Month End Sale Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: estly75

Fundamental capabilities needed by other services within the Zscaler Zero Trust Exchange are provided by which of these?

A.

Access Control Services

B.

Digital Experience Monitoring

C.

Cyber Security Services

D.

Platform Services

Is SCIM mandatory for ZIA?

A.

No

B.

Depends

C.

Yes

D.

Maybe

Which feature does Zscaler Client Connector Z-Tunnel 2.0 enable over Z-Tunnel 1.0?

A.

Enables SSL Inspection for Client Connector

B.

Inspection of all ports and protocols via Cloud Firewall

C.

Enables Browser Isolation

D.

Enables multicast traffic

What is the immediate outcome or effect when the Zscaler Office 365 One Click Rule is enabled?

A.

All traffic undergoes mandatory SSL inspection.

B.

Office 365 traffic is exempted from SSL inspection and other web policies.

C.

Non-Office 365 traffic is blocked.

D.

All Office 365 drive traffic is blocked.

A security lead reviews an executive summary: data-loss risk is driven by high-volume uploads to risky SaaS applications and unmanaged generative AI use; MTTR for BU-West remains high because of ticket-routing delays; and the board wants a 15% reduction in the data-loss risk score within 60 days. Peer benchmarks are similar but show identity risk as the primary driver elsewhere.

Which action should be taken next?

A.

Open UVM remediation for low-severity endpoint findings at scale to create throughput metrics regardless of category alignment

B.

Schedule an updated board narrative and postpone technical changes until the next quarter to avoid conflicting with peer comparisons

C.

Tighten Cloud App Control for risky SaaS and AI usage, and configure MTTR routing by business unit with ITSM integration

D.

Commission an identity-hardening review centered on private-application access patterns to mirror peer drivers even though local data-loss signals persist

Which of the following is the preferred method for authentication in a OneAPI environment?

A.

OIDC

B.

SCIM

C.

SAML

D.

EntraID

An administrator at a branch observes that a private ERP application is accessible when a user is connected to corporate Wi-Fi but intermittently fails when the user moves to a guest SSID at the same location. Zscaler Client Connector frequently transitions between Forwarding and Bypass states when the network changes.

Which action best reduces the instability?

A.

Broaden the application segment to include wildcard subdomains so DNS variations do not cause lookup mismatches

B.

Redesign the Client Connector Forwarding Profile to prioritize stable trusted-network attributes and avoid dependence on volatile SSID-based bypass triggers

C.

Disable posture checks for the ERP application to prevent frequent re-evaluations from affecting access decisions

D.

Backhaul all branch traffic to headquarters so users no longer change Service Edges when moving between SSIDs

A log review shows requests to a sanctioned application being allowed despite a later rule intended to restrict access by time of day.

The rule set is:

    Allow the sanctioned application for All Employees

    Block the sanctioned application outside business hours for All Employees

    Log restricted-access hits

Which cause and risk are most consistent with this behavior?

A.

The time-of-day block inherits timing from device posture, which desynchronizes evaluation and produces inconsistent enforcement

B.

The initial allow rule matches first and stops further evaluation, so the time-of-day block never applies and access remains available after business hours

C.

The logging rule takes precedence because of its action type, preventing the block from being reached

D.

The sanctioned application category becomes invalid during SSL inspection, sending the request to a default allow path that bypasses time restrictions

A manufacturing firm is merging with a subsidiary that uses a separate identity provider. A ZPA Access Policy for an engineering CAD application uses SCIM groups for authorization. A new administrator authenticates successfully through SAML and presents the Engineering claim, but the subsidiary’s SCIM synchronization is delayed, so the administrator does not appear in the expected group in ZIdentity.

Which action should the ZPA administrator take to avoid inconsistent access while preserving auditability?

A.

Reconfigure the policy to use NameID for authorization, accepting reduced traceability of group criteria

B.

Initiate a SCIM resynchronization and validate the user’s group membership in ZIdentity, while keeping the Access Policy bound to SCIM groups

C.

Create a local ZIdentity group with provisional engineering membership, accepting drift from the directory of record

D.

Change identity-provider routing so the engineer authenticates through the parent company’s identity provider, accepting misalignment with the subsidiary’s directory mappings

The Forwarding Profile defines which of the following?

A.

Fallback methods and behavior when a DTLS tunnel cannot be established

B.

Application PAC file location

C.

System PAC file when off trusted network

D.

Fallback methods and behavior when a TLS tunnel cannot be established