An administrator wants to allow users to access a wide variety of untrusted URLs. Which of the following would allow users to access these URLs in a safe manner?
Which of the following statements accurately reflects Zscaler ' s file size limitation for Malware Protection scans?
What does a DLP Engine consist of?
A company must enforce least-privileged access to private applications when contractors connect from varying locations using devices with inconsistent security posture. The security team wants decisions to use identity and per-session context instead of broad network assumptions.
Which approach best meets the requirement?
A log review shows requests to a sanctioned application being allowed despite a later rule intended to restrict access by time of day.
The rule set is:
Allow the sanctioned application for All Employees
Block the sanctioned application outside business hours for All Employees
Log restricted-access hits
Which cause and risk are most consistent with this behavior?
An administrator needs to SSL inspect all traffic but one specific URL category. The administrator decides to create two policies, one to inspect all traffic and another one to bypass the specific category. What is the logical sequence in which they have to appear in the list?
An investigation at a regional office identifies sensitive files leaving a sanctioned SaaS platform outside business hours. Follow-up analysis shows that several users transferred content through native mobile applications that do not consistently traverse ZIA inline inspection.
Which action should the security lead take next to assess security across the SaaS environment?
Which of the following scenarios would generate a “Patient 0” alert?
How is data gathered with ZDX Advanced client performance?
What does Advanced Threat Protection defend users from?
How should an administrator determine why a website was allowed during web browsing when overlapping policies appeared to require a block, and verify which policy took precedence?
Which of the following is an open standard used to provide automatic updates of a user ' s group and department information? A Import B. LDAP Sync C. SCIM D. SAML
What does Allow Cascading Enabled allow for?
An operations team relies on API-driven exports of ZDX scores and Firewall Insights to track application performance over time. The team encounters periodic HTTP 429 errors during peak hours, and performance regressions are missed when exports fail.
Which mitigation best reduces blind spots that contribute to preventable performance issues?
Is SCIM mandatory for ZIA?
Which Advanced Threat Protection feature restricts website access by geographic location?
A pilot update is underway for Zscaler Client Connector in three regions to reduce known vulnerabilities. In one region, ZDX shows latency spikes and tunnel failures correlated with a specific operating-system build during the pilot.
Which action should the administrator take to proceed toward broader rollout with minimal disruption?
Users connected through one ISP in a single country report a sudden decline in UCaaS call quality. The operations team must determine whether the degradation is ISP-specific or caused by local endpoints.
Which ZDX diagnostic best isolates the provider and geographic area responsible for the issue?
Cross-Site Scripting (XSS) attacks are a type of injection, in which malicious scripts are injected into otherwise benign and trusted websites. XSS includes which of the following?
An organization mandates strict BYOD controls and does not permit endpoint agents on personal devices. Which Zscaler deployment approach aligns with this requirement while maintaining data protection for access to corporate applications?
An administrator needs to refine a custom URL category so that low-risk sites in that category are allowed while high-risk or uncertain sites are isolated or blocked, without weakening overall protection.
Which configuration approach aligns with this goal?
A user assigned to the Contractors group reaches an internal web app despite a rule to prevent contractor access.
Taking into consideration evaluation order and rule logic, which explanation best accounts for the access outcome?
What is the recommended default rule for the cloud-gen firewall configuration when deploying a new ZIA tenant?
An administrator is provisioning new App Connectors in Microsoft Azure. A new egress policy enforces TLS inspection for outbound traffic from the workload subnets.
Which action should the ZPA administrator take to prevent App Connector registration failures?
An administrator must apply file-type controls to a subset of users while ensuring evasion-resistant detection.
Which configuration most directly maps a file-type policy to a user group and role-based security requirements?
For a deployment using both ZIA and ZPA set of services, what is the best authentication solution?
Which three levels of inspection are used by Zscaler for File Type Identification?
Audit and access logs show that a user was able to access an application segment even though the user was recently moved into a restricted group referenced by a deny rule.
What is an accurate explanation for the discrepancy?
What is the ZIA feature that ensures certain SaaS applications cannot be accessed from an unmanaged device?
Zscaler utilized a Zero Trust Network Architecture (ZTNA) for segmentation in an environment.
Which of the following prevents lateral movement within an organization?
Operations teams are investigating repeated port-based blocks for outbound traffic and need to correlate the blocked sessions with the applications involved and the applicable Firewall policies.
Which steps should the operations team follow?
Which of the following is a key feature of Zscaler Data Protection?
What enables zero trust to be properly implemented and enforced between an originator and the destination application?
Which are valid criteria for use in Access Policy Rules for ZPA?
A Gold-class SaaS application performs poorly even though its bandwidth class has a generous minimum and moderate maximum. Usage dashboards show available capacity during incidents, and other applications are not saturating the link.
What is the most defensible next step to prevent recurring degradation?
A new customer has just purchased Zscaler for Users.
Which of the following Zscaler service entitlements is enabled by default?
What method does Zscaler Identity Threat Detection and Response use to gather information about AD domains?
A regional data center hosts a payroll web application that communicates with a database over TCP port 1433. Recent telemetry shows attempted lateral movement from the compromised payroll web server to unrelated internal services. Contractors also have ZPA access to a separate internal wiki that resides in the same segment as the payroll application.
Which action should the administrator take to refine microsegmentation and reduce risk?
Audit logs show configuration changes performed by members of a group outside its intended administrative area.
Which step reduces this exposure while preserving required functionality?
A contractor team in a regional lab must upload ZIP archives to an approved code repository but must not upload archives or executables to generic file-sharing sites. A sudden increase in renamed executables, such as an .exe file disguised with a .jpg extension, complicates monitoring.
Which action best applies the correct file-type policy to this team while aligning with security requirements?
A data center requires connectivity to Zscaler for traffic inspection without an encryption requirement. The site must support a defined bandwidth profile of 2.2 Gbps and has no high-availability requirement.
Which configuration uses the minimum number of tunnels while meeting the throughput requirement?
Zscaler Data Protection supports custom dictionaries. What actions can administrators take with these dictionaries to protect data in motion?
A branch wants to block unmanaged devices from a private HR web application while allowing managed devices to work. The branch egress IP is configured as a trusted network. A Client Forwarding Policy currently bypasses the HR application for traffic on that trusted network, causing inconsistent enforcement for devices tunneling through the site.
What change should be made to achieve the intended outcome?
Which of the following options will protect against Botnet activity using IPS and Yara type content analysis?
What is a seed in Asset Discovery within External Attack Surface Management?
What conditions can be referenced for Trusted Network Detection?
A device connects to the Zero Trust Exchange with missing antivirus telemetry and an unverified client certificate in its posture profile.
Assuming Leading Practice for posture-driven enforcement are implemented, what is the outcome for the session?
Which action should be taken during a regional policy-tuning effort that requires evidence of egress-control effectiveness by correlating rule-hit counts and application usage across locations under network-layer enforcement?
Which of the following is a unified management console for internet and SaaS applications, private applications, digital experience monitoring and endpoint agents?
When creating an installer package or using the command-line for installation, which Zscaler Client Connector installer options are used to automatically redirect to your corporate SAML IdP on launch?
An administrator suspects that users in Europe are being routed to a distant service edge, inflating latency before traffic reaches a SaaS provider.
Which ZDX diagnostic provides evidence of inefficient client-to-service-edge routing?
Zscaler Advanced Threat Protection (ATP) is a key capability within Zscaler Internet Access (ZIA), protecting users against attacks such as phishing. Which of the following is NOT part of the ATP workflow?
The security exceptions allow list for Advanced Threat Protection apply to which of the following Policies?
What can Zscaler Client Connector evaluate that provides the most thorough determination of the trust level of a device as criteria for an access policy enabling remote access to sensitive private applications?
What is a Landmine in Deception?
You are planning to use Z-Tunnel 2.0 as the forwarding mechanism to support TCP, UDP, and ICMP traffic going to ZIA.
What type of tunnel will Zscaler Client Connector form with the Zero Trust Exchange?
A mixed policy set contains an Allow for high-value assets with posture, followed by a Block for high-value assets, then role-specific Allow rules for contractors and employees. Multiple users report unexpected reach to internal apps from unmanaged devices.
Considering rule order, attribute evaluation, and logical operators in ZPA Access Policies, which change best narrows access while minimizing unintended matches?
A user authenticates through an IdP. The SAML assertion and SCIM provisioning return different group memberships.
Which placement and policy-evaluation outcome ensures the most consistently up-to-date results?
How deeply can the Zscaler service scan recursively compressed files for malicious content?
Which of the following components is installed on an endpoint to connect users to the Zero Trust Exchange regardless of their location - home, work, while traveling, etc.?
The Zscaler platform can protect against malicious files, URLs and content based on a number of criteria including reputation type. What type of checking is virus scanning?
Is SCIM required for ZIA?
Security wants to trace a user ' s attempted upload over HTTP to determine whether web policy blocked the transfer and to confirm the category and rule that drove the decision.
Which option is appropriate for confirming a block on an HTTP upload?
Can URL Filtering make use of Cloud Browser Isolation?
Which Zscaler feature detects whether an intruder is accessing your internal resources?
What must new administrators in ZIdentity be assigned to perform administrative functions for Zscaler products?
A firewall policy set evaluates rules from top to bottom and stops at the first match. Rule 1 allows Marketing users outbound TCP 80/443 to any destination. Rule 2 blocks the Anonymizers network-application category globally. Rule 3 blocks all traffic to 203.0.113.0/24.
What outcome and risk are most likely when a Marketing user accesses an anonymizer over HTTPS?
A campus requires 1.5 Gbps of throughput to Zscaler Service Edges. The underlay is trusted, and the design explicitly excludes high availability.
Which option meets the bandwidth target with the minimum tunnel count?
What is an App Profile PAC file used for?
Which of the following methods can be used to notify an end-user of a potential DLP violation in Zscaler’s Workflow Automation solution?
The Zscaler Gen AI Security Report gives visibility and insight into an organization ' s use of generative AI applications. What kind of log will include Prompt for administrators to view for different prompts entered by users in those applications?
What is one business risk introduced by the use of legacy firewalls?
How does ZDX compute the score for an application?
What does Zscaler Advanced Firewall support that Zscaler Standard Firewall does not?
Which type of malware is specifically used to deliver other malware?
Which of the following are correct request methods when configuring a URL filtering rule with a Caution action?
When are users granted conditional access to segmented private applications?
How does a Zscaler administrator troubleshoot a certificate pinned application?
What are the two types of Probe supported in ZDX?
The Forwarding Profile defines which of the following?
What are the two types of Alert Rules that can be defined?