Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

Zscaler ZDTA - Zscaler Digital Transformation Administrator

Page: 8 / 9
Total 273 questions

Which Zscaler feature detects whether an intruder is accessing your internal resources?

A.

SandBox

B.

SSL Decryption Bypass

C.

Browser Isolation

D.

Deception

A policy set uses a custom URL category to permit a pilot group ' s access to specific Newly Registered Domains (NRDs). A broader rule blocks NRDs globally. After recent changes, logs show unexpected allows to suspicious NRDs outside the pilot list.

Which modification achieves tight control while preserving the pilot exception with minimal unintended exposure?

A.

Restore parent category membership and add a narrowly scoped user-level rule above the global NRD block to allow or isolate the pilot domains.

B.

Move the global NRD block to the top and reference the custom category in a lower rule for limited visibility rather than enforcement.

C.

Expand the custom category to include all observed NRDs to reduce discrepancies between global and user-level rules.

D.

Lower the global NRD control to Caution to reduce denials during categorization volatility in the broader environment.

Policy troubleshooting identifies inconsistent enforcement across web and private-application channels for a regulated data type. The inconsistency causes inefficient investigations and intermittent blocking.

Which action would most plausibly improve platform performance under this policy framework?

A.

Align the policies to shared DLP engines and classification labels, with clearly defined precedence to eliminate cross-channel conflicts

B.

Create separate custom rules for each channel to isolate false positives despite using different classification references

C.

Reduce detection scope for private applications and prioritize web controls to minimize cross-channel matches

D.

Segment enforcement by department so identical data types can be handled differently without policy overlap

A company requires stricter control of non-web traffic when users are outside the corporate network.

Which adjustment best reduces unintended exposure for off-network users?

A.

Configure Zscaler Client Connector to use Z-Tunnel 2.0 when off-network, and enable the appropriate Cloud Firewall rules

B.

Increase inspection depth for on-network users to compensate for off-network access risks, assuming that stricter internal analysis provides an aggregate deterrent

C.

Configure Zscaler Client Connector to use Z-Tunnel 1.0 when off-network, and enable the appropriate Cloud Firewall rules

D.

Duplicate the off-network block rule and place both copies below the global allow rule to provide redundant coverage and increased monitoring

What conditions can be referenced for Trusted Network Detection?

A.

Hostname Resolution, Network Adapter IP, Default Gateway

B.

DNS Servers, DNS Search Domain, Network Adapter IP

C.

Hostname Resolution, DNS Servers, Geo Location

D.

DNS Search Domain, DNS Server, Hostname Resolution

Which are valid criteria for use in Access Policy Rules for ZPA?

A.

Group Membership, ZIA Risk Score, Domain Joined, Certificate Trust

B.

Username, Trusted Network Status, Password, Location

C.

SCIM Group, Time of Day, Client Type, Country Code

D.

Department, SNI, Branch Connector Group, Machine Group

For a deployment using both ZIA and ZPA set of services, what is the best authentication solution?

A.

Use forms Authentication in ZPA and SAML in ZIA

B.

Use forms Authentication in ZIA and SAML in ZPA

C.

Configure Authentication using SAML on both ZIA and ZPA

D.

Use forms Authentication for both ZIA and ZPA

A team needs to validate who changed an entitlement and whether the change succeeded, and then correlate the activity with broader events.

Which audit source best supports this review before adding SIEM context?

A.

DLP event dashboards, because data-movement visualizations can uncover configuration edits through exposure trend shifts

B.

Firewall Insights, because network-layer telemetry can expose configuration changes through connection-state deviations

C.

Web Insights, because application traffic views can infer administrative behavior through session lineage and path analysis

D.

ZIdentity or Administrator Management audit logs, because they record administrator actions with the actor, timestamp, target, and outcome for direct attribution

A branch office uses a trusted-network bypass that routes traffic directly to the internet. Incident reviews show that unmanaged laptops at the branch are reaching SaaS applications without device-posture evaluation.

Which action should the administrator take next to ensure that devices are compliant before receiving access?

A.

Amend the trusted-network bypass and enforce posture-based access through Zscaler Client Connector for branch traffic

B.

Expand application segments to redefine which subnets are considered internal for discovery

C.

Add Caution actions to web policies to prompt users about risks on popular collaboration platforms

D.

Lower bandwidth quotas for the branch to discourage access spikes from unmanaged devices

A security lead reviews an executive summary: data-loss risk is driven by high-volume uploads to risky SaaS applications and unmanaged generative AI use; MTTR for BU-West remains high because of ticket-routing delays; and the board wants a 15% reduction in the data-loss risk score within 60 days. Peer benchmarks are similar but show identity risk as the primary driver elsewhere.

Which action should be taken next?

A.

Open UVM remediation for low-severity endpoint findings at scale to create throughput metrics regardless of category alignment

B.

Schedule an updated board narrative and postpone technical changes until the next quarter to avoid conflicting with peer comparisons

C.

Tighten Cloud App Control for risky SaaS and AI usage, and configure MTTR routing by business unit with ITSM integration

D.

Commission an identity-hardening review centered on private-application access patterns to mirror peer drivers even though local data-loss signals persist