An administrator needs to refine a custom URL category so that low-risk sites in that category are allowed while high-risk or uncertain sites are isolated or blocked, without weakening overall protection.
Which configuration approach aligns with this goal?
A user assigned to the Contractors group reaches an internal web app despite a rule to prevent contractor access.
Taking into consideration evaluation order and rule logic, which explanation best accounts for the access outcome?
What is the recommended default rule for the cloud-gen firewall configuration when deploying a new ZIA tenant?
An administrator is provisioning new App Connectors in Microsoft Azure. A new egress policy enforces TLS inspection for outbound traffic from the workload subnets.
Which action should the ZPA administrator take to prevent App Connector registration failures?