Summer Certification Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: clap70

ZDTA Zscaler Digital Transformation Administrator Questions and Answers

Questions 4

SSH use or tunneling was detected and blocked by which feature?

Options:

A.

Cloud App Control

B.

URL Filtering

C.

Advanced Threat Protection

D.

Mobile Malware Protection

Buy Now
Questions 5

Does the Cloud Firewall detect evasion techniques that would allow applications to communicate over non-standard ports to bypass its controls?

Options:

A.

The Cloud Firewall includes Deep Packet Inspection, which detects protocol evasions and sends the traffic to the respective engines for inspection and handling.

B.

Zscaler Client Connector will prevent evasion on the endpoint in conjunction with the endpoint operating system’s firewall.

C.

As traffic usually is forwarded from an on-premise firewall, this firewall will handle any evasion and will make sure that the protocols are corrected.

D.

The Cloud Firewall includes an IPS engine, which will detect the evasion techniques and will just block the transactions as it is invalid.

Buy Now
Questions 6

Architecture reviews reveal trusted network bypass is configured for headquarters, while roaming users route through the service edge. The goal is stricter controls for accessing SaaS application when off-network traffic.

What policy ensures the best coverage for this scenario?

Options:

A.

ZPA App Segment policies that constrain ports for legacy private applications accessed by remote users

B.

Leverage conditional access policies to ensure client sessions only come from known location or via the Zero Trust Exchange

C.

CASB app governance policies that rely on user risk scores to restrict cloud activities across all locations

D.

Data center firewall tiers that mirror internal VLANs and apply deny rules for roaming identities

Buy Now
Questions 7

Does the Access Control suite include features that prevent lateral movement?

Options:

A.

No. Access Control Services will only control access to the Internet and cloud applications.

B.

Yes. Controls for segmentation and conditional access are part of the Access Control Services.

C.

Yes. The Cloud Firewall will detect network segments and provide conditional access.

D.

No. The endpoint firewall will detect network segments and steer access.

Buy Now
Questions 8

What is a Landmine in Deception?

Options:

A.

Agentless plug-in installed on endpoints, such as desktops or laptops on a network. These plug-ins deploy decoy credentials, files, processes, and lures to other decoys at endpoints.

B.

Software agent installed on a centralized server in datacenter or in cloud. The agents running in the server deploy decoy credentials, files, processes, and lures to other decoys at endpoints.

C.

Software agent installed on endpoints, such as desktops or laptops on a network. These agents deploy decoy credentials, files, processes, and lures to other decoys at endpoints.

D.

Agentless plug-in installed on endpoints, such as desktops or laptops on a network. These plug-ins auto rotates decoy credentials, files, processes, and lures to other decoys at endpoints.

Buy Now
Questions 9

Which of the following is a benefit of tunneling?

Options:

A.

Increased latency.

B.

Enhanced data security.

C.

Support for only TCP/IP traffic.

D.

Increased header size.

Buy Now
Questions 10

An administrator needs to SSL inspect all traffic but one specific URL category. The administrator decides to create two policies, one to inspect all traffic and another one to bypass the specific category. What is the logical sequence in which they have to appear in the list?

Options:

A.

Both policies are incompatible, so it is not possible to have them together.

B.

First the policy for the exception Category, then further down the list the policy for the generic " inspect all. "

C.

First the policy for the generic " inspect all " , then further down the list the policy for the exception Category.

D.

All policies both generic and specific will be evaluated so no specific order is required.

Buy Now
Questions 11

How is the relationship between App Connector Groups and Server Groups created?

Options:

A.

The relationship between App Connector Groups and Server Groups is established dynamically in the Zero Trust Exchange as users try to access Applications

B.

When a new Server Group is created it points to the App Connector Groups that provide visibility to this Server Group

C.

Both App Connector Groups and Server Groups are linked together via the Data Center element

D.

When you create a new App Connector Group you must select the list of Server Groups to which it provides visibility

Buy Now
Questions 12

Which attack type is characterized by a commonly used website or service that has malicious content like malicious JavaScript running on it?

Options:

A.

Watering Hole Attack

B.

Pre-existing Compromise

C.

Phishing Attack

D.

Exploit Kits

Buy Now
Questions 13

An administrator needs to refine a custom URL category so that low-risk sites in that category are allowed while high-risk or uncertain sites are isolated or blocked, without weakening overall protection.

Which configuration approach aligns with this goal?

Options:

A.

Defer behavior to Cloud App Control so that URL Filtering is bypassed for known applications that match the category criteria

B.

Consolidate controls under a broad global allow rule and depend on bandwidth shaping to constrain risky traffic within the category

C.

Retain parent-category membership and reference the custom category in a higher-priority rule that applies Allow or Isolate actions as needed

D.

Replace parent-category assignments with a custom list to reduce overlap and simplify rule evaluation

Buy Now
Questions 14

A regional SOC analyst reviews ZIdentity audit logs during a surge in administrator-related anomalies at a hosted data center. The same session shows a successful sign-in from a new geography, a change that relaxes an MFA requirement in a sign-on policy, and an entitlement grant to a service account used by build automation.

Which action should the incident responder take to constrain privilege-escalation exposure while preserving forensic continuity?

Options:

A.

Revoke the service account’s elevated entitlements and restore the previous sign-on policy conditions that enforced stronger MFA

B.

Initiate a broad sign-on policy rollback across all roles and defer entitlement changes until the next maintenance cycle

C.

Increase audit verbosity for administrator actions and monitor for additional anomalies before applying restrictions

D.

Pause SIEM ingestion and collect on-appliance logs while delaying changes to avoid affecting correlation

Buy Now
Questions 15

A finance user downloads a password-protected spreadsheet from a sanctioned SaaS platform. Cloud Sandbox indicates that detonation is delayed because the file is encrypted.

Which action should the administrator take next?

Options:

A.

Configure a File Type Control policy to block unscannable files

B.

Reduce DLP thresholds for the finance department so benign matches are treated as policy violations

C.

Block tenant-wide access to third-party integrations and suspend the finance user’s uploads until further notice

D.

Move inspection exclusively to API-based scanning and disable inline controls to avoid workflow interruptions

Buy Now
Questions 16

What is the scale used to represent a users Zscaler Digital Experience (ZDX) score?

Options:

A.

1-100

B.

1-10

C.

1 - 1000

D.

0 - 50

Buy Now
Questions 17

An organization must comply with privacy requirements that restrict decrypting healthcare and financial websites.

Which configuration most precisely implements SSL/TLS bypass for these requirements while preserving inspection elsewhere?

Options:

A.

Update DLP policy to redact regulated data after decryption during inline inspection

B.

Redistribute the enterprise root CA to endpoints to strengthen trust and maintain decryption across all categories

C.

Create an SSL/TLS Inspection rule that designates the regulated URL categories as Do Not Inspect and exempts those destinations from decryption

D.

Use out-of-band CASB to quarantine sensitive content discovered at rest in SaaS platforms

Buy Now
Questions 18

What role does an App Connector serve?

Options:

A.

App Connectors enforce security policies for traffic destined for SaaS applications.

B.

App Connectors enable user experience monitoring for all applications.

C.

App Connectors expose a public IP for users to connect to for private application access.

D.

App Connectors mediate seamless communication for applications, services and data sources.

Buy Now
Questions 19

How does Zscaler Risk360 quantify risk?

Options:

A.

The number of risk events is totaled by location and combined.

B.

A risk score is computed based on the number of remediations needed compared to the industry peer average.

C.

Time to mitigate each identified risk is totaled, averaged, and tracked to show ongoing trends.

D.

A risk score is computed for each of the four stages of breach.

Buy Now
Questions 20

An administrator wants to allow users to access a wide variety of untrusted URLs. Which of the following would allow users to access these URLs in a safe manner?

Options:

A.

Browser Isolation

B.

App Connector

C.

Zscaler Private Access

D.

Zscaler Client Connector

Buy Now
Questions 21

An organization has more than one ZIA instance, each on different clouds. The organization is using the same login domain for both and upon login users are given this menu in ZCC asking which cloud they would like to join. What steps could an Administrator take to avoid having this menu appear?

Options:

A.

Customize an MSI version of the ZCC file specifying the USERDOMAIN variable.

B.

Customize an MSI version of the ZCC file specifying the CLOUDNAME variable.

C.

Federate the login domain between two different IDP instances.

D.

Create only one SAML integration with the desired ZIA instance.

Buy Now
Questions 22

What does Allow Cascading Enabled allow for?

Options:

A.

It ensures both Cloud App Control and URL Filtering Rules are applied.

B.

It ensures both Cloud App Control and File Type Control Rules are applied.

C.

It ensures both Cloud App Control and Bandwidth Control Rules are applied.

D.

It ensures both Cloud App Control and DLP Rules are applied.

Buy Now
Questions 23

A security team suspects that data exfiltration is occurring through encrypted channels to attackers.

To assess the company’s posture before tuning controls, which next step should be taken to validate whether existing protections cover this behavior?

Options:

A.

Raise the severity of egress firewall rules across segments to constrain outbound flows that might be exploited

B.

Review ZIA DLP outbound logs for anomalous uploads to unsanctioned SaaS applications and newly registered domains to gauge detection coverage

C.

Correlate ZIA threat insights with ZPA analytics to identify anomalous outbound patterns and unusual private-application access, and then verify that DLP and botnet controls apply to TLS-decrypted traffic

D.

Trigger broad Cloud Sandbox reanalysis of recent endpoint downloads to look for latent payloads that could facilitate exfiltration

Buy Now
Questions 24

When configuring a ZDX custom application and choosing Type: ' Network ' and completing the configuration by defining the necessary probe(s), which performance metrics will an administrator NOT get for users after enabling the application?

Options:

A.

Server Response Time

B.

ZDX Score

C.

Client Gateway IP Address

D.

Disk I/O

Buy Now
Questions 25

Which of the following statements most accurately describes Zero Trust Connections?

Options:

A.

They require that SSH inspection be enabled.

B.

They are dependent on a fixed / static network environment.

C.

They are independent of any network for control or trust.

D.

They require IPv6.

Buy Now
Questions 26

Which of the following can be used as Trusted Network criteria in Zscaler Client Connector?

Options:

A.

DNS Server, DHCP Server and Hostname/IP

B.

DHCP Server, DNS Search Domain and Hostname/IP

C.

Hostname/IP, DNS Server and DNS Search Domain

D.

Hostname/IP, DNS Search Domain and DHCP Server

Buy Now
Questions 27

How do Access Policies relate to the Application Segments and Application Segment Groups?

Options:

A.

When a condition is met, an Access Policy can either allow or block access to Application Segments OR Application Segment Groups.

B.

When a condition is met, an Access Policy can allow access to Application Segments Groups and block access to Application Segment.

C.

When a condition is met. an Access Policy can either allow or block access to Application Segments and Application Segment Groups.

D.

When a condition is met, an Access Policy can allow access to Application Segments and block access to Application Segment Groups.

Buy Now
Questions 28

A campaign alert identifies affected users and devices across multiple sites.

Which action should the SOC lead take to strengthen response performance and reduce repetitive manual tasks?

Options:

A.

Trigger a SOAR playbook through platform APIs to create tickets, block domains in ZIA, and isolate affected endpoints

B.

Assign manual triage to each site and postpone enforcement changes until endpoint teams confirm independent findings

C.

Disable automated notifications to collaboration tools to reduce noise while analysts evaluate logs for each user separately

D.

Increase the alert-severity classification so future campaign alerts appear higher in queues despite limited context enrichment

Buy Now
Questions 29

An administrator at a branch observes that a private ERP application is accessible when a user is connected to corporate Wi-Fi but intermittently fails when the user moves to a guest SSID at the same location. Zscaler Client Connector frequently transitions between Forwarding and Bypass states when the network changes.

Which action best reduces the instability?

Options:

A.

Broaden the application segment to include wildcard subdomains so DNS variations do not cause lookup mismatches

B.

Redesign the Client Connector Forwarding Profile to prioritize stable trusted-network attributes and avoid dependence on volatile SSID-based bypass triggers

C.

Disable posture checks for the ERP application to prevent frequent re-evaluations from affecting access decisions

D.

Backhaul all branch traffic to headquarters so users no longer change Service Edges when moving between SSIDs

Buy Now
Questions 30

What is a seed in Asset Discovery within External Attack Surface Management?

Options:

A.

A legitimate organizational asset, such as a known domain, IP address, or IP block, that serves as the starting point for discovery.

B.

A legitimate asset used to discover sensitive data and identify users accessing sanctioned or unsanctioned applications.

C.

A legitimate asset that allows users to access websites that are not mission-critical or business-critical.

D.

A legitimate decoy asset that triggers notifications and Deception actions when contacted by an attacker.

Buy Now
Questions 31

Which options must be selected when configuring Zscaler Client Connector for Strict Enforcement?

Options:

A.

cloudName and policyToken

B.

userDomain and deviceToken

C.

cloudName and deviceToken

D.

userDomain and policyToken

Buy Now
Questions 32

How does a Zscaler administrator troubleshoot a certificate pinned application?

Options:

A.

They could look at SSL logs for a failed client handshake.

B.

They could reboot the endpoint device.

C.

They could inspect the ZIA Web Policy.

D.

They could look into the SaaS application analytics tab.

Buy Now
Questions 33

What does Advanced Threat Protection defend users from?

Options:

A.

Vulnerable JavaScripts

B.

Large iFrames

C.

Malicious active content

D.

Command injection attacks

Buy Now
Questions 34

Traffic from a remote office traverses an untrusted ISP path and must connect to Zscaler through a mapped location with a defined static IP address and an expected throughput of 300 Mbps. High availability is not required.

Which action provides the appropriate tunnel characteristics with the minimum number of tunnels?

Options:

A.

Implement two GRE tunnels to different Service Edges and rely on SD-WAN latency scoring to steer traffic

B.

Configure a single IPSec tunnel to a regional Service Edge, and configure the location’s static IP address and bandwidth expectation

C.

Deploy a GRE tunnel with aggressive keepalives to compensate for underlay instability, and assign the static IP address to the location

D.

Build two IPSec tunnels with relaxed Dead Peer Detection (DPD) timers to avoid flapping during transient ISP outages

Buy Now
Questions 35

A global rule blocks “File Sharing” for all users. A Finance exception allowing “File Sharing” for its group appears lower in the list.

How is Finance access impacted given the evaluation order?

Options:

A.

Finance requests are inconsistently allowed as the engine re-evaluates category parents during peak hours.

B.

Finance requests are blocked because the global rule is matched first and halts further evaluation.

C.

Finance requests receive partial access as the engine blends actions across both rules to minimize exposure.

D.

Finance requests defer to departmental scope and bypass the global rule if group context is present at session start.

Buy Now
Questions 36

What transport mechanism will Zscaler Client Connector use to forward traffic to the Zero Trust Exchange when configured for Tunnel 2.0?

Options:

A.

Zscaler Client Connector will encapsulate the user ' s traffic in GRE tunnels to the ZTE.

B.

Zscaler Client Connector will encapsulate the user ' s traffic in IPSec tunnels to the ZTE.

C.

Zscaler Client Connector will encapsulate the user ' s traffic in DTLS/TLS tunnels to the ZTE.

D.

Zscaler Client Connector will encapsulate the user ' s traffic in HTTP Connect tunnels to the ZTE.

Buy Now
Questions 37

A team needs to validate who changed an entitlement and whether the change succeeded, and then correlate the activity with broader events.

Which audit source best supports this review before adding SIEM context?

Options:

A.

DLP event dashboards, because data-movement visualizations can uncover configuration edits through exposure trend shifts

B.

Firewall Insights, because network-layer telemetry can expose configuration changes through connection-state deviations

C.

Web Insights, because application traffic views can infer administrative behavior through session lineage and path analysis

D.

ZIdentity or Administrator Management audit logs, because they record administrator actions with the actor, timestamp, target, and outcome for direct attribution

Buy Now
Questions 38

Malware Protection inside HTTPS connections is performed using which parts of the Zero Trust Exchange?

Options:

A.

Deception creating decoy files for malware to discover.

B.

Application Segmentation of users to specific private applications.

C.

TLS Inspection decrypting traffic to compare signatures for known risks.

D.

Data Loss Protection comparing saved filenames for known risks.

Buy Now
Questions 39

An operations team wants to determine whether reported slowness in a SaaS application is caused by the application, the network, or the endpoint.

Which ZDX diagnostic should be prioritized to align performance degradation with regions, ISPs, or time windows?

Options:

A.

Initiate device-telemetry checks for high CPU utilization and unstable Wi-Fi to flag local constraints before considering path conditions

B.

Run CloudPath probes to capture hop-by-hop latency and packet loss along the end-to-end route to the application

C.

Query Inventory APIs to identify endpoints with older Client Connector builds that may lack recent telemetry capabilities

D.

Review the application’s ZDX Score and Page Fetch Time to correlate degradation with geography and time frames

Buy Now
Questions 40

When correlating indicators of privilege escalation with administrator behavior, which log type provides the most direct visibility into role changes and entitlement modifications for administrative accounts?

Options:

A.

Firewall Insights reports centered on rule hits and bandwidth consumption at egress points

B.

ZIdentity Administrator Audit Log filtered for entitlement updates and role assignments

C.

Web Insights transaction logs focusing on URL categories and inline policy actions

D.

Endpoint DLP telemetry summarizing sensitive-data handling and removable-media events

Buy Now
Questions 41

Which of the following external-facing API gateways can enforce authentication for access to Zscaler Client Connector API resources?

Options:

A.

Postman

B.

ZPA API

C.

ZIdentity

D.

OneAPI

Buy Now
Questions 42

A branch office uses a trusted-network bypass that routes traffic directly to the internet. Incident reviews show that unmanaged laptops at the branch are reaching SaaS applications without device-posture evaluation.

Which action should the administrator take next to ensure that devices are compliant before receiving access?

Options:

A.

Amend the trusted-network bypass and enforce posture-based access through Zscaler Client Connector for branch traffic

B.

Expand application segments to redefine which subnets are considered internal for discovery

C.

Add Caution actions to web policies to prompt users about risks on popular collaboration platforms

D.

Lower bandwidth quotas for the branch to discourage access spikes from unmanaged devices

Buy Now
Questions 43

What is the default timer in ZDX Advanced for web probes to be sent?

Options:

A.

1 minute

B.

10 minutes

C.

30 minutes

D.

5 minutes

Buy Now
Questions 44

A microsegmentation policy set contains a broad “allow employees to internal applications” rule before more specific controls. An incident review found SMB access from non-finance hosts to a finance file share.

Which refinement best addresses the unintended access while improving the internal security posture?

Options:

A.

Add bandwidth QoS constraints to the internal applications segment so non-finance SMB attempts are deprioritized at runtime

B.

Insert deception assets in the finance segment to divert suspicious SMB traffic away from the file share and collect telemetry

C.

Tighten URL Filtering for internal destinations so SMB-related domains resolve poorly in non-finance contexts

D.

Reorder the rules so the deny for non-finance SMB is evaluated before broad employee allows, and scope the SMB policy to finance hosts and device posture

Buy Now
Questions 45

The security exceptions allow list for Advanced Threat Protection apply to which of the following Policies?

Options:

A.

Sandbox

B.

URL Filtering

C.

File Type Control

D.

IPS Control

Buy Now
Questions 46

Which field within a URL filtering rule must be defined for Browser Isolation to work?

Options:

A.

Groups

B.

User Agent

C.

Departments

D.

Device Trust

Buy Now
Questions 47

What is an App Profile PAC file used for?

Options:

A.

It is used to encapsulate traffic within a GRE tunnel.

B.

It is used to establish a TLS session with the Zscaler cloud.

C.

It is used by Zscaler Client Connector to make traffic-forwarding decisions.

D.

It is used to categorize sensitive data.

Buy Now
Questions 48

A security lead reviews an executive summary: data-loss risk is driven by high-volume uploads to risky SaaS applications and unmanaged generative AI use; MTTR for BU-West remains high because of ticket-routing delays; and the board wants a 15% reduction in the data-loss risk score within 60 days. Peer benchmarks are similar but show identity risk as the primary driver elsewhere.

Which action should be taken next?

Options:

A.

Open UVM remediation for low-severity endpoint findings at scale to create throughput metrics regardless of category alignment

B.

Schedule an updated board narrative and postpone technical changes until the next quarter to avoid conflicting with peer comparisons

C.

Tighten Cloud App Control for risky SaaS and AI usage, and configure MTTR routing by business unit with ITSM integration

D.

Commission an identity-hardening review centered on private-application access patterns to mirror peer drivers even though local data-loss signals persist

Buy Now
Questions 49

Within ZPA, the mapping relationship between Connector Groups and Server Groups can best be defined as which of the following?

Options:

A.

Server Groups are configured for Dynamic Server Discovery so that mapped Connector Groups can then DNS resolve individual application Segment Groups.

B.

Connector Groups are configured for Dynamic Server Discovery so that mapped Server Groups can DNS resolve and advertise the applications.

C.

Connector Groups are configured for Dynamic Server Discovery so that ZPA can steer traffic through the appropriate Server Group.

D.

Server Groups are configured for Dynamic Server Discovery so that mapped Connector Groups can DNS resolve and make health checks toward the application.

Buy Now
Questions 50

An investigation at a regional office identifies sensitive files leaving a sanctioned SaaS platform outside business hours. Follow-up analysis shows that several users transferred content through native mobile applications that do not consistently traverse ZIA inline inspection.

Which action should the security lead take next to assess security across the SaaS environment?

Options:

A.

Verify that Browser Isolation is enabled for high-risk sessions and restrict uploads during suspicious activity

B.

Audit Client Connector posture checks for operating system, disk encryption, and antivirus status to determine whether compliance gates align with DLP enforcement

C.

Examine DNS telemetry for tunneling to newly registered domains and suppress anomalous outbound queries

D.

Initiate out-of-band CASB scanning with DLP engines to classify data at rest and review external-sharing configurations across the SaaS tenant

Buy Now
Questions 51

Which Zscaler forwarding mechanism creates a loopback address on the machine to forward the traffic towards Zscaler cloud?

Options:

A.

Enforced PAC mode

B.

ZTunnel - Packet Filter Based

C.

ZTunnel with Local Proxy

D.

ZTunnel - Route Based

Buy Now
Questions 52

Zscaler forwards the server SSL/TLS certificate directly to the user ' s browser session in which situation?

Options:

A.

When traffic contains a known threat signature.

B.

When web traffic is on custom TCP ports.

C.

When traffic is exempted in SSL Inspection policy rules.

D.

When user has connected to server in the past.

Buy Now
Questions 53

Which approach minimizes disruption when deploying Client Connector software updates across a heterogeneous user base while maintaining the ability to recover from defects?

Options:

A.

Defer all upgrades to weekend maintenance windows to reduce peak risk, accepting prolonged exposure to known vulnerabilities

B.

Immediately push the latest version to every segment through one channel to reduce fragmentation, and delay monitoring until users report problems

C.

Use staged rollout rings with assigned versions for selected groups, monitor deployment health in the Client Connector dashboard, and retain a revert path for cohorts that show instability

D.

Randomize update timing for each device group to spread the effect across multiple hours and days, relying on support tickets to detect failures

Buy Now
Questions 54

What is a ZIA Sublocation?

Options:

A.

The section of a corporate Location used to separate traffic, like traffic from employees from guest traffic

B.

The section of a corporate Location that sends traffic to a Subcloud

C.

Every one of the sections in a Corporate Location that use overlapping IP addresses

D.

A way to separate generic traffic from that coming from Client Connector

Buy Now
Questions 55

A team begins using domains that were dormant for months and recently revived. TLS inspection is enabled, but some teams added URL exceptions that bypass malware inspection.

Which action should a ZIA administrator take to prevent callbacks while minimizing disruption?

Options:

A.

Enable Browser Isolation for all sites flagged as recently active and let sessions render in isolation to reduce potential impact

B.

Depend on Advanced Threat Protection risk scoring by raising the risk threshold so borderline pages are treated as unsafe and blocked across categories

C.

Remove URL scanning exceptions for the affected teams, enforce a block policy targeting the Newly Revived Domains category, and configure DNS security to deny resolution for those hostnames

D.

Apply detect-only IPS mode to observe behavior, then plan a gradual transition to blocking after signatures show sustained activity

Buy Now
Questions 56

An investigation requires reviewing administrator entitlement changes from nine months ago to confirm suspected privilege escalation.

ZIdentity’s default portal retention period has already elapsed.

Which approach helps preserve and access the required audit trail for governance and forensic analysis?

Options:

A.

Export audit logs to CSV on a scheduled cadence and integrate supported audit streams with a SIEM through NSS or LSS to maintain an extended history

B.

Rely on recent sign-on policy evaluations and extrapolate prior administrator actions from current configurations

C.

Focus on bandwidth trends in Firewall Insights and infer administrative timelines from rule-utilization patterns

D.

Depend on implicit caching in the Experience Center and query historical entries during off-peak hours

Buy Now
Questions 57

How can we protect the Zscaler Client Connector from unauthorized alterations to its files and registry settings?

Options:

A.

StrictEnforcement CLI Parameter of ZCC installation file

B.

TamperProofing options in Forwarding Profile

C.

AntiTampering CLI Parameter of ZCC installation file

D.

DisableTampering options in Forwarding Profile

Buy Now
Questions 58

Which of the following are correct request methods when configuring a URL filtering rule with a Caution action?

Options:

A.

Connect, Get, Head

B.

Options, Delete, Put

C.

Get, Delete, Trace

D.

Connect, Post, Put

Buy Now
Questions 59

How deeply can the Zscaler service scan recursively compressed files for malicious content?

Options:

A.

It scans only uncompressed files.

B.

Up to three layers of recursive compression.

C.

Up to two layers of recursive compression.

D.

Up to five layers of recursive compression.

Buy Now
Questions 60

A policy set uses a custom URL category to permit a pilot group ' s access to specific Newly Registered Domains (NRDs). A broader rule blocks NRDs globally. After recent changes, logs show unexpected allows to suspicious NRDs outside the pilot list.

Which modification achieves tight control while preserving the pilot exception with minimal unintended exposure?

Options:

A.

Restore parent category membership and add a narrowly scoped user-level rule above the global NRD block to allow or isolate the pilot domains.

B.

Move the global NRD block to the top and reference the custom category in a lower rule for limited visibility rather than enforcement.

C.

Expand the custom category to include all observed NRDs to reduce discrepancies between global and user-level rules.

D.

Lower the global NRD control to Caution to reduce denials during categorization volatility in the broader environment.

Buy Now
Questions 61

A threat actor’s command-and-control infrastructure uses hard-coded IP addresses and several domains resolved through DNS. An organization wants Zscaler to block callback attempts with minimal dependence on endpoint agents and to enforce the decision consistently for roaming users.

Which configuration best aligns with ZIA policy enforcement and the zero-trust model?

Options:

A.

Enable Browser Isolation for the suspected destinations so sessions are rendered remotely even when callbacks reach the external hosts

B.

Add the domains to a URL-category override and depend on TLS inspection to identify the traffic after connection

C.

Create a high-risk URL Filtering rule that reduces the Advanced Threat Protection risk threshold and relies on page scoring to suppress suspicious domains

D.

Create a Cloud Firewall destination group containing the indicator IP addresses and apply a high-priority Drop rule, while adding the domains to a globally blocked custom URL category

Buy Now
Questions 62

A Gold-class SaaS application performs poorly even though its bandwidth class has a generous minimum and moderate maximum. Usage dashboards show available capacity during incidents, and other applications are not saturating the link.

What is the most defensible next step to prevent recurring degradation?

Options:

A.

Prioritize streaming media above the SaaS application to normalize queue behavior and reduce circuit jitter

B.

Reduce TLS inspection for the SaaS application to remove inspection latency without first validating the traffic path

C.

Raise the Gold-class maximum to a higher ceiling to address presumed internal throttling

D.

Use ZDX path metrics to validate last-mile or ISP congestion at the affected site and plan a circuit upgrade or provider change while retaining the current policies

Buy Now
Questions 63

A Cloud Sandbox detonation shows a document beaconing through obfuscated scripts and spawning child processes that attempt network calls to newly registered domains. The desired outcome is to prevent users from downloading or accessing similar suspicious files across web and SaaS channels.

What action should be taken next?

Options:

A.

Apply a Sandbox policy that quarantines the document type across all applicable channels above the existing Sandbox policy rule

B.

Shift scanning to out-of-band CASB-only workflows so that analysis occurs after content is stored

C.

Route detections to a manual review queue and postpone policy changes until more analyst capacity is available

D.

Lower Sandbox sensitivity to reduce alert volume and defer enforcement until trend data is gathered

Buy Now
Questions 64

What is the main purpose of Sandbox functionality?

Options:

A.

Block malware that we have previously identified

B.

Build a test environment where we can evaluate the result of policies

C.

Identify Zero-Day Threats

D.

Balance threat detection across customers around the world

Buy Now
Questions 65

For a deployment using both ZIA and ZPA set of services, what is the best authentication solution?

Options:

A.

Use forms Authentication in ZPA and SAML in ZIA

B.

Use forms Authentication in ZIA and SAML in ZPA

C.

Configure Authentication using SAML on both ZIA and ZPA

D.

Use forms Authentication for both ZIA and ZPA

Buy Now
Questions 66

How does Zscaler ensure that sensitive structured data used in the EDM process is not stored in its cloud environment?

Options:

A.

By storing sensitive structured data on servers managed by trusted Zscaler staff for enhanced security.

B.

By using an on-premises VM to index data and only sending hashed values to the cloud.

C.

By requiring customers to manually hash the data and upload it to the cloud.

D.

By encrypting sensitive data directly before storing it in the cloud.

Buy Now
Questions 67

What is the maximum default frequency of device posture profile evaluation by Zscaler Client Connector?

Options:

A.

15 minutes

B.

2 minutes

C.

5 minutes

D.

10 minutes

Buy Now
Questions 68

You recently deployed an additional App Connector to an existing app connector group. What do you need to do before starting the zpa-connector service?

Options:

A.

Copy the group provisioning key to /opt/zscaler/var/provision key

B.

Monitor the peak CPU and memory utilization of the AC

C.

Schedule periodic software updates for the app connector group

D.

Check the status of the new App Connector in the administration portal

Buy Now
Questions 69

When the Zscaler Client Connector launches, which portal does it initially interact with to understand the user ' s domain and identity provider (IdP)?

Options:

A.

Zscaler Private Access (ZPA) Portal

B.

Zscaler Central Authority

C.

Zscaler Internet Access (ZIA) Portal

D.

Zscaler Client Connector Portal

Buy Now
Questions 70

An administrator must apply file-type controls to a subset of users while ensuring evasion-resistant detection.

Which configuration most directly maps a file-type policy to a user group and role-based security requirements?

Options:

A.

Define a global File Type Control rule that blocks risky formats and rely on identity-based reporting to address group-level differences later

B.

Enable MIME-type validation in a baseline content policy and expect extension mismatches to be handled through application restrictions

C.

Create a File Type Control rule using magic-byte, MIME-type, and file-extension checks; scope it to the target SCIM group and device posture; and place it above broader catch-all rules

D.

Create a URL Filtering rule scoped to the department and reference a custom URL category that lists file extensions for the restricted formats

Buy Now
Questions 71

What are the two types of Alert Rules that can be defined?

Options:

A.

ThreatLabZ pre-defined and customer defined

B.

Snort defined and 3rd party defined

C.

ThreatLabZ pre-defined and 3rd party defined

D.

Customer defined and 3rd party defined

Buy Now
Questions 72

A platform team deploys Bandwidth Control and firewall policy changes through an API. After a large rollout, users report sporadic application slowdowns, yet the monitoring team finds gaps in telemetry for the same time windows.

Which action best prevents these performance issues from persisting and going undetected in similar rollouts?

Options:

A.

Add an implementation step that validates monitoring subscriptions and exports ZDX and Firewall Insights baselines before applying policy changes through APIs

B.

Aggregate logs monthly and perform retrospective correlation to avoid noisy short-term fluctuations in metrics

C.

Increase API client-token lifetimes to reduce HTTP 401 errors and stabilize automation during policy pushes

D.

Restrict automation runs to weekly windows to minimize configuration changes that may obscure trend lines

Buy Now
Questions 73

A security engineer needs the HR portal and SIP voice traffic to bypass inspection on the downtown campus but be fully inspected when staff roam. The campus DHCP service recently began issuing a public DNS resolver that breaks the existing trusted-network match, and users are intermittently inspected on campus.

Which action should the engineer take to restore consistent campus-only bypass for those applications?

Options:

A.

Enable PAC-file fallback in Client Connector and prioritize DNS-based conditions so HR and SIP are suppressed when the resolver aligns with the campus

B.

Strengthen the Trusted Network criteria by adding default-gateway and egress-IP checks to the campus entry, map the campus to a profile with No Forwarding, and place a top-down bypass for HR and SIP on the trusted network followed by a forwarding rule for the same applications off-trusted

C.

Switch the Forwarding Profile to Enforce Proxy and add PAC logic for campus subnets so HR and SIP requests are sent directly at those ranges

D.

Reduce posture checks on the campus and rely on Application Profiles to remap HR and SIP to Tunnel with Local Proxy for roaming users

Buy Now
Questions 74

What is the recommended minimum number of App connectors needed to ensure resiliency?

Options:

A.

2

B.

6

C.

4

D.

3

Buy Now
Questions 75

What are common delivery mechanisms for malware?

Options:

A.

Malware downloads from web pages

B.

Personal emails, company documents, OneDrive

C.

Spam, exploit kits, USB drives, video streaming

D.

Phishing, Exploit Kits, Watering Holes, Pre-existing Compromise

Buy Now
Questions 76

Which of the following statements accurately reflects Zscaler ' s file size limitation for Malware Protection scans?

Options:

A.

Zscaler scans all files regardless of size.

B.

Zscaler scans files only if they are below 100 MB.

C.

Zscaler scans files up to 500 MB

D.

Zscaler scans files up to 400 MB.

Buy Now
Questions 77

When are users granted conditional access to segmented private applications?

Options:

A.

After passing criteria checks related to authorization and security.

B.

Immediately upon connection request for best performance.

C.

After a short delay of a random number of seconds.

D.

After verifying the user password inside of private application.

Buy Now
Questions 78

What is a key feature of OpenID Connect (OIDC)-based authentication for users?

Options:

A.

It supports attribute-based access control.

B.

It requires annual certificate maintenance.

C.

It uses JSON-based web tokens.

D.

It uses XML to format identity information.

Buy Now
Questions 79

A new customer has just purchased Zscaler for Users.

Which of the following Zscaler service entitlements is enabled by default?

Options:

A.

ZPA

B.

Deception

C.

ZIA

D.

ZDX

Buy Now
Questions 80

Which of the following components is installed on an endpoint to connect users to the Zero Trust Exchange regardless of their location - home, work, while traveling, etc.?

Options:

A.

Client connector

B.

Private Service Edge

C.

IPSec/GRE Tunnel

D.

App Connector

Buy Now
Questions 81

Client Connector forwarding profile determines how we want to forward the traffic to the Zscaler Cloud. Assuming we have configured tunnels (GRE or IPSEC) from locations, what is the recommended combination for on-trusted and off-trusted options?

Options:

A.

Tunnel v2.0 for on-trusted and tunnel v2.0 for off-trusted

B.

None for on-trusted and none for off-trusted

C.

None for on-trusted and tunnel v2.0 for off-trusted

D.

Tunnel v2.0 for on-trusted and none for off-trusted

Buy Now
Exam Code: ZDTA
Exam Name: Zscaler Digital Transformation Administrator
Last Update: Aug 21, 2026
Questions: 273
ZDTA pdf

ZDTA PDF

$25.5  $84.99
ZDTA Engine

ZDTA Testing Engine

$30  $99.99
ZDTA PDF + Engine

ZDTA PDF + Testing Engine

$40.5  $134.99