What is the default policy configuration setting for checking for Viruses?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerB
ExplanationOut of the box, Zscaler's Malware Protection policy is configured to block any traffic identified as a virus, ensuring known malicious files are denied immediately.
Which Platform Service enables visibility into the headers and payload of encrypted transactions?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerB
ExplanationThe TLS Decryption platform service intercepts and decrypts SSL/TLS sessions, granting Zscaler access to both headers and payloads of encrypted traffic for inspection and policy enforcement.
Within ZPA, the mapping relationship between Connector Groups and Server Groups can best be defined as which of the following?
-
A
Server Groups are configured for Dynamic Server Discovery so that mapped Connector Groups can then DNS resolve individual application Segment Groups.
-
B
Connector Groups are configured for Dynamic Server Discovery so that mapped Server Groups can DNS resolve and advertise the applications.
-
C
Connector Groups are configured for Dynamic Server Discovery so that ZPA can steer traffic through the appropriate Server Group.
-
D
Server Groups are configured for Dynamic Server Discovery so that mapped Connector Groups can DNS resolve and make health checks toward the application.
Reveal answer details
Close answer details
Correct answerD
ExplanationServer Groups in ZPA use Dynamic Server Discovery to supply Connector Groups with the application endpoints' DNS names or IPs. The Connector Groups then resolve those addresses and perform health checks to ensure the applications are reachable before steering user traffic.
When configuring Applications to be monitored, what probe types can be created?
-
A
Page Fetch Time Probe and Cloud Path Probe
-
B
Web Probe and Page Fetch Time Probe
-
C
Page Fetch Time Probe and Server Response time Probe
-
D
Web Probe and Cloud Path Probe
Reveal answer details
Close answer details
Correct answerD
ExplanationWhen you set up application monitoring in ZDX, you can create Web Probes to measure application performance from the browser and Cloud Path Probes to map and monitor the network path to those applications.
While troubleshooting a user's slow application access, can a ZDX administrator see degradations in Wi-Fi signal strength?
-
A
Yes, the Wi-Fi hop latency is shown on a cloud path probe.
-
B
Yes. but the current Wi-Fi signal strength is only displayed when doing a deep trace.
-
C
No, ZDX only works on hardwired devices.
-
D
Yes, a low Wi-Fi signal may be seen in either the results of a Cloud Path Probe or in the device health Wi-Fi signal indicator.
Reveal answer details
Close answer details
Correct answerD
ExplanationZDX collects Wi#Fi signal strength as part of its Endpoint Monitoring metrics and also displays it in Cloud Path Probe results, so you can spot low signal quality either in the device health Wi#Fi indicator or when examining the Cloud Path visualization.
Which of the following is a key feature of Zscaler Data Protection?
-
A
-
B
Stopping reconnaissance attacks
-
C
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationData Protection provides comprehensive Data Loss Prevention (DLP) capabilities, inspecting content in motion to identify, block, or encrypt sensitive information based on policy.
What is the maximum default frequency of device posture profile evaluation by Zscaler Client Connector?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationZscaler Client Connector evaluates device posture profiles by default every five minutes, ensuring rapid detection of posture changes that may affect access or policy enforcement.
An administrator wants to allow users to access a wide variety of untrusted URLs. Which of the following would allow users to access these URLs in a safe manner?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationBrowser Isolation enables secure access to potentially malicious or untrusted websites by rendering web pages in a remote containerized environment. This isolates any harmful content away from the user's device, ensuring safe browsing without compromising endpoint security. This approach is especially effective for unknown or risky URLs where traditional content filtering might be insufficient. References: Zscaler Digital Transformation Study Guide - Zscaler Cloud Security Services > Browser Isolation
If you're migrating from an on-premises proxy, you will already have a proxy setting configured within the browser or within the system. With Tunnel Mode, the best practice is to configure what type of proxy configuration?
-
A
Execute a GPO update to retrieve the proxy settings from AD.
-
B
Enforce no Proxy Configuration.
-
C
Use Web Proxy Auto Discovery (WPAD) to auto-configure the proxy.
-
D
Use an automatic configuration script (forwarding PAC file).
Reveal answer details
Close answer details
Question 10
Single choice
Which Advanced Threat Protection feature restricts website access by geographic location?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationThe "Blocked Countries" feature in Advanced Threat Protection lets you restrict access to web destinations based on their geographic location, preventing connections to any sites hosted in the specified countries.
Question 11
Single choice
How does ZDX computes the score for an application?
-
A
Zscaler takes all the users that accessed the application for the selected time period and finds the lowest value each user would have experienced for the application. The lowest values for each user are added together and divided by the number of users.
-
B
Zscaler considers a single user that accessed the application for the selected time period and finds the lowest value that user would have experienced for the application. The lowest values for that user are added together and divided by the number of all users in the organization.
-
C
Zscaler takes sample set of users that accessed the application for the selected time period and finds the lowest value each user would have experienced for the application. The lowest values for each user are added together and divided by the number of sample set of users.
-
D
Zscaler takes the lowest value for each application for a set of users, for time intervals based on the selected time range. The application with the lowest value represents your applications score for that time interval.
Reveal answer details
Close answer details
Correct answerA
ExplanationZDX calculates an application score by identifying the lowest experience value each user encountered for that application in the selected time range and then averaging those lowest values across all users who accessed the application.
Question 12
Single choice
What is one business risk introduced by the use of legacy firewalls?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationA primary business risk introduced by legacy firewalls is performance issues. Traditional firewalls are often unable to efficiently handle modern high-volume and encrypted traffic, leading to latency, bottlenecks, and reduced network performance. This negatively impacts user experience and security posture. The study guide points out that legacy firewalls struggle with scalability and speed in today's cloud-centric environment, making performance a key concern.
Question 13
Single choice
What is the primary function of the on-premises VM in the EDM process?
-
A
To local analyze cloud transactions for potential PII exfiltration.
-
B
To replicate sensitive data across all organizational servers.
-
C
To automate the indexing process by creating hashes for structured data elements.
-
D
To store sensitive data securely and prevent unauthorized data access.
Reveal answer details
Close answer details
Correct answerA
ExplanationThe on-premises VM in the Enterprise Data Management (EDM) process primarily locally analyzes cloud transactions for potential Personally Identifiable Information (PII) exfiltration. This allows organizations to detect and prevent sensitive data leaving their environment by inspecting cloud interactions close to their premises. The study guide highlights that the VM acts as a local control point in the EDM workflow, ensuring sensitive data protection during cloud transactions.
Question 14
Single choice
What is the purpose of the Zscaler Client Connector providing the authentication token to the Zscaler Client Connector Portal after it is received from Zscaler Internet Access?
-
A
To bypass multifactor authentication (MFA) during the enrollment process
-
B
To immediately grant the user access to Zscaler Private Access resources
-
C
To enable the portal to register the user's device and pass the registration to Zscaler Internet Access
-
D
To share the authentication token with the SAML IdP to validate the user session
Reveal answer details
Close answer details
Correct answerC
ExplanationThe Zscaler Client Connector provides the authentication token to the Zscaler Client Connector Portal to enable the portal to register the user's device and pass the registration to Zscaler Internet Access. This registration process is crucial for device posture assessment and policy enforcement, ensuring that only registered and compliant devices receive appropriate access.
Question 15
Single choice
Security analysts need to review logs but must not change policies. How should their access be configured?
-
A
Assign a policy administrator role and ask them not to edit
-
B
Give them a shared unrestricted account
-
C
Assign a read-only role for the required logging scope
-
D
Add them to every synchronized administrative group
Reveal answer details
Close answer details
Correct answerC
ExplanationA read-only logging role supports the analysts' function while preventing configuration changes. Procedural warnings do not provide the same enforcement as scoped authorization.
Question 16
Single choice
Zscaler Platform Services works upon unencrypted data from encrypted communications due to which of the following?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerD
ExplanationZscaler Platform Services, such as web filtering, advanced threat protection, DLP, and more, operate on decrypted traffic. This decryption is enabled by TLS Inspection, which intercepts SSL/TLS sessions, decrypts the payloads for inspection, and then re#encrypts the traffic before forwarding to the destination.
Question 17
Single choice
An organization uses directory groups to assign administrative roles. Which design gives the clearest control over privileged membership?
-
A
Map every general employee group to an administrative role
-
B
Use dedicated administrative groups with documented role mappings and approval ownership
-
C
Let administrators add themselves to privileged groups
-
D
Assign all roles directly to a single shared account
Reveal answer details
Close answer details
Correct answerB
ExplanationDedicated groups make privileged membership and role mappings explicit and reviewable. Broad groups, self-assignment, and shared accounts undermine least privilege and accountability.
Question 18
Single choice
What is the ZIA feature that ensures certain SaaS applications cannot be accessed from an unmanaged device?
-
A
-
B
-
C
Out-of-band Application Access
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationTenant Restriction is the ZIA feature that enforces access control policies to prevent access to certain SaaS applications from unmanaged or non-compliant devices. This ensures that only authorized and managed devices can access sensitive corporate SaaS resources, enhancing security posture. The study guide highlights Tenant Restriction as an essential control for enforcing device compliance in SaaS access policies.
Question 19
Single choice
When configuring Webhook alerts in ZIA, what are the two Webhook authentications types supported?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationWhen you configure Webhook alerts in Zscaler Internet Access, the only two authentication methods you can choose are Basic (username/password) and Token (API token). References: https://help.zscaler.com/zia/adding-webhook
Question 20
Single choice
Which of the following is a valid action for a SaaS Security API Data Loss Prevention Rule?
-
A
Enable AI/ML based Smart Browser Isolation
-
B
-
C
Create Zero Trust Network Decoy
-
D
Remove External Collaborators and Sharable Link
Reveal answer details
Close answer details
Correct answerD
ExplanationIn SaaS Security API DLP policies you can choose "Remove External Collaborators and Shareable Link" as the enforcement action - Zscaler will report the incident, revoke any external collaborators on the file, and delete its external share links.
Question 21
Single choice
Zscaler Data Protection supports custom dictionaries. What actions can administrators take with these dictionaries to protect data in motion?
-
A
Define specific keywords, phrases, or patterns relevant to their organization's sensitive data policy.
-
B
Define specific governance and regulations relevant to their organization's sensitive data policy.
-
C
Define specific SaaS tenant relevant to their organization's sensitive data policy
-
D
Define specific file types relevant to their organization's sensitive data policy.
Reveal answer details
Close answer details
Correct answerA
ExplanationAdministrators can build custom dictionaries by defining the exact keywords, phrases, or regex patterns that reflect their organization's sensitive data. Zscaler then uses these dictionaries in its data#in#motion policies to accurately identify and block or protect matching content.
Question 22
Single choice
Operations staff manage several Zscaler services and sometimes open the wrong console during incidents. Which practice most improves reliable navigation?
-
A
Give every operator the highest administrative role
-
B
Use one local user account for all operators
-
C
Maintain service-specific runbooks that identify the owning console and tenant
-
D
Disable sign-on policies during incident response
Reveal answer details
Close answer details
Correct answerC
ExplanationA service-specific runbook provides a repeatable path to the correct administrative context. Excess privileges and shared accounts weaken control without resolving navigation errors.
Question 23
Single choice
Zscaler utilized a Zero Trust Network Architecture (ZTNA) for segmentation in an environment. Which of the following prevents lateral movement within an organization?
-
A
Connect users to applications using Identity, device posture, and access policies
-
B
Move all applications into the DMZ
-
C
Turn on all host based firewalls
-
D
Allow access to all resources on the network via VPN
Reveal answer details
Close answer details
Correct answerA
ExplanationZero Trust segmentation is achieved by connecting users directly to specific applications based on identity, device posture, and granular access policies. This removes network-level access and prevents lateral movement because users never gain access to the broader network - only to the individual applications they are authorized to use.
Question 24
Single choice
Zscaler Client Connector checks for software updates automatically at which interval?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationZscaler Client Connector automatically checks for software updates every 2 hours by default.
Question 25
Single choice
What does the user risk score enable a user to do?
-
A
Compare the user risk score with other companies to evaluate users vs other companies.
-
B
Determine whether or not a user is authorized to view unencrypted data.
-
C
Configure stronger user-specific policies to monitor & control user-level risk exposure.
-
D
Determine if a user has been compromised
Reveal answer details
Close answer details
Correct answerC
ExplanationThe user risk score enables organizations to configure stronger user-specific policies to monitor and control user-level risk exposure. This score reflects a user's risk posture based on behaviors and detected anomalies and helps in tailoring security policies to address individual risk levels. While the score gives insight into user risk, it is primarily designed for adaptive policy enforcement rather than direct compromise detection or cross-company comparison. The study guide highlights that user risk scores drive policy adjustments to better secure user activity.
Question 26
Single choice
What are the two types of Alert Rules that can be defined?
-
A
ThreatLabZ pre-defined and customer defined
-
B
Snort defined and 3rd party defined
-
C
ThreatLabZ pre-defined and 3rd party defined
-
D
Customer defined and 3rd party defined
Reveal answer details
Close answer details
Correct answerA
ExplanationZscaler ships a set of Alert Rules curated and maintained by its ThreatLabZ research team, and administrators can also build their own custom (customer#defined) rules to meet specific organizational needs.
Question 27
Single choice
For a deployment using both ZIA and ZPA set of services, what is the best authentication solution?
-
A
Use forms Authentication in ZPA and SAML in ZIA
-
B
Use forms Authentication in ZIA and SAML in ZPA
-
C
Configure Authentication using SAML on both ZIA and ZPA
-
D
Use forms Authentication for both ZIA and ZPA
Reveal answer details
Close answer details
Correct answerC
ExplanationFor a unified, seamless experience - and because ZPA only supports SAML while ZIA's recommended authentication is also SAML - you should configure SAML#based SSO on both ZIA and ZPA. This ensures one consistent identity flow and eliminates multiple credential prompts across the platforms.
Question 28
Single choice
An administrator receives permissions through a synchronized directory group. The administrator leaves that group in the source directory. What outcome should the access design produce?
-
A
The permissions remain permanently assigned in Zscaler
-
B
The administrator receives a broader local role
-
C
The source directory creates a replacement account
-
D
The group removal is synchronized and the associated permissions are withdrawn
Reveal answer details
Close answer details
Correct answerD
ExplanationGroup-based administration should follow the authoritative group lifecycle. Synchronizing removal prevents stale privileges from surviving after the source assignment has ended.
Question 29
Single choice
When users are authenticated using SAML, what are the two most efficient ways of provisioning the users?
-
A
Hosted User Database and Directory Server Synchronization
-
B
SAML and Hosted User Database
-
C
SCIM and Directory Server Synchronization
-
D
SCIM and SAML Autoprovisioning
Reveal answer details
Close answer details
Correct answerD
ExplanationThe two most efficient ways to provision users authenticated via SAML are SCIM (System for Cross-domain Identity Management) and SAML Autoprovisioning. SCIM allows automated user provisioning and deprovisioning, while SAML Autoprovisioning enables dynamic user account creation upon authentication, streamlining user lifecycle management.
Question 30
Single choice
A policy depends on a department attribute, but a newly provisioned user does not receive the expected access. What is the most relevant check?
-
A
Increase the user's administrative role
-
B
Delete unrelated traffic logs
-
C
Change the organization's verified domain
-
D
Verify that the identity source sends the attribute and that it maps to the expected user field
Reveal answer details
Close answer details
Correct answerD
ExplanationAttribute-based policy requires the expected value to be supplied and mapped correctly. Administrative privilege and unrelated domain or logging changes do not repair missing identity data.
Question 31
Single choice
What is the purpose of a Microtunnel (M-Tunnel) in Zscaler?
-
A
To provide an end-to-end communication channel between ZCC clients
-
B
To provide an end-to-end communication channel to Microsoft Applications such as M365
-
C
To create an end-to-end communication channel to Azure AD for authentication
-
D
To create an end-to-end communication channel to internal applications
Reveal answer details
Close answer details
Correct answerD
ExplanationThe Microtunnel (M-Tunnel) in Zscaler is designed to create an end-to-end communication channel to internal applications. This tunnel facilitates secure and direct access from the client device to internal corporate applications without exposing the network or requiring traditional VPN infrastructure. The M-Tunnel is part of ZPA's mechanism to ensure secure, zero-trust access to private resources.
|