Summer Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70track

Free Zscaler ZDTA Practice Exam with Questions & Answers | Set: 6

Questions 51

Can Notifications, based on Alert Rules, be sent with methods other than email?

Options:
A.

Email is the only method for notifications as that is universally applicable and no other way of sending them makes sense.

B.

In addition to email, text messages can be sent directly to one cell phone to alert the CISO who is then coordinating the work on the incident.

C.

Leading ITSM systems can be connected to the Zero Trust Exchange using a NSS server, which will then connect to ITSM tools and forwards the alert.

D.

In addition to email, notifications, based on Alert Rules, can be shared with leading ITSM or UCAAS tools over Webhooks.

Zscaler ZDTA Premium Access
Questions 52

How does a Zscaler administrator troubleshoot a certificate pinned application?

Options:
A.

They could look at SSL logs for a failed client handshake.

B.

They could reboot the endpoint device.

C.

They could inspect the ZIA Web Policy.

D.

They could look into the SaaS application analytics tab.

Questions 53

A ZIA URL Filtering policy aims to meet compliance goals by blocking Social Networking for all users. A departmental exception intended for Marketing to permit scheduled access is placed below the global block in the rule list.

Which action should an administrator take to align Marketing group access with the exception while tempering unintended exposure?

Options:
A.

Reorder the exception above the global block and constrain it with a time window and Marketing group conditions.

B.

Broaden the exception to include Marketing and Sales to reduce marginal mismatches in app categorization.

C.

Replicate the exception at user level to counteract hierarchy gaps and reduce dependency on group scope.

D.

Turn off Allow Cascading to URL Filtering to dampen category evaluation across control layers.

Questions 54

Assume that you have four data centers around the globe, each hosting multiple applications for your users. What is the minimum number of App Connectors you should deploy?

Options:
A.

Six - one per data center plus two for cold standby.

B.

Eight -two per data center.

C.

Four - one per data center.

D.

Sixteen - to support a full mesh to the other data centers.

Questions 55

Administrators report that a content-inspection rule is blocking source-code uploads to a sanctioned repository, although uploads should be permitted only for that application and the engineering group.

Which action and policy ownership are most appropriate for addressing the issue?

Options:
A.

Engage the DLP policy owners to refine the rule context, scope the exception to the approved application and engineering group, and retain enforcement everywhere else

B.

Ask SIEM analysts to suppress correlated alerts for source-code uploads to reduce operational noise

C.

Direct the firewall team to relax deep packet inspection on developer ports to prevent inspection-related disruptions

D.

Ask the identity team to remap group attributes so engineers inherit a less restrictive baseline and bypass the data-protection rule

Questions 56

What is an App Profile PAC file used for?

Options:
A.

It is used to encapsulate traffic within a GRE tunnel.

B.

It is used to establish a TLS session with the Zscaler cloud.

C.

It is used by Zscaler Client Connector to make traffic-forwarding decisions.

D.

It is used to categorize sensitive data.

Questions 57

What is the minimum polling interval if one has ZDX Advanced license enabled in their tenant?

Options:
A.

1 minute

B.

10 minutes

C.

15 minutes

D.

5 minutes

Questions 58

What does Advanced Threat Protection defend users from?

Options:
A.

Vulnerable JavaScripts

B.

Large iFrames

C.

Malicious active content

D.

Command injection attacks

Questions 59

The Forwarding Profile defines which of the following?

Options:
A.

Fallback methods and behavior when a DTLS tunnel cannot be established

B.

Application PAC file location

C.

System PAC file when off trusted network

D.

Fallback methods and behavior when a TLS tunnel cannot be established

Questions 60

What method does Zscaler Identity Threat Detection and Response use to gather information about AD domains?

Options:
A.

Scanning network ports

B.

Running LDAP queries

C.

Analyzing firewall logs

D.

Packet sniffing