Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

Zscaler ZDTA - Zscaler Digital Transformation Administrator

Page: 5 / 9
Total 273 questions

A team begins using domains that were dormant for months and recently revived. TLS inspection is enabled, but some teams added URL exceptions that bypass malware inspection.

Which action should a ZIA administrator take to prevent callbacks while minimizing disruption?

A.

Enable Browser Isolation for all sites flagged as recently active and let sessions render in isolation to reduce potential impact

B.

Depend on Advanced Threat Protection risk scoring by raising the risk threshold so borderline pages are treated as unsafe and blocked across categories

C.

Remove URL scanning exceptions for the affected teams, enforce a block policy targeting the Newly Revived Domains category, and configure DNS security to deny resolution for those hostnames

D.

Apply detect-only IPS mode to observe behavior, then plan a gradual transition to blocking after signatures show sustained activity

A team plans to deploy ZPA App Connectors as virtual machines in two data centers and one AWS VPC.

Which information should be communicated upfront to align network placement and access controls with Zero Trust principles?

A.

The external NAT addresses to advertise for inbound reachability and the BGP communities to tag for internet-facing routes

B.

The application subnets reachable from connector network interfaces, the requirement for outbound TLS to ZPA Service Edges, and the prohibition of inline TLS interception

C.

The GRE or IPsec tunnel endpoints that will terminate user traffic at the data-center perimeter for centralized inspection

D.

The reverse-proxy access control lists that will accept client-initiated TLS from the internet and the static public IP addresses required for allowlists

What is the duration of Zscaler ' s short-lived issuing CA for SSL Inspection?

A.

7-day expiry with 0-day rotation

B.

14-day expiry with 7-day rotation

C.

30-day expiry with 7-day rotation

D.

21-day expiry with 14-day rotation

Traffic from a remote office traverses an untrusted ISP path and must connect to Zscaler through a mapped location with a defined static IP address and an expected throughput of 300 Mbps. High availability is not required.

Which action provides the appropriate tunnel characteristics with the minimum number of tunnels?

A.

Implement two GRE tunnels to different Service Edges and rely on SD-WAN latency scoring to steer traffic

B.

Configure a single IPSec tunnel to a regional Service Edge, and configure the location’s static IP address and bandwidth expectation

C.

Deploy a GRE tunnel with aggressive keepalives to compensate for underlay instability, and assign the static IP address to the location

D.

Build two IPSec tunnels with relaxed Dead Peer Detection (DPD) timers to avoid flapping during transient ISP outages

An organization must comply with privacy requirements that restrict decrypting healthcare and financial websites.

Which configuration most precisely implements SSL/TLS bypass for these requirements while preserving inspection elsewhere?

A.

Update DLP policy to redact regulated data after decryption during inline inspection

B.

Redistribute the enterprise root CA to endpoints to strengthen trust and maintain decryption across all categories

C.

Create an SSL/TLS Inspection rule that designates the regulated URL categories as Do Not Inspect and exempts those destinations from decryption

D.

Use out-of-band CASB to quarantine sensitive content discovered at rest in SaaS platforms

As technology that exists for a very long period of time, has URL Filtering lost its effectiveness?

A.

URL Filter is the most commonly used web filtering technique in the arsenal. It acts as first line of defense.

B.

In a modern cloud world, access to all Internet sites and cloud applications should be granted by default. URL Filtering is no longer needed.

C.

URL Filtering has been replaced by CASB functionality through blocking access to all Internet sites and only allowing a few corporate applications.

D.

URL Filtering is outdated and no longer needed. The rise of HTTPS leads renders URL Filtering ineffective as all traffic is encrypted.

During the authentication process while accessing a private web application, how is the SAML assertion delivered to the service provider?

A.

HTTP Redirect on the browser

B.

API request/response sequence

C.

Through the client connector

D.

Form POST via the browser

Can Notifications, based on Alert Rules, be sent with methods other than email?

A.

Email is the only method for notifications as that is universally applicable and no other way of sending them makes sense.

B.

In addition to email, text messages can be sent directly to one cell phone to alert the CISO who is then coordinating the work on the incident.

C.

Leading ITSM systems can be connected to the Zero Trust Exchange using a NSS server, which will then connect to ITSM tools and forwards the alert.

D.

In addition to email, notifications, based on Alert Rules, can be shared with leading ITSM or UCAAS tools over Webhooks.

How is data gathered with ZDX Advanced client performance?

A.

By generating synthetic transactions to designated Internet and Private applications every 5 minutes and measuring the performance of those sessions.

B.

By constantly analyzing live user sessions to both Internet and Private applications and measuring the performance of those sessions.

C.

By using AI predictive analysis ZDX can extrapolate near-term client performance based upon recent past data observed.

D.

By constantly analyzing live user sessions to critical SaaS applications and measuring the performance of those sessions.

When configuring webhook alerts in ZIA, which two webhook authentication types are supported?

A.

Basic and OAuth

B.

Token and OAuth

C.

Basic and Token

D.

Digest and OAuth