option
Cuestiones
ayuda
daypo
buscar.php

ZDTA

COMENTARIOS ESTADÍSTICAS RÉCORDS
REALIZAR TEST
Título del Test:
ZDTA

Descripción:
zdta zdta

Fecha de Creación: 2026/09/28

Categoría: Otros

Número Preguntas: 60

Valoración:(0)
COMPARTE EL TEST
Nuevo ComentarioNuevo Comentario
Comentarios
NO HAY REGISTROS
Temario:

Within ZPA, the mapping relationship between Connector Groups and Server Groups can best be defined as which of the following?. Server Groups are configured for Dynamic Server Discovery so that mapped Connector Groups can then DNS resolve individual application Segment Groups. Connector Groups are configured for Dynamic Server Discovery so that mapped Server Groups can DNS resolve and advertise the applications. Connector Groups are configured for Dynamic Server Discovery so that ZPA can steer traffic through the appropriate Server Group. Server Groups are configured for Dynamic Server Discovery so that mapped Connector Groups can DNS resolve and make health checks toward the application.

A user has opened a support case to complain about poor user experience when trying to manage their AWS resources. How could a helpdesk administrator get a useful root cause analysis to help isolate the issue in the least amount of time?. Check the Zscaler Trust page for any indications of cloud outages or incidents that would be causing a slowdown. Check the user's ZDX score for a period of low score for AWS and use Analyze Score to get the ZDX Y-Engine analysis. Do a Deep Trace on the user's traffic and check for excessive DNS resolution times and other slowdowns. Initiate a packet capture from Zscaler Client Connector and escalate the case to have the trace analyzed for root cause.

How do Access Policies relate to the Application Segments and Application Segment Groups?. When a condition is met, an Access Policy can either allow or block access to Application Segments OR Application Segment Groups. When a condition is met, an Access Policy can allow access to Application Segments Groups and block access to Application Segment. When a condition is met, an Access Policy can either allow or block access to Application Segments and Application Segment Groups. When a condition is met, an Access Policy can allow access to Application Segments and block access to Application Segment Groups.

As technology that exists for a very long period of time, has URL Filtering lost its effectiveness?. URL Filter is the most commonly used web filtering technique in the arsenal. It acts as first line of defense. In a modern cloud world, access to all Internet sites and cloud applications should be granted by default. URL Filtering is no longer needed. URL Filtering has been replaced by CASB functionality through blocking access to all Internet sites and only allowing a few corporate applications. URL Filtering is outdated and no longer needed. The rise of HTTPS leads renders URL Filtering ineffective as all traffic is encrypted.

You need to SSL inspect all traffic but one specific URL category. You decide to create two policies, one to inspect all traffic and another one to bypass the specific category. What is the logical sequence in which they have to appear in the list?. Both policies are incompatible, so it is not possible to have them together. First the policy for the generic "inspect all", then further down the list the policy for the exception Category. First the policy for the exception Category, then further down the list the policy for the generic "inspect all.". All policies both generic and specific will be evaluated so no specific order is required.

How is the relationship between App Connector Groups and Server Groups created?. The relationship between App Connector Groups and Server Groups is established dynamically in the Zero Trust Exchange as users try to access Applications. When a new Server Group is created it points to the App Connector Groups that provide visibility to this Server Group. Both App Connector Groups and Server Groups are linked together via the Data Center element. When you create a new App Connector Group you must select the list of Server Groups to which it provides visibility.

How would an administrator retrieve the access token to use the Zscaler One API?. The administrator needs to send a POST request along with the required parameters to ZIdentity's token endpoint. The administrator needs to send a GET request along with the required parameters to ZIdentity's token endpoint. The administrator needs to logon to the ZIA portal to generate the access token with Super Admin role. The administrator needs to logon to the ZIA portal to generate the access token with API Admin role.

What transport mechanism will Zscaler Client Connector use to forward traffic to the Zero Trust Exchange when configured for Tunnel 2.0?. Zscaler Client Connector will encapsulate the user's traffic in GRE tunnels to the ZTE. Zscaler Client Connector will encapsulate the user's traffic in IPSec tunnels to the ZTE. Zscaler Client Connector will encapsulate the user's traffic in dTLS/TLS tunnels to the ZTE. Zscaler Client Connector will encapsulate the user's traffic in HTTP Connect tunnels to the ZTE.

Zscaler Data Protection supports custom dictionaries. What actions can administrators take with these dictionaries to protect data in motion?. Define specific keywords, phrases, or patterns relevant to their organization's sensitive data policy. Define specific governance and regulations relevant to their organization's sensitive data policy. Define specific SaaS tenant relevant to their organization's sensitive data policy. Define specific file types relevant to their organization's sensitive data policy.

What enables zero trust to be properly implemented and enforced between an originator and the destination application?. Trusted network criteria designate the locations of originators which can be trusted. Access is granted without sharing the network between the originator and the destination application. Cloud firewall policies ensure that only authenticated users are allowed access to destination applications. Connectivity between the originator and the destination application is over IPSec tunnels.

If you're migrating from an on-premises proxy, you will already have a proxy setting configured within the browser or within the system. With Tunnel Mode, the best practice is to configure what type of proxy configuration?. Execute a GPO update to retrieve the proxy settings from AD. Enforce no Proxy Configuration. Use Web Proxy Auto Discovery (WPAD) to auto-configure the proxy. Use an automatic configuration script (forwarding PAC file).

While troubleshooting a user's slow application access, can a ZDX administrator see degradations in Wi-Fi signal strength?. Yes, the Wi-Fi hop latency is shown on a cloud path probe. Yes, but the current Wi-Fi signal strength is only displayed when doing a deep trace. No, ZDX only works on hardwired devices. Yes, a low Wi-Fi signal may be seen in either the results of a Cloud Path Probe or in the device health Wi-Fi signal indicator.

Which types of Botnet Protection are supplied by Advanced Threat Protection?. Connections to known C&C servers, Detection of phishing sites, Access to spam sites. Malicious file downloads, Command traffic (sending / receiving), Data exfiltration. Connections to known C&C servers, Command traffic (sending / receiving), Unknown C&C using AI ML. Vulnerabilities in web server applications, Unknown C&C using AI ML, vulnerable ActiveX controls.

Does the Access Control suite include features that prevent lateral movement?. Yes. The Cloud Firewall will detect network segments and provide conditional access. No. The endpoint firewall will detect network segments and steer access. Yes. Controls for segmentation and conditional access are part of the Access Control Services. No. Access Control Services will only control access to the Internet and cloud applications.

From a user perspective, Zscaler Bandwidth Control performs traffic shaping and buffering on what direction(s) of traffic?. Outbound traffic is shaped. Inbound or localhost traffic is unshaped. Outbound or inbound traffic is shaped. Localhost traffic is unshaped. Inbound traffic is shaped. Outbound or localhost traffic is unshaped. Localhost traffic is shaped. Outbound or Inbound traffic is unshaped.

How does Zscaler Risk360 quantify risk?. A risk score is computed based on the number of remediations needed compared to the industry peer average. A risk score is computed for each of the four stages of breach. The number of risk events is totaled by location and combined. Time to mitigate each identified risk is totaled, averaged, and tracked to show ongoing trends.

What does TLS Inspection for Zscaler Internet Access secure public internet browsing with?. Intermediate certificates are created for each client connection. Logging which clients receive the original webserver certificate. Removing certificates and reconnecting client connection using HTTP. Storing connection streams for future customer review.

You've configured the API connection to automatically download Microsoft Information Protection (MIP) labels into ZIA; where will you use these imported labels to protect sensitive data in motion?. Creating a custom DLP Dictionary. Creating a SaaS Security Posture Control Policy. Creating a File Type Control Policy. Creating a custom DLP Policy.

When filtering user access to certain web destinations what can be a better option, URL or Cloud Application filtering Policies?. Cloud Application policies provide better access control. URL filtering policies provide better access control. Wherever possible URL policies are recommended. Both provide the same filtering capabilities.

Assume that you have four data centers around the globe, each hosting multiple applications for your users. What is the minimum number of App Connectors you should deploy?. Six – one per data center plus two for cold standby. Eight – two per data center. Four – one per data center. Sixteen – to support a full mesh to the other data centers.

When are users granted conditional access to segmented private applications?. After passing criteria checks related to authorization and security. Immediately upon connection request for best performance. After a short delay of a random number of seconds. After verifying the user password inside of private application.

What mechanism identifies the ZIA Service Edge node that the Zscaler Client Connector should connect to?. The PAC file used in the Forwarding Profile. The PAC file used in the Application Profile. The IP ranges included/excluded in the App Profile. The Machine Key used in the Application Profile.

Zscaler forwards the server SSL/TLS certificate directly to the user's browser session in which situation?. When traffic contains a known threat signature. When web traffic is on custom TCP ports. When traffic is exempted in SSL Inspection policy rules. When user has connected to server in the past.

What conditions can be referenced for Trusted Network Detection?. Hostname Resolution, Network Adapter IP, Default Gateway. DNS Servers, DNS Search Domain, Network Adapter IP. Hostname Resolution, DNS Servers, Geo Location. DNS Search Domain, DNS Server, Hostname Resolution.

What can Zscaler Client Connector evaluate that provides the most thorough determination of the trust level of a device as criteria for an access policy enabling remote access to sensitive private applications?. Client Type. SCIM User Attributes. Trusted Network. Posture Profiles.

Which of the following statements most accurately describes Zero Trust Connections?. They require that SSH inspection be enabled. They are dependent on a fixed / static network environment. They are independent of any network for control or trust. They require IPV6.

Which of the following are types of device posture?. Certificate Trust, File Path, Full Disk Encryption. Unauthorized Modification, OS Version, License Key. Domain Joined, Process Check, Deception Check. Detect CrowdStrike, CrowdStrike ZTA score, First name.

Which of the following is a common use case for adopting Zscaler's Data Protection?. Prevent download of Malicious Files. Prevent loss to Internet and Cloud Apps. Securely connect users to Private Applications. Reduce your Internet Attack Surface.

Which of the following methods can be used to notify an end-user of a potential DLP violation in Zscaler’s Workflow Automation solution?. Notifications in MS Teams / Slack. SMS text message. Automated phone call. Twitter post with custom hashtag.

What are common delivery mechanisms for malware?. Malware downloads from web pages. Personal emails, company documents, OneDrive. Spam, exploit kits, USB drives, video streaming. Phishing, Exploit Kits, Watering Holes, Pre-existing Compromise.

Which of the following is a valid action for a SaaS Security API Data Loss Prevention Rule?. Enable AI/ML based Smart Browser Isolation. Quarantine Malware. Create Zero Trust Network Decoy. Remove External Collaborators and Sharable Link.

Which of the following is a feature of ITDR (Identity Threat Detection and Response)?. Prevents Patient Zero Infections. Reduces identity related risks. Prevents connections to Embargoed Countries. Blocks malicious traffic by dropping packets.

Which of the following is a unified management console for internet and SaaS applications, private applications, digital experience monitoring and endpoint agents?. ZIdentity Admin Portal. Mobile Admin Portal. Experience Center. One API.

In support of data privacy about TLS/SSL inspection, when you subscribe to ZIA, you enter into what kind of agreement?. Zscaler Compliance Policy. Zscaler Privacy Policy. Acceptable Use Policy. Zscaler Data Processing Agreement.

Fundamental capabilities needed by other services within the Zscaler Zero Trust Exchange are provided by which of these?. Access Control Services. Platform Services. Digital Experience Monitoring. Cyber Security Services.

The Security Alerts section of the Alerts dashboard has a graph showing what information?. Top 5 Malware Programs Detected. Top 5 Viruses by Region. Top 5 Threats by Systems Impacted. Top 5 Unified Threat Yara Options.

What are the two types of Alert Rules that can be defined?. ThreatLabZ pre-defined and customer defined. Snort defined and 3rd party defined. ThreatLabZ pre-defined and 3rd party defined. Customer defined and 3rd party defined.

Which Risk360 key focus area observes a broad range of event, security configurations, and traffic flow attributes?. External Attack Surface. Prevent Compromise. Data Loss. Lateral Propagation.

Which of the following options will protect against Botnet activity using IPS and Yara type content analysis?. Command and Control Traffic. Ransomware. Trojans. Adware/Spyware Protection.

Zscaler Platform Services works upon unencrypted data from encrypted communications due to which of the following?. Antivirus. Tenant Restrictions. Web Filtering. TLS Inspection.

Which of the following is an open standard used to provide automatic updates of a user's group and department information?. Import. LDAP Sync. SCIM. SAML.

Which Advanced Threat Protection feature restricts website access by geographic location?. Spyware Callback. Botnet Protection. Blocked Countries. Browser Exploits.

SSH use or tunneling was detected and blocked by which feature?. Cloud App Control. URL Filtering. Advanced Threat Protection. Mobile Malware Protection.

The security exceptions allow list for Advanced Threat Protection apply to which of the following Policies?. Sandbox. URL Filtering. File Type Control. IPS Control.

Which SaaS platform is supported by Zscaler's SaaS Security Posture Management (SSPM)?. Amazon S3. Webex Teams. Dropbox. Google Workspace.

What is the default policy configuration setting for checking for Viruses?. Allow. Block. Unwanted Applications. Malware Protection.

Which of the following is the preferred method for authentication in a OneAPI environment?. OIDC. SCIM. SAML. EntraID.

Which filtering policy blocked access to the Network Application?. Sandbox. Browser Control. Firewall Filtering. DLP.

What is the default timer in ZDX Advanced for web probes to be sent?. 1 minute. 30 minutes. 10 minutes. 5 minutes.

What is the scale used to represent a users Zscaler Digital Experience (ZDX) score?. 1 – 100. 1 – 10. 1 – 1000. 0 – 50.

When configuring an inline Data Loss Prevention policy with content inspection, which of the following are used to detect data, allow or block transactions, and notify your organization's auditor when a user's transaction triggers a DLP rule?. Hosted PAC Files. Index Tool. DLP engines. VPN Credentials.

Can Notifications, based on Alert Rules, be sent with methods other than email?. Email is the only method for notifications as that is universally applicable and no other way of sending them makes sense. In addition to email, text messages can be sent directly to one cell phone to alert the CISO who is then coordinating the work on the incident. Leading ITSM systems can be connected to the Zero Trust Exchange using a NSS server, which will then connect to ITSM tools and forwards the alert. In addition to email, notifications, based on Alert Rules, can be shared with leading ITSM or UCAAS tools over Webhooks.

Which of the following is a key feature of Zscaler Data Protection?. Data loss prevention. Stopping reconnaissance attacks. DDoS protection. Log analysis.

Cross-Site Scripting (XSS) attacks are a type of injection, in which malicious scripts are injected into otherwise benign and trusted websites. XSS includes which of the following?. Spyware Callback. Anonymizers. Cookie Stealing. IRC Tunneling.

What is the main purpose of Sandbox functionality?. Block malware that we have previously identified. Build a test environment where we can evaluate the result of policies. Identify Zero-Day Threats. Balance thread detection across customers around the world.

Which of the following are correct request methods when configuring a URL filtering rule with a Caution action?. Connect, Get, Head. Options, Delete, Put. Get, Delete, Trace. Connect, Post, Put.

Does the Cloud Firewall detect evasion techniques that would allow applications to communicate over non-standard ports to bypass its controls?. The Cloud Firewall includes an IPS engine, which will detect the evasion techniques and will just block the transactions as it is invalid. Zscaler Client Connector will prevent evasion on the endpoint in conjunction with the endpoint operating system's firewall. As traffic usually is forwarded from an on-premise firewall, this firewall will handle any evasion and will make sure that the protocols are corrected. The Cloud Firewall includes Deep Packed Inspection, which detects protocol evasions and sends the traffic to the respective engines for inspection and handling.

What is Zscaler's rotation policy for intermediate certificate authority certificates?. Certificates are rotated every 90 days and have a 180-day expiration. Lifetime certificates have no expiration date. Certificates are rotated every seven days and have a 14-day expiration. Certificates are issued dynamically and expire in 24 hours.

Malware Protection inside HTTPS connections is performed using which parts of the Zero Trust Exchange?. Deception creating decoy files for malware to discover. Application Segmentation of users to specific private applications. TLS Inspection decrypting traffic to compare signatures for known risks. Data Loss Protection comparing saved filenames for known risks.

What are the two types of Probe supported in ZDX?. Web Probes and Cloud Path Probes. Application Probes and Network Probes. Page Speed Probes and Connection Speed Probes. Saas Probes and Router Probes.

Denunciar Test