS?

Options:

A.

Traffic matches the Marketing allow at Rule 1, the global anonymizer block is not evaluated, and the user gains access to anonymizers, increasing exposure

B.

Traffic is deferred to application categorization first and is blocked at Rule 2, with the user denied but with ambiguous logging

C.

Traffic is inspected by IPS before Firewall Filtering and is dropped preemptively, reducing the effect of rule order but causing false positives

D.

Traffic collides with the destination block at Rule 3 because of subnet inference, resulting in intermittent denial and noisy alerts

Question 62

What is the recommended minimum number of App connectors needed to ensure resiliency?

Options:

A.

2

B.

6

C.

4

D.

3

Question 63

Does the Access Control suite include features that prevent lateral movement?

Options:

A.

No. Access Control Services will only control access to the Internet and cloud applications.

B.

Yes. Controls for segmentation and conditional access are part of the Access Control Services.

C.

Yes. The Cloud Firewall will detect network segments and provide conditional access.

D.

No. The endpoint firewall will detect network segments and steer access.

Question 64

Cloud Sandbox detonations begin returning indicators of compromise associated with TrickBot infrastructure, including domains and IP addresses. The SOC wants consistent enforcement in ZIA with less manual effort.

Which operational approach best fits this goal?

Options:

A.

Perform daily manual updates to a URL blocklist and a separate firewall address group for each new indicator, deferring changes during peak hours

B.

Switch IPS to detect-only mode to gather more evidence and postpone blocking until campaign indicators stabilize across multiple users

C.

Increase Advanced Threat Protection risk sensitivity and rely on page-risk analysis to identify newly observed destinations

D.

Use a SOAR workflow with Zscaler APIs to add domains to a custom URL category and IP addresses to a firewall destination group, with block policies applied automatically

Question 65

Which of the following can be used as Trusted Network criteria in Zscaler Client Connector?

Options:

A.

DNS Server, DHCP Server and Hostname/IP

B.

DHCP Server, DNS Search Domain and Hostname/IP

C.

Hostname/IP, DNS Server and DNS Search Domain

D.

Hostname/IP, DNS Search Domain and DHCP Server

Question 66

Malicious File Protection exclusions can be configured for which type of file?

Options:

A.

Files sent using the PPTP protocol

B.

Files sent using the SCP protocol

C.

Files sent using the RTSP protocol

D.

Password-encrypted files

Question 67

In which of the following SaaS apps can you protect data at rest via Zscaler ' s out-of-band CASB solution?

Options:

A.

Yahoo Mail

B.

Twitter.

C.

Google Drive.

D.

Facebook.

Question 68

Zscaler Data Protection supports custom dictionaries. What actions can administrators take with these dictionaries to protect data in motion?

Options:

A.

Define specific keywords, phrases, or patterns relevant to their organization ' s sensitive data policy.

B.

Define specific governance and regulations relevant to their organization ' s sensitive data policy.

C.

Define specific SaaS tenant relevant to their organization ' s sensitive data policy

D.

Define specific file types relevant to their organization ' s sensitive data policy.

Question 69

Zscaler Platform Services works upon unencrypted data from encrypted communications due to which of the following?

Options:

A.

Antivirus

B.

Tenant Restrictions

C.

Web Filtering

D.

TLS Inspection

Question 70

What Zscaler control can be implemented to limit exposure to malicious content?

Options:

A.

Role Based Access control (RBAC)

B.

Bandwidth Controls

C.

File type Controls

D.

Zscaler Digital Experience

Question 71

Which attack type is characterized by a commonly used website or service that has malicious content like malicious JavaScript running on it?

Options:

A.

Watering Hole Attack

B.

Pre-existing Compromise

C.

Phishing Attack

D.

Exploit Kits

Question 72

Which is an example of Inline Data Protection?

Options:

A.

Preventing the copying of a sensitive document to a USB drive.

B.

Preventing the sharing of a sensitive document in OneDrive.

C.

Analyzing a customer’s M365 tenant for security best practices.

D.

Blocking the attachment of a sensitive document in webmail.

Question 73

Which Risk360 key focus area observes a broad range of event, security configurations, and traffic flow attributes?

Options:

A.

External Attack Surface

B.

Prevent Compromise

C.

Data Loss

D.

Lateral Propagation

Question 74

An executive summary correlates Risk360 category-contribution views with audit commitments: identity risk has decreased, but data-loss risk is trending upward; business-unit mean time to remediate (MTTR) variance suggests uneven remediation; and leadership requests board-ready evidence of continuous improvement mapped to the NIST Cybersecurity Framework (CSF).

What is the appropriate next step based on this summary and goal?

Options:

A.

Emphasize a single recent incident in a narrative memo and deprioritize category-contribution drill-downs to avoid distracting detail

B.

Replace Unified Vulnerability Management tasking with ad hoc email assignments to reduce tooling reliance, even if closure tracking becomes inconsistent

C.

Hold reporting until after policy changes take effect to avoid confusing auditors with fluctuating score baselines

D.

Produce framework-aligned dashboards with MTTR variance reporting and schedule cross-team reviews to track category-level risk reduction

Question 75

What is the default policy configuration setting for checking for Viruses?

Options:

A.

Allow

B.

Block

C.

Unwanted Applications

D.

Malware Protection

Question 76

What is a key advantage of Zscaler ' s unified approach to data protection?

Options:

A.

Reducing visibility into data movement across the cloud.

B.

Working together with traditional hardware appliances.

C.

Increasing complexity and manageability in DLP security policies.

D.

Eliminating of gaps associated with multiple point solutions.

Question 77

Which of the following external-facing API gateways can enforce authentication for access to Zscaler Client Connector API resources?

Options:

A.

Postman

B.

ZPA API

C.

ZIdentity

D.

OneAPI

Question 78

An operations team relies on API-driven exports of ZDX scores and Firewall Insights to track application performance over time. The team encounters periodic HTTP 429 errors during peak hours, and performance regressions are missed when exports fail.

Which mitigation best reduces blind spots that contribute to preventable performance issues?

Options:

A.

Shorten token-expiry intervals to force more frequent reauthentication and improve client statefulness under contention

B.

Increase the number of parallel API workers during peak hours to clear the telemetry backlog faster

C.

Assign broader API scopes to the client so retries can fetch more datasets during each export cycle

D.

Use client-side rate limiting with exponential backoff, schedule batch exports during off-peak periods, and optimize queries to reduce redundant calls

Question 79

What Malware Protection setting can be selected when setting up a Malware Policy?

Options:

A.

Isolate

B.

Bypass

C.

Block

D.

Do Not Decrypt

Question 80

How deeply can the Zscaler service scan recursively compressed files for malicious content?

Options:

A.

It scans only uncompressed files.

B.

Up to three layers of recursive compression.

C.

Up to two layers of recursive compression.

D.

Up to five layers of recursive compression.

Question 81

What is the preferred method for authentication to access OneAPI?

Options:

A.

OpenID Connect (OIDC)

B.

Transport Layer Security (TLS)

C.

Security Assertion Markup Language (SAML)

D.

System for Cross-domain Identity Management (SCIM)

Page: 1 / 27
Total 273 questions