Summer Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70track

Free Zscaler ZDTA Practice Exam with Questions & Answers | Set: 3

Questions 21

An administrator at a branch observes that a private ERP application is accessible when a user is connected to corporate Wi-Fi but intermittently fails when the user moves to a guest SSID at the same location. Zscaler Client Connector frequently transitions between Forwarding and Bypass states when the network changes.

Which action best reduces the instability?

Options:
A.

Broaden the application segment to include wildcard subdomains so DNS variations do not cause lookup mismatches

B.

Redesign the Client Connector Forwarding Profile to prioritize stable trusted-network attributes and avoid dependence on volatile SSID-based bypass triggers

C.

Disable posture checks for the ERP application to prevent frequent re-evaluations from affecting access decisions

D.

Backhaul all branch traffic to headquarters so users no longer change Service Edges when moving between SSIDs

Zscaler ZDTA Premium Access
Questions 22

Security teams are vetting approaches to private application access across two merging organizations to reduce post-acquisition lateral movement.

Which approach best constrains internal discovery and probing while preserving required connectivity?

Options:
A.

Adopt ZPA user-to-app segmentation with inside-out connectivity so users reach defined applications and cannot traverse broader IP ranges.

B.

Centralize VPN concentrators and restrict subnet access by department to contain exploratory traffic during initial entitlement mapping.

C.

Extend shared VLANs across the combined data centers and use access control lists to discourage host-to-host enumeration during audits.

D.

Apply IDS signatures at core routing layers to flag port scans and perform rate limiting until both environments complete segmentation.

Questions 23

A branch location must connect to Zscaler for web inspection. The underlay is trusted, the site requires a static egress IP mapped to the location, expected throughput is 700 Mbps, and high availability is not required.

Which tunnel approach and count meet these requirements with the least overhead?

Options:
A.

Configure one IPSec tunnel to the regional Service Edge and declare the bandwidth expectation to match the site profile

B.

Configure one GRE tunnel to a regional Service Edge and bind the location to a static IP to meet the throughput target

C.

Provision two GRE tunnels to separate Service Edges and balance traffic through policy-based routing

D.

Establish two IPSec peers with conservative IKE lifetimes to reduce rekey churn and configure the location’s static IP

Questions 24

An organization experiences frequent changes in team structure and wants to keep group membership and access aligned consistently.

Which approach supports scalable, controlled administration?

Options:
A.

Rely on SAML assertions to grant administrator rights during authentication events

B.

Consume SCIM-provisioned groups from the identity provider and drive entitlements through those groups

C.

Assign administrative capabilities individually to each user to avoid group-level drift

D.

Create local user accounts to separate access from external directories

Questions 25

A security engineer needs the HR portal and SIP voice traffic to bypass inspection on the downtown campus but be fully inspected when staff roam. The campus DHCP service recently began issuing a public DNS resolver that breaks the existing trusted-network match, and users are intermittently inspected on campus.

Which action should the engineer take to restore consistent campus-only bypass for those applications?

Options:
A.

Enable PAC-file fallback in Client Connector and prioritize DNS-based conditions so HR and SIP are suppressed when the resolver aligns with the campus

B.

Strengthen the Trusted Network criteria by adding default-gateway and egress-IP checks to the campus entry, map the campus to a profile with No Forwarding, and place a top-down bypass for HR and SIP on the trusted network followed by a forwarding rule for the same applications off-trusted

C.

Switch the Forwarding Profile to Enforce Proxy and add PAC logic for campus subnets so HR and SIP requests are sent directly at those ranges

D.

Reduce posture checks on the campus and rely on Application Profiles to remap HR and SIP to Tunnel with Local Proxy for roaming users

Questions 26

If you ' re migrating from an on-premises proxy, you will already have a proxy setting configured within the browser or within the system. With Tunnel Mode, the best practice is to configure what type of proxy configuration?

Options:
A.

Execute a GPO update to retrieve the proxy settings from AD.

B.

Enforce no Proxy Configuration.

C.

Use Web Proxy Auto Discovery (WPAD) to auto-configure the proxy.

D.

Use an automatic configuration script (forwarding PAC file).

Questions 27

Zscaler forwards the server SSL/TLS certificate directly to the user ' s browser session in which situation?

Options:
A.

When traffic contains a known threat signature.

B.

When web traffic is on custom TCP ports.

C.

When traffic is exempted in SSL Inspection policy rules.

D.

When user has connected to server in the past.

Questions 28

A contractor in the Field_Eng SAML group attempts to access an internal CAD application through ZPA from a branch designated as a Trusted Network. The Access Policy requires Field_Eng membership AND a device-posture profile confirming full-disk encryption and a CrowdStrike ZTA score above 80. The user passes the ZTA score requirement, but Device Posture reports that disk encryption is disabled.

Which enforcement outcome should be expected for this session?

Options:
A.

Quarantine the traffic through ZIA Cloud Sandbox for risk analysis

B.

Deny access to the private application because the device fails the mandatory disk-encryption requirement

C.

Permit restricted access through a more distant App Connector

D.

Bypass Access Policy evaluation because the branch is designated as a Trusted Network

Questions 29

An operations team creates a Contractor ZPA Users group to provide least-privileged access to private applications and allow Zscaler policies to evaluate the group accurately.

What is the next step required to align the group with the intended authorization model?

Options:
A.

Create equivalent local user records to avoid delays in identity-provider group propagation

B.

Reduce the administrator sign-on session lifetime so contractors must refresh their credentials more frequently

C.

Add the group to device-posture requirements so posture checks compensate for missing service permissions

D.

Assign the Private Access service entitlement to the group so its members can consume ZPA subject to Access Policy controls

Questions 30

A SOC subscribes to a third-party blocklist and must ensure that listed destinations are denied while preserving predefined rules required for Microsoft 365 access. ZIA Firewall Filtering rules are evaluated from top to bottom using first-match processing.

How should the blocking rule be positioned?

Options:
A.

Insert a drop rule for the third-party destination group above generic outbound allow rules while keeping the essential Microsoft 365 predefined rules intact

B.

Move the third-party block rule to the bottom so it is evaluated after application identification for standard services

C.

Modify the Microsoft 365 predefined rules to include third-party exclusions, then append a general deny rule for unclassified traffic

D.

Place broad SaaS allow rules at the top and insert the third-party block rule below them to avoid unintended denial of legitimate sessions