Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Zscaler Digital Transformation Administrator ZDTA Questions and answers with CertsForce

Viewing page 6 out of 9 pages
Viewing questions 51-60 out of questions
Questions # 51:

A microsegmentation policy set contains a broad “allow employees to internal applications” rule before more specific controls. An incident review found SMB access from non-finance hosts to a finance file share.

Which refinement best addresses the unintended access while improving the internal security posture?

Options:

A.

Add bandwidth QoS constraints to the internal applications segment so non-finance SMB attempts are deprioritized at runtime


B.

Insert deception assets in the finance segment to divert suspicious SMB traffic away from the file share and collect telemetry


C.

Tighten URL Filtering for internal destinations so SMB-related domains resolve poorly in non-finance contexts


D.

Reorder the rules so the deny for non-finance SMB is evaluated before broad employee allows, and scope the SMB policy to finance hosts and device posture


Expert Solution
Questions # 52:

How can we protect the Zscaler Client Connector from unauthorized alterations to its files and registry settings?

Options:

A.

StrictEnforcement CLI Parameter of ZCC installation file


B.

TamperProofing options in Forwarding Profile


C.

AntiTampering CLI Parameter of ZCC installation file


D.

DisableTampering options in Forwarding Profile


Expert Solution
Questions # 53:

What does Allow Cascading Enabled allow for?

Options:

A.

It ensures both Cloud App Control and URL Filtering Rules are applied.


B.

It ensures both Cloud App Control and File Type Control Rules are applied.


C.

It ensures both Cloud App Control and Bandwidth Control Rules are applied.


D.

It ensures both Cloud App Control and DLP Rules are applied.


Expert Solution
Questions # 54:

A security engineer needs the HR portal and SIP voice traffic to bypass inspection on the downtown campus but be fully inspected when staff roam. The campus DHCP service recently began issuing a public DNS resolver that breaks the existing trusted-network match, and users are intermittently inspected on campus.

Which action should the engineer take to restore consistent campus-only bypass for those applications?

Options:

A.

Enable PAC-file fallback in Client Connector and prioritize DNS-based conditions so HR and SIP are suppressed when the resolver aligns with the campus


B.

Strengthen the Trusted Network criteria by adding default-gateway and egress-IP checks to the campus entry, map the campus to a profile with No Forwarding, and place a top-down bypass for HR and SIP on the trusted network followed by a forwarding rule for the same applications off-trusted


C.

Switch the Forwarding Profile to Enforce Proxy and add PAC logic for campus subnets so HR and SIP requests are sent directly at those ranges


D.

Reduce posture checks on the campus and rely on Application Profiles to remap HR and SIP to Tunnel with Local Proxy for roaming users


Expert Solution
Questions # 55:

Zscaler utilized a Zero Trust Network Architecture (ZTNA) for segmentation in an environment.

Which of the following prevents lateral movement within an organization?

Options:

A.

Connect users to applications using Identity, device posture, and access policies


B.

Move all applications into the DMZ


C.

Turn on all host based firewalls


D.

Allow access to all resources on the network via VPN


Expert Solution
Questions # 56:

From a user perspective, Zscaler Bandwidth Control performs traffic shaping and buffering on what direction(s) of traffic?

Options:

A.

Outbound traffic is shaped. Inbound or localhost traffic is unshaped.


B.

Outbound or inbound traffic is shaped. Localhost traffic is unshaped.


C.

Inbound traffic is shaped. Outbound or localhost traffic is unshaped.


D.

Localhost traffic is shaped. Outbound or Inbound traffic is unshaped.


Expert Solution
Questions # 57:

Malware Protection inside HTTPS connections is performed using which parts of the Zero Trust Exchange?

Options:

A.

Deception creating decoy files for malware to discover.


B.

Application Segmentation of users to specific private applications.


C.

TLS Inspection decrypting traffic to compare signatures for known risks.


D.

Data Loss Protection comparing saved filenames for known risks.


Expert Solution
Questions # 58:

How does a Zscaler administrator troubleshoot a certificate pinned application?

Options:

A.

They could look at SSL logs for a failed client handshake.


B.

They could reboot the endpoint device.


C.

They could inspect the ZIA Web Policy.


D.

They could look into the SaaS application analytics tab.


Expert Solution
Questions # 59:

Zscaler forwards the server SSL/TLS certificate directly to the user ' s browser session in which situation?

Options:

A.

When traffic contains a known threat signature.


B.

When web traffic is on custom TCP ports.


C.

When traffic is exempted in SSL Inspection policy rules.


D.

When user has connected to server in the past.


Expert Solution
Questions # 60:

A new customer has just purchased Zscaler for Users.

Which of the following Zscaler service entitlements is enabled by default?

Options:

A.

ZPA


B.

Deception


C.

ZIA


D.

ZDX


Expert Solution
Viewing page 6 out of 9 pages
Viewing questions 51-60 out of questions