Pre-Summer Sale - Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70dumps

ZDTA Questions and Answers

Question # 6

Which Zscaler feature detects whether an intruder is accessing your internal resources?

A.

SandBox

B.

SSL Decryption Bypass

C.

Browser Isolation

D.

Deception

Full Access
Question # 7

An administrator needs to SSL inspect all traffic but one specific URL category. The administrator decides to create two policies, one to inspect all traffic and another one to bypass the specific category. What is the logical sequence in which they have to appear in the list?

A.

Both policies are incompatible, so it is not possible to have them together.

B.

First the policy for the exception Category, then further down the list the policy for the generic "inspect all."

C.

First the policy for the generic "inspect all", then further down the list the policy for the exception Category.

D.

All policies both generic and specific will be evaluated so no specific order is required.

Full Access
Question # 8

Which of the following can be used as Trusted Network criteria in Zscaler Client Connector?

A.

DNS Server, DHCP Server and Hostname/IP

B.

DHCP Server, DNS Search Domain and Hostname/IP

C.

Hostname/IP, DNS Server and DNS Search Domain

D.

Hostname/IP, DNS Search Domain and DHCP Server

Full Access
Question # 9

What is a key advantage of Zscaler's unified approach to data protection?

A.

Reducing visibility into data movement across the cloud.

B.

Working together with traditional hardware appliances.

C.

Increasing complexity and manageability in DLP security policies.

D.

Eliminating of gaps associated with multiple point solutions.

Full Access
Question # 10

Which options must be selected when configuring Zscaler Client Connector for Strict Enforcement?

A.

cloudName and policyToken

B.

userDomain and deviceToken

C.

cloudName and deviceToken

D.

userDomain and policyToken

Full Access
Question # 11

Zscaler Data Protection supports custom dictionaries. What actions can administrators take with these dictionaries to protect data in motion?

A.

Define specific keywords, phrases, or patterns relevant to their organization's sensitive data policy.

B.

Define specific governance and regulations relevant to their organization's sensitive data policy.

C.

Define specific SaaS tenant relevant to their organization's sensitive data policy

D.

Define specific file types relevant to their organization's sensitive data policy.

Full Access
Question # 12

What is Zscaler's rotation policy for intermediate certificate authority certificates?

A.

Certificates are rotated every 90 days and have a 180-day expiration.

B.

Lifetime certificates have no expiration date.

C.

Certificates are rotated every seven days and have a 14-day expiration.

D.

Certificates are issued dynamically and expire in 24 hours.

Full Access
Question # 13

Which of the following methods can be used to notify an end-user of a potential DLP violation in Zscaler’s Workflow Automation solution?

A.

Notifications in MS Teams / Slack

B.

SMS text message.

C.

Automated phone call.

D.

Twitter post with custom hashtag

Full Access
Question # 14

What is the minimum polling interval if one has ZDX Advanced license enabled in their tenant?

A.

1 minute

B.

10 minutes

C.

15 minutes

D.

5 minutes

Full Access
Question # 15

Which are valid criteria for use in Access Policy Rules for ZPA?

A.

Group Membership, ZIA Risk Score, Domain Joined, Certificate Trust

B.

Username, Trusted Network Status, Password, Location

C.

SCIM Group, Time of Day, Client Type, Country Code

D.

Department, SNI, Branch Connector Group, Machine Group

Full Access
Question # 16

Which algorithm is used to determine the PageRisk?

A.

Zscaler licenses a PageRisk Feed from a 3rd party.

B.

It applies deobfuscation to all data.

C.

It is the RSA Security algorithm.

D.

Zscaler applies a multi data algorithm to the web page.

Full Access
Question # 17

How do Access Policies relate to the Application Segments and Application Segment Groups?

A.

When a condition is met, an Access Policy can either allow or block access to Application Segments OR Application Segment Groups.

B.

When a condition is met, an Access Policy can allow access to Application Segments Groups and block access to Application Segment.

C.

When a condition is met. an Access Policy can either allow or block access to Application Segments and Application Segment Groups.

D.

When a condition is met, an Access Policy can allow access to Application Segments and block access to Application Segment Groups.

Full Access
Question # 18

When configuring Zscaler Private Access, what is the function of the Server Group?

A.

Maps FQDNs to IP Addresses

B.

Maps Applications to FQDNs

C.

Maps App Connector Groups to Application Segments

D.

Maps Applications to Application Groups

Full Access
Question # 19

Which attack type is characterized by a commonly used website or service that has malicious content like malicious JavaScript running on it?

A.

Watering Hole Attack

B.

Pre-existing Compromise

C.

Phishing Attack

D.

Exploit Kits

Full Access
Question # 20

What is the preferred method for authentication to access OneAPI?

A.

OpenID Connect (OIDC)

B.

Transport Layer Security (TLS)

C.

Security Assertion Markup Language (SAML)

D.

System for Cross-domain Identity Management (SCIM)

Full Access
Question # 21

Layered defense throughout an organization security platform is valuable because of which of the following?

A.

Layered defense increases costs to attackers to operate.

B.

Layered defense from multiple vendor solutions easily share attacker data.

C.

Layered defense ensures attackers are prevented eventually.

D.

Layered defense with multiple endpoint agents protects from attackers.

Full Access
Question # 22

According to the Zero Trust Exchange Functional Services Diagram, which services does Antivirus belong to?

A.

Platform Services

B.

Access Control Services

C.

Security Services

D.

Advanced Threat Prevention Services

Full Access
Question # 23

What are the two types of Probe supported in ZDX?

A.

Web Probes and Cloud Path Probes

B.

Application Probes and Network Probes

C.

Page Speed Probes and Connection Speed Probes

D.

SaaS Probes and Router Probes

Full Access
Question # 24

An administrator wants to allow users to access a wide variety of untrusted URLs. Which of the following would allow users to access these URLs in a safe manner?

A.

Browser Isolation

B.

App Connector

C.

Zscaler Private Access

D.

Zscaler Client Connector

Full Access
Question # 25

The Zscaler Gen AI Security Report gives visibility and insight into an organization's use of generative AI applications. What kind of log will include Prompt for administrators to view for different prompts entered by users in those applications?

A.

SaaS Security Logs

B.

Web Insights Logs

C.

Gen AI Insights Logs

D.

Advanced Firewall Logs

Full Access
Question # 26

What does TLS Inspection for Zscaler Internet Access secure public internet browsing with?

A.

Storing connection streams for future customer review.

B.

Removing certificates and reconnecting client connection using HTTP.

C.

Intermediate certificates are created for each client connection.

D.

Logging which clients receive the original webserver certificate.

Full Access
Question # 27

What conditions can be referenced for Trusted Network Detection?

A.

Hostname Resolution, Network Adapter IP, Default Gateway

B.

DNS Servers, DNS Search Domain, Network Adapter IP

C.

Hostname Resolution, DNS Servers, Geo Location

D.

DNS Search Domain, DNS Server, Hostname Resolution

Full Access
Question # 28

You've configured the API connection to automatically download Microsoft Information Protection (MIP) labels into ZIA; where will you use these imported labels to protect sensitive data in motion?

A.

Creating a custom DLP Dictionary

B.

Creating a SaaS Security Posture Control Policy.

C.

Creating a File Type Control Policy.

D.

Creating a custom DLP Policy.

Full Access
Question # 29

What is the default timer in ZDX Advanced for web probes to be sent?

A.

1 minute

B.

10 minutes

C.

30 minutes

D.

5 minutes

Full Access
Question # 30

How does Zscaler ensure that sensitive structured data used in the EDM process is not stored in its cloud environment?

A.

By storing sensitive structured data on servers managed by trusted Zscaler staff for enhanced security.

B.

By using an on-premises VM to index data and only sending hashed values to the cloud.

C.

By requiring customers to manually hash the data and upload it to the cloud.

D.

By encrypting sensitive data directly before storing it in the cloud.

Full Access
Question # 31

Which of the following is a feature of ITDR (Identity Threat Detection and Response)?

A.

Prevents Patient Zero Infections

B.

Reduces identity related risks

C.

Prevents connections to Embargoed Countries

D.

Blocks malicious traffic by dropping packets

Full Access
Question # 32

Which of the following is a common use case for adopting Zscaler’s Data Protection?

A.

Reduce your Internet Attack Surface

B.

Prevent download of Malicious Files

C.

Prevent loss to Internet and Cloud Apps

D.

Securely connect users to Private Applications

Full Access
Question # 33

Which filtering policy blocked access to the Network Application?

A.

Sandbox

B.

Browser Control

C.

Firewall Filtering

D.

DLP

Full Access
Question # 34

Which of the following is the preferred method for authentication in a OneAPI environment?

A.

OIDC

B.

SCIM

C.

SAML

D.

EntraID

Full Access
Question # 35

Which is an example of Inline Data Protection?

A.

Preventing the copying of a sensitive document to a USB drive.

B.

Preventing the sharing of a sensitive document in OneDrive.

C.

Analyzing a customer’s M365 tenant for security best practices.

D.

Blocking the attachment of a sensitive document in webmail.

Full Access
Question # 36

Which of the following are correct request methods when configuring a URL filtering rule with a Caution action?

A.

Connect, Get, Head

B.

Options, Delete, Put

C.

Get, Delete, Trace

D.

Connect, Post, Put

Full Access
Question # 37

What is the purpose of the Zscaler Client Connector providing the authentication token to the Zscaler Client Connector Portal after it is received from Zscaler Internet Access?

A.

To bypass multifactor authentication (MFA) during the enrollment process

B.

To immediately grant the user access to Zscaler Private Access resources

C.

To enable the portal to register the user’s device and pass the registration to Zscaler Internet Access

D.

To share the authentication token with the SAML IdP to validate the user session

Full Access
Question # 38

What transport mechanism will Zscaler Client Connector use to forward traffic to the Zero Trust Exchange when configured for Tunnel 2.0?

A.

Zscaler Client Connector will encapsulate the user's traffic in GRE tunnels to the ZTE.

B.

Zscaler Client Connector will encapsulate the user's traffic in IPSec tunnels to the ZTE.

C.

Zscaler Client Connector will encapsulate the user's traffic in DTLS/TLS tunnels to the ZTE.

D.

Zscaler Client Connector will encapsulate the user's traffic in HTTP Connect tunnels to the ZTE.

Full Access
Question # 39

What Malware Protection setting can be selected when setting up a Malware Policy?

A.

Isolate

B.

Bypass

C.

Block

D.

Do Not Decrypt

Full Access
Question # 40

When filtering user access to certain web destinations what can be a better option, URL or Cloud Application filtering Policies?

A.

Cloud Application policies provide better access control.

B.

URL filtering policies provide better access control.

C.

Wherever possible URL policies are recommended.

D.

Both provide the same filtering capabilities.

Full Access
Question # 41

In support of data privacy for TLS/SSL inspection, when you subscribe to ZIA, you enter into what kind of agreement?

A.

Zscaler Compliance Policy

B.

Zscaler Privacy Policy

C.

Acceptable Use Policy

D.

Zscaler Data Processing Agreement

Full Access
Question # 42

The security exceptions allow list for Advanced Threat Protection apply to which of the following Policies?

A.

Sandbox

B.

URL Filtering

C.

File Type Control

D.

IPS Control

Full Access
Question # 43

What ports and protocols are forwarded to the Zero Trust Exchange when Zscaler Client Connector is using Tunnel 2.0?

A.

TCP ports 80, 443 and 8080 only.

B.

Any HTTP/HTTPS traffic as well as DNS.

C.

All TCP and UDP ports as well as ICMP traffic.

D.

All Web ports as well as FTP and SSH.

Full Access
Question # 44

Which of the following is unrelated to the properties of 'Trusted Networks'?

A.

DNS Server

B.

Default Gateway

C.

Org ID

D.

Network Range

Full Access
Question # 45

Which of the following components is installed on an endpoint to connect users to the Zero Trust Exchange regardless of their location - home, work, while traveling, etc.?

A.

Client connector

B.

Private Service Edge

C.

IPSec/GRE Tunnel

D.

App Connector

Full Access