Summer Certification Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Passed Exam Today ZDTA

Page: 15 / 20
Total 273 questions

Zscaler Digital Transformation Administrator Questions and Answers

Question 57

A mixed policy set contains an Allow for high-value assets with posture, followed by a Block for high-value assets, then role-specific Allow rules for contractors and employees. Multiple users report unexpected reach to internal apps from unmanaged devices.

Considering rule order, attribute evaluation, and logical operators in ZPA Access Policies, which change best narrows access while minimizing unintended matches?

Options:

A.

Move the Block for high-value assets ahead of the posture-gated Allow to force stricter denial before any role-specific permissions are evaluated

B.

Convert client type and application segment fields to AND logic within the Allow rules so fewer sessions qualify during initial matching

C.

Add a trusted network condition to the employee Allow rule so sessions originating from external locations match a later Block action

D.

Place the posture-gated Allow for sensitive apps above role-specific Allows and apply AND logic to SAML/SCIM attributes and posture in those role rules

Question 58

A user authenticates through an IdP. The SAML assertion and SCIM provisioning return different group memberships.

Which placement and policy-evaluation outcome ensures the most consistently up-to-date results?

Options:

A.

Place the user into SCIM-synchronized groups that drive ZIA and ZPA service entitlements, evaluated with SAML and SCIM attributes in the Policy Framework.

B.

Place the user into the IdP Entity ID-specific realm, evaluated against ZPA policies that derive access primarily from the department attribute.

C.

Place the user in a local ZIdentity group inferred from NameID, evaluated against ZIA policies that prioritize session MFA status over SCIM groups.

D.

Place the user into a transient session group based on MFA, evaluated against ZIA Firewall rules that map Entity ID to service entitlements.

Question 59

How deeply can the Zscaler service scan recursively compressed files for malicious content?

Options:

A.

It scans only uncompressed files.

B.

Up to three layers of recursive compression.

C.

Up to two layers of recursive compression.

D.

Up to five layers of recursive compression.

Question 60

Which of the following components is installed on an endpoint to connect users to the Zero Trust Exchange regardless of their location - home, work, while traveling, etc.?

Options:

A.

Client connector

B.

Private Service Edge

C.

IPSec/GRE Tunnel

D.

App Connector

Page: 15 / 20
Total 273 questions