Summer Certification Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Free ZDTA Questions Attempt

Page: 6 / 20
Total 273 questions

Zscaler Digital Transformation Administrator Questions and Answers

Question 21

An administrator needs to refine a custom URL category so that low-risk sites in that category are allowed while high-risk or uncertain sites are isolated or blocked, without weakening overall protection.

Which configuration approach aligns with this goal?

Options:

A.

Defer behavior to Cloud App Control so that URL Filtering is bypassed for known applications that match the category criteria

B.

Consolidate controls under a broad global allow rule and depend on bandwidth shaping to constrain risky traffic within the category

C.

Retain parent-category membership and reference the custom category in a higher-priority rule that applies Allow or Isolate actions as needed

D.

Replace parent-category assignments with a custom list to reduce overlap and simplify rule evaluation

Question 22

A user assigned to the Contractors group reaches an internal web app despite a rule to prevent contractor access.

Taking into consideration evaluation order and rule logic, which explanation best accounts for the access outcome?

Options:

A.

An inspection policy relaxed enforcement through HTTP method handling, leaving the session permitted despite the deny.

B.

A data protection engine recalibrated risk and weakened access control through orchestration overlaps in the stack.

C.

An earlier allow scoped to the application segment matched due to a trusted network condition, and the later catch-all deny did not evaluate.

D.

A client forwarding bypass reduced enforcement fidelity and triggered a secondary pass where the deny was sidelined.

Question 23

What is the recommended default rule for the cloud-gen firewall configuration when deploying a new ZIA tenant?

Options:

A.

Block all traffic

B.

Permit all traffic

C.

Disable the firewall

D.

Allow only web traffic (ports 80/443)

Question 24

An administrator is provisioning new App Connectors in Microsoft Azure. A new egress policy enforces TLS inspection for outbound traffic from the workload subnets.

Which action should the ZPA administrator take to prevent App Connector registration failures?

Options:

A.

Request static NAT gateway pinning for App Connector egress so ZPA anchors microtunnels to fixed public IP addresses across virtual networks

B.

Explain that App Connector egress traffic to ZPA Service Edges must bypass TLS interception

C.

Recommend disabling App Connector health checks during application-mobility windows to prevent premature failover

D.

Advise the cloud team to delay virtual-machine scale-set events until DNS TTLs expire to minimize App Connector group changes

Page: 6 / 20
Total 273 questions