An administrator at a branch observes that a private ERP application is accessible when a user is connected to corporate Wi-Fi but intermittently fails when the user moves to a guest SSID at the same location. Zscaler Client Connector frequently transitions between Forwarding and Bypass states when the network changes.
Which action best reduces the instability?
Security teams are vetting approaches to private application access across two merging organizations to reduce post-acquisition lateral movement.
Which approach best constrains internal discovery and probing while preserving required connectivity?
A branch location must connect to Zscaler for web inspection. The underlay is trusted, the site requires a static egress IP mapped to the location, expected throughput is 700 Mbps, and high availability is not required.
Which tunnel approach and count meet these requirements with the least overhead?
An organization experiences frequent changes in team structure and wants to keep group membership and access aligned consistently.
Which approach supports scalable, controlled administration?
A security engineer needs the HR portal and SIP voice traffic to bypass inspection on the downtown campus but be fully inspected when staff roam. The campus DHCP service recently began issuing a public DNS resolver that breaks the existing trusted-network match, and users are intermittently inspected on campus.
Which action should the engineer take to restore consistent campus-only bypass for those applications?
If you ' re migrating from an on-premises proxy, you will already have a proxy setting configured within the browser or within the system. With Tunnel Mode, the best practice is to configure what type of proxy configuration?
Zscaler forwards the server SSL/TLS certificate directly to the user ' s browser session in which situation?
A contractor in the Field_Eng SAML group attempts to access an internal CAD application through ZPA from a branch designated as a Trusted Network. The Access Policy requires Field_Eng membership AND a device-posture profile confirming full-disk encryption and a CrowdStrike ZTA score above 80. The user passes the ZTA score requirement, but Device Posture reports that disk encryption is disabled.
Which enforcement outcome should be expected for this session?
An operations team creates a Contractor ZPA Users group to provide least-privileged access to private applications and allow Zscaler policies to evaluate the group accurately.
What is the next step required to align the group with the intended authorization model?
A SOC subscribes to a third-party blocklist and must ensure that listed destinations are denied while preserving predefined rules required for Microsoft 365 access. ZIA Firewall Filtering rules are evaluated from top to bottom using first-match processing.
How should the blocking rule be positioned?