Summer Certification Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

ZDTA Leak Questions

Page: 11 / 20
Total 273 questions

Zscaler Digital Transformation Administrator Questions and Answers

Question 41

A data center requires connectivity to Zscaler for traffic inspection without an encryption requirement. The site must support a defined bandwidth profile of 2.2 Gbps and has no high-availability requirement.

Which configuration uses the minimum number of tunnels while meeting the throughput requirement?

Options:

A.

Configure three GRE tunnels mapped to the same location and use equal-cost multipath routing to support the aggregate 2.2 Gbps throughput

B.

Configure one IPSec peer with Dead Peer Detection enabled and conservative cipher settings to reduce processing load on the edge device

C.

Configure two GRE tunnels to different Service Edges and apply strict MTU policing to reduce fragmentation

D.

Configure two IPSec peers with static routing to divide traffic while accepting the additional key-exchange processing

Question 42

Zscaler Data Protection supports custom dictionaries. What actions can administrators take with these dictionaries to protect data in motion?

Options:

A.

Define specific keywords, phrases, or patterns relevant to their organization ' s sensitive data policy.

B.

Define specific governance and regulations relevant to their organization ' s sensitive data policy.

C.

Define specific SaaS tenant relevant to their organization ' s sensitive data policy

D.

Define specific file types relevant to their organization ' s sensitive data policy.

Question 43

A branch wants to block unmanaged devices from a private HR web application while allowing managed devices to work. The branch egress IP is configured as a trusted network. A Client Forwarding Policy currently bypasses the HR application for traffic on that trusted network, causing inconsistent enforcement for devices tunneling through the site.

What change should be made to achieve the intended outcome?

Options:

A.

Redefine the HR App Segment to consolidate FQDNs and ports, anticipating that segmentation changes will suppress unmanaged-device access

B.

Tighten the Access Policy posture requirements for the HR application and add a risk-score threshold, despite the existing bypass

C.

Modify the Isolation Policy to insert browser isolation for all HR application sessions from the branch, accepting the overhead and limited interactivity

D.

Adjust the Client Forwarding Policy to stop bypassing the HR application on the trusted network so posture-based access rules can evaluate the sessions

Question 44

Which of the following options will protect against Botnet activity using IPS and Yara type content analysis?

Options:

A.

Command and Control Traffic

B.

Ransomware

C.

Trojans

D.

Adware/Spyware Protection

Page: 11 / 20
Total 273 questions