Summer Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70track

Free Zscaler ZDTA Practice Exam with Questions & Answers | Set: 5

Questions 41

What is the main purpose of Sandbox functionality?

Options:
A.

Block malware that we have previously identified

B.

Build a test environment where we can evaluate the result of policies

C.

Identify Zero-Day Threats

D.

Balance threat detection across customers around the world

Zscaler ZDTA Premium Access
Questions 42

What is Zscaler ' s rotation policy for intermediate certificate authority certificates?

Options:
A.

Certificates are rotated every 90 days and have a 180-day expiration.

B.

Lifetime certificates have no expiration date.

C.

Certificates are rotated every seven days and have a 14-day expiration.

D.

Certificates are issued dynamically and expire in 24 hours.

Questions 43

How can we protect the Zscaler Client Connector from unauthorized alterations to its files and registry settings?

Options:
A.

StrictEnforcement CLI Parameter of ZCC installation file

B.

TamperProofing options in Forwarding Profile

C.

AntiTampering CLI Parameter of ZCC installation file

D.

DisableTampering options in Forwarding Profile

Questions 44

Which Zscaler forwarding mechanism creates a loopback address on the machine to forward the traffic towards Zscaler cloud?

Options:
A.

Enforced PAC mode

B.

ZTunnel - Packet Filter Based

C.

ZTunnel with Local Proxy

D.

ZTunnel - Route Based

Questions 45

What ports and protocols are forwarded to the Zero Trust Exchange when Zscaler Client Connector is using Tunnel 2.0?

Options:
A.

TCP ports 80, 443 and 8080 only.

B.

Any HTTP/HTTPS traffic as well as DNS.

C.

All TCP and UDP ports as well as ICMP traffic.

D.

All Web ports as well as FTP and SSH.

Questions 46

Which type of attack plants malware on commonly accessed services?

Options:
A.

Remote access trojans

B.

Phishing

C.

Exploit kits

D.

Watering hole attack

Questions 47

A security team suspects that data exfiltration is occurring through encrypted channels to attackers.

To assess the company’s posture before tuning controls, which next step should be taken to validate whether existing protections cover this behavior?

Options:
A.

Raise the severity of egress firewall rules across segments to constrain outbound flows that might be exploited

B.

Review ZIA DLP outbound logs for anomalous uploads to unsanctioned SaaS applications and newly registered domains to gauge detection coverage

C.

Correlate ZIA threat insights with ZPA analytics to identify anomalous outbound patterns and unusual private-application access, and then verify that DLP and botnet controls apply to TLS-decrypted traffic

D.

Trigger broad Cloud Sandbox reanalysis of recent endpoint downloads to look for latent payloads that could facilitate exfiltration

Questions 48

The security exceptions allow list for Advanced Threat Protection apply to which of the following Policies?

Options:
A.

Sandbox

B.

URL Filtering

C.

File Type Control

D.

IPS Control

Questions 49

When filtering user access to certain web destinations what can be a better option, URL or Cloud Application filtering Policies?

Options:
A.

Cloud Application policies provide better access control.

B.

URL filtering policies provide better access control.

C.

Wherever possible URL policies are recommended.

D.

Both provide the same filtering capabilities.

Questions 50

A user’s access to a private CRM application fails occasionally during video calls. ZDX shows sharp jitter spikes and rising packet loss on the ISP path, with client-egress latency increasing when calls begin.

What will reduce CRM access variability?

Options:
A.

Expand URL categories for CRM domains to improve classification fidelity under heavy traffic

B.

Steer traffic to a nearer Service Edge and validate path quality with ZDX and Tunnel Insights to minimize latency and jitter

C.

Constrain the user’s identity claims to limit token size and reduce authentication overhead during calls

D.

Move CRM traffic to a Silver bandwidth class so collaboration traffic no longer competes with business data