A regional data center experiences intermittent loss of access to an internal ERP application through ZPA during maintenance windows. The site runs two virtual-machine App Connectors mapped to the ERP segment. Maintenance affects one hypervisor at a time, and support tickets show that sessions drop sporadically but recover.
Which change should the ZPA administrator request to improve continuity within the site’s constraints?
Which of the following are correct request methods when configuring a URL filtering rule with a Caution action?
When correlating indicators of privilege escalation with administrator behavior, which log type provides the most direct visibility into role changes and entitlement modifications for administrative accounts?
A tenant’s Cloud App Control policy permits Webmail globally. Security requires members of the Sales group to receive a CAUTION prompt when accessing personal Webmail, while all other groups must continue to receive unrestricted access.
Sales users and other groups are currently matched by a Cloud App Control rule that allows all Webmail.
Which action should the administrator take to meet the requirement for the Sales group?
To design an update-governance process that reduces disruption and supports reporting, which practice aligns with continuous improvement and defensible decision-making?
When the Zscaler Client Connector launches, which portal does it initially interact with to understand the user ' s domain and identity provider (IdP)?
Security teams are vetting approaches to private application access across two merging organizations to reduce post-acquisition lateral movement.
Which approach best constrains internal discovery and probing while preserving required connectivity?
A managed device on a known corporate LAN cannot reach a private application through the Zero Trust Exchange because of forwarding behavior.
Which bypass configuration would enable access while respecting how policies are evaluated?
You are planning to use Z-Tunnel 2.0 as the forwarding mechanism to support TCP, UDP, and ICMP traffic going to ZIA.
What type of tunnel will Zscaler Client Connector form with the Zero Trust Exchange?
A contractor in the Field_Eng SAML group attempts to access an internal CAD application through ZPA from a branch designated as a Trusted Network. The Access Policy requires Field_Eng membership AND a device-posture profile confirming full-disk encryption and a CrowdStrike ZTA score above 80. The user passes the ZTA score requirement, but Device Posture reports that disk encryption is disabled.
Which enforcement outcome should be expected for this session?
An administrator wants to allow users to access a wide variety of untrusted URLs. Which of the following would allow users to access these URLs in a safe manner?
Which attack type is characterized by a commonly used website or service that has malicious content like malicious JavaScript running on it?
Cross-Site Scripting (XSS) Protection can protect you against which two types of exploits?
Which Zscaler feature detects whether an intruder is accessing your internal resources?
A security lead reviews an executive summary: data-loss risk is driven by high-volume uploads to risky SaaS applications and unmanaged generative AI use; MTTR for BU-West remains high because of ticket-routing delays; and the board wants a 15% reduction in the data-loss risk score within 60 days. Peer benchmarks are similar but show identity risk as the primary driver elsewhere.
Which action should be taken next?
An operations team creates a Contractor ZPA Users group to provide least-privileged access to private applications and allow Zscaler policies to evaluate the group accurately.
What is the next step required to align the group with the intended authorization model?
Which approach minimizes disruption when deploying Client Connector software updates across a heterogeneous user base while maintaining the ability to recover from defects?
Which options must be selected when configuring Zscaler Client Connector for Strict Enforcement?
A contractor team in a regional lab must upload ZIP archives to an approved code repository but must not upload archives or executables to generic file-sharing sites. A sudden increase in renamed executables, such as an .exe file disguised with a .jpg extension, complicates monitoring.
Which action best applies the correct file-type policy to this team while aligning with security requirements?
What enables zero trust to be properly implemented and enforced between an originator and the destination application?
Which Zscaler Client Connector configuration setting allows administrators to assign a hosted PAC file to individual users?
Which feature does Zscaler Client Connector Z-Tunnel 2.0 enable over Z-Tunnel 1.0?
A macOS desktop application connecting to api.vendor.com fails during the TLS handshake whenever SSL/TLS Inspection is enabled. The application uses certificate pinning, and users intermittently connect through networks that prefer Google QUIC.
Which action should the security administrator take to restore functionality while retaining inspection for unrelated traffic?
Which of the following statements most accurately describes Zero Trust Connections?
Which proprietary technology does Zscaler use to calculate risk attributes dynamically for websites?
Which Advanced Threats policy can be configured to protect users against a credential attack?
When a SAML IDP returns an assertion containing device attributes, which Zscaler component consumes the attributes first, for policy creation?
A campus requires 1.5 Gbps of throughput to Zscaler Service Edges. The underlay is trusted, and the design explicitly excludes high availability.
Which option meets the bandwidth target with the minimum tunnel count?
An investigation requires reviewing administrator entitlement changes from nine months ago to confirm suspected privilege escalation.
ZIdentity’s default portal retention period has already elapsed.
Which approach helps preserve and access the required audit trail for governance and forensic analysis?
Which of the following statements accurately reflects Zscaler ' s file size limitation for Malware Protection scans?
The Zscaler Gen AI Security Report gives visibility and insight into an organization ' s use of generative AI applications. What kind of log will include Prompt for administrators to view for different prompts entered by users in those applications?
Which of the following refers to employees’ use of unauthorized applications and services?
A test administrator is not present in the identity provider and requires constrained access to configure ZIA policies for a short period.
Which step provides controlled administrative capability?
Which of the following is an open standard used to provide automatic updates of a user ' s group and department information? A Import B. LDAP Sync C. SCIM D. SAML
What transport mechanism will Zscaler Client Connector use to forward traffic to the Zero Trust Exchange when configured for Tunnel 2.0?
Logs indicate traffic to an internal hostname was permitted and not inspected, despite a posture-based access policy that should have blocked the session.
Which statement best explains this outcome?
What happens after the Zscaler Client Connector receives a valid SAML response from the Identity Provider (IdP)?
As technology that exists for a very long period of time, has URL Filtering lost its effectiveness?
Malicious File Protection exclusions can be configured for which type of file?
A sequence in the Administrator Audit Log shows several failed sign-ins from an unfamiliar location, followed by a successful administrator sign-in and a near-immediate role upgrade on the same identity.
Which entry combination constitutes the clearest escalation indicator requiring a containment step?
A Gold-class SaaS application performs poorly even though its bandwidth class has a generous minimum and moderate maximum. Usage dashboards show available capacity during incidents, and other applications are not saturating the link.
What is the most defensible next step to prevent recurring degradation?
In which of the following SaaS apps can you protect data at rest via Zscaler ' s out-of-band CASB solution?
Which of the following connects Zscaler users to the nearest Microsoft 365 servers for a better experience?
What is the ZIA feature that ensures certain SaaS applications cannot be accessed from an unmanaged device?
Which of the following is the preferred method for authentication in a OneAPI environment?
If you ' re migrating from an on-premises proxy, you will already have a proxy setting configured within the browser or within the system. With Tunnel Mode, the best practice is to configure what type of proxy configuration?
An administrator is provisioning new App Connectors in Microsoft Azure. A new egress policy enforces TLS inspection for outbound traffic from the workload subnets.
Which action should the ZPA administrator take to prevent App Connector registration failures?
An organization wants to let a contractor group reach a single internal web application while restricting access to all other private resources. The team needs the policy to reflect contractor group-membership changes during normal operations and to ensure device risk is accounted for per session.
Which configuration most effectively enforces least privilege in this case?
A data center requires connectivity to Zscaler for traffic inspection without an encryption requirement. The site must support a defined bandwidth profile of 2.2 Gbps and has no high-availability requirement.
Which configuration uses the minimum number of tunnels while meeting the throughput requirement?
A user authenticates through the correct IdP and is synchronized as a member of the SCIM group Contractors. Device posture is compliant, the network is public, and the user attempts to reach an internal HR portal categorized under an internal App Segment for employees.
The Access Policy rule order is:
Allow High_Value_Assets with Posture
Block High_Value_Assets
Allow Contractor Apps
Block Contractors from Internal Apps
Allow Internal Apps_2_Employees
Which outcome is most consistent with rule ordering and the evaluated attributes?
An organization mandates strict BYOD controls and does not permit endpoint agents on personal devices. Which Zscaler deployment approach aligns with this requirement while maintaining data protection for access to corporate applications?
You ' ve configured the API connection to automatically download Microsoft Information Protection (MIP) labels into ZIA; where will you use these imported labels to protect sensitive data in motion?
Zscaler forwards the server SSL/TLS certificate directly to the user ' s browser session in which situation?
Which types of Botnet Protection are supplied by Advanced Threat Protection?
Your company has a new ZIA subscription. Which is the most effective and secure method of provisioning users?
When users are authenticated using SAML, what are the two most efficient ways of provisioning the users?
Which Risk360 key focus area observes a broad range of event, security configurations, and traffic flow attributes?
Which of the following can be used as Trusted Network criteria in Zscaler Client Connector?
Audit logs show configuration changes performed by members of a group outside its intended administrative area.
Which step reduces this exposure while preserving required functionality?
Which Zscaler forwarding mechanism creates a loopback address on the machine to forward the traffic towards Zscaler cloud?
Which Platform Service enables visibility into the headers and payload of encrypted transactions?
Which command-line parameter is used to activate tamper proofing during the installation of Zscaler Client Connector?
A security team suspects that data exfiltration is occurring through encrypted channels to attackers.
To assess the company’s posture before tuning controls, which next step should be taken to validate whether existing protections cover this behavior?
What is the recommended default rule for the cloud-gen firewall configuration when deploying a new ZIA tenant?