Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Zscaler Digital Transformation Administrator ZDTA Question # 31 Topic 4 Discussion

Zscaler Digital Transformation Administrator ZDTA Question # 31 Topic 4 Discussion

ZDTA Exam Topic 4 Question 31 Discussion:
Question #: 31
Topic #: 4

A mixed policy set contains an Allow for high-value assets with posture, followed by a Block for high-value assets, then role-specific Allow rules for contractors and employees. Multiple users report unexpected reach to internal apps from unmanaged devices.

Considering rule order, attribute evaluation, and logical operators in ZPA Access Policies, which change best narrows access while minimizing unintended matches?


A.

Move the Block for high-value assets ahead of the posture-gated Allow to force stricter denial before any role-specific permissions are evaluated


B.

Convert client type and application segment fields to AND logic within the Allow rules so fewer sessions qualify during initial matching


C.

Add a trusted network condition to the employee Allow rule so sessions originating from external locations match a later Block action


D.

Place the posture-gated Allow for sensitive apps above role-specific Allows and apply AND logic to SAML/SCIM attributes and posture in those role rules


Get Premium ZDTA Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.