Summer Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

Zscaler ZDTA Zscaler Digital Transformation Administrator Exam Practice Test

Demo: 80 questions
Total 273 questions

Zscaler Digital Transformation Administrator Questions and Answers

Question 1

Which action should be taken during a regional policy-tuning effort that requires evidence of egress-control effectiveness by correlating rule-hit counts and application usage across locations under network-layer enforcement?

Options:

A.

Review Data Discovery reports to visualize sensitive-data movement trends across channels

B.

Check Administrator Audit Logs to evaluate configuration changes that might affect outcomes

C.

Use Web Insights to compare browsing categories and threat actions across users and URLs

D.

Open Firewall Insights to analyze rule-hit metrics, network-application usage, and bandwidth by location

Question 2

What does an Endpoint refer to in an API architecture?

Options:

A.

An end-user device like a laptop or an OT/IoT device

B.

A URL providing access to a specific resource

C.

Zscaler public service edges

D.

Zscaler API gateway providing access to various components

Question 3

Which of the following DLP Notification methods can be used to forward a copy of the data that triggered the DLP policy to the auditor?

Options:

A.

Email Notification Template

B.

NSS Log Forwarding to SIEM

C.

SMS Text Message via PagerDuty

D.

Zscaler Client Connector pop-up message

Question 4

A log review shows requests to a sanctioned application being allowed despite a later rule intended to restrict access by time of day.

The rule set is:

    Allow the sanctioned application for All Employees

    Block the sanctioned application outside business hours for All Employees

    Log restricted-access hits

Which cause and risk are most consistent with this behavior?

Options:

A.

The time-of-day block inherits timing from device posture, which desynchronizes evaluation and produces inconsistent enforcement

B.

The initial allow rule matches first and stops further evaluation, so the time-of-day block never applies and access remains available after business hours

C.

The logging rule takes precedence because of its action type, preventing the block from being reached

D.

The sanctioned application category becomes invalid during SSL inspection, sending the request to a default allow path that bypasses time restrictions

Question 5

How does ZDX compute the score for an application?

Options:

A.

Zscaler takes all the users that accessed the application for the selected time period and finds the lowest value each user would have experienced for the application. The lowest values for each user are added together and divided by the number of users.

B.

Zscaler considers a single user that accessed the application for the selected time period and finds the lowest value that user would have experienced for the application. The lowest values for that user are added together and divided by the number of all users in the organization.

C.

Zscaler takes sample set of users that accessed the application for the selected time period and finds the lowest value each user would have experienced for the application. The lowest values for each user are added together and divided by the number of sample set of users.

D.

Zscaler takes the lowest value for each application for a set of users, for time intervals based on the selected time range. The application with the lowest value represents your applications score for that time interval.

Question 6

Which of the following are types of device posture?

Options:

A.

Detect Crowdstrike, Crowdstrike ZTA score, First name

B.

Certificate Trust, File Path, Full Disk Encryption

C.

Domain Joined, Process Check, Deception Check

D.

Unauthorized Modification, OS Version, License Key

Question 7

A macOS desktop application connecting to api.vendor.com fails during the TLS handshake whenever SSL/TLS Inspection is enabled. The application uses certificate pinning, and users intermittently connect through networks that prefer Google QUIC.

Which action should the security administrator take to restore functionality while retaining inspection for unrelated traffic?

Options:

A.

Modify ZPA application segments to route the SaaS traffic through the private-application plane and avoid public inspection

B.

Create a user-agent-based exception that disables decryption for the application’s HTTP stack across all destinations

C.

Configure a trusted-network bypass so Zscaler Client Connector disengages on corporate Wi-Fi

D.

Create a custom URL category for the vendor FQDNs, add an SSL/TLS Inspection bypass rule for those destinations, and block QUIC so the connection falls back to HTTPS over TCP

Question 8

What is the preferred method for authentication to access OneAPI?

Options:

A.

OpenID Connect (OIDC)

B.

Transport Layer Security (TLS)

C.

Security Assertion Markup Language (SAML)

D.

System for Cross-domain Identity Management (SCIM)

Question 9

What is the purpose of Browser Access in relation to Zscaler Private Access (ZPA)?

Options:

A.

To make applications accessible from any web browser with Zscaler Client Connector deployed on the device.

B.

To make applications accessible using a browser plug-in and additional browser configuration controlled by the organization.

C.

To make applications accessible without user authentication, Zscaler Client Connector, browser plug-ins, or browser configuration.

D.

To make applications accessible from any web browser without requiring Zscaler Client Connector, browser plug-ins, or additional browser configuration.

Question 10

A regional SOC analyst reviews ZIdentity audit logs during a surge in administrator-related anomalies at a hosted data center. The same session shows a successful sign-in from a new geography, a change that relaxes an MFA requirement in a sign-on policy, and an entitlement grant to a service account used by build automation.

Which action should the incident responder take to constrain privilege-escalation exposure while preserving forensic continuity?

Options:

A.

Revoke the service account’s elevated entitlements and restore the previous sign-on policy conditions that enforced stronger MFA

B.

Initiate a broad sign-on policy rollback across all roles and defer entitlement changes until the next maintenance cycle

C.

Increase audit verbosity for administrator actions and monitor for additional anomalies before applying restrictions

D.

Pause SIEM ingestion and collect on-appliance logs while delaying changes to avoid affecting correlation

Question 11

Which filtering policy blocked access to the Network Application?

Options:

A.

Sandbox

B.

Browser Control

C.

Firewall Filtering

D.

DLP

Question 12

Audit logs show configuration changes performed by members of a group outside its intended administrative area.

Which step reduces this exposure while preserving required functionality?

Options:

A.

Adjust department classifications to redefine reporting lines for the group

B.

Switch to just-in-time provisioning only so that attributes are reapplied during every session

C.

Revise the group’s administrative entitlements and role assignments to constrain its scope according to least privilege

D.

Relax sign-on policies to reduce failed authentication events across locations

Question 13

What is a Landmine in Deception?

Options:

A.

Agentless plug-in installed on endpoints, such as desktops or laptops on a network. These plug-ins deploy decoy credentials, files, processes, and lures to other decoys at endpoints.

B.

Software agent installed on a centralized server in datacenter or in cloud. The agents running in the server deploy decoy credentials, files, processes, and lures to other decoys at endpoints.

C.

Software agent installed on endpoints, such as desktops or laptops on a network. These agents deploy decoy credentials, files, processes, and lures to other decoys at endpoints.

D.

Agentless plug-in installed on endpoints, such as desktops or laptops on a network. These plug-ins auto rotates decoy credentials, files, processes, and lures to other decoys at endpoints.

Question 14

Audit and access logs show that a user was able to access an application segment even though the user was recently moved into a restricted group referenced by a deny rule.

What is an accurate explanation for the discrepancy?

Options:

A.

URL Filtering precedence suppressed the access policy to prevent duplicate enforcement

B.

Posture profiles enforced an AND condition that masked identity checks at session start

C.

The policy relied on SAML group attributes that had not refreshed, so the session was evaluated against stale membership

D.

The deny rule matched but was downgraded because of location-group prioritization

Question 15

What mechanism identifies the ZIA Service Edge node that the Zscaler Client Connector should connect to?

Options:

A.

The IP ranges included/excluded in the App Profile

B.

The PAC file used in the Forwarding Profile

C.

The PAC file used in the Application Profile

D.

The Machine Key used in the Application Profile

Question 16

Which of the following is a benefit of tunneling?

Options:

A.

Increased latency.

B.

Enhanced data security.

C.

Support for only TCP/IP traffic.

D.

Increased header size.

Question 17

Which of the following DLP components make use of Boolean Logic?

Options:

A.

DLP Rules

B.

DLP dictionaries

C.

DLP Engines

D.

DLP identifiers

Question 18

A branch location must connect to Zscaler for web inspection. The underlay is trusted, the site requires a static egress IP mapped to the location, expected throughput is 700 Mbps, and high availability is not required.

Which tunnel approach and count meet these requirements with the least overhead?

Options:

A.

Configure one IPSec tunnel to the regional Service Edge and declare the bandwidth expectation to match the site profile

B.

Configure one GRE tunnel to a regional Service Edge and bind the location to a static IP to meet the throughput target

C.

Provision two GRE tunnels to separate Service Edges and balance traffic through policy-based routing

D.

Establish two IPSec peers with conservative IKE lifetimes to reduce rekey churn and configure the location’s static IP

Question 19

When configuring an inline Data Loss Prevention policy with content inspection, which of the following are used to detect data, allow or block transactions, and notify your organization ' s auditor when a user ' s transaction triggers a DLP rule?

Options:

A.

Hosted PAC Files

B.

Index Tool

C.

DLP engines

D.

VPN Credentials

Question 20

Which Zscaler feature detects whether an intruder is accessing your internal resources?

Options:

A.

SandBox

B.

SSL Decryption Bypass

C.

Browser Isolation

D.

Deception

Question 21

How does Zscaler ensure that sensitive structured data used in the EDM process is not stored in its cloud environment?

Options:

A.

By storing sensitive structured data on servers managed by trusted Zscaler staff for enhanced security.

B.

By using an on-premises VM to index data and only sending hashed values to the cloud.

C.

By requiring customers to manually hash the data and upload it to the cloud.

D.

By encrypting sensitive data directly before storing it in the cloud.

Question 22

Traffic from a remote office traverses an untrusted ISP path and must connect to Zscaler through a mapped location with a defined static IP address and an expected throughput of 300 Mbps. High availability is not required.

Which action provides the appropriate tunnel characteristics with the minimum number of tunnels?

Options:

A.

Implement two GRE tunnels to different Service Edges and rely on SD-WAN latency scoring to steer traffic

B.

Configure a single IPSec tunnel to a regional Service Edge, and configure the location’s static IP address and bandwidth expectation

C.

Deploy a GRE tunnel with aggressive keepalives to compensate for underlay instability, and assign the static IP address to the location

D.

Build two IPSec tunnels with relaxed Dead Peer Detection (DPD) timers to avoid flapping during transient ISP outages

Question 23

What is the name of the feature that allows the platform to apply URL filtering even when a Cloud App control policy explicitly permits a transaction?

Options:

A.

Allow Cascading

B.

Allow and Quarantine

C.

Allow URL Filtering

D.

Allow and Scan

Question 24

Which three levels of inspection are used by Zscaler for File Type Identification?

Options:

A.

Mime type, file extension and file size

B.

File extension, content type and file size

C.

Magic bytes, mime type and file extension

D.

Magic bytes, mime type and MS Office version

Question 25

What does TLS Inspection for Zscaler Internet Access secure public internet browsing with?

Options:

A.

Storing connection streams for future customer review.

B.

Removing certificates and reconnecting client connection using HTTP.

C.

Intermediate certificates are created for each client connection.

D.

Logging which clients receive the original webserver certificate.

Question 26

A campus requires 1.5 Gbps of throughput to Zscaler Service Edges. The underlay is trusted, and the design explicitly excludes high availability.

Which option meets the bandwidth target with the minimum tunnel count?

Options:

A.

Establish a single GRE tunnel with Path MTU Discovery enabled and defer scaling until usage grows

B.

Provision two GRE tunnels associated with the same location and distribute flows through ECMP to achieve 1.5 Gbps

C.

Define two IPsec peers and tune lifetimes to minimize renegotiation during peak demand

D.

Configure one IPsec peer to avoid GRE MTU concerns and rely on static routing to sustain the required throughput

Question 27

Which of the following methods can be used to notify an end-user of a potential DLP violation in Zscaler’s Workflow Automation solution?

Options:

A.

Notifications in MS Teams / Slack

B.

SMS text message.

C.

Automated phone call.

D.

Twitter post with custom hashtag

Question 28

The Zscaler platform can protect against malicious files, URLs and content based on a number of criteria including reputation type. What type of checking is virus scanning?

Options:

A.

Malware protection

B.

File reputation

C.

SHA-256 hashing

D.

Site reputation

Question 29

How should an administrator determine why a website was allowed during web browsing when overlapping policies appeared to require a block, and verify which policy took precedence?

Options:

A.

Consult SaaS Security Insights to assess cloud-application exposure and control posture

B.

Check Administrator Audit Logs to correlate administrative activity with traffic dispositions

C.

Use Web Insights to trace the transaction, identify the matched web rule, and confirm the action

D.

Inspect Firewall Insights to review port-based rule evaluations and bandwidth constraints

Question 30

When correlating indicators of privilege escalation with administrator behavior, which log type provides the most direct visibility into role changes and entitlement modifications for administrative accounts?

Options:

A.

Firewall Insights reports centered on rule hits and bandwidth consumption at egress points

B.

ZIdentity Administrator Audit Log filtered for entitlement updates and role assignments

C.

Web Insights transaction logs focusing on URL categories and inline policy actions

D.

Endpoint DLP telemetry summarizing sensitive-data handling and removable-media events

Question 31

Which algorithm is used to determine the PageRisk?

Options:

A.

Zscaler licenses a PageRisk Feed from a 3rd party.

B.

It applies deobfuscation to all data.

C.

It is the RSA Security algorithm.

D.

Zscaler applies a multi data algorithm to the web page.

Question 32

How do Access Policies relate to the Application Segments and Application Segment Groups?

Options:

A.

When a condition is met, an Access Policy can either allow or block access to Application Segments OR Application Segment Groups.

B.

When a condition is met, an Access Policy can allow access to Application Segments Groups and block access to Application Segment.

C.

When a condition is met. an Access Policy can either allow or block access to Application Segments and Application Segment Groups.

D.

When a condition is met, an Access Policy can allow access to Application Segments and block access to Application Segment Groups.

Question 33

A device meets VPN-trusted-network criteria where existing corporate controls apply, and administrators want to minimize unnecessary tunneling while relying on application and IP bypasses in the Application Profile for selected low-latency traffic.

Which Forwarding Profile action aligns with this approach for the VPN-trusted context?

Options:

A.

Tunnel with Local Proxy to introduce loopback-proxy handling and then wrap flows in a secure tunnel

B.

Tunnel mode (Z-Tunnel 2.0) to encapsulate traffic despite the presence of VPN-based corporate enforcement

C.

No Forwarding to permit direct breakout under established corporate controls on VPN-trusted networks

D.

Enforce Proxy with PAC routing to apply proxy semantics even when VPN-based controls are already in place

Question 34

Cross-Site Scripting (XSS) attacks are a type of injection, in which malicious scripts are injected into otherwise benign and trusted websites. XSS includes which of the following?

Options:

A.

Spyware Callback

B.

Anonymizers

C.

Cookie Stealing

D.

IRC Tunneling

Question 35

Zscaler Advanced Threat Protection (ATP) is a key capability within Zscaler Internet Access (ZIA), protecting users against attacks such as phishing. Which of the following is NOT part of the ATP workflow?

Options:

A.

IPS coverages for client-side and server-side

B.

Reporting high latency from the CEO ' s Teams call due to a low Wi-Fi signal

C.

Comprehensive URL categories for newly registered domains

D.

Preventing the download of a password protected zip file

Question 36

Which are valid criteria for use in Access Policy Rules for ZPA?

Options:

A.

Group Membership, ZIA Risk Score, Domain Joined, Certificate Trust

B.

Username, Trusted Network Status, Password, Location

C.

SCIM Group, Time of Day, Client Type, Country Code

D.

Department, SNI, Branch Connector Group, Machine Group

Question 37

A unified acceptable use policy is being migrated during an acquisition. Finance requires TLS bypass for specific banking portals, however traffic for other users that should be inspected is also bypassed.

What policy should be adjusted to prevent TLS inspection from being bypassed for the other users?

Options:

A.

Reorder policies in the Zscaler Policy Framework so decryption exceptions evaluate before Cloud App Control decisions, and apply Bandwidth Control after access decisions.

B.

Increase threat protection engine sensitivity and rely on default precedence to resolve conflicts between decryption, app controls, and QoS rules.

C.

Place Bandwidth Control policies at the top of the stack and expect decryption exceptions and SaaS restrictions to evaluate subsequently.

D.

Enable global SSL inspection and create a group and category-based bypass policy above the global inspection rule.

Question 38

An administrator would like users to be able to use the corporate instance of a SaaS application. Which of the following allows an administrator to make that distinction?

Options:

A.

Out-of-band CASB

B.

Cloud application control

C.

URL filtering with SSL inspection

D.

Endpoint DLP

Question 39

What is one business risk introduced by the use of legacy firewalls?

Options:

A.

Performance issues

B.

Reduced management

C.

Low costs

D.

Low licensing support

Question 40

An executive summary correlates Risk360 category-contribution views with audit commitments: identity risk has decreased, but data-loss risk is trending upward; business-unit mean time to remediate (MTTR) variance suggests uneven remediation; and leadership requests board-ready evidence of continuous improvement mapped to the NIST Cybersecurity Framework (CSF).

What is the appropriate next step based on this summary and goal?

Options:

A.

Emphasize a single recent incident in a narrative memo and deprioritize category-contribution drill-downs to avoid distracting detail

B.

Replace Unified Vulnerability Management tasking with ad hoc email assignments to reduce tooling reliance, even if closure tracking becomes inconsistent

C.

Hold reporting until after policy changes take effect to avoid confusing auditors with fluctuating score baselines

D.

Produce framework-aligned dashboards with MTTR variance reporting and schedule cross-team reviews to track category-level risk reduction

Question 41

The Security Alerts section of the Alerts dashboard has a graph showing what information?

Options:

A.

Top 5 Malware Programs Detected

B.

Top 5 Viruses by Region

C.

Top 5 Threats by Systems Impacted

D.

Top 5 Unified Threat Yara Options

Question 42

Which type of attack plants malware on commonly accessed services?

Options:

A.

Remote access trojans

B.

Phishing

C.

Exploit kits

D.

Watering hole attack

Question 43

Which of the following is a common use case for adopting Zscaler’s Data Protection?

Options:

A.

Reduce your Internet Attack Surface

B.

Prevent download of Malicious Files

C.

Prevent loss to Internet and Cloud Apps

D.

Securely connect users to Private Applications

Question 44

If you ' re migrating from an on-premises proxy, you will already have a proxy setting configured within the browser or within the system. With Tunnel Mode, the best practice is to configure what type of proxy configuration?

Options:

A.

Execute a GPO update to retrieve the proxy settings from AD.

B.

Enforce no Proxy Configuration.

C.

Use Web Proxy Auto Discovery (WPAD) to auto-configure the proxy.

D.

Use an automatic configuration script (forwarding PAC file).

Question 45

Which of the following connects Zscaler users to the nearest Microsoft 365 servers for a better experience?

Options:

A.

Single DNS resolver with forwarders providing centralized results

B.

Private MPLS in each branch office providing connection

C.

Multiple distributed DNS resolvers providing local results

D.

Optimized TCP Scaling for maximum throughput of files

Question 46

What is Zscaler ' s rotation policy for intermediate certificate authority certificates?

Options:

A.

Certificates are rotated every 90 days and have a 180-day expiration.

B.

Lifetime certificates have no expiration date.

C.

Certificates are rotated every seven days and have a 14-day expiration.

D.

Certificates are issued dynamically and expire in 24 hours.

Question 47

Which of the following is the preferred method for authentication in a OneAPI environment?

Options:

A.

OIDC

B.

SCIM

C.

SAML

D.

EntraID

Question 48

Which approach minimizes disruption when deploying Client Connector software updates across a heterogeneous user base while maintaining the ability to recover from defects?

Options:

A.

Defer all upgrades to weekend maintenance windows to reduce peak risk, accepting prolonged exposure to known vulnerabilities

B.

Immediately push the latest version to every segment through one channel to reduce fragmentation, and delay monitoring until users report problems

C.

Use staged rollout rings with assigned versions for selected groups, monitor deployment health in the Client Connector dashboard, and retain a revert path for cohorts that show instability

D.

Randomize update timing for each device group to spread the effect across multiple hours and days, relying on support tickets to detect failures

Question 49

What method does Zscaler Identity Threat Detection and Response use to gather information about AD domains?

Options:

A.

Scanning network ports

B.

Running LDAP queries

C.

Analyzing firewall logs

D.

Packet sniffing

Question 50

Which attack type is characterized by a commonly used website or service that has malicious content like malicious JavaScript running on it?

Options:

A.

Watering Hole Attack

B.

Pre-existing Compromise

C.

Phishing Attack

D.

Exploit Kits

Question 51

During the authentication process while accessing a private web application, how is the SAML assertion delivered to the service provider?

Options:

A.

HTTP Redirect on the browser

B.

API request/response sequence

C.

Through the client connector

D.

Form POST via the browser

Question 52

A URL policy set includes an early allow rule based on a location group for a collaboration application, with no HTTP-method restrictions. A later rule targets high-risk users and blocks PUT and DELETE requests to the same application. A high-risk user in the allowed location attempts a PUT request.

What outcome results from this arrangement of controls?

Options:

A.

The request is throttled because of conflicting attributes, resulting in degraded service with limited data transfer

B.

The request is partially restricted at the enforcement point, causing intermittent failures instead of a deterministic block

C.

The request is blocked by the method-aware rule because protocol specificity overrides the broader location-based allow

D.

The request is allowed by the earlier location-based rule, preventing the later method-aware block from taking effect

Question 53

An investigation requires reviewing administrator entitlement changes from nine months ago to confirm suspected privilege escalation.

ZIdentity’s default portal retention period has already elapsed.

Which approach helps preserve and access the required audit trail for governance and forensic analysis?

Options:

A.

Export audit logs to CSV on a scheduled cadence and integrate supported audit streams with a SIEM through NSS or LSS to maintain an extended history

B.

Rely on recent sign-on policy evaluations and extrapolate prior administrator actions from current configurations

C.

Focus on bandwidth trends in Firewall Insights and infer administrative timelines from rule-utilization patterns

D.

Depend on implicit caching in the Experience Center and query historical entries during off-peak hours

Question 54

A regional hospital must provide a vendor with intermittent access to a legacy device-management application hosted on two on-premises servers. The vendor’s previous VPN caused noisy port scans to appear in logs and exposed nearby subnets to probing.

Which action should the administrator take to constrain access to the application while reducing lateral movement?

Options:

A.

Create ZPA Application Segments for the device-management FQDNs and ports, and enforce identity- and posture-based policies for the vendor group

B.

Configure DNS sinkholes to divert off-port vendor traffic and apply URL Filtering to suppress non-application flows

C.

Deploy a dedicated VLAN and a jump host near the application, and restrict traffic with subnet ACLs that limit the vendor to the jump host’s IP address

D.

Implement host-based firewall rules on both servers and advertise a reduced VPN route set to the vendor client

Question 55

Which step has a default frequency of two hours in the Zscaler client connector process?

Options:

A.

Policy update check

B.

PAC File Download

C.

Software update policy check

D.

Refresh on Network Changes

Question 56

A security lead reviews an executive summary: data-loss risk is driven by high-volume uploads to risky SaaS applications and unmanaged generative AI use; MTTR for BU-West remains high because of ticket-routing delays; and the board wants a 15% reduction in the data-loss risk score within 60 days. Peer benchmarks are similar but show identity risk as the primary driver elsewhere.

Which action should be taken next?

Options:

A.

Open UVM remediation for low-severity endpoint findings at scale to create throughput metrics regardless of category alignment

B.

Schedule an updated board narrative and postpone technical changes until the next quarter to avoid conflicting with peer comparisons

C.

Tighten Cloud App Control for risky SaaS and AI usage, and configure MTTR routing by business unit with ITSM integration

D.

Commission an identity-hardening review centered on private-application access patterns to mirror peer drivers even though local data-loss signals persist

Question 57

A sequence in the Administrator Audit Log shows several failed sign-ins from an unfamiliar location, followed by a successful administrator sign-in and a near-immediate role upgrade on the same identity.

Which entry combination constitutes the clearest escalation indicator requiring a containment step?

Options:

A.

A successful sign-in by a read-only auditor from a branch office and a subsequent group-membership cleanup with a comment

B.

Multiple lockout events for a non-administrator account and a later unremarkable sign-in from a corporate VPN

C.

Two expired-token errors for an API client and a later password change logged with a documented request ID

D.

A successful administrative sign-in from an untrusted IP address promptly followed by role elevation on the same account session

Question 58

Security wants to trace a user ' s attempted upload over HTTP to determine whether web policy blocked the transfer and to confirm the category and rule that drove the decision.

Which option is appropriate for confirming a block on an HTTP upload?

Options:

A.

Leverage ZDX telemetry to explore path performance and endpoint experience during the attempt

B.

Review DNS Insights to examine name-resolution activity aligned with the destination service

C.

Use Web Insights to view transaction details, category attribution, and the matched web rule

D.

Open Firewall Insights to study rule hits and bandwidth distribution across egress points

Question 59

What is a seed in Asset Discovery within External Attack Surface Management?

Options:

A.

A legitimate organizational asset, such as a known domain, IP address, or IP block, that serves as the starting point for discovery.

B.

A legitimate asset used to discover sensitive data and identify users accessing sanctioned or unsanctioned applications.

C.

A legitimate asset that allows users to access websites that are not mission-critical or business-critical.

D.

A legitimate decoy asset that triggers notifications and Deception actions when contacted by an attacker.

Question 60

A network team needs to prevent recurring congestion while meeting performance goals for critical applications. The team has several months of application-usage and bandwidth data across multiple sites.

What approach is most appropriate for avoiding congestion?

Options:

A.

Defer policy changes until user complaints stabilize, then adjust application classes based on the most recent incident set

B.

Analyze multiweek trends by location to identify consistently congested circuits and plan targeted capacity upgrades before peak periods

C.

Convert several high-usage business applications to the Silver class to distribute utilization more evenly across queues

D.

Relax quality-of-service constraints to reduce strict queue boundaries that may be causing packet drops

Question 61

Operations teams are investigating repeated port-based blocks for outbound traffic and need to correlate the blocked sessions with the applications involved and the applicable Firewall policies.

Which steps should the operations team follow?

Options:

A.

Use Web Insights to examine URL categories and inline web actions for browser traffic

B.

Run the URL Test tool to verify static categorization and destination risk scores

C.

Review Endpoint DLP Insights to analyze device-level data handling and exfiltration attempts

D.

Open Firewall Insights and review rule hits together with application usage and transferred-byte information

Question 62

What is a ZIA Sublocation?

Options:

A.

The section of a corporate Location used to separate traffic, like traffic from employees from guest traffic

B.

The section of a corporate Location that sends traffic to a Subcloud

C.

Every one of the sections in a Corporate Location that use overlapping IP addresses

D.

A way to separate generic traffic from that coming from Client Connector

Question 63

Policy troubleshooting identifies inconsistent enforcement across web and private-application channels for a regulated data type. The inconsistency causes inefficient investigations and intermittent blocking.

Which action would most plausibly improve platform performance under this policy framework?

Options:

A.

Align the policies to shared DLP engines and classification labels, with clearly defined precedence to eliminate cross-channel conflicts

B.

Create separate custom rules for each channel to isolate false positives despite using different classification references

C.

Reduce detection scope for private applications and prioritize web controls to minimize cross-channel matches

D.

Segment enforcement by department so identical data types can be handled differently without policy overlap

Question 64

What does a DLP Engine consist of?

Options:

A.

DLP Policies

B.

DLP Rules

C.

DLP dictionaries

D.

DLP identifiers

Question 65

Architecture reviews reveal trusted network bypass is configured for headquarters, while roaming users route through the service edge. The goal is stricter controls for accessing SaaS application when off-network traffic.

What policy ensures the best coverage for this scenario?

Options:

A.

ZPA App Segment policies that constrain ports for legacy private applications accessed by remote users

B.

Leverage conditional access policies to ensure client sessions only come from known location or via the Zero Trust Exchange

C.

CASB app governance policies that rely on user risk scores to restrict cloud activities across all locations

D.

Data center firewall tiers that mirror internal VLANs and apply deny rules for roaming identities

Question 66

What is the duration of Zscaler ' s short-lived issuing CA for SSL Inspection?

Options:

A.

7-day expiry with 0-day rotation

B.

14-day expiry with 7-day rotation

C.

30-day expiry with 7-day rotation

D.

21-day expiry with 14-day rotation

Question 67

A user’s access to a private CRM application fails occasionally during video calls. ZDX shows sharp jitter spikes and rising packet loss on the ISP path, with client-egress latency increasing when calls begin.

What will reduce CRM access variability?

Options:

A.

Expand URL categories for CRM domains to improve classification fidelity under heavy traffic

B.

Steer traffic to a nearer Service Edge and validate path quality with ZDX and Tunnel Insights to minimize latency and jitter

C.

Constrain the user’s identity claims to limit token size and reduce authentication overhead during calls

D.

Move CRM traffic to a Silver bandwidth class so collaboration traffic no longer competes with business data

Question 68

A firewall policy set evaluates rules from top to bottom and stops at the first match. Rule 1 allows Marketing users outbound TCP 80/443 to any destination. Rule 2 blocks the Anonymizers network-application category globally. Rule 3 blocks all traffic to 203.0.113.0/24.

What outcome and risk are most likely when a Marketing user accesses an anonymizer over HTTPS?

Options:

A.

Traffic matches the Marketing allow at Rule 1, the global anonymizer block is not evaluated, and the user gains access to anonymizers, increasing exposure

B.

Traffic is deferred to application categorization first and is blocked at Rule 2, with the user denied but with ambiguous logging

C.

Traffic is inspected by IPS before Firewall Filtering and is dropped preemptively, reducing the effect of rule order but causing false positives

D.

Traffic collides with the destination block at Rule 3 because of subnet inference, resulting in intermittent denial and noisy alerts

Question 69

What is the purpose of the Zscaler Client Connector providing the authentication token to the Zscaler Client Connector Portal after it is received from Zscaler Internet Access?

Options:

A.

To bypass multifactor authentication (MFA) during the enrollment process

B.

To immediately grant the user access to Zscaler Private Access resources

C.

To enable the portal to register the user’s device and pass the registration to Zscaler Internet Access

D.

To share the authentication token with the SAML IdP to validate the user session

Question 70

You recently deployed an additional App Connector to an existing app connector group. What do you need to do before starting the zpa-connector service?

Options:

A.

Copy the group provisioning key to /opt/zscaler/var/provision key

B.

Monitor the peak CPU and memory utilization of the AC

C.

Schedule periodic software updates for the app connector group

D.

Check the status of the new App Connector in the administration portal

Question 71

A security team suspects that data exfiltration is occurring through encrypted channels to attackers.

To assess the company’s posture before tuning controls, which next step should be taken to validate whether existing protections cover this behavior?

Options:

A.

Raise the severity of egress firewall rules across segments to constrain outbound flows that might be exploited

B.

Review ZIA DLP outbound logs for anomalous uploads to unsanctioned SaaS applications and newly registered domains to gauge detection coverage

C.

Correlate ZIA threat insights with ZPA analytics to identify anomalous outbound patterns and unusual private-application access, and then verify that DLP and botnet controls apply to TLS-decrypted traffic

D.

Trigger broad Cloud Sandbox reanalysis of recent endpoint downloads to look for latent payloads that could facilitate exfiltration

Question 72

Which proprietary technology does Zscaler use to calculate risk attributes dynamically for websites?

Options:

A.

Third-Party Sandbox

B.

Zscaler PageRisk

C.

Browser Isolation Feedback Form

D.

Deception Controller

Question 73

Does the Access Control suite include features that prevent lateral movement?

Options:

A.

No. Access Control Services will only control access to the Internet and cloud applications.

B.

Yes. Controls for segmentation and conditional access are part of the Access Control Services.

C.

Yes. The Cloud Firewall will detect network segments and provide conditional access.

D.

No. The endpoint firewall will detect network segments and steer access.

Question 74

A Gold-class SaaS application performs poorly even though its bandwidth class has a generous minimum and moderate maximum. Usage dashboards show available capacity during incidents, and other applications are not saturating the link.

What is the most defensible next step to prevent recurring degradation?

Options:

A.

Prioritize streaming media above the SaaS application to normalize queue behavior and reduce circuit jitter

B.

Reduce TLS inspection for the SaaS application to remove inspection latency without first validating the traffic path

C.

Raise the Gold-class maximum to a higher ceiling to address presumed internal throttling

D.

Use ZDX path metrics to validate last-mile or ISP congestion at the affected site and plan a circuit upgrade or provider change while retaining the current policies

Question 75

Which of the following is a valid action for a SaaS Security API Data Loss Prevention Rule?

Options:

A.

Enable AI/ML based Smart Browser Isolation

B.

Quarantine Malware

C.

Create Zero Trust Network Decoy

D.

Remove External Collaborators and Sharable Link

Question 76

What does Advanced Threat Protection defend users from?

Options:

A.

Vulnerable JavaScripts

B.

Large iFrames

C.

Malicious active content

D.

Command injection attacks

Question 77

An organization wants to let a contractor group reach a single internal web application while restricting access to all other private resources. The team needs the policy to reflect contractor group-membership changes during normal operations and to ensure device risk is accounted for per session.

Which configuration most effectively enforces least privilege in this case?

Options:

A.

Define a dedicated App Segment for the target application and use a ZPA Access Policy that references a SCIM-synchronized contractor group with a device posture condition.

B.

Apply a user-agent-filtered allow control for the application hostname and add a time-based constraint during working hours.

C.

Create a location-scoped allow rule tied to the contractor egress IP range and monitor downstream access through audit reports.

D.

Enable a department-based SAML attribute in a broad allow rule and rely on a later block rule to curb lateral access.

Question 78

Which of the following is unrelated to the properties of ' Trusted Networks ' ?

Options:

A.

DNS Server

B.

Default Gateway

C.

Org ID

D.

Network Range

Question 79

Which API architectural style is used by Zscaler for Zero Trust Automation?

Options:

A.

JSON-RPC

B.

SOAP

C.

GraphQL

D.

REST

Question 80

A user has opened a support case to complain about poor user experience when trying to manage their AWS resources. How could a helpdesk administrator get a useful root cause analysis to help isolate the issue in the least amount of time?

Options:

A.

Check the Zscaler Trust page for any indications of cloud outages or incidents that would be causing a slowdown.

B.

Check the user ' s ZDX score for a period of low score for AWS and use Analyze Score to get the ZDX Y-Engine analysis.

C.

Do a Deep Trace on the user ' s traffic and check for excessive DNS resolution times and other slowdowns.

D.

Initiate a packet capture from Zscaler Client Connector and escalate the case to have the trace analyzed for root cause.

Demo: 80 questions
Total 273 questions