Summer Sale - Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 65percent

Welcome To DumpsPedia

ZDTA Sample Questions Answers

Questions 4

When creating an installer package or using the command-line for installation, which Zscaler Client Connector installer options are used to automatically redirect to your corporate SAML IdP on launch?

Options:

A.

--deviceToken and --strictEnforcement

B.

This is automatic when SAML is configured. No options are required.

C.

--cloudName and --userDomain

D.

--policyToken and --userDomain

Buy Now
Questions 5

Which Zscaler feature detects whether an intruder is accessing your internal resources?

Options:

A.

SandBox

B.

SSL Decryption Bypass

C.

Browser Isolation

D.

Deception

Buy Now
Questions 6

A platform team deploys Bandwidth Control and firewall policy changes through an API. After a large rollout, users report sporadic application slowdowns, yet the monitoring team finds gaps in telemetry for the same time windows.

Which action best prevents these performance issues from persisting and going undetected in similar rollouts?

Options:

A.

Add an implementation step that validates monitoring subscriptions and exports ZDX and Firewall Insights baselines before applying policy changes through APIs

B.

Aggregate logs monthly and perform retrospective correlation to avoid noisy short-term fluctuations in metrics

C.

Increase API client-token lifetimes to reduce HTTP 401 errors and stabilize automation during policy pushes

D.

Restrict automation runs to weekly windows to minimize configuration changes that may obscure trend lines

Buy Now
Questions 7

A mixed policy set contains an Allow for high-value assets with posture, followed by a Block for high-value assets, then role-specific Allow rules for contractors and employees. Multiple users report unexpected reach to internal apps from unmanaged devices.

Considering rule order, attribute evaluation, and logical operators in ZPA Access Policies, which change best narrows access while minimizing unintended matches?

Options:

A.

Move the Block for high-value assets ahead of the posture-gated Allow to force stricter denial before any role-specific permissions are evaluated

B.

Convert client type and application segment fields to AND logic within the Allow rules so fewer sessions qualify during initial matching

C.

Add a trusted network condition to the employee Allow rule so sessions originating from external locations match a later Block action

D.

Place the posture-gated Allow for sensitive apps above role-specific Allows and apply AND logic to SAML/SCIM attributes and posture in those role rules

Buy Now
Questions 8

Which Platform Service enables visibility into the headers and payload of encrypted transactions?

Options:

A.

Policy Framework

B.

TLS Decryption

C.

Reporting and Logging

D.

Device Posture

Buy Now
Questions 9

A company observes risky uploads from unmanaged devices connecting over public Wi-Fi to cloud storage. The devices intermittently fail posture checks, and logs show inconsistent category enforcement.

Which action places the stricter control where it will be applied consistently to off-network traffic?

Options:

A.

Attach tenant-restriction profiles to a limited set of users in CASB and rely on inherited group mappings to constrain cloud activity

B.

Add connector-level ZPA policies that restrict FQDNs for storage endpoints and deny remote TCP ports used by synchronization clients

C.

Create a ZIA rule set scoped to roaming users and unauthenticated sessions, positioned early in the policy order to enforce stronger Cloud App Control and URL Filtering

D.

Deploy branch bandwidth classes that shape storage traffic in sublocations to reduce large upload attempts from remote users

Buy Now
Questions 10

Layered defense throughout an organization security platform is valuable because of which of the following?

Options:

A.

Layered defense increases costs to attackers to operate.

B.

Layered defense from multiple vendor solutions easily share attacker data.

C.

Layered defense ensures attackers are prevented eventually.

D.

Layered defense with multiple endpoint agents protects from attackers.

Buy Now
Questions 11

A sanctioned SaaS application is allowed in Cloud App Control but appears to be blocked by URL Filtering.

Which configuration would permit access through a controlled bypass that follows policy precedence?

Options:

A.

Move the URL Filtering Allow rule above the Block rule, noting that Cloud App Control-to-URL precedence can still cause an unintended denial

B.

Disable cascading to URL Filtering so Cloud App Control precedence applies and the URL layer does not override the permitted application

C.

Refine Device Posture profile thresholds, acknowledging that posture conditions do not reorder URL policy evaluation

D.

Configure a Trusted Network condition to bypass forwarding, accepting that the block might persist in the URL layer

Buy Now
Questions 12

A new customer has just purchased Zscaler for Users.

Which of the following Zscaler service entitlements is enabled by default?

Options:

A.

ZPA

B.

Deception

C.

ZIA

D.

ZDX

Buy Now
Questions 13

An organization mandates strict BYOD controls and does not permit endpoint agents on personal devices. Which Zscaler deployment approach aligns with this requirement while maintaining data protection for access to corporate applications?

Options:

A.

Adopt agentless access by combining Browser Isolation for SaaS applications and clientless ZPA for private applications

B.

Require self-enrollment in Zscaler Client Connector across personal endpoints to enforce forwarding profiles

C.

Depend on location-based rules and user agents to shape traffic from home and public networks

D.

Use per-application Zscaler Client Connector tunnels for unmanaged devices to segment private application access

Buy Now
Questions 14

A data center requires connectivity to Zscaler for traffic inspection without an encryption requirement. The site must support a defined bandwidth profile of 2.2 Gbps and has no high-availability requirement.

Which configuration uses the minimum number of tunnels while meeting the throughput requirement?

Options:

A.

Configure three GRE tunnels mapped to the same location and use equal-cost multipath routing to support the aggregate 2.2 Gbps throughput

B.

Configure one IPSec peer with Dead Peer Detection enabled and conservative cipher settings to reduce processing load on the edge device

C.

Configure two GRE tunnels to different Service Edges and apply strict MTU policing to reduce fragmentation

D.

Configure two IPSec peers with static routing to divide traffic while accepting the additional key-exchange processing

Buy Now
Questions 15

What is the recommended default rule for the cloud-gen firewall configuration when deploying a new ZIA tenant?

Options:

A.

Block all traffic

B.

Permit all traffic

C.

Disable the firewall

D.

Allow only web traffic (ports 80/443)

Buy Now
Questions 16

A regional hospital must provide a vendor with intermittent access to a legacy device-management application hosted on two on-premises servers. The vendor’s previous VPN caused noisy port scans to appear in logs and exposed nearby subnets to probing.

Which action should the administrator take to constrain access to the application while reducing lateral movement?

Options:

A.

Create ZPA Application Segments for the device-management FQDNs and ports, and enforce identity- and posture-based policies for the vendor group

B.

Configure DNS sinkholes to divert off-port vendor traffic and apply URL Filtering to suppress non-application flows

C.

Deploy a dedicated VLAN and a jump host near the application, and restrict traffic with subnet ACLs that limit the vendor to the jump host’s IP address

D.

Implement host-based firewall rules on both servers and advertise a reduced VPN route set to the vendor client

Buy Now
Questions 17

What conditions can be referenced for Trusted Network Detection?

Options:

A.

Hostname Resolution, Network Adapter IP, Default Gateway

B.

DNS Servers, DNS Search Domain, Network Adapter IP

C.

Hostname Resolution, DNS Servers, Geo Location

D.

DNS Search Domain, DNS Server, Hostname Resolution

Buy Now
Questions 18

What is a ZIA Sublocation?

Options:

A.

The section of a corporate Location used to separate traffic, like traffic from employees from guest traffic

B.

The section of a corporate Location that sends traffic to a Subcloud

C.

Every one of the sections in a Corporate Location that use overlapping IP addresses

D.

A way to separate generic traffic from that coming from Client Connector

Buy Now
Questions 19

A company must enforce least-privileged access to private applications when contractors connect from varying locations using devices with inconsistent security posture. The security team wants decisions to use identity and per-session context instead of broad network assumptions.

Which approach best meets the requirement?

Options:

A.

Build ZPA Access Policy rules around a SCIM-synchronized contractor group, apply device-posture conditions to sensitive application segments, and retain a final catch-all deny rule

B.

Prioritize ZIA URL Filtering rules that use department attributes to shape contractor access, and leave ZPA unchanged

C.

Use location groups to provide contractors with tiered access to most internal services and defer device evaluation to downstream controls

D.

Require session MFA for contractor authentication and use SAML attributes to relax private-application access broadly

Buy Now
Questions 20

A regional SOC analyst reviews ZIdentity audit logs during a surge in administrator-related anomalies at a hosted data center. The same session shows a successful sign-in from a new geography, a change that relaxes an MFA requirement in a sign-on policy, and an entitlement grant to a service account used by build automation.

Which action should the incident responder take to constrain privilege-escalation exposure while preserving forensic continuity?

Options:

A.

Revoke the service account’s elevated entitlements and restore the previous sign-on policy conditions that enforced stronger MFA

B.

Initiate a broad sign-on policy rollback across all roles and defer entitlement changes until the next maintenance cycle

C.

Increase audit verbosity for administrator actions and monitor for additional anomalies before applying restrictions

D.

Pause SIEM ingestion and collect on-appliance logs while delaying changes to avoid affecting correlation

Buy Now
Questions 21

An executive summary correlates Risk360 category-contribution views with audit commitments: identity risk has decreased, but data-loss risk is trending upward; business-unit mean time to remediate (MTTR) variance suggests uneven remediation; and leadership requests board-ready evidence of continuous improvement mapped to the NIST Cybersecurity Framework (CSF).

What is the appropriate next step based on this summary and goal?

Options:

A.

Emphasize a single recent incident in a narrative memo and deprioritize category-contribution drill-downs to avoid distracting detail

B.

Replace Unified Vulnerability Management tasking with ad hoc email assignments to reduce tooling reliance, even if closure tracking becomes inconsistent

C.

Hold reporting until after policy changes take effect to avoid confusing auditors with fluctuating score baselines

D.

Produce framework-aligned dashboards with MTTR variance reporting and schedule cross-team reviews to track category-level risk reduction

Buy Now
Questions 22

How does a Zscaler administrator troubleshoot a certificate pinned application?

Options:

A.

They could look at SSL logs for a failed client handshake.

B.

They could reboot the endpoint device.

C.

They could inspect the ZIA Web Policy.

D.

They could look into the SaaS application analytics tab.

Buy Now
Questions 23

What is a Landmine in Deception?

Options:

A.

Agentless plug-in installed on endpoints, such as desktops or laptops on a network. These plug-ins deploy decoy credentials, files, processes, and lures to other decoys at endpoints.

B.

Software agent installed on a centralized server in datacenter or in cloud. The agents running in the server deploy decoy credentials, files, processes, and lures to other decoys at endpoints.

C.

Software agent installed on endpoints, such as desktops or laptops on a network. These agents deploy decoy credentials, files, processes, and lures to other decoys at endpoints.

D.

Agentless plug-in installed on endpoints, such as desktops or laptops on a network. These plug-ins auto rotates decoy credentials, files, processes, and lures to other decoys at endpoints.

Buy Now
Questions 24

A finance user downloads a password-protected spreadsheet from a sanctioned SaaS platform. Cloud Sandbox indicates that detonation is delayed because the file is encrypted.

Which action should the administrator take next?

Options:

A.

Configure a File Type Control policy to block unscannable files

B.

Reduce DLP thresholds for the finance department so benign matches are treated as policy violations

C.

Block tenant-wide access to third-party integrations and suspend the finance user’s uploads until further notice

D.

Move inspection exclusively to API-based scanning and disable inline controls to avoid workflow interruptions

Buy Now
Questions 25

What is the purpose of Browser Access in relation to Zscaler Private Access (ZPA)?

Options:

A.

To make applications accessible from any web browser with Zscaler Client Connector deployed on the device.

B.

To make applications accessible using a browser plug-in and additional browser configuration controlled by the organization.

C.

To make applications accessible without user authentication, Zscaler Client Connector, browser plug-ins, or browser configuration.

D.

To make applications accessible from any web browser without requiring Zscaler Client Connector, browser plug-ins, or additional browser configuration.

Buy Now
Questions 26

Which of the following components is installed on an endpoint to connect users to the Zero Trust Exchange regardless of their location - home, work, while traveling, etc.?

Options:

A.

Client connector

B.

Private Service Edge

C.

IPSec/GRE Tunnel

D.

App Connector

Buy Now
Questions 27

In Data Loss Prevention, how are Dictionaries and Engines related?

Options:

A.

A DLP Engine runs over the traffic being sent out and dynamically selects DLP dictionaries to apply

B.

A Data Loss Prevention policy applies a DLP dictionaries

C.

A Data Loss Prevention policy applies a DLP Engine and a DLP engine uses DLP dictionaries

D.

A Data Loss Prevention policy applies a DLP Engine

Buy Now
Questions 28

A branch wants to block unmanaged devices from a private HR web application while allowing managed devices to work. The branch egress IP is configured as a trusted network. A Client Forwarding Policy currently bypasses the HR application for traffic on that trusted network, causing inconsistent enforcement for devices tunneling through the site.

What change should be made to achieve the intended outcome?

Options:

A.

Redefine the HR App Segment to consolidate FQDNs and ports, anticipating that segmentation changes will suppress unmanaged-device access

B.

Tighten the Access Policy posture requirements for the HR application and add a risk-score threshold, despite the existing bypass

C.

Modify the Isolation Policy to insert browser isolation for all HR application sessions from the branch, accepting the overhead and limited interactivity

D.

Adjust the Client Forwarding Policy to stop bypassing the HR application on the trusted network so posture-based access rules can evaluate the sessions

Buy Now
Questions 29

Zscaler utilized a Zero Trust Network Architecture (ZTNA) for segmentation in an environment.

Which of the following prevents lateral movement within an organization?

Options:

A.

Connect users to applications using Identity, device posture, and access policies

B.

Move all applications into the DMZ

C.

Turn on all host based firewalls

D.

Allow access to all resources on the network via VPN

Buy Now
Questions 30

Which of the following are types of device posture?

Options:

A.

Detect Crowdstrike, Crowdstrike ZTA score, First name

B.

Certificate Trust, File Path, Full Disk Encryption

C.

Domain Joined, Process Check, Deception Check

D.

Unauthorized Modification, OS Version, License Key

Buy Now
Questions 31

In a policy set where a department-specific file-type category must take precedence over a broader global control, what action is most appropriate to ensure that the desired category is evaluated first?

Options:

A.

Create a shadow custom URL category to steer evaluation indirectly toward the department rule

B.

Increase the weight of DLP dictionaries so content-inspection outcomes override file-type category evaluation

C.

Place the department-scoped rule above the broader global rule so the specific match is evaluated before the general criteria

D.

Apply bandwidth shaping to de-emphasize the broader rule so that its action is deferred during evaluation

Buy Now
Questions 32

An investigation at a regional office identifies sensitive files leaving a sanctioned SaaS platform outside business hours. Follow-up analysis shows that several users transferred content through native mobile applications that do not consistently traverse ZIA inline inspection.

Which action should the security lead take next to assess security across the SaaS environment?

Options:

A.

Verify that Browser Isolation is enabled for high-risk sessions and restrict uploads during suspicious activity

B.

Audit Client Connector posture checks for operating system, disk encryption, and antivirus status to determine whether compliance gates align with DLP enforcement

C.

Examine DNS telemetry for tunneling to newly registered domains and suppress anomalous outbound queries

D.

Initiate out-of-band CASB scanning with DLP engines to classify data at rest and review external-sharing configurations across the SaaS tenant

Buy Now
Questions 33

A contractor in the Field_Eng SAML group attempts to access an internal CAD application through ZPA from a branch designated as a Trusted Network. The Access Policy requires Field_Eng membership AND a device-posture profile confirming full-disk encryption and a CrowdStrike ZTA score above 80. The user passes the ZTA score requirement, but Device Posture reports that disk encryption is disabled.

Which enforcement outcome should be expected for this session?

Options:

A.

Quarantine the traffic through ZIA Cloud Sandbox for risk analysis

B.

Deny access to the private application because the device fails the mandatory disk-encryption requirement

C.

Permit restricted access through a more distant App Connector

D.

Bypass Access Policy evaluation because the branch is designated as a Trusted Network

Buy Now
Questions 34

Which of the following features protects traffic to internal applications from attacks such as cross-site scripting (XSS), cookie poisoning, and SQL injection?

Options:

A.

Zscaler Digital Experience

B.

ZIdentity

C.

Zscaler Private AppProtection

D.

Zscaler Cloud Firewall

Buy Now
Questions 35

The security exceptions allow list for Advanced Threat Protection apply to which of the following Policies?

Options:

A.

Sandbox

B.

URL Filtering

C.

File Type Control

D.

IPS Control

Buy Now
Questions 36

Which API architectural style is used by Zscaler for Zero Trust Automation?

Options:

A.

JSON-RPC

B.

SOAP

C.

GraphQL

D.

REST

Buy Now
Questions 37

A security lead reviews an executive summary: data-loss risk is driven by high-volume uploads to risky SaaS applications and unmanaged generative AI use; MTTR for BU-West remains high because of ticket-routing delays; and the board wants a 15% reduction in the data-loss risk score within 60 days. Peer benchmarks are similar but show identity risk as the primary driver elsewhere.

Which action should be taken next?

Options:

A.

Open UVM remediation for low-severity endpoint findings at scale to create throughput metrics regardless of category alignment

B.

Schedule an updated board narrative and postpone technical changes until the next quarter to avoid conflicting with peer comparisons

C.

Tighten Cloud App Control for risky SaaS and AI usage, and configure MTTR routing by business unit with ITSM integration

D.

Commission an identity-hardening review centered on private-application access patterns to mirror peer drivers even though local data-loss signals persist

Buy Now
Questions 38

Which proprietary technology does Zscaler use to calculate risk attributes dynamically for websites?

Options:

A.

Third-Party Sandbox

B.

Zscaler PageRisk

C.

Browser Isolation Feedback Form

D.

Deception Controller

Buy Now
Questions 39

From a user perspective, Zscaler Bandwidth Control performs traffic shaping and buffering on what direction(s) of traffic?

Options:

A.

Outbound traffic is shaped. Inbound or localhost traffic is unshaped.

B.

Outbound or inbound traffic is shaped. Localhost traffic is unshaped.

C.

Inbound traffic is shaped. Outbound or localhost traffic is unshaped.

D.

Localhost traffic is shaped. Outbound or Inbound traffic is unshaped.

Buy Now
Questions 40

How does ZDX compute the score for an application?

Options:

A.

Zscaler takes all the users that accessed the application for the selected time period and finds the lowest value each user would have experienced for the application. The lowest values for each user are added together and divided by the number of users.

B.

Zscaler considers a single user that accessed the application for the selected time period and finds the lowest value that user would have experienced for the application. The lowest values for that user are added together and divided by the number of all users in the organization.

C.

Zscaler takes sample set of users that accessed the application for the selected time period and finds the lowest value each user would have experienced for the application. The lowest values for each user are added together and divided by the number of sample set of users.

D.

Zscaler takes the lowest value for each application for a set of users, for time intervals based on the selected time range. The application with the lowest value represents your applications score for that time interval.

Buy Now
Questions 41

A user authenticates through an IdP. The SAML assertion and SCIM provisioning return different group memberships.

Which placement and policy-evaluation outcome ensures the most consistently up-to-date results?

Options:

A.

Place the user into SCIM-synchronized groups that drive ZIA and ZPA service entitlements, evaluated with SAML and SCIM attributes in the Policy Framework.

B.

Place the user into the IdP Entity ID-specific realm, evaluated against ZPA policies that derive access primarily from the department attribute.

C.

Place the user in a local ZIdentity group inferred from NameID, evaluated against ZIA policies that prioritize session MFA status over SCIM groups.

D.

Place the user into a transient session group based on MFA, evaluated against ZIA Firewall rules that map Entity ID to service entitlements.

Buy Now
Questions 42

The Forwarding Profile defines which of the following?

Options:

A.

Fallback methods and behavior when a DTLS tunnel cannot be established

B.

Application PAC file location

C.

System PAC file when off trusted network

D.

Fallback methods and behavior when a TLS tunnel cannot be established

Buy Now
Questions 43

What are common delivery mechanisms for malware?

Options:

A.

Malware downloads from web pages

B.

Personal emails, company documents, OneDrive

C.

Spam, exploit kits, USB drives, video streaming

D.

Phishing, Exploit Kits, Watering Holes, Pre-existing Compromise

Buy Now
Questions 44

Which of the following refers to employees’ use of unauthorized applications and services?

Options:

A.

Shadow IT

B.

Browser Isolation

C.

Data Discovery

D.

Posture Control

Buy Now
Questions 45

A network team needs to prevent recurring congestion while meeting performance goals for critical applications. The team has several months of application-usage and bandwidth data across multiple sites.

What approach is most appropriate for avoiding congestion?

Options:

A.

Defer policy changes until user complaints stabilize, then adjust application classes based on the most recent incident set

B.

Analyze multiweek trends by location to identify consistently congested circuits and plan targeted capacity upgrades before peak periods

C.

Convert several high-usage business applications to the Silver class to distribute utilization more evenly across queues

D.

Relax quality-of-service constraints to reduce strict queue boundaries that may be causing packet drops

Buy Now
Questions 46

Which filtering policy blocked access to the Network Application?

Options:

A.

Sandbox

B.

Browser Control

C.

Firewall Filtering

D.

DLP

Buy Now
Questions 47

What is one business risk introduced by the use of legacy firewalls?

Options:

A.

Performance issues

B.

Reduced management

C.

Low costs

D.

Low licensing support

Buy Now
Questions 48

Administrators report that some non-compliant devices can still reach private applications. A broad Allow rule precedes device-posture checks in the policy set.

What is the most appropriate next step to satisfy the compliance-before-access requirement?

Options:

A.

Broaden URL Filtering blocks for high-risk categories to curtail non-business browsing on those devices

B.

Apply stricter user-group scoping to limit access for departments with higher incident rates

C.

Increase time-based restrictions on access windows to reduce exposure during off-hours

D.

Reorder the policy so posture-based access rules are evaluated before any general Allow statements

Buy Now
Questions 49

What does Zscaler Cloud Sandbox protect from?

Options:

A.

It protects sensitive data from leaving through external channels.

B.

It protects from potential zero-day threats and advanced persistent threats.

C.

It protects cloud workloads from lateral movement.

D.

It protects users from known malicious files and attacks.

Buy Now
Questions 50

A device connects to the Zero Trust Exchange with missing antivirus telemetry and an unverified client certificate in its posture profile.

Assuming Leading Practice for posture-driven enforcement are implemented, what is the outcome for the session?

Options:

A.

Route to the nearest service edge and record a posture exception in logs

B.

Apply an isolation policy that constrains interaction until posture is compliant

C.

Treat the session as trusted because the network context is corporate Wi-Fi

D.

Defer the decision to the identity provider due to incomplete posture telemetry

Buy Now
Questions 51

What is a key feature of OpenID Connect (OIDC)-based authentication for users?

Options:

A.

It supports attribute-based access control.

B.

It requires annual certificate maintenance.

C.

It uses JSON-based web tokens.

D.

It uses XML to format identity information.

Buy Now
Questions 52

What Zscaler control can be implemented to limit exposure to malicious content?

Options:

A.

Role Based Access control (RBAC)

B.

Bandwidth Controls

C.

File type Controls

D.

Zscaler Digital Experience

Buy Now
Questions 53

Which feature does Zscaler Client Connector Z-Tunnel 2.0 enable over Z-Tunnel 1.0?

Options:

A.

Enables SSL Inspection for Client Connector

B.

Inspection of all ports and protocols via Cloud Firewall

C.

Enables Browser Isolation

D.

Enables multicast traffic

Buy Now
Questions 54

Which of the following scenarios would generate a “Patient 0” alert?

Options:

A.

Zscaler ' s AI/ML based Smart Browser Isolation was triggered due to a users accessing a newly-registered domain.

B.

A new malicious file was detected by the sandbox due to an “allow and scan” First-Time Action in the sandbox policy.

C.

A new malicious file was detected by the sandbox due to an “quarantine” First-Time Action in the sandbox policy.

D.

Zscaler detected a HIPAA violation with in-band Data Protection scanning.

Buy Now
Questions 55

A campus requires 1.5 Gbps of throughput to Zscaler Service Edges. The underlay is trusted, and the design explicitly excludes high availability.

Which option meets the bandwidth target with the minimum tunnel count?

Options:

A.

Establish a single GRE tunnel with Path MTU Discovery enabled and defer scaling until usage grows

B.

Provision two GRE tunnels associated with the same location and distribute flows through ECMP to achieve 1.5 Gbps

C.

Define two IPsec peers and tune lifetimes to minimize renegotiation during peak demand

D.

Configure one IPsec peer to avoid GRE MTU concerns and rely on static routing to sustain the required throughput

Buy Now
Questions 56

While troubleshooting a user ' s slow application access, can a ZDX administrator see degradations in Wi-Fi signal strength?

Options:

A.

Yes, the Wi-Fi hop latency is shown on a cloud path probe.

B.

Yes. but the current Wi-Fi signal strength is only displayed when doing a deep trace.

C.

No, ZDX only works on hardwired devices.

D.

Yes, a low Wi-Fi signal may be seen in either the results of a Cloud Path Probe or in the device health Wi-Fi signal indicator.

Buy Now
Questions 57

What does a DLP Engine consist of?

Options:

A.

DLP Policies

B.

DLP Rules

C.

DLP dictionaries

D.

DLP identifiers

Buy Now
Questions 58

Company A acquires Company B. Users from both companies require reliable access to internet and SaaS services and to each other’s private applications across overlapping RFC1918 address ranges. A legacy VPN retained temporarily for a third-party integration causes intermittent route conflicts and noticeable latency.

Which action should the administrator prioritize to stabilize access and minimize network-level collisions?

Options:

A.

Move all private-application traffic to a shared MPLS core and rely on centralized firewalls to normalize traffic while retaining split tunneling for internet access

B.

Expand the legacy VPN mesh, tighten BGP route filters, and defer access transformation until IP renumbering is complete

C.

Onboard private applications into ZPA using application segments and dedicated App Connector groups for each environment, enable Client Connector forwarding for private access, and use ZIA with local internet breakouts, Bandwidth Control, and Microsoft 365 optimization

D.

Implement SD-WAN steering policies to pin traffic to preferred links and use access control lists to block disallowed subnets as an interim control

Buy Now
Questions 59

An administrator is provisioning new App Connectors in Microsoft Azure. A new egress policy enforces TLS inspection for outbound traffic from the workload subnets.

Which action should the ZPA administrator take to prevent App Connector registration failures?

Options:

A.

Request static NAT gateway pinning for App Connector egress so ZPA anchors microtunnels to fixed public IP addresses across virtual networks

B.

Explain that App Connector egress traffic to ZPA Service Edges must bypass TLS interception

C.

Recommend disabling App Connector health checks during application-mobility windows to prevent premature failover

D.

Advise the cloud team to delay virtual-machine scale-set events until DNS TTLs expire to minimize App Connector group changes

Buy Now
Questions 60

If you ' re migrating from an on-premises proxy, you will already have a proxy setting configured within the browser or within the system. With Tunnel Mode, the best practice is to configure what type of proxy configuration?

Options:

A.

Execute a GPO update to retrieve the proxy settings from AD.

B.

Enforce no Proxy Configuration.

C.

Use Web Proxy Auto Discovery (WPAD) to auto-configure the proxy.

D.

Use an automatic configuration script (forwarding PAC file).

Buy Now
Questions 61

Policy troubleshooting identifies inconsistent enforcement across web and private-application channels for a regulated data type. The inconsistency causes inefficient investigations and intermittent blocking.

Which action would most plausibly improve platform performance under this policy framework?

Options:

A.

Align the policies to shared DLP engines and classification labels, with clearly defined precedence to eliminate cross-channel conflicts

B.

Create separate custom rules for each channel to isolate false positives despite using different classification references

C.

Reduce detection scope for private applications and prioritize web controls to minimize cross-channel matches

D.

Segment enforcement by department so identical data types can be handled differently without policy overlap

Buy Now
Questions 62

What is the recommended minimum number of App connectors needed to ensure resiliency?

Options:

A.

2

B.

6

C.

4

D.

3

Buy Now
Questions 63

When enabled during Zscaler Client Connector (ZCC) installation, what specific control does the Strict Enforcement feature apply to internet access on end-user Windows workstations?

Options:

A.

It requires users to restart their Windows workstations after ZCC installation before accessing the internet.

B.

It prevents users from uninstalling ZCC without proper authorization.

C.

It requires users to enroll with ZCC before accessing the internet.

D.

It prevents users from logging out of ZCC without proper authorization.

Buy Now
Questions 64

A firewall policy set evaluates rules from top to bottom and stops at the first match. Rule 1 allows Marketing users outbound TCP 80/443 to any destination. Rule 2 blocks the Anonymizers network-application category globally. Rule 3 blocks all traffic to 203.0.113.0/24.

What outcome and risk are most likely when a Marketing user accesses an anonymizer over HTTPS?

Options:

A.

Traffic matches the Marketing allow at Rule 1, the global anonymizer block is not evaluated, and the user gains access to anonymizers, increasing exposure

B.

Traffic is deferred to application categorization first and is blocked at Rule 2, with the user denied but with ambiguous logging

C.

Traffic is inspected by IPS before Firewall Filtering and is dropped preemptively, reducing the effect of rule order but causing false positives

D.

Traffic collides with the destination block at Rule 3 because of subnet inference, resulting in intermittent denial and noisy alerts

Buy Now
Questions 65

Zscaler Advanced Threat Protection (ATP) is a key capability within Zscaler Internet Access (ZIA), protecting users against attacks such as phishing. Which of the following is NOT part of the ATP workflow?

Options:

A.

IPS coverages for client-side and server-side

B.

Reporting high latency from the CEO ' s Teams call due to a low Wi-Fi signal

C.

Comprehensive URL categories for newly registered domains

D.

Preventing the download of a password protected zip file

Buy Now
Questions 66

Operations teams are investigating repeated port-based blocks for outbound traffic and need to correlate the blocked sessions with the applications involved and the applicable Firewall policies.

Which steps should the operations team follow?

Options:

A.

Use Web Insights to examine URL categories and inline web actions for browser traffic

B.

Run the URL Test tool to verify static categorization and destination risk scores

C.

Review Endpoint DLP Insights to analyze device-level data handling and exfiltration attempts

D.

Open Firewall Insights and review rule hits together with application usage and transferred-byte information

Buy Now
Questions 67

Which options must be selected when configuring Zscaler Client Connector for Strict Enforcement?

Options:

A.

cloudName and policyToken

B.

userDomain and deviceToken

C.

cloudName and deviceToken

D.

userDomain and policyToken

Buy Now
Questions 68

Which type of malware is specifically used to deliver other malware?

Options:

A.

RAT

B.

Maldocs

C.

Downloaders

D.

Exploitation tool

Buy Now
Questions 69

A company requires stricter control of non-web traffic when users are outside the corporate network.

Which adjustment best reduces unintended exposure for off-network users?

Options:

A.

Configure Zscaler Client Connector to use Z-Tunnel 2.0 when off-network, and enable the appropriate Cloud Firewall rules

B.

Increase inspection depth for on-network users to compensate for off-network access risks, assuming that stricter internal analysis provides an aggregate deterrent

C.

Configure Zscaler Client Connector to use Z-Tunnel 1.0 when off-network, and enable the appropriate Cloud Firewall rules

D.

Duplicate the off-network block rule and place both copies below the global allow rule to provide redundant coverage and increased monitoring

Buy Now
Questions 70

A managed device on a known corporate LAN cannot reach a private application through the Zero Trust Exchange because of forwarding behavior.

Which bypass configuration would enable access while respecting how policies are evaluated?

Options:

A.

Place a broader App Segment earlier in the rule list, conceding that misalignment could widen exposure and still fail to route the session.

B.

Enable a Trusted Network bypass in the Client Forwarding Policy, recognizing that direct access on the corporate LAN limits dependency on ZPA routing.

C.

Apply an Inspection Policy to the application traffic, acknowledging that added parsing may not resolve the routing path.

D.

Introduce an Access Policy allow rule based on group membership, accepting that forwarding mismatches may still block sessions.

Buy Now
Questions 71

Which of the following are correct request methods when configuring a URL filtering rule with a Caution action?

Options:

A.

Connect, Get, Head

B.

Options, Delete, Put

C.

Get, Delete, Trace

D.

Connect, Post, Put

Buy Now
Questions 72

You are planning to use Z-Tunnel 2.0 as the forwarding mechanism to support TCP, UDP, and ICMP traffic going to ZIA.

What type of tunnel will Zscaler Client Connector form with the Zero Trust Exchange?

Options:

A.

TLS with fallback to DTLS

B.

DTLS with fallback to TLS

C.

TLS with fallback to IPsec

D.

DTLS with fallback to IPsec

Buy Now
Questions 73

A sequence in the Administrator Audit Log shows several failed sign-ins from an unfamiliar location, followed by a successful administrator sign-in and a near-immediate role upgrade on the same identity.

Which entry combination constitutes the clearest escalation indicator requiring a containment step?

Options:

A.

A successful sign-in by a read-only auditor from a branch office and a subsequent group-membership cleanup with a comment

B.

Multiple lockout events for a non-administrator account and a later unremarkable sign-in from a corporate VPN

C.

Two expired-token errors for an API client and a later password change logged with a documented request ID

D.

A successful administrative sign-in from an untrusted IP address promptly followed by role elevation on the same account session

Buy Now
Questions 74

The Zscaler Gen AI Security Report gives visibility and insight into an organization ' s use of generative AI applications. What kind of log will include Prompt for administrators to view for different prompts entered by users in those applications?

Options:

A.

SaaS Security Logs

B.

Web Insights Logs

C.

Gen AI Insights Logs

D.

Advanced Firewall Logs

Buy Now
Questions 75

A manufacturing firm is merging with a subsidiary that uses a separate identity provider. A ZPA Access Policy for an engineering CAD application uses SCIM groups for authorization. A new administrator authenticates successfully through SAML and presents the Engineering claim, but the subsidiary’s SCIM synchronization is delayed, so the administrator does not appear in the expected group in ZIdentity.

Which action should the ZPA administrator take to avoid inconsistent access while preserving auditability?

Options:

A.

Reconfigure the policy to use NameID for authorization, accepting reduced traceability of group criteria

B.

Initiate a SCIM resynchronization and validate the user’s group membership in ZIdentity, while keeping the Access Policy bound to SCIM groups

C.

Create a local ZIdentity group with provisional engineering membership, accepting drift from the directory of record

D.

Change identity-provider routing so the engineer authenticates through the parent company’s identity provider, accepting misalignment with the subsidiary’s directory mappings

Buy Now
Questions 76

A Cloud Sandbox detonation shows a document beaconing through obfuscated scripts and spawning child processes that attempt network calls to newly registered domains. The desired outcome is to prevent users from downloading or accessing similar suspicious files across web and SaaS channels.

What action should be taken next?

Options:

A.

Apply a Sandbox policy that quarantines the document type across all applicable channels above the existing Sandbox policy rule

B.

Shift scanning to out-of-band CASB-only workflows so that analysis occurs after content is stored

C.

Route detections to a manual review queue and postpone policy changes until more analyst capacity is available

D.

Lower Sandbox sensitivity to reduce alert volume and defer enforcement until trend data is gathered

Buy Now
Questions 77

What ports and protocols are forwarded to the Zero Trust Exchange when Zscaler Client Connector is using Tunnel 2.0?

Options:

A.

TCP ports 80, 443 and 8080 only.

B.

Any HTTP/HTTPS traffic as well as DNS.

C.

All TCP and UDP ports as well as ICMP traffic.

D.

All Web ports as well as FTP and SSH.

Buy Now
Questions 78

What are the two types of Probe supported in ZDX?

Options:

A.

Web Probes and Cloud Path Probes

B.

Application Probes and Network Probes

C.

Page Speed Probes and Connection Speed Probes

D.

SaaS Probes and Router Probes

Buy Now
Questions 79

Which are valid criteria for use in Access Policy Rules for ZPA?

Options:

A.

Group Membership, ZIA Risk Score, Domain Joined, Certificate Trust

B.

Username, Trusted Network Status, Password, Location

C.

SCIM Group, Time of Day, Client Type, Country Code

D.

Department, SNI, Branch Connector Group, Machine Group

Buy Now
Questions 80

A team plans to deploy ZPA App Connectors as virtual machines in two data centers and one AWS VPC.

Which information should be communicated upfront to align network placement and access controls with Zero Trust principles?

Options:

A.

The external NAT addresses to advertise for inbound reachability and the BGP communities to tag for internet-facing routes

B.

The application subnets reachable from connector network interfaces, the requirement for outbound TLS to ZPA Service Edges, and the prohibition of inline TLS interception

C.

The GRE or IPsec tunnel endpoints that will terminate user traffic at the data-center perimeter for centralized inspection

D.

The reverse-proxy access control lists that will accept client-initiated TLS from the internet and the static public IP addresses required for allowlists

Buy Now
Questions 81

An operations team wants to determine whether reported slowness in a SaaS application is caused by the application, the network, or the endpoint.

Which ZDX diagnostic should be prioritized to align performance degradation with regions, ISPs, or time windows?

Options:

A.

Initiate device-telemetry checks for high CPU utilization and unstable Wi-Fi to flag local constraints before considering path conditions

B.

Run CloudPath probes to capture hop-by-hop latency and packet loss along the end-to-end route to the application

C.

Query Inventory APIs to identify endpoints with older Client Connector builds that may lack recent telemetry capabilities

D.

Review the application’s ZDX Score and Page Fetch Time to correlate degradation with geography and time frames

Buy Now
Exam Code: ZDTA
Exam Name: Zscaler Digital Transformation Administrator
Last Update: Aug 24, 2026
Questions: 273

PDF + Testing Engine

$59.99 $171.4

Testing Engine

$44.99 $128.55

PDF (Q&A)

$49.99 $142.82