When creating an installer package or using the command-line for installation, which Zscaler Client Connector installer options are used to automatically redirect to your corporate SAML IdP on launch?
Which Zscaler feature detects whether an intruder is accessing your internal resources?
A platform team deploys Bandwidth Control and firewall policy changes through an API. After a large rollout, users report sporadic application slowdowns, yet the monitoring team finds gaps in telemetry for the same time windows.
Which action best prevents these performance issues from persisting and going undetected in similar rollouts?
A mixed policy set contains an Allow for high-value assets with posture, followed by a Block for high-value assets, then role-specific Allow rules for contractors and employees. Multiple users report unexpected reach to internal apps from unmanaged devices.
Considering rule order, attribute evaluation, and logical operators in ZPA Access Policies, which change best narrows access while minimizing unintended matches?
Which Platform Service enables visibility into the headers and payload of encrypted transactions?
A company observes risky uploads from unmanaged devices connecting over public Wi-Fi to cloud storage. The devices intermittently fail posture checks, and logs show inconsistent category enforcement.
Which action places the stricter control where it will be applied consistently to off-network traffic?
Layered defense throughout an organization security platform is valuable because of which of the following?
A sanctioned SaaS application is allowed in Cloud App Control but appears to be blocked by URL Filtering.
Which configuration would permit access through a controlled bypass that follows policy precedence?
A new customer has just purchased Zscaler for Users.
Which of the following Zscaler service entitlements is enabled by default?
An organization mandates strict BYOD controls and does not permit endpoint agents on personal devices. Which Zscaler deployment approach aligns with this requirement while maintaining data protection for access to corporate applications?
A data center requires connectivity to Zscaler for traffic inspection without an encryption requirement. The site must support a defined bandwidth profile of 2.2 Gbps and has no high-availability requirement.
Which configuration uses the minimum number of tunnels while meeting the throughput requirement?
What is the recommended default rule for the cloud-gen firewall configuration when deploying a new ZIA tenant?
A regional hospital must provide a vendor with intermittent access to a legacy device-management application hosted on two on-premises servers. The vendor’s previous VPN caused noisy port scans to appear in logs and exposed nearby subnets to probing.
Which action should the administrator take to constrain access to the application while reducing lateral movement?
A company must enforce least-privileged access to private applications when contractors connect from varying locations using devices with inconsistent security posture. The security team wants decisions to use identity and per-session context instead of broad network assumptions.
Which approach best meets the requirement?
A regional SOC analyst reviews ZIdentity audit logs during a surge in administrator-related anomalies at a hosted data center. The same session shows a successful sign-in from a new geography, a change that relaxes an MFA requirement in a sign-on policy, and an entitlement grant to a service account used by build automation.
Which action should the incident responder take to constrain privilege-escalation exposure while preserving forensic continuity?
An executive summary correlates Risk360 category-contribution views with audit commitments: identity risk has decreased, but data-loss risk is trending upward; business-unit mean time to remediate (MTTR) variance suggests uneven remediation; and leadership requests board-ready evidence of continuous improvement mapped to the NIST Cybersecurity Framework (CSF).
What is the appropriate next step based on this summary and goal?
How does a Zscaler administrator troubleshoot a certificate pinned application?
A finance user downloads a password-protected spreadsheet from a sanctioned SaaS platform. Cloud Sandbox indicates that detonation is delayed because the file is encrypted.
Which action should the administrator take next?
What is the purpose of Browser Access in relation to Zscaler Private Access (ZPA)?
Which of the following components is installed on an endpoint to connect users to the Zero Trust Exchange regardless of their location - home, work, while traveling, etc.?
A branch wants to block unmanaged devices from a private HR web application while allowing managed devices to work. The branch egress IP is configured as a trusted network. A Client Forwarding Policy currently bypasses the HR application for traffic on that trusted network, causing inconsistent enforcement for devices tunneling through the site.
What change should be made to achieve the intended outcome?
Zscaler utilized a Zero Trust Network Architecture (ZTNA) for segmentation in an environment.
Which of the following prevents lateral movement within an organization?
In a policy set where a department-specific file-type category must take precedence over a broader global control, what action is most appropriate to ensure that the desired category is evaluated first?
An investigation at a regional office identifies sensitive files leaving a sanctioned SaaS platform outside business hours. Follow-up analysis shows that several users transferred content through native mobile applications that do not consistently traverse ZIA inline inspection.
Which action should the security lead take next to assess security across the SaaS environment?
A contractor in the Field_Eng SAML group attempts to access an internal CAD application through ZPA from a branch designated as a Trusted Network. The Access Policy requires Field_Eng membership AND a device-posture profile confirming full-disk encryption and a CrowdStrike ZTA score above 80. The user passes the ZTA score requirement, but Device Posture reports that disk encryption is disabled.
Which enforcement outcome should be expected for this session?
Which of the following features protects traffic to internal applications from attacks such as cross-site scripting (XSS), cookie poisoning, and SQL injection?
The security exceptions allow list for Advanced Threat Protection apply to which of the following Policies?
A security lead reviews an executive summary: data-loss risk is driven by high-volume uploads to risky SaaS applications and unmanaged generative AI use; MTTR for BU-West remains high because of ticket-routing delays; and the board wants a 15% reduction in the data-loss risk score within 60 days. Peer benchmarks are similar but show identity risk as the primary driver elsewhere.
Which action should be taken next?
Which proprietary technology does Zscaler use to calculate risk attributes dynamically for websites?
From a user perspective, Zscaler Bandwidth Control performs traffic shaping and buffering on what direction(s) of traffic?
A user authenticates through an IdP. The SAML assertion and SCIM provisioning return different group memberships.
Which placement and policy-evaluation outcome ensures the most consistently up-to-date results?
Which of the following refers to employees’ use of unauthorized applications and services?
A network team needs to prevent recurring congestion while meeting performance goals for critical applications. The team has several months of application-usage and bandwidth data across multiple sites.
What approach is most appropriate for avoiding congestion?
Administrators report that some non-compliant devices can still reach private applications. A broad Allow rule precedes device-posture checks in the policy set.
What is the most appropriate next step to satisfy the compliance-before-access requirement?
A device connects to the Zero Trust Exchange with missing antivirus telemetry and an unverified client certificate in its posture profile.
Assuming Leading Practice for posture-driven enforcement are implemented, what is the outcome for the session?
What Zscaler control can be implemented to limit exposure to malicious content?
Which feature does Zscaler Client Connector Z-Tunnel 2.0 enable over Z-Tunnel 1.0?
A campus requires 1.5 Gbps of throughput to Zscaler Service Edges. The underlay is trusted, and the design explicitly excludes high availability.
Which option meets the bandwidth target with the minimum tunnel count?
While troubleshooting a user ' s slow application access, can a ZDX administrator see degradations in Wi-Fi signal strength?
Company A acquires Company B. Users from both companies require reliable access to internet and SaaS services and to each other’s private applications across overlapping RFC1918 address ranges. A legacy VPN retained temporarily for a third-party integration causes intermittent route conflicts and noticeable latency.
Which action should the administrator prioritize to stabilize access and minimize network-level collisions?
An administrator is provisioning new App Connectors in Microsoft Azure. A new egress policy enforces TLS inspection for outbound traffic from the workload subnets.
Which action should the ZPA administrator take to prevent App Connector registration failures?
If you ' re migrating from an on-premises proxy, you will already have a proxy setting configured within the browser or within the system. With Tunnel Mode, the best practice is to configure what type of proxy configuration?
Policy troubleshooting identifies inconsistent enforcement across web and private-application channels for a regulated data type. The inconsistency causes inefficient investigations and intermittent blocking.
Which action would most plausibly improve platform performance under this policy framework?
What is the recommended minimum number of App connectors needed to ensure resiliency?
When enabled during Zscaler Client Connector (ZCC) installation, what specific control does the Strict Enforcement feature apply to internet access on end-user Windows workstations?
A firewall policy set evaluates rules from top to bottom and stops at the first match. Rule 1 allows Marketing users outbound TCP 80/443 to any destination. Rule 2 blocks the Anonymizers network-application category globally. Rule 3 blocks all traffic to 203.0.113.0/24.
What outcome and risk are most likely when a Marketing user accesses an anonymizer over HTTPS?
Zscaler Advanced Threat Protection (ATP) is a key capability within Zscaler Internet Access (ZIA), protecting users against attacks such as phishing. Which of the following is NOT part of the ATP workflow?
Operations teams are investigating repeated port-based blocks for outbound traffic and need to correlate the blocked sessions with the applications involved and the applicable Firewall policies.
Which steps should the operations team follow?
Which options must be selected when configuring Zscaler Client Connector for Strict Enforcement?
A company requires stricter control of non-web traffic when users are outside the corporate network.
Which adjustment best reduces unintended exposure for off-network users?
A managed device on a known corporate LAN cannot reach a private application through the Zero Trust Exchange because of forwarding behavior.
Which bypass configuration would enable access while respecting how policies are evaluated?
Which of the following are correct request methods when configuring a URL filtering rule with a Caution action?
You are planning to use Z-Tunnel 2.0 as the forwarding mechanism to support TCP, UDP, and ICMP traffic going to ZIA.
What type of tunnel will Zscaler Client Connector form with the Zero Trust Exchange?
A sequence in the Administrator Audit Log shows several failed sign-ins from an unfamiliar location, followed by a successful administrator sign-in and a near-immediate role upgrade on the same identity.
Which entry combination constitutes the clearest escalation indicator requiring a containment step?
The Zscaler Gen AI Security Report gives visibility and insight into an organization ' s use of generative AI applications. What kind of log will include Prompt for administrators to view for different prompts entered by users in those applications?
A manufacturing firm is merging with a subsidiary that uses a separate identity provider. A ZPA Access Policy for an engineering CAD application uses SCIM groups for authorization. A new administrator authenticates successfully through SAML and presents the Engineering claim, but the subsidiary’s SCIM synchronization is delayed, so the administrator does not appear in the expected group in ZIdentity.
Which action should the ZPA administrator take to avoid inconsistent access while preserving auditability?
A Cloud Sandbox detonation shows a document beaconing through obfuscated scripts and spawning child processes that attempt network calls to newly registered domains. The desired outcome is to prevent users from downloading or accessing similar suspicious files across web and SaaS channels.
What action should be taken next?
What ports and protocols are forwarded to the Zero Trust Exchange when Zscaler Client Connector is using Tunnel 2.0?
A team plans to deploy ZPA App Connectors as virtual machines in two data centers and one AWS VPC.
Which information should be communicated upfront to align network placement and access controls with Zero Trust principles?
An operations team wants to determine whether reported slowness in a SaaS application is caused by the application, the network, or the endpoint.
Which ZDX diagnostic should be prioritized to align performance degradation with regions, ISPs, or time windows?