Weekend Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: discactive

Zscaler ZDTA Zscaler Digital Transformation Administrator Exam Practice Test

Page: 1 / 27
Total 273 questions

Zscaler Digital Transformation Administrator Questions and Answers

Question 1

You are planning to use Z-Tunnel 2.0 as the forwarding mechanism to support TCP, UDP, and ICMP traffic going to ZIA.

What type of tunnel will Zscaler Client Connector form with the Zero Trust Exchange?

Options:

A.

TLS with fallback to DTLS

B.

DTLS with fallback to TLS

C.

TLS with fallback to IPsec

D.

DTLS with fallback to IPsec

Question 2

A platform team deploys Bandwidth Control and firewall policy changes through an API. After a large rollout, users report sporadic application slowdowns, yet the monitoring team finds gaps in telemetry for the same time windows.

Which action best prevents these performance issues from persisting and going undetected in similar rollouts?

Options:

A.

Add an implementation step that validates monitoring subscriptions and exports ZDX and Firewall Insights baselines before applying policy changes through APIs

B.

Aggregate logs monthly and perform retrospective correlation to avoid noisy short-term fluctuations in metrics

C.

Increase API client-token lifetimes to reduce HTTP 401 errors and stabilize automation during policy pushes

D.

Restrict automation runs to weekly windows to minimize configuration changes that may obscure trend lines

Question 3

Assume that you have four data centers around the globe, each hosting multiple applications for your users. What is the minimum number of App Connectors you should deploy?

Options:

A.

Six - one per data center plus two for cold standby.

B.

Eight -two per data center.

C.

Four - one per data center.

D.

Sixteen - to support a full mesh to the other data centers.

Question 4

Audit and access logs show that a user was able to access an application segment even though the user was recently moved into a restricted group referenced by a deny rule.

What is an accurate explanation for the discrepancy?

Options:

A.

URL Filtering precedence suppressed the access policy to prevent duplicate enforcement

B.

Posture profiles enforced an AND condition that masked identity checks at session start

C.

The policy relied on SAML group attributes that had not refreshed, so the session was evaluated against stale membership

D.

The deny rule matched but was downgraded because of location-group prioritization

Question 5

Which of the following external-facing API gateways can enforce authentication for access to Zscaler Client Connector API resources?

Options:

A.

Postman

B.

ZPA API

C.

ZIdentity

D.

OneAPI

Question 6

What ports and protocols are forwarded to the Zero Trust Exchange when Zscaler Client Connector is using Tunnel 2.0?

Options:

A.

TCP ports 80, 443 and 8080 only.

B.

Any HTTP/HTTPS traffic as well as DNS.

C.

All TCP and UDP ports as well as ICMP traffic.

D.

All Web ports as well as FTP and SSH.

Question 7

Cross-Site Scripting (XSS) Protection can protect you against which two types of exploits?

Options:

A.

Security Exceptions and Malicious Active Content Protection

B.

File Format Vulnerabilities and Browser Exploits

C.

Cookie Stealing and Potentially Malicious Requests

D.

Cookie Stealing and Advanced Threats Policy

Question 8

What are the two types of Alert Rules that can be defined?

Options:

A.

ThreatLabZ pre-defined and customer defined

B.

Snort defined and 3rd party defined

C.

ThreatLabZ pre-defined and 3rd party defined

D.

Customer defined and 3rd party defined

Question 9

What is the purpose of Browser Access in relation to Zscaler Private Access (ZPA)?

Options:

A.

To make applications accessible from any web browser with Zscaler Client Connector deployed on the device.

B.

To make applications accessible using a browser plug-in and additional browser configuration controlled by the organization.

C.

To make applications accessible without user authentication, Zscaler Client Connector, browser plug-ins, or browser configuration.

D.

To make applications accessible from any web browser without requiring Zscaler Client Connector, browser plug-ins, or additional browser configuration.

Question 10

A device meets VPN-trusted-network criteria where existing corporate controls apply, and administrators want to minimize unnecessary tunneling while relying on application and IP bypasses in the Application Profile for selected low-latency traffic.

Which Forwarding Profile action aligns with this approach for the VPN-trusted context?

Options:

A.

Tunnel with Local Proxy to introduce loopback-proxy handling and then wrap flows in a secure tunnel

B.

Tunnel mode (Z-Tunnel 2.0) to encapsulate traffic despite the presence of VPN-based corporate enforcement

C.

No Forwarding to permit direct breakout under established corporate controls on VPN-trusted networks

D.

Enforce Proxy with PAC routing to apply proxy semantics even when VPN-based controls are already in place

Question 11

Which is an example of Inline Data Protection?

Options:

A.

Preventing the copying of a sensitive document to a USB drive.

B.

Preventing the sharing of a sensitive document in OneDrive.

C.

Analyzing a customer’s M365 tenant for security best practices.

D.

Blocking the attachment of a sensitive document in webmail.

Question 12

What is the purpose of a Microtunnel (M-Tunnel) in Zscaler?

Options:

A.

To provide an end-to-end communication channel between ZCC clients

B.

To provide an end-to-end communication channel to Microsoft Applications such as M365

C.

To create an end-to-end communication channel to Azure AD for authentication

D.

To create an end-to-end communication channel to internal applications

Question 13

How does Zscaler ensure that sensitive structured data used in the EDM process is not stored in its cloud environment?

Options:

A.

By storing sensitive structured data on servers managed by trusted Zscaler staff for enhanced security.

B.

By using an on-premises VM to index data and only sending hashed values to the cloud.

C.

By requiring customers to manually hash the data and upload it to the cloud.

D.

By encrypting sensitive data directly before storing it in the cloud.

Question 14

When configuring webhook alerts in ZIA, which two webhook authentication types are supported?

Options:

A.

Basic and OAuth

B.

Token and OAuth

C.

Basic and Token

D.

Digest and OAuth

Question 15

What must new administrators in ZIdentity be assigned to perform administrative functions for Zscaler products?

Options:

A.

Service Entitlements

B.

Just-in-Time (JIT) provisioning

C.

Environments

D.

Administrative Entitlements

Question 16

A tenant’s Cloud App Control policy permits Webmail globally. Security requires members of the Sales group to receive a CAUTION prompt when accessing personal Webmail, while all other groups must continue to receive unrestricted access.

Sales users and other groups are currently matched by a Cloud App Control rule that allows all Webmail.

Which action should the administrator take to meet the requirement for the Sales group?

Options:

A.

Configure a time-based URL Filtering rule for Webmail that targets Sales so business hours force re-evaluation under URL Filtering criteria

B.

Create a Cloud App Control rule that targets the Sales group and personal Webmail applications, set its action to CAUTION, and place it above the general allow rule

C.

Place the Sales URL Filtering rule below the global acceptable-use baseline so broader actions are inherited before group-specific evaluation

D.

Create a Bandwidth Control rule for Webmail that applies to Sales, expecting URL Filtering to engage when traffic is constrained

Question 17

Which of the following can be used as Trusted Network criteria in Zscaler Client Connector?

Options:

A.

DNS Server, DHCP Server and Hostname/IP

B.

DHCP Server, DNS Search Domain and Hostname/IP

C.

Hostname/IP, DNS Server and DNS Search Domain

D.

Hostname/IP, DNS Search Domain and DHCP Server

Question 18

An operations team relies on API-driven exports of ZDX scores and Firewall Insights to track application performance over time. The team encounters periodic HTTP 429 errors during peak hours, and performance regressions are missed when exports fail.

Which mitigation best reduces blind spots that contribute to preventable performance issues?

Options:

A.

Shorten token-expiry intervals to force more frequent reauthentication and improve client statefulness under contention

B.

Increase the number of parallel API workers during peak hours to clear the telemetry backlog faster

C.

Assign broader API scopes to the client so retries can fetch more datasets during each export cycle

D.

Use client-side rate limiting with exponential backoff, schedule batch exports during off-peak periods, and optimize queries to reduce redundant calls

Question 19

What is the default policy configuration setting for checking for Viruses?

Options:

A.

Allow

B.

Block

C.

Unwanted Applications

D.

Malware Protection

Question 20

Which command-line parameter is used to activate tamper proofing during the installation of Zscaler Client Connector?

Options:

A.

--secureInstall

B.

--antiTamper

C.

--disableTampering

D.

--enableAntiTampering

Question 21

A log review shows requests to a sanctioned application being allowed despite a later rule intended to restrict access by time of day.

The rule set is:

    Allow the sanctioned application for All Employees

    Block the sanctioned application outside business hours for All Employees

    Log restricted-access hits

Which cause and risk are most consistent with this behavior?

Options:

A.

The time-of-day block inherits timing from device posture, which desynchronizes evaluation and produces inconsistent enforcement

B.

The initial allow rule matches first and stops further evaluation, so the time-of-day block never applies and access remains available after business hours

C.

The logging rule takes precedence because of its action type, preventing the block from being reached

D.

The sanctioned application category becomes invalid during SSL inspection, sending the request to a default allow path that bypasses time restrictions

Question 22

Which of the following is a key feature of Zscaler Data Protection?

Options:

A.

Data loss prevention

B.

Stopping reconnaissance attacks

C.

DDoS protection

D.

Log analysis

Question 23

Zscaler Platform Services works upon unencrypted data from encrypted communications due to which of the following?

Options:

A.

Antivirus

B.

Tenant Restrictions

C.

Web Filtering

D.

TLS Inspection

Question 24

What Zscaler control can be implemented to limit exposure to malicious content?

Options:

A.

Role Based Access control (RBAC)

B.

Bandwidth Controls

C.

File type Controls

D.

Zscaler Digital Experience

Question 25

Fundamental capabilities needed by other services within the Zscaler Zero Trust Exchange are provided by which of these?

Options:

A.

Access Control Services

B.

Digital Experience Monitoring

C.

Cyber Security Services

D.

Platform Services

Question 26

Which of the following statements most accurately describes Zero Trust Connections?

Options:

A.

They require that SSH inspection be enabled.

B.

They are dependent on a fixed / static network environment.

C.

They are independent of any network for control or trust.

D.

They require IPv6.

Question 27

Which Advanced Threat Protection feature restricts website access by geographic location?

Options:

A.

Spyware Callback

B.

Botnet Protection

C.

Blocked Countries

D.

Browser Exploits

Question 28

When creating an installer package or using the command-line for installation, which Zscaler Client Connector installer options are used to automatically redirect to your corporate SAML IdP on launch?

Options:

A.

--deviceToken and --strictEnforcement

B.

This is automatic when SAML is configured. No options are required.

C.

--cloudName and --userDomain

D.

--policyToken and --userDomain

Question 29

A Gold-class SaaS application performs poorly even though its bandwidth class has a generous minimum and moderate maximum. Usage dashboards show available capacity during incidents, and other applications are not saturating the link.

What is the most defensible next step to prevent recurring degradation?

Options:

A.

Prioritize streaming media above the SaaS application to normalize queue behavior and reduce circuit jitter

B.

Reduce TLS inspection for the SaaS application to remove inspection latency without first validating the traffic path

C.

Raise the Gold-class maximum to a higher ceiling to address presumed internal throttling

D.

Use ZDX path metrics to validate last-mile or ISP congestion at the affected site and plan a circuit upgrade or provider change while retaining the current policies

Question 30

Zscaler Advanced Threat Protection (ATP) is a key capability within Zscaler Internet Access (ZIA), protecting users against attacks such as phishing. Which of the following is NOT part of the ATP workflow?

Options:

A.

IPS coverages for client-side and server-side

B.

Reporting high latency from the CEO ' s Teams call due to a low Wi-Fi signal

C.

Comprehensive URL categories for newly registered domains

D.

Preventing the download of a password protected zip file

Question 31

When are users granted conditional access to segmented private applications?

Options:

A.

After passing criteria checks related to authorization and security.

B.

Immediately upon connection request for best performance.

C.

After a short delay of a random number of seconds.

D.

After verifying the user password inside of private application.

Question 32

In support of data privacy for TLS/SSL inspection, when you subscribe to ZIA, you enter into what kind of agreement?

Options:

A.

Zscaler Compliance Policy

B.

Zscaler Privacy Policy

C.

Acceptable Use Policy

D.

Zscaler Data Processing Agreement

Question 33

Your company has a new ZIA subscription. Which is the most effective and secure method of provisioning users?

Options:

A.

Kerberos

B.

SAML auto-provisioning

C.

LDAP synchronization

D.

Zscaler Authentication Bridge

Question 34

Which of the following options will protect against Botnet activity using IPS and Yara type content analysis?

Options:

A.

Command and Control Traffic

B.

Ransomware

C.

Trojans

D.

Adware/Spyware Protection

Question 35

A contractor in the Field_Eng SAML group attempts to access an internal CAD application through ZPA from a branch designated as a Trusted Network. The Access Policy requires Field_Eng membership AND a device-posture profile confirming full-disk encryption and a CrowdStrike ZTA score above 80. The user passes the ZTA score requirement, but Device Posture reports that disk encryption is disabled.

Which enforcement outcome should be expected for this session?

Options:

A.

Quarantine the traffic through ZIA Cloud Sandbox for risk analysis

B.

Deny access to the private application because the device fails the mandatory disk-encryption requirement

C.

Permit restricted access through a more distant App Connector

D.

Bypass Access Policy evaluation because the branch is designated as a Trusted Network

Question 36

What are the two types of Probe supported in ZDX?

Options:

A.

Web Probes and Cloud Path Probes

B.

Application Probes and Network Probes

C.

Page Speed Probes and Connection Speed Probes

D.

SaaS Probes and Router Probes

Question 37

An investigation at a regional office identifies sensitive files leaving a sanctioned SaaS platform outside business hours. Follow-up analysis shows that several users transferred content through native mobile applications that do not consistently traverse ZIA inline inspection.

Which action should the security lead take next to assess security across the SaaS environment?

Options:

A.

Verify that Browser Isolation is enabled for high-risk sessions and restrict uploads during suspicious activity

B.

Audit Client Connector posture checks for operating system, disk encryption, and antivirus status to determine whether compliance gates align with DLP enforcement

C.

Examine DNS telemetry for tunneling to newly registered domains and suppress anomalous outbound queries

D.

Initiate out-of-band CASB scanning with DLP engines to classify data at rest and review external-sharing configurations across the SaaS tenant

Question 38

How do Access Policies relate to the Application Segments and Application Segment Groups?

Options:

A.

When a condition is met, an Access Policy can either allow or block access to Application Segments OR Application Segment Groups.

B.

When a condition is met, an Access Policy can allow access to Application Segments Groups and block access to Application Segment.

C.

When a condition is met. an Access Policy can either allow or block access to Application Segments and Application Segment Groups.

D.

When a condition is met, an Access Policy can allow access to Application Segments and block access to Application Segment Groups.

Question 39

Which list of protocols is supported by Zscaler for Privileged Remote Access?

Options:

A.

RDP, VNC and SSH

B.

RDP, SSH and DHCP

C.

SSH, DNS and DHCP

D.

RDP, DNS and VNC

Question 40

What does Zscaler Cloud Sandbox protect from?

Options:

A.

It protects sensitive data from leaving through external channels.

B.

It protects from potential zero-day threats and advanced persistent threats.

C.

It protects cloud workloads from lateral movement.

D.

It protects users from known malicious files and attacks.

Question 41

A user authenticates through the correct IdP and is synchronized as a member of the SCIM group Contractors. Device posture is compliant, the network is public, and the user attempts to reach an internal HR portal categorized under an internal App Segment for employees.

The Access Policy rule order is:

    Allow High_Value_Assets with Posture

    Block High_Value_Assets

    Allow Contractor Apps

    Block Contractors from Internal Apps

    Allow Internal Apps_2_Employees

Which outcome is most consistent with rule ordering and the evaluated attributes?

Options:

A.

The user is blocked by the contractor restriction on internal apps because the first matching rule for the user ' s group denies internal segments.

B.

The user is blocked by the high-value asset rule set because the internal HR portal is treated as a high-value application.

C.

The user is permitted by the contractor allowance because posture is compliant and the application category is internal.

D.

The user is permitted by the employee-focused allowance because posture is compliant and the application is internal.

Question 42

How does Zscaler Risk360 quantify risk?

Options:

A.

The number of risk events is totaled by location and combined.

B.

A risk score is computed based on the number of remediations needed compared to the industry peer average.

C.

Time to mitigate each identified risk is totaled, averaged, and tracked to show ongoing trends.

D.

A risk score is computed for each of the four stages of breach.

Question 43

Which of the following is a valid action for a SaaS Security API Data Loss Prevention Rule?

Options:

A.

Enable AI/ML based Smart Browser Isolation

B.

Quarantine Malware

C.

Create Zero Trust Network Decoy

D.

Remove External Collaborators and Sharable Link

Question 44

An administrator wants to allow users to access a wide variety of untrusted URLs. Which of the following would allow users to access these URLs in a safe manner?

Options:

A.

Browser Isolation

B.

App Connector

C.

Zscaler Private Access

D.

Zscaler Client Connector

Question 45

A firewall policy set evaluates rules from top to bottom and stops at the first match. Rule 1 allows Marketing users outbound TCP 80/443 to any destination. Rule 2 blocks the Anonymizers network-application category globally. Rule 3 blocks all traffic to 203.0.113.0/24.

What outcome and risk are most likely when a Marketing user accesses an anonymizer over HTTPS?

Options:

A.

Traffic matches the Marketing allow at Rule 1, the global anonymizer block is not evaluated, and the user gains access to anonymizers, increasing exposure

B.

Traffic is deferred to application categorization first and is blocked at Rule 2, with the user denied but with ambiguous logging

C.

Traffic is inspected by IPS before Firewall Filtering and is dropped preemptively, reducing the effect of rule order but causing false positives

D.

Traffic collides with the destination block at Rule 3 because of subnet inference, resulting in intermittent denial and noisy alerts

Question 46

An administrator needs to refine a custom URL category so that low-risk sites in that category are allowed while high-risk or uncertain sites are isolated or blocked, without weakening overall protection.

Which configuration approach aligns with this goal?

Options:

A.

Defer behavior to Cloud App Control so that URL Filtering is bypassed for known applications that match the category criteria

B.

Consolidate controls under a broad global allow rule and depend on bandwidth shaping to constrain risky traffic within the category

C.

Retain parent-category membership and reference the custom category in a higher-priority rule that applies Allow or Isolate actions as needed

D.

Replace parent-category assignments with a custom list to reduce overlap and simplify rule evaluation

Question 47

When configuring an inline Data Loss Prevention policy with content inspection, which of the following are used to detect data, allow or block transactions, and notify your organization ' s auditor when a user ' s transaction triggers a DLP rule?

Options:

A.

Hosted PAC Files

B.

Index Tool

C.

DLP engines

D.

VPN Credentials

Question 48

What does Zscaler Advanced Firewall support that Zscaler Standard Firewall does not?

Options:

A.

Destination NAT

B.

FQDN Filtering with wildcard

C.

DNS Dashboards, Insights and Logs

D.

DNS Tunnel and DNS Application Control

Question 49

What is the name of the feature that allows the platform to apply URL filtering even when a Cloud App control policy explicitly permits a transaction?

Options:

A.

Allow Cascading

B.

Allow and Quarantine

C.

Allow URL Filtering

D.

Allow and Scan

Question 50

Cross-Site Scripting (XSS) attacks are a type of injection, in which malicious scripts are injected into otherwise benign and trusted websites. XSS includes which of the following?

Options:

A.

Spyware Callback

B.

Anonymizers

C.

Cookie Stealing

D.

IRC Tunneling

Question 51

Which of the following enables the discovery of newly observed domains within three minutes of the domain coming online?

Options:

A.

IP Chicken

B.

MXToolbox

C.

Farsight Feed

D.

Dig

Question 52

If you ' re migrating from an on-premises proxy, you will already have a proxy setting configured within the browser or within the system. With Tunnel Mode, the best practice is to configure what type of proxy configuration?

Options:

A.

Execute a GPO update to retrieve the proxy settings from AD.

B.

Enforce no Proxy Configuration.

C.

Use Web Proxy Auto Discovery (WPAD) to auto-configure the proxy.

D.

Use an automatic configuration script (forwarding PAC file).

Question 53

Which of the following is a unified management console for internet and SaaS applications, private applications, digital experience monitoring and endpoint agents?

Options:

A.

identity Admin Portal

B.

Mobile Admin Portal

C.

Experience Center

D.

One API

Question 54

A company requires stricter control of non-web traffic when users are outside the corporate network.

Which adjustment best reduces unintended exposure for off-network users?

Options:

A.

Configure Zscaler Client Connector to use Z-Tunnel 2.0 when off-network, and enable the appropriate Cloud Firewall rules

B.

Increase inspection depth for on-network users to compensate for off-network access risks, assuming that stricter internal analysis provides an aggregate deterrent

C.

Configure Zscaler Client Connector to use Z-Tunnel 1.0 when off-network, and enable the appropriate Cloud Firewall rules

D.

Duplicate the off-network block rule and place both copies below the global allow rule to provide redundant coverage and increased monitoring

Question 55

An organization must comply with privacy requirements that restrict decrypting healthcare and financial websites.

Which configuration most precisely implements SSL/TLS bypass for these requirements while preserving inspection elsewhere?

Options:

A.

Update DLP policy to redact regulated data after decryption during inline inspection

B.

Redistribute the enterprise root CA to endpoints to strengthen trust and maintain decryption across all categories

C.

Create an SSL/TLS Inspection rule that designates the regulated URL categories as Do Not Inspect and exempts those destinations from decryption

D.

Use out-of-band CASB to quarantine sensitive content discovered at rest in SaaS platforms

Question 56

Which of the following secures all IP unicast traffic?

Options:

A.

Secure Shell (SSH)

B.

Tunnel with local proxy

C.

Enforce PAC

D.

Z-Tunnel 2.0

Question 57

A security team suspects that data exfiltration is occurring through encrypted channels to attackers.

To assess the company’s posture before tuning controls, which next step should be taken to validate whether existing protections cover this behavior?

Options:

A.

Raise the severity of egress firewall rules across segments to constrain outbound flows that might be exploited

B.

Review ZIA DLP outbound logs for anomalous uploads to unsanctioned SaaS applications and newly registered domains to gauge detection coverage

C.

Correlate ZIA threat insights with ZPA analytics to identify anomalous outbound patterns and unusual private-application access, and then verify that DLP and botnet controls apply to TLS-decrypted traffic

D.

Trigger broad Cloud Sandbox reanalysis of recent endpoint downloads to look for latent payloads that could facilitate exfiltration

Question 58

An administrator suspects that users in Europe are being routed to a distant service edge, inflating latency before traffic reaches a SaaS provider.

Which ZDX diagnostic provides evidence of inefficient client-to-service-edge routing?

Options:

A.

Audit alerting thresholds for regional score drops and assume that the trigger implies service-edge misalignment

B.

Check endpoint CPU and memory telemetry to argue that device constraints are producing perceived routing inefficiencies

C.

Review Page Fetch Time graphs for the application and deduce that service-edge selection is suboptimal based on slow loads

D.

Examine CloudPath probes for the client-to-service-edge leg to verify latency spikes and excessive hop counts

Question 59

The Forwarding Profile defines which of the following?

Options:

A.

Fallback methods and behavior when a DTLS tunnel cannot be established

B.

Application PAC file location

C.

System PAC file when off trusted network

D.

Fallback methods and behavior when a TLS tunnel cannot be established

Question 60

When users are authenticated using SAML, what are the two most efficient ways of provisioning the users?

Options:

A.

Hosted User Database and Directory Server Synchronization

B.

SAML and Hosted User Database

C.

SCIM and Directory Server Synchronization

D.

SCIM and SAML Autoprovisioning

Question 61

How is data gathered with ZDX Advanced client performance?

Options:

A.

By generating synthetic transactions to designated Internet and Private applications every 5 minutes and measuring the performance of those sessions.

B.

By constantly analyzing live user sessions to both Internet and Private applications and measuring the performance of those sessions.

C.

By using AI predictive analysis ZDX can extrapolate near-term client performance based upon recent past data observed.

D.

By constantly analyzing live user sessions to critical SaaS applications and measuring the performance of those sessions.

Question 62

Which options must be selected when configuring Zscaler Client Connector for Strict Enforcement?

Options:

A.

cloudName and policyToken

B.

userDomain and deviceToken

C.

cloudName and deviceToken

D.

userDomain and policyToken

Question 63

Which are valid criteria for use in Access Policy Rules for ZPA?

Options:

A.

Group Membership, ZIA Risk Score, Domain Joined, Certificate Trust

B.

Username, Trusted Network Status, Password, Location

C.

SCIM Group, Time of Day, Client Type, Country Code

D.

Department, SNI, Branch Connector Group, Machine Group

Question 64

When enabled during Zscaler Client Connector (ZCC) installation, what specific control does the Strict Enforcement feature apply to internet access on end-user Windows workstations?

Options:

A.

It requires users to restart their Windows workstations after ZCC installation before accessing the internet.

B.

It prevents users from uninstalling ZCC without proper authorization.

C.

It requires users to enroll with ZCC before accessing the internet.

D.

It prevents users from logging out of ZCC without proper authorization.

Question 65

Security wants to trace a user ' s attempted upload over HTTP to determine whether web policy blocked the transfer and to confirm the category and rule that drove the decision.

Which option is appropriate for confirming a block on an HTTP upload?

Options:

A.

Leverage ZDX telemetry to explore path performance and endpoint experience during the attempt

B.

Review DNS Insights to examine name-resolution activity aligned with the destination service

C.

Use Web Insights to view transaction details, category attribution, and the matched web rule

D.

Open Firewall Insights to study rule hits and bandwidth distribution across egress points

Question 66

A global URL Filtering rule blocks Newly Registered Domains and Anonymizers. Marketing has a rule that allows Social Media with a Caution action, and specific group-based rules appear above broader global rules. A user who belongs to both Marketing and Contractors attempts to access a social-media subdomain that is newly registered and classified under both Social Media and Newly Registered Domains.

What enforcement outcome is most consistent with the rule hierarchy and category matching?

Options:

A.

Continuous evaluation defers the decision until the domain’s reputation stabilizes, causing temporarily degraded access instead of a definitive allow or block

B.

The global block preempts departmental allows regardless of rule order, resulting in denial because high-risk categories are automatically prioritized

C.

Cloud App Control is evaluated first and blocks the request at the application level, making URL Filtering irrelevant to the transaction

D.

The Marketing-specific rule matches first because of its higher position and category criteria, applies the Caution action, and prevents the later global block from being evaluated

Question 67

An operations team wants to determine whether reported slowness in a SaaS application is caused by the application, the network, or the endpoint.

Which ZDX diagnostic should be prioritized to align performance degradation with regions, ISPs, or time windows?

Options:

A.

Initiate device-telemetry checks for high CPU utilization and unstable Wi-Fi to flag local constraints before considering path conditions

B.

Run CloudPath probes to capture hop-by-hop latency and packet loss along the end-to-end route to the application

C.

Query Inventory APIs to identify endpoints with older Client Connector builds that may lack recent telemetry capabilities

D.

Review the application’s ZDX Score and Page Fetch Time to correlate degradation with geography and time frames

Question 68

A Zscaler Client Connector App Profile is configured to apply a Forwarding Profile that forwards all traffic to the Zero Trust Exchange using Z-Tunnel 2.0. If a change is made to the Logout password in the App Profile, how long will it be before the new logout password is in effect?

Options:

A.

Policy updates happen in real time, so the new logout password is in effect as soon as the change is saved.

B.

The new logout password will be in effect after the Activate button is clicked in the Admin portal.

C.

The new logout password will be in effect after the user clicks Update Policy on the client.

D.

Policy updates occur every 60 minutes, so the logout password will be in effect after the next scheduled update.

Question 69

What is the maximum default frequency of device posture profile evaluation by Zscaler Client Connector?

Options:

A.

15 minutes

B.

2 minutes

C.

5 minutes

D.

10 minutes

Question 70

A regional office reports persistent throttling of a critical SaaS application during business hours. The Bandwidth Control dashboard shows the application assigned to a class with a narrow maximum, while rule-hit counts indicate that non-critical streaming traffic is receiving excessive bandwidth.

Which action should the network team take to improve performance?

Options:

A.

Add a parallel rule for the critical application in the same class to increase match frequency despite the existing caps

B.

Broaden minimum bandwidth globally, accepting reduced headroom for all locations to offset localized congestion

C.

Stream firewall logs to the SIEM and defer policy updates until multi-source correlation identifies external bottlenecks

D.

Refactor the bandwidth-class definitions and rule order to increase the critical application’s allocation and restrict non-critical streaming, then validate the change in Firewall Insights

Question 71

Layered defense throughout an organization security platform is valuable because of which of the following?

Options:

A.

Layered defense increases costs to attackers to operate.

B.

Layered defense from multiple vendor solutions easily share attacker data.

C.

Layered defense ensures attackers are prevented eventually.

D.

Layered defense with multiple endpoint agents protects from attackers.

Question 72

When configuring Applications to be monitored, what probe types can be created?

Options:

A.

Page Fetch Time Probe and Cloud Path Probe

B.

Web Probe and Page Fetch Time Probe

C.

Page Fetch Time Probe and Server Response time Probe

D.

Web Probe and Cloud Path Probe

Question 73

What is the scale used to represent a users Zscaler Digital Experience (ZDX) score?

Options:

A.

1-100

B.

1-10

C.

1 - 1000

D.

0 - 50

Question 74

An organization has more than one ZIA instance, each on different clouds. The organization is using the same login domain for both and upon login users are given this menu in ZCC asking which cloud they would like to join. What steps could an Administrator take to avoid having this menu appear?

Options:

A.

Customize an MSI version of the ZCC file specifying the USERDOMAIN variable.

B.

Customize an MSI version of the ZCC file specifying the CLOUDNAME variable.

C.

Federate the login domain between two different IDP instances.

D.

Create only one SAML integration with the desired ZIA instance.

Question 75

What is the main purpose of Sandbox functionality?

Options:

A.

Block malware that we have previously identified

B.

Build a test environment where we can evaluate the result of policies

C.

Identify Zero-Day Threats

D.

Balance threat detection across customers around the world

Question 76

When configuring Zscaler Private Access, what is the function of the Server Group?

Options:

A.

Maps FQDNs to IP Addresses

B.

Maps Applications to FQDNs

C.

Maps App Connector Groups to Application Segments

D.

Maps Applications to Application Groups

Question 77

Which Platform Service enables visibility into the headers and payload of encrypted transactions?

Options:

A.

Policy Framework

B.

TLS Decryption

C.

Reporting and Logging

D.

Device Posture

Question 78

What method does Zscaler Identity Threat Detection and Response use to gather information about AD domains?

Options:

A.

Scanning network ports

B.

Running LDAP queries

C.

Analyzing firewall logs

D.

Packet sniffing

Question 79

An organization experiences frequent changes in team structure and wants to keep group membership and access aligned consistently.

Which approach supports scalable, controlled administration?

Options:

A.

Rely on SAML assertions to grant administrator rights during authentication events

B.

Consume SCIM-provisioned groups from the identity provider and drive entitlements through those groups

C.

Assign administrative capabilities individually to each user to avoid group-level drift

D.

Create local user accounts to separate access from external directories

Question 80

When correlating indicators of privilege escalation with administrator behavior, which log type provides the most direct visibility into role changes and entitlement modifications for administrative accounts?

Options:

A.

Firewall Insights reports centered on rule hits and bandwidth consumption at egress points

B.

ZIdentity Administrator Audit Log filtered for entitlement updates and role assignments

C.

Web Insights transaction logs focusing on URL categories and inline policy actions

D.

Endpoint DLP telemetry summarizing sensitive-data handling and removable-media events

Question 81

A team begins using domains that were dormant for months and recently revived. TLS inspection is enabled, but some teams added URL exceptions that bypass malware inspection.

Which action should a ZIA administrator take to prevent callbacks while minimizing disruption?

Options:

A.

Enable Browser Isolation for all sites flagged as recently active and let sessions render in isolation to reduce potential impact

B.

Depend on Advanced Threat Protection risk scoring by raising the risk threshold so borderline pages are treated as unsafe and blocked across categories

C.

Remove URL scanning exceptions for the affected teams, enforce a block policy targeting the Newly Revived Domains category, and configure DNS security to deny resolution for those hostnames

D.

Apply detect-only IPS mode to observe behavior, then plan a gradual transition to blocking after signatures show sustained activity

Page: 1 / 27
Total 273 questions