Month End Sale - Special 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 75onlydt

ZDTA Questions and Answers

Question # 6

A regional data center experiences intermittent loss of access to an internal ERP application through ZPA during maintenance windows. The site runs two virtual-machine App Connectors mapped to the ERP segment. Maintenance affects one hypervisor at a time, and support tickets show that sessions drop sporadically but recover.

Which change should the ZPA administrator request to improve continuity within the site’s constraints?

A.

Reduce application health-check frequency so ZPA waits longer before reassigning sessions during transient failures

B.

Add another App Connector on a separate host to increase the available capacity for session redistribution

C.

Increase App Connector CPU reservations to reduce contention spikes during hypervisor maintenance

D.

Modify Access Policy priorities to prefer identity attributes that remain stable during maintenance windows

Full Access
Question # 7

Which of the following are correct request methods when configuring a URL filtering rule with a Caution action?

A.

Connect, Get, Head

B.

Options, Delete, Put

C.

Get, Delete, Trace

D.

Connect, Post, Put

Full Access
Question # 8

When correlating indicators of privilege escalation with administrator behavior, which log type provides the most direct visibility into role changes and entitlement modifications for administrative accounts?

A.

Firewall Insights reports centered on rule hits and bandwidth consumption at egress points

B.

ZIdentity Administrator Audit Log filtered for entitlement updates and role assignments

C.

Web Insights transaction logs focusing on URL categories and inline policy actions

D.

Endpoint DLP telemetry summarizing sensitive-data handling and removable-media events

Full Access
Question # 9

A tenant’s Cloud App Control policy permits Webmail globally. Security requires members of the Sales group to receive a CAUTION prompt when accessing personal Webmail, while all other groups must continue to receive unrestricted access.

Sales users and other groups are currently matched by a Cloud App Control rule that allows all Webmail.

Which action should the administrator take to meet the requirement for the Sales group?

A.

Configure a time-based URL Filtering rule for Webmail that targets Sales so business hours force re-evaluation under URL Filtering criteria

B.

Create a Cloud App Control rule that targets the Sales group and personal Webmail applications, set its action to CAUTION, and place it above the general allow rule

C.

Place the Sales URL Filtering rule below the global acceptable-use baseline so broader actions are inherited before group-specific evaluation

D.

Create a Bandwidth Control rule for Webmail that applies to Sales, expecting URL Filtering to engage when traffic is constrained

Full Access
Question # 10

What is the main purpose of Sandbox functionality?

A.

Block malware that we have previously identified

B.

Build a test environment where we can evaluate the result of policies

C.

Identify Zero-Day Threats

D.

Balance threat detection across customers around the world

Full Access
Question # 11

To design an update-governance process that reduces disruption and supports reporting, which practice aligns with continuous improvement and defensible decision-making?

A.

Isolate security operations from IT to control messaging around updates, accepting coordination gaps during rollout

B.

Limit telemetry integration to reduce operational overhead, accepting reduced evidence for trend analysis and planning

C.

Establish regular risk-review cycles using Risk360 dashboards and MTTR metrics, tying ticket routing and wave scheduling to observed trends and remediation progress

D.

Trigger update waves on an ad hoc basis in response to incidents, accepting inconsistent visibility and reactive coordination

Full Access
Question # 12

Which of the following scenarios would generate a “Patient 0” alert?

A.

Zscaler ' s AI/ML based Smart Browser Isolation was triggered due to a users accessing a newly-registered domain.

B.

A new malicious file was detected by the sandbox due to an “allow and scan” First-Time Action in the sandbox policy.

C.

A new malicious file was detected by the sandbox due to an “quarantine” First-Time Action in the sandbox policy.

D.

Zscaler detected a HIPAA violation with in-band Data Protection scanning.

Full Access
Question # 13

How is data gathered with ZDX Advanced client performance?

A.

By generating synthetic transactions to designated Internet and Private applications every 5 minutes and measuring the performance of those sessions.

B.

By constantly analyzing live user sessions to both Internet and Private applications and measuring the performance of those sessions.

C.

By using AI predictive analysis ZDX can extrapolate near-term client performance based upon recent past data observed.

D.

By constantly analyzing live user sessions to critical SaaS applications and measuring the performance of those sessions.

Full Access
Question # 14

Which of the following secures all IP unicast traffic?

A.

Secure Shell (SSH)

B.

Tunnel with local proxy

C.

Enforce PAC

D.

Z-Tunnel 2.0

Full Access
Question # 15

When the Zscaler Client Connector launches, which portal does it initially interact with to understand the user ' s domain and identity provider (IdP)?

A.

Zscaler Private Access (ZPA) Portal

B.

Zscaler Central Authority

C.

Zscaler Internet Access (ZIA) Portal

D.

Zscaler Client Connector Portal

Full Access
Question # 16

Security teams are vetting approaches to private application access across two merging organizations to reduce post-acquisition lateral movement.

Which approach best constrains internal discovery and probing while preserving required connectivity?

A.

Adopt ZPA user-to-app segmentation with inside-out connectivity so users reach defined applications and cannot traverse broader IP ranges.

B.

Centralize VPN concentrators and restrict subnet access by department to contain exploratory traffic during initial entitlement mapping.

C.

Extend shared VLANs across the combined data centers and use access control lists to discourage host-to-host enumeration during audits.

D.

Apply IDS signatures at core routing layers to flag port scans and perform rate limiting until both environments complete segmentation.

Full Access
Question # 17

A managed device on a known corporate LAN cannot reach a private application through the Zero Trust Exchange because of forwarding behavior.

Which bypass configuration would enable access while respecting how policies are evaluated?

A.

Place a broader App Segment earlier in the rule list, conceding that misalignment could widen exposure and still fail to route the session.

B.

Enable a Trusted Network bypass in the Client Forwarding Policy, recognizing that direct access on the corporate LAN limits dependency on ZPA routing.

C.

Apply an Inspection Policy to the application traffic, acknowledging that added parsing may not resolve the routing path.

D.

Introduce an Access Policy allow rule based on group membership, accepting that forwarding mismatches may still block sessions.

Full Access
Question # 18

You are planning to use Z-Tunnel 2.0 as the forwarding mechanism to support TCP, UDP, and ICMP traffic going to ZIA.

What type of tunnel will Zscaler Client Connector form with the Zero Trust Exchange?

A.

TLS with fallback to DTLS

B.

DTLS with fallback to TLS

C.

TLS with fallback to IPsec

D.

DTLS with fallback to IPsec

Full Access
Question # 19

A contractor in the Field_Eng SAML group attempts to access an internal CAD application through ZPA from a branch designated as a Trusted Network. The Access Policy requires Field_Eng membership AND a device-posture profile confirming full-disk encryption and a CrowdStrike ZTA score above 80. The user passes the ZTA score requirement, but Device Posture reports that disk encryption is disabled.

Which enforcement outcome should be expected for this session?

A.

Quarantine the traffic through ZIA Cloud Sandbox for risk analysis

B.

Deny access to the private application because the device fails the mandatory disk-encryption requirement

C.

Permit restricted access through a more distant App Connector

D.

Bypass Access Policy evaluation because the branch is designated as a Trusted Network

Full Access
Question # 20

An administrator wants to allow users to access a wide variety of untrusted URLs. Which of the following would allow users to access these URLs in a safe manner?

A.

Browser Isolation

B.

App Connector

C.

Zscaler Private Access

D.

Zscaler Client Connector

Full Access
Question # 21

Which attack type is characterized by a commonly used website or service that has malicious content like malicious JavaScript running on it?

A.

Watering Hole Attack

B.

Pre-existing Compromise

C.

Phishing Attack

D.

Exploit Kits

Full Access
Question # 22

Cross-Site Scripting (XSS) Protection can protect you against which two types of exploits?

A.

Security Exceptions and Malicious Active Content Protection

B.

File Format Vulnerabilities and Browser Exploits

C.

Cookie Stealing and Potentially Malicious Requests

D.

Cookie Stealing and Advanced Threats Policy

Full Access
Question # 23

Which Zscaler feature detects whether an intruder is accessing your internal resources?

A.

SandBox

B.

SSL Decryption Bypass

C.

Browser Isolation

D.

Deception

Full Access
Question # 24

A security lead reviews an executive summary: data-loss risk is driven by high-volume uploads to risky SaaS applications and unmanaged generative AI use; MTTR for BU-West remains high because of ticket-routing delays; and the board wants a 15% reduction in the data-loss risk score within 60 days. Peer benchmarks are similar but show identity risk as the primary driver elsewhere.

Which action should be taken next?

A.

Open UVM remediation for low-severity endpoint findings at scale to create throughput metrics regardless of category alignment

B.

Schedule an updated board narrative and postpone technical changes until the next quarter to avoid conflicting with peer comparisons

C.

Tighten Cloud App Control for risky SaaS and AI usage, and configure MTTR routing by business unit with ITSM integration

D.

Commission an identity-hardening review centered on private-application access patterns to mirror peer drivers even though local data-loss signals persist

Full Access
Question # 25

An operations team creates a Contractor ZPA Users group to provide least-privileged access to private applications and allow Zscaler policies to evaluate the group accurately.

What is the next step required to align the group with the intended authorization model?

A.

Create equivalent local user records to avoid delays in identity-provider group propagation

B.

Reduce the administrator sign-on session lifetime so contractors must refresh their credentials more frequently

C.

Add the group to device-posture requirements so posture checks compensate for missing service permissions

D.

Assign the Private Access service entitlement to the group so its members can consume ZPA subject to Access Policy controls

Full Access
Question # 26

Which approach minimizes disruption when deploying Client Connector software updates across a heterogeneous user base while maintaining the ability to recover from defects?

A.

Defer all upgrades to weekend maintenance windows to reduce peak risk, accepting prolonged exposure to known vulnerabilities

B.

Immediately push the latest version to every segment through one channel to reduce fragmentation, and delay monitoring until users report problems

C.

Use staged rollout rings with assigned versions for selected groups, monitor deployment health in the Client Connector dashboard, and retain a revert path for cohorts that show instability

D.

Randomize update timing for each device group to spread the effect across multiple hours and days, relying on support tickets to detect failures

Full Access
Question # 27

Which options must be selected when configuring Zscaler Client Connector for Strict Enforcement?

A.

cloudName and policyToken

B.

userDomain and deviceToken

C.

cloudName and deviceToken

D.

userDomain and policyToken

Full Access
Question # 28

What are the two types of Alert Rules that can be defined?

A.

ThreatLabZ pre-defined and customer defined

B.

Snort defined and 3rd party defined

C.

ThreatLabZ pre-defined and 3rd party defined

D.

Customer defined and 3rd party defined

Full Access
Question # 29

A contractor team in a regional lab must upload ZIP archives to an approved code repository but must not upload archives or executables to generic file-sharing sites. A sudden increase in renamed executables, such as an .exe file disguised with a .jpg extension, complicates monitoring.

Which action best applies the correct file-type policy to this team while aligning with security requirements?

A.

Define one enterprise-wide file-type block for executables and archives, reference the repository as an exception host, and base decisions on MIME-type matches in the baseline policy

B.

Configure an out-of-band CASB scan to flag archives in the code repository, and create a generic SaaS block that checks file extensions for executables

C.

Create two File Type Control rules: an allow rule for archive types scoped to the contractor group and approved application, and a block rule for archives and executables scoped to the contractor group and generic file-sharing applications; place the allow rule above the broader block rule

D.

Add a URL Filtering rule scoped to the contractor group that allows the repository domain and blocks generic file-sharing domains, relying on file-extension inspection to detect renamed binaries

Full Access
Question # 30

What enables zero trust to be properly implemented and enforced between an originator and the destination application?

A.

Trusted network criteria designate the locations of originators which can be trusted.

B.

Access is granted without sharing the network between the originator and the destination application.

C.

Cloud firewall policies ensure that only authenticated users are allowed access to destination applications.

D.

Connectivity between the originator and the destination application is over IPSec tunnels.

Full Access
Question # 31

Which Zscaler Client Connector configuration setting allows administrators to assign a hosted PAC file to individual users?

A.

Traffic Steering in the App Profile

B.

Forwarding Profile Action in the Forwarding Profile

C.

Global Settings in the App Profile

D.

Global Settings in the Forwarding Profile

Full Access
Question # 32

Which feature does Zscaler Client Connector Z-Tunnel 2.0 enable over Z-Tunnel 1.0?

A.

Enables SSL Inspection for Client Connector

B.

Inspection of all ports and protocols via Cloud Firewall

C.

Enables Browser Isolation

D.

Enables multicast traffic

Full Access
Question # 33

A macOS desktop application connecting to api.vendor.com fails during the TLS handshake whenever SSL/TLS Inspection is enabled. The application uses certificate pinning, and users intermittently connect through networks that prefer Google QUIC.

Which action should the security administrator take to restore functionality while retaining inspection for unrelated traffic?

A.

Modify ZPA application segments to route the SaaS traffic through the private-application plane and avoid public inspection

B.

Create a user-agent-based exception that disables decryption for the application’s HTTP stack across all destinations

C.

Configure a trusted-network bypass so Zscaler Client Connector disengages on corporate Wi-Fi

D.

Create a custom URL category for the vendor FQDNs, add an SSL/TLS Inspection bypass rule for those destinations, and block QUIC so the connection falls back to HTTPS over TCP

Full Access
Question # 34

Which of the following statements most accurately describes Zero Trust Connections?

A.

They require that SSH inspection be enabled.

B.

They are dependent on a fixed / static network environment.

C.

They are independent of any network for control or trust.

D.

They require IPv6.

Full Access
Question # 35

Which proprietary technology does Zscaler use to calculate risk attributes dynamically for websites?

A.

Third-Party Sandbox

B.

Zscaler PageRisk

C.

Browser Isolation Feedback Form

D.

Deception Controller

Full Access
Question # 36

Which Advanced Threats policy can be configured to protect users against a credential attack?

A.

Configure Advanced Cloud Sandbox policies.

B.

Block Suspected phishing sites.

C.

Enable Watering Hole detection.

D.

Block Windows executable files from uncategorized websites.

Full Access
Question # 37

What is the preferred method for authentication to access OneAPI?

A.

OpenID Connect (OIDC)

B.

Transport Layer Security (TLS)

C.

Security Assertion Markup Language (SAML)

D.

System for Cross-domain Identity Management (SCIM)

Full Access
Question # 38

When a SAML IDP returns an assertion containing device attributes, which Zscaler component consumes the attributes first, for policy creation?

A.

Enforcement node

B.

Zscaler SAML SP

C.

Mobile Admin Portal

D.

Zero Trust Exchange

Full Access
Question # 39

A campus requires 1.5 Gbps of throughput to Zscaler Service Edges. The underlay is trusted, and the design explicitly excludes high availability.

Which option meets the bandwidth target with the minimum tunnel count?

A.

Establish a single GRE tunnel with Path MTU Discovery enabled and defer scaling until usage grows

B.

Provision two GRE tunnels associated with the same location and distribute flows through ECMP to achieve 1.5 Gbps

C.

Define two IPsec peers and tune lifetimes to minimize renegotiation during peak demand

D.

Configure one IPsec peer to avoid GRE MTU concerns and rely on static routing to sustain the required throughput

Full Access
Question # 40

An investigation requires reviewing administrator entitlement changes from nine months ago to confirm suspected privilege escalation.

ZIdentity’s default portal retention period has already elapsed.

Which approach helps preserve and access the required audit trail for governance and forensic analysis?

A.

Export audit logs to CSV on a scheduled cadence and integrate supported audit streams with a SIEM through NSS or LSS to maintain an extended history

B.

Rely on recent sign-on policy evaluations and extrapolate prior administrator actions from current configurations

C.

Focus on bandwidth trends in Firewall Insights and infer administrative timelines from rule-utilization patterns

D.

Depend on implicit caching in the Experience Center and query historical entries during off-peak hours

Full Access
Question # 41

Which of the following statements accurately reflects Zscaler ' s file size limitation for Malware Protection scans?

A.

Zscaler scans all files regardless of size.

B.

Zscaler scans files only if they are below 100 MB.

C.

Zscaler scans files up to 500 MB

D.

Zscaler scans files up to 400 MB.

Full Access
Question # 42

The Zscaler Gen AI Security Report gives visibility and insight into an organization ' s use of generative AI applications. What kind of log will include Prompt for administrators to view for different prompts entered by users in those applications?

A.

SaaS Security Logs

B.

Web Insights Logs

C.

Gen AI Insights Logs

D.

Advanced Firewall Logs

Full Access
Question # 43

Which of the following refers to employees’ use of unauthorized applications and services?

A.

Shadow IT

B.

Browser Isolation

C.

Data Discovery

D.

Posture Control

Full Access
Question # 44

A test administrator is not present in the identity provider and requires constrained access to configure ZIA policies for a short period.

Which step provides controlled administrative capability?

A.

Grant Zscaler Client Connector service entitlements to the account so it can reach the admin console

B.

Add a new department and expect policy inheritance to provide the required administrative permissions

C.

Use OpenID Connect to import the account and defer role mapping until sign-in

D.

Create a local user in ZIdentity and grant a least-privileged administrative entitlement scoped to Internet & SaaS

Full Access
Question # 45

Which of the following is an open standard used to provide automatic updates of a user ' s group and department information? A Import B. LDAP Sync C. SCIM D. SAML

A.

Import

B.

LDAP Sync

C.

SCIM

D.

SAML

Full Access
Question # 46

What transport mechanism will Zscaler Client Connector use to forward traffic to the Zero Trust Exchange when configured for Tunnel 2.0?

A.

Zscaler Client Connector will encapsulate the user ' s traffic in GRE tunnels to the ZTE.

B.

Zscaler Client Connector will encapsulate the user ' s traffic in IPSec tunnels to the ZTE.

C.

Zscaler Client Connector will encapsulate the user ' s traffic in DTLS/TLS tunnels to the ZTE.

D.

Zscaler Client Connector will encapsulate the user ' s traffic in HTTP Connect tunnels to the ZTE.

Full Access
Question # 47

Logs indicate traffic to an internal hostname was permitted and not inspected, despite a posture-based access policy that should have blocked the session.

Which statement best explains this outcome?

A.

Inspection policy overrode access controls because of protocol heuristics.

B.

SAML attribute mapping suppressed posture checks during reauthentication.

C.

A Client Forwarding Policy bypass matched first, preventing the access policy from evaluating the session.

D.

Connector selection failed closed and defaulted to passthrough to reduce latency.

Full Access
Question # 48

What happens after the Zscaler Client Connector receives a valid SAML response from the Identity Provider (IdP)?

A.

The Zscaler Client Connector Portal authenticates the user directly.

B.

There is no need for further actions as the SAML is valid, access is granted immediately.

C.

The SAML response is sent back to the user’s device for local validation.

D.

Zscaler Internet Access validates the SAML response and returns an authentication token.

Full Access
Question # 49

As technology that exists for a very long period of time, has URL Filtering lost its effectiveness?

A.

URL Filter is the most commonly used web filtering technique in the arsenal. It acts as first line of defense.

B.

In a modern cloud world, access to all Internet sites and cloud applications should be granted by default. URL Filtering is no longer needed.

C.

URL Filtering has been replaced by CASB functionality through blocking access to all Internet sites and only allowing a few corporate applications.

D.

URL Filtering is outdated and no longer needed. The rise of HTTPS leads renders URL Filtering ineffective as all traffic is encrypted.

Full Access
Question # 50

Malicious File Protection exclusions can be configured for which type of file?

A.

Files sent using the PPTP protocol

B.

Files sent using the SCP protocol

C.

Files sent using the RTSP protocol

D.

Password-encrypted files

Full Access
Question # 51

A sequence in the Administrator Audit Log shows several failed sign-ins from an unfamiliar location, followed by a successful administrator sign-in and a near-immediate role upgrade on the same identity.

Which entry combination constitutes the clearest escalation indicator requiring a containment step?

A.

A successful sign-in by a read-only auditor from a branch office and a subsequent group-membership cleanup with a comment

B.

Multiple lockout events for a non-administrator account and a later unremarkable sign-in from a corporate VPN

C.

Two expired-token errors for an API client and a later password change logged with a documented request ID

D.

A successful administrative sign-in from an untrusted IP address promptly followed by role elevation on the same account session

Full Access
Question # 52

A Gold-class SaaS application performs poorly even though its bandwidth class has a generous minimum and moderate maximum. Usage dashboards show available capacity during incidents, and other applications are not saturating the link.

What is the most defensible next step to prevent recurring degradation?

A.

Prioritize streaming media above the SaaS application to normalize queue behavior and reduce circuit jitter

B.

Reduce TLS inspection for the SaaS application to remove inspection latency without first validating the traffic path

C.

Raise the Gold-class maximum to a higher ceiling to address presumed internal throttling

D.

Use ZDX path metrics to validate last-mile or ISP congestion at the affected site and plan a circuit upgrade or provider change while retaining the current policies

Full Access
Question # 53

In which of the following SaaS apps can you protect data at rest via Zscaler ' s out-of-band CASB solution?

A.

Yahoo Mail

B.

Twitter.

C.

Google Drive.

D.

Facebook.

Full Access
Question # 54

Which of the following connects Zscaler users to the nearest Microsoft 365 servers for a better experience?

A.

Single DNS resolver with forwarders providing centralized results

B.

Private MPLS in each branch office providing connection

C.

Multiple distributed DNS resolvers providing local results

D.

Optimized TCP Scaling for maximum throughput of files

Full Access
Question # 55

What is the ZIA feature that ensures certain SaaS applications cannot be accessed from an unmanaged device?

A.

Tenant Restriction

B.

Identity Proxy

C.

Out-of-band Application Access

D.

SaaS Application Access

Full Access
Question # 56

Which of the following is the preferred method for authentication in a OneAPI environment?

A.

OIDC

B.

SCIM

C.

SAML

D.

EntraID

Full Access
Question # 57

If you ' re migrating from an on-premises proxy, you will already have a proxy setting configured within the browser or within the system. With Tunnel Mode, the best practice is to configure what type of proxy configuration?

A.

Execute a GPO update to retrieve the proxy settings from AD.

B.

Enforce no Proxy Configuration.

C.

Use Web Proxy Auto Discovery (WPAD) to auto-configure the proxy.

D.

Use an automatic configuration script (forwarding PAC file).

Full Access
Question # 58

An administrator is provisioning new App Connectors in Microsoft Azure. A new egress policy enforces TLS inspection for outbound traffic from the workload subnets.

Which action should the ZPA administrator take to prevent App Connector registration failures?

A.

Request static NAT gateway pinning for App Connector egress so ZPA anchors microtunnels to fixed public IP addresses across virtual networks

B.

Explain that App Connector egress traffic to ZPA Service Edges must bypass TLS interception

C.

Recommend disabling App Connector health checks during application-mobility windows to prevent premature failover

D.

Advise the cloud team to delay virtual-machine scale-set events until DNS TTLs expire to minimize App Connector group changes

Full Access
Question # 59

An organization wants to let a contractor group reach a single internal web application while restricting access to all other private resources. The team needs the policy to reflect contractor group-membership changes during normal operations and to ensure device risk is accounted for per session.

Which configuration most effectively enforces least privilege in this case?

A.

Define a dedicated App Segment for the target application and use a ZPA Access Policy that references a SCIM-synchronized contractor group with a device posture condition.

B.

Apply a user-agent-filtered allow control for the application hostname and add a time-based constraint during working hours.

C.

Create a location-scoped allow rule tied to the contractor egress IP range and monitor downstream access through audit reports.

D.

Enable a department-based SAML attribute in a broad allow rule and rely on a later block rule to curb lateral access.

Full Access
Question # 60

A data center requires connectivity to Zscaler for traffic inspection without an encryption requirement. The site must support a defined bandwidth profile of 2.2 Gbps and has no high-availability requirement.

Which configuration uses the minimum number of tunnels while meeting the throughput requirement?

A.

Configure three GRE tunnels mapped to the same location and use equal-cost multipath routing to support the aggregate 2.2 Gbps throughput

B.

Configure one IPSec peer with Dead Peer Detection enabled and conservative cipher settings to reduce processing load on the edge device

C.

Configure two GRE tunnels to different Service Edges and apply strict MTU policing to reduce fragmentation

D.

Configure two IPSec peers with static routing to divide traffic while accepting the additional key-exchange processing

Full Access
Question # 61

A user authenticates through the correct IdP and is synchronized as a member of the SCIM group Contractors. Device posture is compliant, the network is public, and the user attempts to reach an internal HR portal categorized under an internal App Segment for employees.

The Access Policy rule order is:

    Allow High_Value_Assets with Posture

    Block High_Value_Assets

    Allow Contractor Apps

    Block Contractors from Internal Apps

    Allow Internal Apps_2_Employees

Which outcome is most consistent with rule ordering and the evaluated attributes?

A.

The user is blocked by the contractor restriction on internal apps because the first matching rule for the user ' s group denies internal segments.

B.

The user is blocked by the high-value asset rule set because the internal HR portal is treated as a high-value application.

C.

The user is permitted by the contractor allowance because posture is compliant and the application category is internal.

D.

The user is permitted by the employee-focused allowance because posture is compliant and the application is internal.

Full Access
Question # 62

What does Advanced Threat Protection defend users from?

A.

Vulnerable JavaScripts

B.

Large iFrames

C.

Malicious active content

D.

Command injection attacks

Full Access
Question # 63

An organization mandates strict BYOD controls and does not permit endpoint agents on personal devices. Which Zscaler deployment approach aligns with this requirement while maintaining data protection for access to corporate applications?

A.

Adopt agentless access by combining Browser Isolation for SaaS applications and clientless ZPA for private applications

B.

Require self-enrollment in Zscaler Client Connector across personal endpoints to enforce forwarding profiles

C.

Depend on location-based rules and user agents to shape traffic from home and public networks

D.

Use per-application Zscaler Client Connector tunnels for unmanaged devices to segment private application access

Full Access
Question # 64

You ' ve configured the API connection to automatically download Microsoft Information Protection (MIP) labels into ZIA; where will you use these imported labels to protect sensitive data in motion?

A.

Creating a custom DLP Dictionary

B.

Creating a SaaS Security Posture Control Policy.

C.

Creating a File Type Control Policy.

D.

Creating a custom DLP Policy.

Full Access
Question # 65

Zscaler forwards the server SSL/TLS certificate directly to the user ' s browser session in which situation?

A.

When traffic contains a known threat signature.

B.

When web traffic is on custom TCP ports.

C.

When traffic is exempted in SSL Inspection policy rules.

D.

When user has connected to server in the past.

Full Access
Question # 66

Which of the following is a benefit of tunneling?

A.

Increased latency.

B.

Enhanced data security.

C.

Support for only TCP/IP traffic.

D.

Increased header size.

Full Access
Question # 67

Which types of Botnet Protection are supplied by Advanced Threat Protection?

A.

Malicious file downloads, Command traffic (sending / receiving), Data exfiltration

B.

Connections to known C & C servers, Command traffic (sending / receiving), Unknown C & C using AI/ML

C.

Connections to known C & C servers, Detection of phishing sites, Access to spam sites

D.

Vulnerabilities in web server applications, Unknown C & C using AI/ML, Vulnerable ActiveX controls

Full Access
Question # 68

Your company has a new ZIA subscription. Which is the most effective and secure method of provisioning users?

A.

Kerberos

B.

SAML auto-provisioning

C.

LDAP synchronization

D.

Zscaler Authentication Bridge

Full Access
Question # 69

When users are authenticated using SAML, what are the two most efficient ways of provisioning the users?

A.

Hosted User Database and Directory Server Synchronization

B.

SAML and Hosted User Database

C.

SCIM and Directory Server Synchronization

D.

SCIM and SAML Autoprovisioning

Full Access
Question # 70

Which Risk360 key focus area observes a broad range of event, security configurations, and traffic flow attributes?

A.

External Attack Surface

B.

Prevent Compromise

C.

Data Loss

D.

Lateral Propagation

Full Access
Question # 71

Which of the following can be used as Trusted Network criteria in Zscaler Client Connector?

A.

DNS Server, DHCP Server and Hostname/IP

B.

DHCP Server, DNS Search Domain and Hostname/IP

C.

Hostname/IP, DNS Server and DNS Search Domain

D.

Hostname/IP, DNS Search Domain and DHCP Server

Full Access
Question # 72

Which of the following is a feature of Vulnerability Management?

A.

Mitigates, transfers, accepts, or avoids risks.

B.

Focuses on technical weaknesses.

C.

Focuses on nontechnical weaknesses.

D.

Ensures business continuity.

Full Access
Question # 73

What does the user risk score enable a user to do?

A.

Compare the user risk score with other companies to evaluate users vs other companies.

B.

Determine whether or not a user is authorized to view unencrypted data.

C.

Configure stronger user-specific policies to monitor & control user-level risk exposure.

D.

Determine if a user has been compromised

Full Access
Question # 74

Which filtering policy blocked access to the Network Application?

A.

Sandbox

B.

Browser Control

C.

Firewall Filtering

D.

DLP

Full Access
Question # 75

Which type of attack plants malware on commonly accessed services?

A.

Remote access trojans

B.

Phishing

C.

Exploit kits

D.

Watering hole attack

Full Access
Question # 76

Audit logs show configuration changes performed by members of a group outside its intended administrative area.

Which step reduces this exposure while preserving required functionality?

A.

Adjust department classifications to redefine reporting lines for the group

B.

Switch to just-in-time provisioning only so that attributes are reapplied during every session

C.

Revise the group’s administrative entitlements and role assignments to constrain its scope according to least privilege

D.

Relax sign-on policies to reduce failed authentication events across locations

Full Access
Question # 77

Which Zscaler forwarding mechanism creates a loopback address on the machine to forward the traffic towards Zscaler cloud?

A.

Enforced PAC mode

B.

ZTunnel - Packet Filter Based

C.

ZTunnel with Local Proxy

D.

ZTunnel - Route Based

Full Access
Question # 78

Which Platform Service enables visibility into the headers and payload of encrypted transactions?

A.

Policy Framework

B.

TLS Decryption

C.

Reporting and Logging

D.

Device Posture

Full Access
Question # 79

Which command-line parameter is used to activate tamper proofing during the installation of Zscaler Client Connector?

A.

--secureInstall

B.

--antiTamper

C.

--disableTampering

D.

--enableAntiTampering

Full Access
Question # 80

A security team suspects that data exfiltration is occurring through encrypted channels to attackers.

To assess the company’s posture before tuning controls, which next step should be taken to validate whether existing protections cover this behavior?

A.

Raise the severity of egress firewall rules across segments to constrain outbound flows that might be exploited

B.

Review ZIA DLP outbound logs for anomalous uploads to unsanctioned SaaS applications and newly registered domains to gauge detection coverage

C.

Correlate ZIA threat insights with ZPA analytics to identify anomalous outbound patterns and unusual private-application access, and then verify that DLP and botnet controls apply to TLS-decrypted traffic

D.

Trigger broad Cloud Sandbox reanalysis of recent endpoint downloads to look for latent payloads that could facilitate exfiltration

Full Access
Question # 81

What is the recommended default rule for the cloud-gen firewall configuration when deploying a new ZIA tenant?

A.

Block all traffic

B.

Permit all traffic

C.

Disable the firewall

D.

Allow only web traffic (ports 80/443)

Full Access