Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

Zscaler ZDTA - Zscaler Digital Transformation Administrator

Page: 6 / 9
Total 273 questions

Logs indicate traffic to an internal hostname was permitted and not inspected, despite a posture-based access policy that should have blocked the session.

Which statement best explains this outcome?

A.

Inspection policy overrode access controls because of protocol heuristics.

B.

SAML attribute mapping suppressed posture checks during reauthentication.

C.

A Client Forwarding Policy bypass matched first, preventing the access policy from evaluating the session.

D.

Connector selection failed closed and defaulted to passthrough to reduce latency.

How would an administrator retrieve the access token to use the Zscaler One API?

A.

The administrator needs to send a POST request along with the required parameters to ZIdentity " s token endpoint.

B.

The administrator needs to send a GET request along with the required parameters to ZIdentity ' s token endpoint.

C.

The administrator needs to logon to the ZIA portal to generate the access token with Super Admin role.

D.

The administrator needs to logon to the ZIA portal to generate the access token with API Admin role.

A test administrator is not present in the identity provider and requires constrained access to configure ZIA policies for a short period.

Which step provides controlled administrative capability?

A.

Grant Zscaler Client Connector service entitlements to the account so it can reach the admin console

B.

Add a new department and expect policy inheritance to provide the required administrative permissions

C.

Use OpenID Connect to import the account and defer role mapping until sign-in

D.

Create a local user in ZIdentity and grant a least-privileged administrative entitlement scoped to Internet & SaaS

A regional office reports persistent throttling of a critical SaaS application during business hours. The Bandwidth Control dashboard shows the application assigned to a class with a narrow maximum, while rule-hit counts indicate that non-critical streaming traffic is receiving excessive bandwidth.

Which action should the network team take to improve performance?

A.

Add a parallel rule for the critical application in the same class to increase match frequency despite the existing caps

B.

Broaden minimum bandwidth globally, accepting reduced headroom for all locations to offset localized congestion

C.

Stream firewall logs to the SIEM and defer policy updates until multi-source correlation identifies external bottlenecks

D.

Refactor the bandwidth-class definitions and rule order to increase the critical application’s allocation and restrict non-critical streaming, then validate the change in Firewall Insights

Security teams are vetting approaches to private application access across two merging organizations to reduce post-acquisition lateral movement.

Which approach best constrains internal discovery and probing while preserving required connectivity?

A.

Adopt ZPA user-to-app segmentation with inside-out connectivity so users reach defined applications and cannot traverse broader IP ranges.

B.

Centralize VPN concentrators and restrict subnet access by department to contain exploratory traffic during initial entitlement mapping.

C.

Extend shared VLANs across the combined data centers and use access control lists to discourage host-to-host enumeration during audits.

D.

Apply IDS signatures at core routing layers to flag port scans and perform rate limiting until both environments complete segmentation.

An organization wants to reduce implicit trust while preserving user access to both internet and private applications.

Which configuration approach best aligns with a least-privilege design that also reduces the attack surface?

A.

Apply URL Filtering and Cloud App Control for outbound access, and enforce ZPA application segmentation with inside-out connectivity to restrict private-application reachability

B.

Adopt SD-WAN hairpinning for SaaS access and use VLAN-based controls to partition legacy environments while policies converge

C.

Standardize on shared subnets and rely on internal firewalls to control access, while using broad URL categories to shape outbound traffic

D.

Increase TLS decryption coverage for all destinations and rely on VPN access control lists to constrain private-network discovery during coexistence

Company A acquires Company B. Users from both companies require reliable access to internet and SaaS services and to each other’s private applications across overlapping RFC1918 address ranges. A legacy VPN retained temporarily for a third-party integration causes intermittent route conflicts and noticeable latency.

Which action should the administrator prioritize to stabilize access and minimize network-level collisions?

A.

Move all private-application traffic to a shared MPLS core and rely on centralized firewalls to normalize traffic while retaining split tunneling for internet access

B.

Expand the legacy VPN mesh, tighten BGP route filters, and defer access transformation until IP renumbering is complete

C.

Onboard private applications into ZPA using application segments and dedicated App Connector groups for each environment, enable Client Connector forwarding for private access, and use ZIA with local internet breakouts, Bandwidth Control, and Microsoft 365 optimization

D.

Implement SD-WAN steering policies to pin traffic to preferred links and use access control lists to block disallowed subnets as an interim control

A log review shows requests to a sanctioned application being allowed despite a later rule intended to restrict access by time of day.

The rule set is:

    Allow the sanctioned application for All Employees

    Block the sanctioned application outside business hours for All Employees

    Log restricted-access hits

Which cause and risk are most consistent with this behavior?

A.

The time-of-day block inherits timing from device posture, which desynchronizes evaluation and produces inconsistent enforcement

B.

The initial allow rule matches first and stops further evaluation, so the time-of-day block never applies and access remains available after business hours

C.

The logging rule takes precedence because of its action type, preventing the block from being reached

D.

The sanctioned application category becomes invalid during SSL inspection, sending the request to a default allow path that bypasses time restrictions

An operations team relies on API-driven exports of ZDX scores and Firewall Insights to track application performance over time. The team encounters periodic HTTP 429 errors during peak hours, and performance regressions are missed when exports fail.

Which mitigation best reduces blind spots that contribute to preventable performance issues?

A.

Shorten token-expiry intervals to force more frequent reauthentication and improve client statefulness under contention

B.

Increase the number of parallel API workers during peak hours to clear the telemetry backlog faster

C.

Assign broader API scopes to the client so retries can fetch more datasets during each export cycle

D.

Use client-side rate limiting with exponential backoff, schedule batch exports during off-peak periods, and optimize queries to reduce redundant calls

Which of the following statements accurately reflects Zscaler ' s file size limitation for Malware Protection scans?

A.

Zscaler scans all files regardless of size.

B.

Zscaler scans files only if they are below 100 MB.

C.

Zscaler scans files up to 500 MB

D.

Zscaler scans files up to 400 MB.