Which action should be taken during a regional policy-tuning effort that requires evidence of egress-control effectiveness by correlating rule-hit counts and application usage across locations under network-layer enforcement?
What does an Endpoint refer to in an API architecture?
Which of the following DLP Notification methods can be used to forward a copy of the data that triggered the DLP policy to the auditor?
A log review shows requests to a sanctioned application being allowed despite a later rule intended to restrict access by time of day.
The rule set is:
Allow the sanctioned application for All Employees
Block the sanctioned application outside business hours for All Employees
Log restricted-access hits
Which cause and risk are most consistent with this behavior?
How does ZDX compute the score for an application?
Which of the following are types of device posture?
A macOS desktop application connecting to api.vendor.com fails during the TLS handshake whenever SSL/TLS Inspection is enabled. The application uses certificate pinning, and users intermittently connect through networks that prefer Google QUIC.
Which action should the security administrator take to restore functionality while retaining inspection for unrelated traffic?
What is the preferred method for authentication to access OneAPI?
What is the purpose of Browser Access in relation to Zscaler Private Access (ZPA)?
A regional SOC analyst reviews ZIdentity audit logs during a surge in administrator-related anomalies at a hosted data center. The same session shows a successful sign-in from a new geography, a change that relaxes an MFA requirement in a sign-on policy, and an entitlement grant to a service account used by build automation.
Which action should the incident responder take to constrain privilege-escalation exposure while preserving forensic continuity?
Which filtering policy blocked access to the Network Application?
Audit logs show configuration changes performed by members of a group outside its intended administrative area.
Which step reduces this exposure while preserving required functionality?
What is a Landmine in Deception?
Audit and access logs show that a user was able to access an application segment even though the user was recently moved into a restricted group referenced by a deny rule.
What is an accurate explanation for the discrepancy?
What mechanism identifies the ZIA Service Edge node that the Zscaler Client Connector should connect to?
Which of the following is a benefit of tunneling?
Which of the following DLP components make use of Boolean Logic?
A branch location must connect to Zscaler for web inspection. The underlay is trusted, the site requires a static egress IP mapped to the location, expected throughput is 700 Mbps, and high availability is not required.
Which tunnel approach and count meet these requirements with the least overhead?
When configuring an inline Data Loss Prevention policy with content inspection, which of the following are used to detect data, allow or block transactions, and notify your organization ' s auditor when a user ' s transaction triggers a DLP rule?
Which Zscaler feature detects whether an intruder is accessing your internal resources?
How does Zscaler ensure that sensitive structured data used in the EDM process is not stored in its cloud environment?
Traffic from a remote office traverses an untrusted ISP path and must connect to Zscaler through a mapped location with a defined static IP address and an expected throughput of 300 Mbps. High availability is not required.
Which action provides the appropriate tunnel characteristics with the minimum number of tunnels?
What is the name of the feature that allows the platform to apply URL filtering even when a Cloud App control policy explicitly permits a transaction?
Which three levels of inspection are used by Zscaler for File Type Identification?
What does TLS Inspection for Zscaler Internet Access secure public internet browsing with?
A campus requires 1.5 Gbps of throughput to Zscaler Service Edges. The underlay is trusted, and the design explicitly excludes high availability.
Which option meets the bandwidth target with the minimum tunnel count?
Which of the following methods can be used to notify an end-user of a potential DLP violation in Zscaler’s Workflow Automation solution?
The Zscaler platform can protect against malicious files, URLs and content based on a number of criteria including reputation type. What type of checking is virus scanning?
How should an administrator determine why a website was allowed during web browsing when overlapping policies appeared to require a block, and verify which policy took precedence?
When correlating indicators of privilege escalation with administrator behavior, which log type provides the most direct visibility into role changes and entitlement modifications for administrative accounts?
Which algorithm is used to determine the PageRisk?
How do Access Policies relate to the Application Segments and Application Segment Groups?
A device meets VPN-trusted-network criteria where existing corporate controls apply, and administrators want to minimize unnecessary tunneling while relying on application and IP bypasses in the Application Profile for selected low-latency traffic.
Which Forwarding Profile action aligns with this approach for the VPN-trusted context?
Cross-Site Scripting (XSS) attacks are a type of injection, in which malicious scripts are injected into otherwise benign and trusted websites. XSS includes which of the following?
Zscaler Advanced Threat Protection (ATP) is a key capability within Zscaler Internet Access (ZIA), protecting users against attacks such as phishing. Which of the following is NOT part of the ATP workflow?
Which are valid criteria for use in Access Policy Rules for ZPA?
A unified acceptable use policy is being migrated during an acquisition. Finance requires TLS bypass for specific banking portals, however traffic for other users that should be inspected is also bypassed.
What policy should be adjusted to prevent TLS inspection from being bypassed for the other users?
An administrator would like users to be able to use the corporate instance of a SaaS application. Which of the following allows an administrator to make that distinction?
What is one business risk introduced by the use of legacy firewalls?
An executive summary correlates Risk360 category-contribution views with audit commitments: identity risk has decreased, but data-loss risk is trending upward; business-unit mean time to remediate (MTTR) variance suggests uneven remediation; and leadership requests board-ready evidence of continuous improvement mapped to the NIST Cybersecurity Framework (CSF).
What is the appropriate next step based on this summary and goal?
The Security Alerts section of the Alerts dashboard has a graph showing what information?
Which type of attack plants malware on commonly accessed services?
Which of the following is a common use case for adopting Zscaler’s Data Protection?
If you ' re migrating from an on-premises proxy, you will already have a proxy setting configured within the browser or within the system. With Tunnel Mode, the best practice is to configure what type of proxy configuration?
Which of the following connects Zscaler users to the nearest Microsoft 365 servers for a better experience?
What is Zscaler ' s rotation policy for intermediate certificate authority certificates?
Which of the following is the preferred method for authentication in a OneAPI environment?
Which approach minimizes disruption when deploying Client Connector software updates across a heterogeneous user base while maintaining the ability to recover from defects?
What method does Zscaler Identity Threat Detection and Response use to gather information about AD domains?
Which attack type is characterized by a commonly used website or service that has malicious content like malicious JavaScript running on it?
During the authentication process while accessing a private web application, how is the SAML assertion delivered to the service provider?
A URL policy set includes an early allow rule based on a location group for a collaboration application, with no HTTP-method restrictions. A later rule targets high-risk users and blocks PUT and DELETE requests to the same application. A high-risk user in the allowed location attempts a PUT request.
What outcome results from this arrangement of controls?
An investigation requires reviewing administrator entitlement changes from nine months ago to confirm suspected privilege escalation.
ZIdentity’s default portal retention period has already elapsed.
Which approach helps preserve and access the required audit trail for governance and forensic analysis?
A regional hospital must provide a vendor with intermittent access to a legacy device-management application hosted on two on-premises servers. The vendor’s previous VPN caused noisy port scans to appear in logs and exposed nearby subnets to probing.
Which action should the administrator take to constrain access to the application while reducing lateral movement?
Which step has a default frequency of two hours in the Zscaler client connector process?
A security lead reviews an executive summary: data-loss risk is driven by high-volume uploads to risky SaaS applications and unmanaged generative AI use; MTTR for BU-West remains high because of ticket-routing delays; and the board wants a 15% reduction in the data-loss risk score within 60 days. Peer benchmarks are similar but show identity risk as the primary driver elsewhere.
Which action should be taken next?
A sequence in the Administrator Audit Log shows several failed sign-ins from an unfamiliar location, followed by a successful administrator sign-in and a near-immediate role upgrade on the same identity.
Which entry combination constitutes the clearest escalation indicator requiring a containment step?
Security wants to trace a user ' s attempted upload over HTTP to determine whether web policy blocked the transfer and to confirm the category and rule that drove the decision.
Which option is appropriate for confirming a block on an HTTP upload?
What is a seed in Asset Discovery within External Attack Surface Management?
A network team needs to prevent recurring congestion while meeting performance goals for critical applications. The team has several months of application-usage and bandwidth data across multiple sites.
What approach is most appropriate for avoiding congestion?
Operations teams are investigating repeated port-based blocks for outbound traffic and need to correlate the blocked sessions with the applications involved and the applicable Firewall policies.
Which steps should the operations team follow?
What is a ZIA Sublocation?
Policy troubleshooting identifies inconsistent enforcement across web and private-application channels for a regulated data type. The inconsistency causes inefficient investigations and intermittent blocking.
Which action would most plausibly improve platform performance under this policy framework?
What does a DLP Engine consist of?
Architecture reviews reveal trusted network bypass is configured for headquarters, while roaming users route through the service edge. The goal is stricter controls for accessing SaaS application when off-network traffic.
What policy ensures the best coverage for this scenario?
What is the duration of Zscaler ' s short-lived issuing CA for SSL Inspection?
A user’s access to a private CRM application fails occasionally during video calls. ZDX shows sharp jitter spikes and rising packet loss on the ISP path, with client-egress latency increasing when calls begin.
What will reduce CRM access variability?
A firewall policy set evaluates rules from top to bottom and stops at the first match. Rule 1 allows Marketing users outbound TCP 80/443 to any destination. Rule 2 blocks the Anonymizers network-application category globally. Rule 3 blocks all traffic to 203.0.113.0/24.
What outcome and risk are most likely when a Marketing user accesses an anonymizer over HTTPS?
What is the purpose of the Zscaler Client Connector providing the authentication token to the Zscaler Client Connector Portal after it is received from Zscaler Internet Access?
You recently deployed an additional App Connector to an existing app connector group. What do you need to do before starting the zpa-connector service?
A security team suspects that data exfiltration is occurring through encrypted channels to attackers.
To assess the company’s posture before tuning controls, which next step should be taken to validate whether existing protections cover this behavior?
Which proprietary technology does Zscaler use to calculate risk attributes dynamically for websites?
Does the Access Control suite include features that prevent lateral movement?
A Gold-class SaaS application performs poorly even though its bandwidth class has a generous minimum and moderate maximum. Usage dashboards show available capacity during incidents, and other applications are not saturating the link.
What is the most defensible next step to prevent recurring degradation?
Which of the following is a valid action for a SaaS Security API Data Loss Prevention Rule?
What does Advanced Threat Protection defend users from?
An organization wants to let a contractor group reach a single internal web application while restricting access to all other private resources. The team needs the policy to reflect contractor group-membership changes during normal operations and to ensure device risk is accounted for per session.
Which configuration most effectively enforces least privilege in this case?
Which of the following is unrelated to the properties of ' Trusted Networks ' ?
Which API architectural style is used by Zscaler for Zero Trust Automation?
A user has opened a support case to complain about poor user experience when trying to manage their AWS resources. How could a helpdesk administrator get a useful root cause analysis to help isolate the issue in the least amount of time?