Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

Zscaler ZDTA - Zscaler Digital Transformation Administrator

Page: 1 / 9
Total 273 questions

Does the Cloud Firewall detect evasion techniques that would allow applications to communicate over non-standard ports to bypass its controls?

A.

The Cloud Firewall includes Deep Packet Inspection, which detects protocol evasions and sends the traffic to the respective engines for inspection and handling.

B.

Zscaler Client Connector will prevent evasion on the endpoint in conjunction with the endpoint operating system’s firewall.

C.

As traffic usually is forwarded from an on-premise firewall, this firewall will handle any evasion and will make sure that the protocols are corrected.

D.

The Cloud Firewall includes an IPS engine, which will detect the evasion techniques and will just block the transactions as it is invalid.

What happens after the Zscaler Client Connector receives a valid SAML response from the Identity Provider (IdP)?

A.

The Zscaler Client Connector Portal authenticates the user directly.

B.

There is no need for further actions as the SAML is valid, access is granted immediately.

C.

The SAML response is sent back to the user’s device for local validation.

D.

Zscaler Internet Access validates the SAML response and returns an authentication token.

Which of the following is a common use case for adopting Zscaler’s Data Protection?

A.

Reduce your Internet Attack Surface

B.

Prevent download of Malicious Files

C.

Prevent loss to Internet and Cloud Apps

D.

Securely connect users to Private Applications

Which of the following secures all IP unicast traffic?

A.

Secure Shell (SSH)

B.

Tunnel with local proxy

C.

Enforce PAC

D.

Z-Tunnel 2.0

A user’s access to a private CRM application fails occasionally during video calls. ZDX shows sharp jitter spikes and rising packet loss on the ISP path, with client-egress latency increasing when calls begin.

What will reduce CRM access variability?

A.

Expand URL categories for CRM domains to improve classification fidelity under heavy traffic

B.

Steer traffic to a nearer Service Edge and validate path quality with ZDX and Tunnel Insights to minimize latency and jitter

C.

Constrain the user’s identity claims to limit token size and reduce authentication overhead during calls

D.

Move CRM traffic to a Silver bandwidth class so collaboration traffic no longer competes with business data

A tenant’s Cloud App Control policy permits Webmail globally. Security requires members of the Sales group to receive a CAUTION prompt when accessing personal Webmail, while all other groups must continue to receive unrestricted access.

Sales users and other groups are currently matched by a Cloud App Control rule that allows all Webmail.

Which action should the administrator take to meet the requirement for the Sales group?

A.

Configure a time-based URL Filtering rule for Webmail that targets Sales so business hours force re-evaluation under URL Filtering criteria

B.

Create a Cloud App Control rule that targets the Sales group and personal Webmail applications, set its action to CAUTION, and place it above the general allow rule

C.

Place the Sales URL Filtering rule below the global acceptable-use baseline so broader actions are inherited before group-specific evaluation

D.

Create a Bandwidth Control rule for Webmail that applies to Sales, expecting URL Filtering to engage when traffic is constrained

How does a Zscaler administrator troubleshoot a certificate pinned application?

A.

They could look at SSL logs for a failed client handshake.

B.

They could reboot the endpoint device.

C.

They could inspect the ZIA Web Policy.

D.

They could look into the SaaS application analytics tab.

Which step has a default frequency of two hours in the Zscaler client connector process?

A.

Policy update check

B.

PAC File Download

C.

Software update policy check

D.

Refresh on Network Changes

A Gold-class SaaS application performs poorly even though its bandwidth class has a generous minimum and moderate maximum. Usage dashboards show available capacity during incidents, and other applications are not saturating the link.

What is the most defensible next step to prevent recurring degradation?

A.

Prioritize streaming media above the SaaS application to normalize queue behavior and reduce circuit jitter

B.

Reduce TLS inspection for the SaaS application to remove inspection latency without first validating the traffic path

C.

Raise the Gold-class maximum to a higher ceiling to address presumed internal throttling

D.

Use ZDX path metrics to validate last-mile or ISP congestion at the affected site and plan a circuit upgrade or provider change while retaining the current policies

When creating an installer package or using the command-line for installation, which Zscaler Client Connector installer options are used to automatically redirect to your corporate SAML IdP on launch?

A.

--deviceToken and --strictEnforcement

B.

This is automatic when SAML is configured. No options are required.

C.

--cloudName and --userDomain

D.

--policyToken and --userDomain