Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

Zscaler ZDTA - Zscaler Digital Transformation Administrator

Page: 2 / 9
Total 273 questions

An administrator wants to allow users to access a wide variety of untrusted URLs. Which of the following would allow users to access these URLs in a safe manner?

A.

Browser Isolation

B.

App Connector

C.

Zscaler Private Access

D.

Zscaler Client Connector

What does Zscaler Advanced Firewall support that Zscaler Standard Firewall does not?

A.

Destination NAT

B.

FQDN Filtering with wildcard

C.

DNS Dashboards, Insights and Logs

D.

DNS Tunnel and DNS Application Control

Users connected through one ISP in a single country report a sudden decline in UCaaS call quality. The operations team must determine whether the degradation is ISP-specific or caused by local endpoints.

Which ZDX diagnostic best isolates the provider and geographic area responsible for the issue?

A.

Use ISP Insights and geographic latency maps to aggregate experience scores and network-path measurements by provider and region

B.

Correlate meeting-level mean opinion scores with endpoint CPU spikes and conclude that local resource limitations are constraining audio and video

C.

Examine individual CloudPath traces for per-hop jitter and packet loss while assuming that the last-mile segment is the bottleneck

D.

Compare device Wi-Fi measurements with UCaaS quality trends and infer that users’ local networks are responsible

A company must enforce least-privileged access to private applications when contractors connect from varying locations using devices with inconsistent security posture. The security team wants decisions to use identity and per-session context instead of broad network assumptions.

Which approach best meets the requirement?

A.

Build ZPA Access Policy rules around a SCIM-synchronized contractor group, apply device-posture conditions to sensitive application segments, and retain a final catch-all deny rule

B.

Prioritize ZIA URL Filtering rules that use department attributes to shape contractor access, and leave ZPA unchanged

C.

Use location groups to provide contractors with tiered access to most internal services and defer device evaluation to downstream controls

D.

Require session MFA for contractor authentication and use SAML attributes to relax private-application access broadly

A microsegmentation policy set contains a broad “allow employees to internal applications” rule before more specific controls. An incident review found SMB access from non-finance hosts to a finance file share.

Which refinement best addresses the unintended access while improving the internal security posture?

A.

Add bandwidth QoS constraints to the internal applications segment so non-finance SMB attempts are deprioritized at runtime

B.

Insert deception assets in the finance segment to divert suspicious SMB traffic away from the file share and collect telemetry

C.

Tighten URL Filtering for internal destinations so SMB-related domains resolve poorly in non-finance contexts

D.

Reorder the rules so the deny for non-finance SMB is evaluated before broad employee allows, and scope the SMB policy to finance hosts and device posture

From a user perspective, Zscaler Bandwidth Control performs traffic shaping and buffering on what direction(s) of traffic?

A.

Outbound traffic is shaped. Inbound or localhost traffic is unshaped.

B.

Outbound or inbound traffic is shaped. Localhost traffic is unshaped.

C.

Inbound traffic is shaped. Outbound or localhost traffic is unshaped.

D.

Localhost traffic is shaped. Outbound or Inbound traffic is unshaped.

Administrators report that some non-compliant devices can still reach private applications. A broad Allow rule precedes device-posture checks in the policy set.

What is the most appropriate next step to satisfy the compliance-before-access requirement?

A.

Broaden URL Filtering blocks for high-risk categories to curtail non-business browsing on those devices

B.

Apply stricter user-group scoping to limit access for departments with higher incident rates

C.

Increase time-based restrictions on access windows to reduce exposure during off-hours

D.

Reorder the policy so posture-based access rules are evaluated before any general Allow statements

Which of the following is the preferred method for authentication in a OneAPI environment?

A.

OIDC

B.

SCIM

C.

SAML

D.

EntraID

A new Zscaler Client Connector version causes intermittent tunnel drops for macOS devices in one region during a controlled rollout.

Which action enables broader deployment with minimal disruption while addressing the instability?

A.

Delay updates in every region until vendor remediation is available, accepting prolonged exposure to vulnerabilities fixed in the new version

B.

Revert the affected segment to the previous version and continue pilots in unaffected cohorts, monitoring the Zscaler Client Connector dashboard and logs for recurrence

C.

Reassign every group to an earlier stable version regardless of local stability, sacrificing rollout progress and increasing coordination overhead

D.

Push diagnostic packet-capture collection to the entire user base, accepting a performance impact for unaffected cohorts

A SOC subscribes to a third-party blocklist and must ensure that listed destinations are denied while preserving predefined rules required for Microsoft 365 access. ZIA Firewall Filtering rules are evaluated from top to bottom using first-match processing.

How should the blocking rule be positioned?

A.

Insert a drop rule for the third-party destination group above generic outbound allow rules while keeping the essential Microsoft 365 predefined rules intact

B.

Move the third-party block rule to the bottom so it is evaluated after application identification for standard services

C.

Modify the Microsoft 365 predefined rules to include third-party exclusions, then append a general deny rule for unclassified traffic

D.

Place broad SaaS allow rules at the top and insert the third-party block rule below them to avoid unintended denial of legitimate sessions