Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Zscaler Digital Transformation Administrator ZDTA Questions and answers with CertsForce

Viewing page 7 out of 9 pages
Viewing questions 61-70 out of questions
Questions # 61:

An organization wants to reduce implicit trust while preserving user access to both internet and private applications.

Which configuration approach best aligns with a least-privilege design that also reduces the attack surface?

Options:

A.

Apply URL Filtering and Cloud App Control for outbound access, and enforce ZPA application segmentation with inside-out connectivity to restrict private-application reachability


B.

Adopt SD-WAN hairpinning for SaaS access and use VLAN-based controls to partition legacy environments while policies converge


C.

Standardize on shared subnets and rely on internal firewalls to control access, while using broad URL categories to shape outbound traffic


D.

Increase TLS decryption coverage for all destinations and rely on VPN access control lists to constrain private-network discovery during coexistence


Expert Solution
Questions # 62:

What is the purpose of Browser Access in relation to Zscaler Private Access (ZPA)?

Options:

A.

To make applications accessible from any web browser with Zscaler Client Connector deployed on the device.


B.

To make applications accessible using a browser plug-in and additional browser configuration controlled by the organization.


C.

To make applications accessible without user authentication, Zscaler Client Connector, browser plug-ins, or browser configuration.


D.

To make applications accessible from any web browser without requiring Zscaler Client Connector, browser plug-ins, or additional browser configuration.


Expert Solution
Questions # 63:

A Zscaler Client Connector App Profile is configured to apply a Forwarding Profile that forwards all traffic to the Zero Trust Exchange using Z-Tunnel 2.0. If a change is made to the Logout password in the App Profile, how long will it be before the new logout password is in effect?

Options:

A.

Policy updates happen in real time, so the new logout password is in effect as soon as the change is saved.


B.

The new logout password will be in effect after the Activate button is clicked in the Admin portal.


C.

The new logout password will be in effect after the user clicks Update Policy on the client.


D.

Policy updates occur every 60 minutes, so the logout password will be in effect after the next scheduled update.


Expert Solution
Questions # 64:

What ports and protocols are forwarded to the Zero Trust Exchange when Zscaler Client Connector is using Tunnel 2.0?

Options:

A.

TCP ports 80, 443 and 8080 only.


B.

Any HTTP/HTTPS traffic as well as DNS.


C.

All TCP and UDP ports as well as ICMP traffic.


D.

All Web ports as well as FTP and SSH.


Expert Solution
Questions # 65:

What is the name of the feature that allows the platform to apply URL filtering even when a Cloud App control policy explicitly permits a transaction?

Options:

A.

Allow Cascading


B.

Allow and Quarantine


C.

Allow URL Filtering


D.

Allow and Scan


Expert Solution
Questions # 66:

Which of the following is a common use case for adopting Zscaler’s Data Protection?

Options:

A.

Reduce your Internet Attack Surface


B.

Prevent download of Malicious Files


C.

Prevent loss to Internet and Cloud Apps


D.

Securely connect users to Private Applications


Expert Solution
Questions # 67:

A user’s access to a private CRM application fails occasionally during video calls. ZDX shows sharp jitter spikes and rising packet loss on the ISP path, with client-egress latency increasing when calls begin.

What will reduce CRM access variability?

Options:

A.

Expand URL categories for CRM domains to improve classification fidelity under heavy traffic


B.

Steer traffic to a nearer Service Edge and validate path quality with ZDX and Tunnel Insights to minimize latency and jitter


C.

Constrain the user’s identity claims to limit token size and reduce authentication overhead during calls


D.

Move CRM traffic to a Silver bandwidth class so collaboration traffic no longer competes with business data


Expert Solution
Questions # 68:

What mechanism identifies the ZIA Service Edge node that the Zscaler Client Connector should connect to?

Options:

A.

The IP ranges included/excluded in the App Profile


B.

The PAC file used in the Forwarding Profile


C.

The PAC file used in the Application Profile


D.

The Machine Key used in the Application Profile


Expert Solution
Questions # 69:

Layered defense throughout an organization security platform is valuable because of which of the following?

Options:

A.

Layered defense increases costs to attackers to operate.


B.

Layered defense from multiple vendor solutions easily share attacker data.


C.

Layered defense ensures attackers are prevented eventually.


D.

Layered defense with multiple endpoint agents protects from attackers.


Expert Solution
Questions # 70:

What Malware Protection setting can be selected when setting up a Malware Policy?

Options:

A.

Isolate


B.

Bypass


C.

Block


D.

Do Not Decrypt


Expert Solution
Viewing page 7 out of 9 pages
Viewing questions 61-70 out of questions