ZDTA Sample Questions

ZDTA Sample Questions & Answers

Authentication and ZIdentity administration carry the most weight, next to device connectivity and private access, controlling web and network access, guarding against malware and command-and-control traffic, data loss prevention, ZDX monitoring, and API automation.

Launch the full ZDTA simulator →

Showing 10 of 20 free samples.

  1. Question 1Beginner

    Identity Services · SCIM Configuration

    True or False: When configuring SCIM for user and group provisioning from an IdP like Azure AD to Zscaler, the SCIM bearer token generated in the Zscaler admin portal must be stored securely in the IdP, as it grants administrative privileges to manage Zscaler's user database.

    Show answer & explanation

    Correct answer: A

    This statement is true. The SCIM bearer token is a long-lived API key that authorizes the IdP to make create, read, update, and delete (CRUD) operations on Zscaler's user and group database via the SCIM API. It must be treated as a sensitive secret and stored securely within the IdP's enterprise application configuration.

  2. Question 2Intermediate

    Zscaler Digital Experience · ZDX Troubleshooting

    A helpdesk team receives multiple complaints from remote users about poor performance with a critical SaaS application. The team needs to determine if the issue is with the users' local network, the internet path, or the Zscaler cloud. Which ZDX feature provides a hop-by-hop network path visualization and performance metrics from the user's device to the application to pinpoint the source of latency?

    Show answer & explanation

    Correct answer: C

    ZDX Deep Tracing is the specific feature designed for this purpose. It initiates a detailed, real-time analysis of the network path from the user's device, across their local network, through the Zscaler cloud, and across the internet to the application's servers. It provides latency and packet loss metrics for each hop, allowing administrators to visually identify the exact segment of the path causing the performance degradation.

  3. Question 3Intermediate

    Zero Trust Automation · API for Policy Management

    An organization wants to fully automate the process of adding newly discovered malicious domains from its threat intelligence platform (TIP) into a ZIA custom URL category used in a block policy. Which Zscaler component is required to achieve this programmatic update?

    Show answer & explanation

    Correct answer: B

    The ZIA REST API provides endpoints for programmatically managing various ZIA configurations, including URL categories. The threat intelligence platform would use a script or its built-in integration capabilities to authenticate to the ZIA API and issue POST requests to the /urlCategories endpoint to add the new malicious domains to the specified block list. This enables a fully automated threat response workflow.

  4. Question 4AdvancedSelect 3

    Connectivity Services · ZPA Browser Access

    A healthcare organization needs to provide secure, clientless access to a legacy electronic health record (EHR) system for external auditors. The EHR is a web application hosted in a private data center. The auditors must not be required to install any software on their machines. Which Zscaler components and configurations are required to meet this requirement? (Select THREE)

    Show answer & explanation

    Correct answers: A, C, D

    The App Connector is the fundamental component that establishes an inside-out connection from the private network to the Zscaler cloud, making the internal application available without opening inbound firewall ports.

    The Application Segment defines the application being accessed. Enabling the 'Browser Access' option specifically activates the clientless access feature for that application.

    Access in ZPA is deny-by-default. An explicit Access Policy is required to connect a specific user group (the auditors) to a specific Application Segment (the EHR system).

  5. Question 5Beginner

    Access Control Services · URL Filtering Categories

    During a security audit, an administrator needs to demonstrate how Zscaler prevents access to newly registered domains (NRDs), which are often used in phishing campaigns. Which ZIA policy setting directly addresses this threat?

    Show answer & explanation

    Correct answer: D

    Zscaler maintains a dynamic URL category specifically for 'Newly Registered and Observed Domains'. This category automatically includes domains that have been registered or become active within the last 30 days. By creating a URL Filtering policy to block this category, an organization can proactively prevent users from accessing these high-risk sites, which are frequently used for malicious activities.

  6. Question 6Intermediate

    Access Control Services · ZIA Firewall Policy

    A university is using ZIA's firewall service to control outbound traffic. They want to allow students to access external SSH servers but only if the connection is initiated from a specific campus computer lab. The campus lab is defined as a Location in ZIA. Which set of criteria in a ZIA Firewall Control policy rule would correctly enforce this?

    Show answer & explanation

    Correct answer: C

    A ZIA Firewall Control policy rule is evaluated based on multiple criteria. To meet this requirement, the rule must specify the source of the traffic ('Location: Campus Lab'), the type of traffic ('Network Service: TCP_22' which is the standard service object for SSH), and the desired outcome ('Action: Allow'). This combination ensures that only SSH traffic originating from the specified location is permitted.

  7. Question 7Intermediate

    Data Protection Services · DLP Policy Configuration

    An administrator is configuring a ZIA DLP policy to prevent the leakage of credit card numbers. They create a policy using the predefined 'Credit Cards' dictionary. During testing, they find that a document containing 15 unique, validly formatted credit card numbers is not being blocked. What is the most likely reason for this policy failure?

    Show answer & explanation

    Correct answer: B

    ZIA DLP policies trigger based on a 'Match Count' threshold, which specifies how many times a dictionary term or pattern must be found before the policy action is taken. The default is often higher than 1 to reduce false positives. If the tester's document contained 15 credit card numbers but the policy's match count was set to 20, the policy would not trigger. This is the most common reason for a seemingly correct policy not firing.

  8. Question 8Intermediate

    Identity Services · Device Posture Policy

    A company has a mix of corporate-managed laptops and employee-owned mobile devices (BYOD). The security policy requires that any device accessing internal applications via ZPA must have disk encryption enabled. How can an administrator enforce this policy for both device types?

    flowchart TD subgraph UserDevice [User Device] ZCC[Zscaler Client Connector] end UserDevice -- posture check --> ZPA ZPA{Device Posture Check} ZPA -- |Encrypted| --> Allow[Allow Access] ZPA -- |Not Encrypted| --> Block[Block Access] Allow --> App[(Internal App)]
    Show answer & explanation

    Correct answer: B

    Zscaler Client Connector (ZCC) has the native ability to check the device's state for various security attributes, including whether disk encryption (like BitLocker on Windows or FileVault on macOS) is enabled. An administrator can create a Device Posture Profile for this check. This profile can then be used as a mandatory criterion in a ZPA Access Policy, ensuring that only devices with active disk encryption are granted access to the specified application segments.

  9. Question 9Beginner

    Connectivity Services · ZPA Architecture

    Which Zscaler component uses an inside-out connection model to connect private applications to the Zero Trust Exchange without requiring any inbound firewall rules in the data center?

    Show answer & explanation

    Correct answer: B

    The ZPA App Connector is a lightweight virtual machine deployed within the customer's data center or VPC. It establishes a secure, outbound-only TLS tunnel to the Zscaler cloud. All communication is initiated from the inside out, meaning no inbound ports need to be opened on the firewall, which is a core principle of the Zero Trust model.

  10. Question 10Intermediate

    Cyberthreat Protection Services · ATP Troubleshooting

    A user is blocked from accessing a legitimate website. The ZIA block page indicates the reason is 'Advanced Threat Protection'. The user insists the site is safe. A security analyst needs to investigate the reason for the block and potentially release the transaction if it is a false positive. What is the most direct location in the ZIA portal to find detailed information about this specific ATP block?

    Show answer & explanation

    Correct answer: C

    The Web Insights Logs provide transaction-level detail for all web traffic. To investigate an ATP block, an analyst should navigate to Analytics > Web Insights, filter by the user's name, and look for transactions where the Threat Category is 'Advanced Threat Protection'. This log entry will contain the specific threat name, URL, and other details needed to determine if it was a false positive.

Ready for the real thing?

The full ZDTA simulator has every exam-style question, timed mode, and instant scoring.

Go to the ZDTA simulator →