Month End Sale Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: estly75

An organization has more than one ZIA instance, each on different clouds. The organization is using the same login domain for both and upon login users are given this menu in ZCC asking which cloud they would like to join. What steps could an Administrator take to avoid having this menu appear?

A.

Customize an MSI version of the ZCC file specifying the USERDOMAIN variable.

B.

Customize an MSI version of the ZCC file specifying the CLOUDNAME variable.

C.

Federate the login domain between two different IDP instances.

D.

Create only one SAML integration with the desired ZIA instance.

A contractor in the Field_Eng SAML group attempts to access an internal CAD application through ZPA from a branch designated as a Trusted Network. The Access Policy requires Field_Eng membership AND a device-posture profile confirming full-disk encryption and a CrowdStrike ZTA score above 80. The user passes the ZTA score requirement, but Device Posture reports that disk encryption is disabled.

Which enforcement outcome should be expected for this session?

A.

Quarantine the traffic through ZIA Cloud Sandbox for risk analysis

B.

Deny access to the private application because the device fails the mandatory disk-encryption requirement

C.

Permit restricted access through a more distant App Connector

D.

Bypass Access Policy evaluation because the branch is designated as a Trusted Network

A unified acceptable use policy is being migrated during an acquisition. Finance requires TLS bypass for specific banking portals, however traffic for other users that should be inspected is also bypassed.

What policy should be adjusted to prevent TLS inspection from being bypassed for the other users?

A.

Reorder policies in the Zscaler Policy Framework so decryption exceptions evaluate before Cloud App Control decisions, and apply Bandwidth Control after access decisions.

B.

Increase threat protection engine sensitivity and rely on default precedence to resolve conflicts between decryption, app controls, and QoS rules.

C.

Place Bandwidth Control policies at the top of the stack and expect decryption exceptions and SaaS restrictions to evaluate subsequently.

D.

Enable global SSL inspection and create a group and category-based bypass policy above the global inspection rule.

A security team must apply least-privilege access for hybrid users who work remotely and on-site while preventing sensitive data from residing on unmanaged BYOD endpoints.

Which Zscaler Client Connector-related deployment decision best satisfies the constraints and mitigates the data-exposure risk?

A.

Enable Trusted Network conditions so unmanaged laptops on home Wi-Fi receive reduced scrutiny during application sessions

B.

Assign posture checks requiring disk encryption and antivirus through Client Connector on personal laptops

C.

Rely on protocol-aware URL rules and bandwidth shaping to limit risky transfers from roaming users

D.

Prefer agentless controls by enforcing Browser Isolation for SaaS access and allowing elevated sessions only from managed devices with Client Connector

A finance user downloads a password-protected spreadsheet from a sanctioned SaaS platform. Cloud Sandbox indicates that detonation is delayed because the file is encrypted.

Which action should the administrator take next?

A.

Configure a File Type Control policy to block unscannable files

B.

Reduce DLP thresholds for the finance department so benign matches are treated as policy violations

C.

Block tenant-wide access to third-party integrations and suspend the finance user’s uploads until further notice

D.

Move inspection exclusively to API-based scanning and disable inline controls to avoid workflow interruptions

A data center requires connectivity to Zscaler for traffic inspection without an encryption requirement. The site must support a defined bandwidth profile of 2.2 Gbps and has no high-availability requirement.

Which configuration uses the minimum number of tunnels while meeting the throughput requirement?

A.

Configure three GRE tunnels mapped to the same location and use equal-cost multipath routing to support the aggregate 2.2 Gbps throughput

B.

Configure one IPSec peer with Dead Peer Detection enabled and conservative cipher settings to reduce processing load on the edge device

C.

Configure two GRE tunnels to different Service Edges and apply strict MTU policing to reduce fragmentation

D.

Configure two IPSec peers with static routing to divide traffic while accepting the additional key-exchange processing

A global URL Filtering rule blocks Newly Registered Domains and Anonymizers. Marketing has a rule that allows Social Media with a Caution action, and specific group-based rules appear above broader global rules. A user who belongs to both Marketing and Contractors attempts to access a social-media subdomain that is newly registered and classified under both Social Media and Newly Registered Domains.

What enforcement outcome is most consistent with the rule hierarchy and category matching?

A.

Continuous evaluation defers the decision until the domain’s reputation stabilizes, causing temporarily degraded access instead of a definitive allow or block

B.

The global block preempts departmental allows regardless of rule order, resulting in denial because high-risk categories are automatically prioritized

C.

Cloud App Control is evaluated first and blocks the request at the application level, making URL Filtering irrelevant to the transaction

D.

The Marketing-specific rule matches first because of its higher position and category criteria, applies the Caution action, and prevents the later global block from being evaluated

What is one of the four steps of a cyber attack?

A.

Find Cash Safe

B.

Find Email Addresses

C.

Find Least Secure Office Building

D.

Find Attack Surface

Zscaler Data Protection supports custom dictionaries. What actions can administrators take with these dictionaries to protect data in motion?

A.

Define specific keywords, phrases, or patterns relevant to their organization ' s sensitive data policy.

B.

Define specific governance and regulations relevant to their organization ' s sensitive data policy.

C.

Define specific SaaS tenant relevant to their organization ' s sensitive data policy

D.

Define specific file types relevant to their organization ' s sensitive data policy.

What is the default timer in ZDX Advanced for web probes to be sent?

A.

1 minute

B.

10 minutes

C.

30 minutes

D.

5 minutes