Summer Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: mxmas70

Home > Zscaler > Digital Transformation Administrator > ZDTA

ZDTA Zscaler Digital Transformation Administrator Question and Answers

Question # 4

Is SCIM required for ZIA?

A.

Depends

B.

Maybe

C.

No

D.

Yes

Full Access
Question # 5

A platform team deploys Bandwidth Control and firewall policy changes through an API. After a large rollout, users report sporadic application slowdowns, yet the monitoring team finds gaps in telemetry for the same time windows.

Which action best prevents these performance issues from persisting and going undetected in similar rollouts?

A.

Add an implementation step that validates monitoring subscriptions and exports ZDX and Firewall Insights baselines before applying policy changes through APIs

B.

Aggregate logs monthly and perform retrospective correlation to avoid noisy short-term fluctuations in metrics

C.

Increase API client-token lifetimes to reduce HTTP 401 errors and stabilize automation during policy pushes

D.

Restrict automation runs to weekly windows to minimize configuration changes that may obscure trend lines

Full Access
Question # 6

A company must enforce least-privileged access to private applications when contractors connect from varying locations using devices with inconsistent security posture. The security team wants decisions to use identity and per-session context instead of broad network assumptions.

Which approach best meets the requirement?

A.

Build ZPA Access Policy rules around a SCIM-synchronized contractor group, apply device-posture conditions to sensitive application segments, and retain a final catch-all deny rule

B.

Prioritize ZIA URL Filtering rules that use department attributes to shape contractor access, and leave ZPA unchanged

C.

Use location groups to provide contractors with tiered access to most internal services and defer device evaluation to downstream controls

D.

Require session MFA for contractor authentication and use SAML attributes to relax private-application access broadly

Full Access
Question # 7

Zscaler Platform Services works upon unencrypted data from encrypted communications due to which of the following?

A.

Antivirus

B.

Tenant Restrictions

C.

Web Filtering

D.

TLS Inspection

Full Access
Question # 8

A sanctioned SaaS application is allowed in Cloud App Control but appears to be blocked by URL Filtering.

Which configuration would permit access through a controlled bypass that follows policy precedence?

A.

Move the URL Filtering Allow rule above the Block rule, noting that Cloud App Control-to-URL precedence can still cause an unintended denial

B.

Disable cascading to URL Filtering so Cloud App Control precedence applies and the URL layer does not override the permitted application

C.

Refine Device Posture profile thresholds, acknowledging that posture conditions do not reorder URL policy evaluation

D.

Configure a Trusted Network condition to bypass forwarding, accepting that the block might persist in the URL layer

Full Access
Question # 9

Which of the following is the preferred method for authentication in a OneAPI environment?

A.

OIDC

B.

SCIM

C.

SAML

D.

EntraID

Full Access
Question # 10

Which of the following enables the discovery of newly observed domains within three minutes of the domain coming online?

A.

IP Chicken

B.

MXToolbox

C.

Farsight Feed

D.

Dig

Full Access
Question # 11

What is the purpose of Browser Access in relation to Zscaler Private Access (ZPA)?

A.

To make applications accessible from any web browser with Zscaler Client Connector deployed on the device.

B.

To make applications accessible using a browser plug-in and additional browser configuration controlled by the organization.

C.

To make applications accessible without user authentication, Zscaler Client Connector, browser plug-ins, or browser configuration.

D.

To make applications accessible from any web browser without requiring Zscaler Client Connector, browser plug-ins, or additional browser configuration.

Full Access
Question # 12

Which step has a default frequency of two hours in the Zscaler client connector process?

A.

Policy update check

B.

PAC File Download

C.

Software update policy check

D.

Refresh on Network Changes

Full Access
Question # 13

Which Platform Service enables visibility into the headers and payload of encrypted transactions?

A.

Policy Framework

B.

TLS Decryption

C.

Reporting and Logging

D.

Device Posture

Full Access
Question # 14

A new Zscaler Client Connector version causes intermittent tunnel drops for macOS devices in one region during a controlled rollout.

Which action enables broader deployment with minimal disruption while addressing the instability?

A.

Delay updates in every region until vendor remediation is available, accepting prolonged exposure to vulnerabilities fixed in the new version

B.

Revert the affected segment to the previous version and continue pilots in unaffected cohorts, monitoring the Zscaler Client Connector dashboard and logs for recurrence

C.

Reassign every group to an earlier stable version regardless of local stability, sacrificing rollout progress and increasing coordination overhead

D.

Push diagnostic packet-capture collection to the entire user base, accepting a performance impact for unaffected cohorts

Full Access
Question # 15

What does Zscaler Advanced Firewall support that Zscaler Standard Firewall does not?

A.

Destination NAT

B.

FQDN Filtering with wildcard

C.

DNS Dashboards, Insights and Logs

D.

DNS Tunnel and DNS Application Control

Full Access
Question # 16

Layered defense throughout an organization security platform is valuable because of which of the following?

A.

Layered defense increases costs to attackers to operate.

B.

Layered defense from multiple vendor solutions easily share attacker data.

C.

Layered defense ensures attackers are prevented eventually.

D.

Layered defense with multiple endpoint agents protects from attackers.

Full Access
Question # 17

Which type of attack plants malware on commonly accessed services?

A.

Remote access trojans

B.

Phishing

C.

Exploit kits

D.

Watering hole attack

Full Access
Question # 18

When filtering user access to certain web destinations what can be a better option, URL or Cloud Application filtering Policies?

A.

Cloud Application policies provide better access control.

B.

URL filtering policies provide better access control.

C.

Wherever possible URL policies are recommended.

D.

Both provide the same filtering capabilities.

Full Access
Question # 19

When enabled during Zscaler Client Connector (ZCC) installation, what specific control does the Strict Enforcement feature apply to internet access on end-user Windows workstations?

A.

It requires users to restart their Windows workstations after ZCC installation before accessing the internet.

B.

It prevents users from uninstalling ZCC without proper authorization.

C.

It requires users to enroll with ZCC before accessing the internet.

D.

It prevents users from logging out of ZCC without proper authorization.

Full Access
Question # 20

What is a ZIA Sublocation?

A.

The section of a corporate Location used to separate traffic, like traffic from employees from guest traffic

B.

The section of a corporate Location that sends traffic to a Subcloud

C.

Every one of the sections in a Corporate Location that use overlapping IP addresses

D.

A way to separate generic traffic from that coming from Client Connector

Full Access
Question # 21

Which of the following is a feature of Vulnerability Management?

A.

Mitigates, transfers, accepts, or avoids risks.

B.

Focuses on technical weaknesses.

C.

Focuses on nontechnical weaknesses.

D.

Ensures business continuity.

Full Access
Question # 22

What is the minimum polling interval if one has ZDX Advanced license enabled in their tenant?

A.

1 minute

B.

10 minutes

C.

15 minutes

D.

5 minutes

Full Access
Question # 23

A branch office uses a trusted-network bypass that routes traffic directly to the internet. Incident reviews show that unmanaged laptops at the branch are reaching SaaS applications without device-posture evaluation.

Which action should the administrator take next to ensure that devices are compliant before receiving access?

A.

Amend the trusted-network bypass and enforce posture-based access through Zscaler Client Connector for branch traffic

B.

Expand application segments to redefine which subnets are considered internal for discovery

C.

Add Caution actions to web policies to prompt users about risks on popular collaboration platforms

D.

Lower bandwidth quotas for the branch to discourage access spikes from unmanaged devices

Full Access
Question # 24

From a user perspective, Zscaler Bandwidth Control performs traffic shaping and buffering on what direction(s) of traffic?

A.

Outbound traffic is shaped. Inbound or localhost traffic is unshaped.

B.

Outbound or inbound traffic is shaped. Localhost traffic is unshaped.

C.

Inbound traffic is shaped. Outbound or localhost traffic is unshaped.

D.

Localhost traffic is shaped. Outbound or Inbound traffic is unshaped.

Full Access
Question # 25

How deeply can the Zscaler service scan recursively compressed files for malicious content?

A.

It scans only uncompressed files.

B.

Up to three layers of recursive compression.

C.

Up to two layers of recursive compression.

D.

Up to five layers of recursive compression.

Full Access
Question # 26

Malware Protection inside HTTPS connections is performed using which parts of the Zero Trust Exchange?

A.

Deception creating decoy files for malware to discover.

B.

Application Segmentation of users to specific private applications.

C.

TLS Inspection decrypting traffic to compare signatures for known risks.

D.

Data Loss Protection comparing saved filenames for known risks.

Full Access
Question # 27

A log review shows requests to a sanctioned application being allowed despite a later rule intended to restrict access by time of day.

The rule set is:

    Allow the sanctioned application for All Employees

    Block the sanctioned application outside business hours for All Employees

    Log restricted-access hits

Which cause and risk are most consistent with this behavior?

A.

The time-of-day block inherits timing from device posture, which desynchronizes evaluation and produces inconsistent enforcement

B.

The initial allow rule matches first and stops further evaluation, so the time-of-day block never applies and access remains available after business hours

C.

The logging rule takes precedence because of its action type, preventing the block from being reached

D.

The sanctioned application category becomes invalid during SSL inspection, sending the request to a default allow path that bypasses time restrictions

Full Access
Question # 28

Architecture reviews reveal trusted network bypass is configured for headquarters, while roaming users route through the service edge. The goal is stricter controls for accessing SaaS application when off-network traffic.

What policy ensures the best coverage for this scenario?

A.

ZPA App Segment policies that constrain ports for legacy private applications accessed by remote users

B.

Leverage conditional access policies to ensure client sessions only come from known location or via the Zero Trust Exchange

C.

CASB app governance policies that rely on user risk scores to restrict cloud activities across all locations

D.

Data center firewall tiers that mirror internal VLANs and apply deny rules for roaming identities

Full Access
Question # 29

What is one of the four steps of a cyber attack?

A.

Find Cash Safe

B.

Find Email Addresses

C.

Find Least Secure Office Building

D.

Find Attack Surface

Full Access
Question # 30

What does a DLP Engine consist of?

A.

DLP Policies

B.

DLP Rules

C.

DLP dictionaries

D.

DLP identifiers

Full Access
Question # 31

Users connected through one ISP in a single country report a sudden decline in UCaaS call quality. The operations team must determine whether the degradation is ISP-specific or caused by local endpoints.

Which ZDX diagnostic best isolates the provider and geographic area responsible for the issue?

A.

Use ISP Insights and geographic latency maps to aggregate experience scores and network-path measurements by provider and region

B.

Correlate meeting-level mean opinion scores with endpoint CPU spikes and conclude that local resource limitations are constraining audio and video

C.

Examine individual CloudPath traces for per-hop jitter and packet loss while assuming that the last-mile segment is the bottleneck

D.

Compare device Wi-Fi measurements with UCaaS quality trends and infer that users’ local networks are responsible

Full Access
Question # 32

A global URL Filtering rule blocks Newly Registered Domains and Anonymizers. Marketing has a rule that allows Social Media with a Caution action, and specific group-based rules appear above broader global rules. A user who belongs to both Marketing and Contractors attempts to access a social-media subdomain that is newly registered and classified under both Social Media and Newly Registered Domains.

What enforcement outcome is most consistent with the rule hierarchy and category matching?

A.

Continuous evaluation defers the decision until the domain’s reputation stabilizes, causing temporarily degraded access instead of a definitive allow or block

B.

The global block preempts departmental allows regardless of rule order, resulting in denial because high-risk categories are automatically prioritized

C.

Cloud App Control is evaluated first and blocks the request at the application level, making URL Filtering irrelevant to the transaction

D.

The Marketing-specific rule matches first because of its higher position and category criteria, applies the Caution action, and prevents the later global block from being evaluated

Full Access
Question # 33

What is a key advantage of Zscaler ' s unified approach to data protection?

A.

Reducing visibility into data movement across the cloud.

B.

Working together with traditional hardware appliances.

C.

Increasing complexity and manageability in DLP security policies.

D.

Eliminating of gaps associated with multiple point solutions.

Full Access
Question # 34

When users are authenticated using SAML, what are the two most efficient ways of provisioning the users?

A.

Hosted User Database and Directory Server Synchronization

B.

SAML and Hosted User Database

C.

SCIM and Directory Server Synchronization

D.

SCIM and SAML Autoprovisioning

Full Access
Question # 35

Which of the following features protects traffic to internal applications from attacks such as cross-site scripting (XSS), cookie poisoning, and SQL injection?

A.

Zscaler Digital Experience

B.

ZIdentity

C.

Zscaler Private AppProtection

D.

Zscaler Cloud Firewall

Full Access
Question # 36

A campaign alert identifies affected users and devices across multiple sites.

Which action should the SOC lead take to strengthen response performance and reduce repetitive manual tasks?

A.

Trigger a SOAR playbook through platform APIs to create tickets, block domains in ZIA, and isolate affected endpoints

B.

Assign manual triage to each site and postpone enforcement changes until endpoint teams confirm independent findings

C.

Disable automated notifications to collaboration tools to reduce noise while analysts evaluate logs for each user separately

D.

Increase the alert-severity classification so future campaign alerts appear higher in queues despite limited context enrichment

Full Access
Question # 37

Fundamental capabilities needed by other services within the Zscaler Zero Trust Exchange are provided by which of these?

A.

Access Control Services

B.

Digital Experience Monitoring

C.

Cyber Security Services

D.

Platform Services

Full Access
Question # 38

A regional data center experiences intermittent loss of access to an internal ERP application through ZPA during maintenance windows. The site runs two virtual-machine App Connectors mapped to the ERP segment. Maintenance affects one hypervisor at a time, and support tickets show that sessions drop sporadically but recover.

Which change should the ZPA administrator request to improve continuity within the site’s constraints?

A.

Reduce application health-check frequency so ZPA waits longer before reassigning sessions during transient failures

B.

Add another App Connector on a separate host to increase the available capacity for session redistribution

C.

Increase App Connector CPU reservations to reduce contention spikes during hypervisor maintenance

D.

Modify Access Policy priorities to prefer identity attributes that remain stable during maintenance windows

Full Access
Question # 39

What is the recommended minimum number of App connectors needed to ensure resiliency?

A.

2

B.

6

C.

4

D.

3

Full Access
Question # 40

What ports and protocols are forwarded to the Zero Trust Exchange when Zscaler Client Connector is using Tunnel 2.0?

A.

TCP ports 80, 443 and 8080 only.

B.

Any HTTP/HTTPS traffic as well as DNS.

C.

All TCP and UDP ports as well as ICMP traffic.

D.

All Web ports as well as FTP and SSH.

Full Access
Question # 41

Your company has a new ZIA subscription. Which is the most effective and secure method of provisioning users?

A.

Kerberos

B.

SAML auto-provisioning

C.

LDAP synchronization

D.

Zscaler Authentication Bridge

Full Access
Question # 42

You are planning to use Z-Tunnel 2.0 as the forwarding mechanism to support TCP, UDP, and ICMP traffic going to ZIA.

What type of tunnel will Zscaler Client Connector form with the Zero Trust Exchange?

A.

TLS with fallback to DTLS

B.

DTLS with fallback to TLS

C.

TLS with fallback to IPsec

D.

DTLS with fallback to IPsec

Full Access
Question # 43

Which proprietary technology does Zscaler use to calculate risk attributes dynamically for websites?

A.

Third-Party Sandbox

B.

Zscaler PageRisk

C.

Browser Isolation Feedback Form

D.

Deception Controller

Full Access
Question # 44

To design an update-governance process that reduces disruption and supports reporting, which practice aligns with continuous improvement and defensible decision-making?

A.

Isolate security operations from IT to control messaging around updates, accepting coordination gaps during rollout

B.

Limit telemetry integration to reduce operational overhead, accepting reduced evidence for trend analysis and planning

C.

Establish regular risk-review cycles using Risk360 dashboards and MTTR metrics, tying ticket routing and wave scheduling to observed trends and remediation progress

D.

Trigger update waves on an ad hoc basis in response to incidents, accepting inconsistent visibility and reactive coordination

Full Access
Question # 45

A company must grant engineers and finance staff access to different private resources. After rollout, all users have access to both sets of resources.

Which action should the administrator take to tighten least privilege while keeping access operational?

A.

Retain the current forwarding scope and add a location-based condition to Access Policy to restrict engineers who access the site from off-campus networks

B.

Split the Application Segments by FQDN, scope Client Forwarding Policy appropriately, and define a separate Access Policy for each authorized group

C.

Move posture checks to an inspection policy and apply a department attribute in a broad Allow rule so Client Connector can continue forwarding wide address ranges

D.

Consolidate both applications into one Application Segment with a single Allow rule and relax posture criteria to tolerate posture-probe instability

Full Access
Question # 46

What is one business risk introduced by the use of legacy firewalls?

A.

Performance issues

B.

Reduced management

C.

Low costs

D.

Low licensing support

Full Access
Question # 47

A security team must apply least-privilege access for hybrid users who work remotely and on-site while preventing sensitive data from residing on unmanaged BYOD endpoints.

Which Zscaler Client Connector-related deployment decision best satisfies the constraints and mitigates the data-exposure risk?

A.

Enable Trusted Network conditions so unmanaged laptops on home Wi-Fi receive reduced scrutiny during application sessions

B.

Assign posture checks requiring disk encryption and antivirus through Client Connector on personal laptops

C.

Rely on protocol-aware URL rules and bandwidth shaping to limit risky transfers from roaming users

D.

Prefer agentless controls by enforcing Browser Isolation for SaaS access and allowing elevated sessions only from managed devices with Client Connector

Full Access
Question # 48

A threat actor’s command-and-control infrastructure uses hard-coded IP addresses and several domains resolved through DNS. An organization wants Zscaler to block callback attempts with minimal dependence on endpoint agents and to enforce the decision consistently for roaming users.

Which configuration best aligns with ZIA policy enforcement and the zero-trust model?

A.

Enable Browser Isolation for the suspected destinations so sessions are rendered remotely even when callbacks reach the external hosts

B.

Add the domains to a URL-category override and depend on TLS inspection to identify the traffic after connection

C.

Create a high-risk URL Filtering rule that reduces the Advanced Threat Protection risk threshold and relies on page scoring to suppress suspicious domains

D.

Create a Cloud Firewall destination group containing the indicator IP addresses and apply a high-priority Drop rule, while adding the domains to a globally blocked custom URL category

Full Access
Question # 49

Which of the following is a unified management console for internet and SaaS applications, private applications, digital experience monitoring and endpoint agents?

A.

identity Admin Portal

B.

Mobile Admin Portal

C.

Experience Center

D.

One API

Full Access
Question # 50

What is the ZIA feature that ensures certain SaaS applications cannot be accessed from an unmanaged device?

A.

Tenant Restriction

B.

Identity Proxy

C.

Out-of-band Application Access

D.

SaaS Application Access

Full Access
Question # 51

An administrator must brief a cross-functional team on the prerequisites for allowing a single App Connector group in AWS to serve applications in an on-premises data center over Direct Connect.

Which requirement is most critical to state to avoid reachability gaps and App Connector misbehavior?

A.

Confirm that internal routing permits the App Connector subnets to reach the on-premises application subnets and that App Connector egress to ZPA Service Edges remains outbound TLS over permitted paths

B.

Confirm that client microtunnels terminate on the AWS App Connectors through inbound firewall rules and that Direct Connect advertises public prefixes

C.

Confirm that the on-premises firewalls publish NAT to expose the application servers for App Connector probes and that reverse DNS is authoritative in AWS

D.

Confirm that ZPA control-plane addresses are reachable through inbound ACLs from the Zscaler cloud and that application probes are source-NATed at the data-center edge

Full Access
Question # 52

A Cloud Sandbox detonation shows a document beaconing through obfuscated scripts and spawning child processes that attempt network calls to newly registered domains. The desired outcome is to prevent users from downloading or accessing similar suspicious files across web and SaaS channels.

What action should be taken next?

A.

Apply a Sandbox policy that quarantines the document type across all applicable channels above the existing Sandbox policy rule

B.

Shift scanning to out-of-band CASB-only workflows so that analysis occurs after content is stored

C.

Route detections to a manual review queue and postpone policy changes until more analyst capacity is available

D.

Lower Sandbox sensitivity to reduce alert volume and defer enforcement until trend data is gathered

Full Access
Question # 53

A contractor team in a regional lab must upload ZIP archives to an approved code repository but must not upload archives or executables to generic file-sharing sites. A sudden increase in renamed executables, such as an .exe file disguised with a .jpg extension, complicates monitoring.

Which action best applies the correct file-type policy to this team while aligning with security requirements?

A.

Define one enterprise-wide file-type block for executables and archives, reference the repository as an exception host, and base decisions on MIME-type matches in the baseline policy

B.

Configure an out-of-band CASB scan to flag archives in the code repository, and create a generic SaaS block that checks file extensions for executables

C.

Create two File Type Control rules: an allow rule for archive types scoped to the contractor group and approved application, and a block rule for archives and executables scoped to the contractor group and generic file-sharing applications; place the allow rule above the broader block rule

D.

Add a URL Filtering rule scoped to the contractor group that allows the repository domain and blocks generic file-sharing domains, relying on file-extension inspection to detect renamed binaries

Full Access
Question # 54

Which of the following secures all IP unicast traffic?

A.

Secure Shell (SSH)

B.

Tunnel with local proxy

C.

Enforce PAC

D.

Z-Tunnel 2.0

Full Access
Question # 55

Which filtering policy blocked access to the Network Application?

A.

Sandbox

B.

Browser Control

C.

Firewall Filtering

D.

DLP

Full Access
Question # 56

A user is accessing a private application through Zscaler with SSL Inspection enabled. Which certificate will the user see on the browser session?

A.

No certificate, as the session is decrypted by the Service Edge

B.

A self-signed certificate from Zscaler

C.

Real Server Certificate

D.

Zscaler generated MITM Certificate

Full Access
Question # 57

What does TLS Inspection for Zscaler Internet Access secure public internet browsing with?

A.

Storing connection streams for future customer review.

B.

Removing certificates and reconnecting client connection using HTTP.

C.

Intermediate certificates are created for each client connection.

D.

Logging which clients receive the original webserver certificate.

Full Access
Question # 58

What happens after the Zscaler Client Connector receives a valid SAML response from the Identity Provider (IdP)?

A.

The Zscaler Client Connector Portal authenticates the user directly.

B.

There is no need for further actions as the SAML is valid, access is granted immediately.

C.

The SAML response is sent back to the user’s device for local validation.

D.

Zscaler Internet Access validates the SAML response and returns an authentication token.

Full Access
Question # 59

The Forwarding Profile defines which of the following?

A.

Fallback methods and behavior when a DTLS tunnel cannot be established

B.

Application PAC file location

C.

System PAC file when off trusted network

D.

Fallback methods and behavior when a TLS tunnel cannot be established

Full Access
Question # 60

Security teams are vetting approaches to private application access across two merging organizations to reduce post-acquisition lateral movement.

Which approach best constrains internal discovery and probing while preserving required connectivity?

A.

Adopt ZPA user-to-app segmentation with inside-out connectivity so users reach defined applications and cannot traverse broader IP ranges.

B.

Centralize VPN concentrators and restrict subnet access by department to contain exploratory traffic during initial entitlement mapping.

C.

Extend shared VLANs across the combined data centers and use access control lists to discourage host-to-host enumeration during audits.

D.

Apply IDS signatures at core routing layers to flag port scans and perform rate limiting until both environments complete segmentation.

Full Access
Question # 61

Zscaler forwards the server SSL/TLS certificate directly to the user ' s browser session in which situation?

A.

When traffic contains a known threat signature.

B.

When web traffic is on custom TCP ports.

C.

When traffic is exempted in SSL Inspection policy rules.

D.

When user has connected to server in the past.

Full Access
Question # 62

A help desk receives intermittent Microsoft 365 latency complaints after local Internet breakout was enabled at several sites. The problem increases during peak collaboration windows and dies down unpredictably.

Which action should an administrator take to capture diagnostic information, determine where path issues emerge, and attach evidence to the incident workflow?

A.

Invoke ZDX Troubleshooting APIs to collect current hop-by-hop path metrics, DNS resolution times, and HTTP responses for the affected sessions.

B.

Force traffic-steering changes at egress to prefer alternate service edges, anticipating improvements despite incomplete visibility.

C.

Expand TLS inspection exceptions for Microsoft endpoints to reduce inspection overhead and anticipate lower timeouts.

D.

Increase Bandwidth Control allocations for productivity classes during peak periods, assuming shaping under-provisioning is causing congestion.

Full Access
Question # 63

When creating an installer package or using the command-line for installation, which Zscaler Client Connector installer options are used to automatically redirect to your corporate SAML IdP on launch?

A.

--deviceToken and --strictEnforcement

B.

This is automatic when SAML is configured. No options are required.

C.

--cloudName and --userDomain

D.

--policyToken and --userDomain

Full Access
Question # 64

Which of the following are correct request methods when configuring a URL filtering rule with a Caution action?

A.

Connect, Get, Head

B.

Options, Delete, Put

C.

Get, Delete, Trace

D.

Connect, Post, Put

Full Access
Question # 65

How does Zscaler ensure that sensitive structured data used in the EDM process is not stored in its cloud environment?

A.

By storing sensitive structured data on servers managed by trusted Zscaler staff for enhanced security.

B.

By using an on-premises VM to index data and only sending hashed values to the cloud.

C.

By requiring customers to manually hash the data and upload it to the cloud.

D.

By encrypting sensitive data directly before storing it in the cloud.

Full Access
Question # 66

A location has a trusted network bypass configured. A Client Connector Forwarding Profile applies category controls and private app access. A new departmental rule is added to permit a niche collaboration suite.

Which action should be taken to mitigate the risk of unintended bypass of inspection for that suite when users are on the trusted network?

A.

Shift the departmental permit below the global acceptable use controls to discourage inadvertent matches at the edge.

B.

Refine the trusted network bypass to exclude the collaboration suite ' s domains and ensure the forwarding profile can still apply inspection.

C.

Reduce the forwarding scope and rely on baseline firewall defaults to constrain traffic during office hours.

D.

Constrain the forwarding profile by limiting app segments and defer category enforcement until off-network conditions resume.

Full Access
Question # 67

What are common delivery mechanisms for malware?

A.

Malware downloads from web pages

B.

Personal emails, company documents, OneDrive

C.

Spam, exploit kits, USB drives, video streaming

D.

Phishing, Exploit Kits, Watering Holes, Pre-existing Compromise

Full Access
Question # 68

How does a Zscaler administrator troubleshoot a certificate pinned application?

A.

They could look at SSL logs for a failed client handshake.

B.

They could reboot the endpoint device.

C.

They could inspect the ZIA Web Policy.

D.

They could look into the SaaS application analytics tab.

Full Access
Question # 69

You ' ve configured the API connection to automatically download Microsoft Information Protection (MIP) labels into ZIA; where will you use these imported labels to protect sensitive data in motion?

A.

Creating a custom DLP Dictionary

B.

Creating a SaaS Security Posture Control Policy.

C.

Creating a File Type Control Policy.

D.

Creating a custom DLP Policy.

Full Access
Question # 70

A Gold-class SaaS application performs poorly even though its bandwidth class has a generous minimum and moderate maximum. Usage dashboards show available capacity during incidents, and other applications are not saturating the link.

What is the most defensible next step to prevent recurring degradation?

A.

Prioritize streaming media above the SaaS application to normalize queue behavior and reduce circuit jitter

B.

Reduce TLS inspection for the SaaS application to remove inspection latency without first validating the traffic path

C.

Raise the Gold-class maximum to a higher ceiling to address presumed internal throttling

D.

Use ZDX path metrics to validate last-mile or ISP congestion at the affected site and plan a circuit upgrade or provider change while retaining the current policies

Full Access
Question # 71

During the authentication process while accessing a private web application, how is the SAML assertion delivered to the service provider?

A.

HTTP Redirect on the browser

B.

API request/response sequence

C.

Through the client connector

D.

Form POST via the browser

Full Access
Question # 72

In support of data privacy for TLS/SSL inspection, when you subscribe to ZIA, you enter into what kind of agreement?

A.

Zscaler Compliance Policy

B.

Zscaler Privacy Policy

C.

Acceptable Use Policy

D.

Zscaler Data Processing Agreement

Full Access
Question # 73

Zscaler utilized a Zero Trust Network Architecture (ZTNA) for segmentation in an environment.

Which of the following prevents lateral movement within an organization?

A.

Connect users to applications using Identity, device posture, and access policies

B.

Move all applications into the DMZ

C.

Turn on all host based firewalls

D.

Allow access to all resources on the network via VPN

Full Access
Question # 74

A security lead reviews an executive summary: data-loss risk is driven by high-volume uploads to risky SaaS applications and unmanaged generative AI use; MTTR for BU-West remains high because of ticket-routing delays; and the board wants a 15% reduction in the data-loss risk score within 60 days. Peer benchmarks are similar but show identity risk as the primary driver elsewhere.

Which action should be taken next?

A.

Open UVM remediation for low-severity endpoint findings at scale to create throughput metrics regardless of category alignment

B.

Schedule an updated board narrative and postpone technical changes until the next quarter to avoid conflicting with peer comparisons

C.

Tighten Cloud App Control for risky SaaS and AI usage, and configure MTTR routing by business unit with ITSM integration

D.

Commission an identity-hardening review centered on private-application access patterns to mirror peer drivers even though local data-loss signals persist

Full Access
Question # 75

Which of the following DLP Notification methods can be used to forward a copy of the data that triggered the DLP policy to the auditor?

A.

Email Notification Template

B.

NSS Log Forwarding to SIEM

C.

SMS Text Message via PagerDuty

D.

Zscaler Client Connector pop-up message

Full Access
Question # 76

Which installed component does Zscaler Internet Access (ZIA) use to implement and enforce Endpoint DLP policy on end-user laptops?

A.

Zscaler DLP Agent (ZDA)

B.

Zscaler Client Connector (ZCC)

C.

Zscaler Secure Endpoint (ZSE)

D.

Zscaler Secure Agent (ZSA)

Full Access
Question # 77

An organization has more than one ZIA instance, each on different clouds. The organization is using the same login domain for both and upon login users are given this menu in ZCC asking which cloud they would like to join. What steps could an Administrator take to avoid having this menu appear?

A.

Customize an MSI version of the ZCC file specifying the USERDOMAIN variable.

B.

Customize an MSI version of the ZCC file specifying the CLOUDNAME variable.

C.

Federate the login domain between two different IDP instances.

D.

Create only one SAML integration with the desired ZIA instance.

Full Access
Question # 78

An organization mandates strict BYOD controls and does not permit endpoint agents on personal devices. Which Zscaler deployment approach aligns with this requirement while maintaining data protection for access to corporate applications?

A.

Adopt agentless access by combining Browser Isolation for SaaS applications and clientless ZPA for private applications

B.

Require self-enrollment in Zscaler Client Connector across personal endpoints to enforce forwarding profiles

C.

Depend on location-based rules and user agents to shape traffic from home and public networks

D.

Use per-application Zscaler Client Connector tunnels for unmanaged devices to segment private application access

Full Access
Question # 79

Which Zscaler Client Connector configuration setting allows administrators to assign a hosted PAC file to individual users?

A.

Traffic Steering in the App Profile

B.

Forwarding Profile Action in the Forwarding Profile

C.

Global Settings in the App Profile

D.

Global Settings in the Forwarding Profile

Full Access
Question # 80

Which type of malware is specifically used to deliver other malware?

A.

RAT

B.

Maldocs

C.

Downloaders

D.

Exploitation tool

Full Access
Question # 81

Which of the following is unrelated to the properties of ' Trusted Networks ' ?

A.

DNS Server

B.

Default Gateway

C.

Org ID

D.

Network Range

Full Access