Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Zscaler Digital Transformation Administrator ZDTA Questions and answers with CertsForce

Viewing page 2 out of 9 pages
Viewing questions 11-20 out of questions
Questions # 11:

A SOC subscribes to a third-party blocklist and must ensure that listed destinations are denied while preserving predefined rules required for Microsoft 365 access. ZIA Firewall Filtering rules are evaluated from top to bottom using first-match processing.

How should the blocking rule be positioned?

Options:

A.

Insert a drop rule for the third-party destination group above generic outbound allow rules while keeping the essential Microsoft 365 predefined rules intact


B.

Move the third-party block rule to the bottom so it is evaluated after application identification for standard services


C.

Modify the Microsoft 365 predefined rules to include third-party exclusions, then append a general deny rule for unclassified traffic


D.

Place broad SaaS allow rules at the top and insert the third-party block rule below them to avoid unintended denial of legitimate sessions


Expert Solution
Questions # 12:

A branch office uses a trusted-network bypass that routes traffic directly to the internet. Incident reviews show that unmanaged laptops at the branch are reaching SaaS applications without device-posture evaluation.

Which action should the administrator take next to ensure that devices are compliant before receiving access?

Options:

A.

Amend the trusted-network bypass and enforce posture-based access through Zscaler Client Connector for branch traffic


B.

Expand application segments to redefine which subnets are considered internal for discovery


C.

Add Caution actions to web policies to prompt users about risks on popular collaboration platforms


D.

Lower bandwidth quotas for the branch to discourage access spikes from unmanaged devices


Expert Solution
Questions # 13:

Administrators report that some non-compliant devices can still reach private applications. A broad Allow rule precedes device-posture checks in the policy set.

What is the most appropriate next step to satisfy the compliance-before-access requirement?

Options:

A.

Broaden URL Filtering blocks for high-risk categories to curtail non-business browsing on those devices


B.

Apply stricter user-group scoping to limit access for departments with higher incident rates


C.

Increase time-based restrictions on access windows to reduce exposure during off-hours


D.

Reorder the policy so posture-based access rules are evaluated before any general Allow statements


Expert Solution
Questions # 14:

Which options must be selected when configuring Zscaler Client Connector for Strict Enforcement?

Options:

A.

cloudName and policyToken


B.

userDomain and deviceToken


C.

cloudName and deviceToken


D.

userDomain and policyToken


Expert Solution
Questions # 15:

Within ZPA, the mapping relationship between Connector Groups and Server Groups can best be defined as which of the following?

Options:

A.

Server Groups are configured for Dynamic Server Discovery so that mapped Connector Groups can then DNS resolve individual application Segment Groups.


B.

Connector Groups are configured for Dynamic Server Discovery so that mapped Server Groups can DNS resolve and advertise the applications.


C.

Connector Groups are configured for Dynamic Server Discovery so that ZPA can steer traffic through the appropriate Server Group.


D.

Server Groups are configured for Dynamic Server Discovery so that mapped Connector Groups can DNS resolve and make health checks toward the application.


Expert Solution
Questions # 16:

Which algorithm is used to determine the PageRisk?

Options:

A.

Zscaler licenses a PageRisk Feed from a 3rd party.


B.

It applies deobfuscation to all data.


C.

It is the RSA Security algorithm.


D.

Zscaler applies a multi data algorithm to the web page.


Expert Solution
Questions # 17:

Which of the following is a feature of Vulnerability Management?

Options:

A.

Mitigates, transfers, accepts, or avoids risks.


B.

Focuses on technical weaknesses.


C.

Focuses on nontechnical weaknesses.


D.

Ensures business continuity.


Expert Solution
Questions # 18:

Which field within a URL filtering rule must be defined for Browser Isolation to work?

Options:

A.

Groups


B.

User Agent


C.

Departments


D.

Device Trust


Expert Solution
Questions # 19:

What does TLS Inspection for Zscaler Internet Access secure public internet browsing with?

Options:

A.

Storing connection streams for future customer review.


B.

Removing certificates and reconnecting client connection using HTTP.


C.

Intermediate certificates are created for each client connection.


D.

Logging which clients receive the original webserver certificate.


Expert Solution
Questions # 20:

What is the preferred method for authentication to access OneAPI?

Options:

A.

OpenID Connect (OIDC)


B.

Transport Layer Security (TLS)


C.

Security Assertion Markup Language (SAML)


D.

System for Cross-domain Identity Management (SCIM)


Expert Solution
Viewing page 2 out of 9 pages
Viewing questions 11-20 out of questions