Answer A is correct. ZPA uses identity, device posture, application context, and access policy to create a direct connection between an authorized user and a named application. The user is not placed on the private network and is not given routable access to adjacent systems. Zscaler describes this as a “segment of one”: inside-out connectivity and encrypted microtunnels connect the approved user only to the approved application. That design reduces the attack surface and prevents an authenticated or compromised endpoint from discovering and moving to unrelated resources. A DMZ and host firewalls can be useful defense layers, but they do not inherently replace identity-based user-to-application segmentation. A traditional VPN ordinarily extends network-level reach and can increase lateral-movement opportunities. See Zscaler’s Private Access data sheet and zero trust architecture overview.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit