The security exceptions allow list for Advanced Threat Protection apply to which of the following Policies?
Malware Protection inside HTTPS connections is performed using which parts of the Zero Trust Exchange?
Which of the following is a valid action for a SaaS Security API Data Loss Prevention Rule?
A managed device on a known corporate LAN cannot reach a private application through the Zero Trust Exchange because of forwarding behavior.
Which bypass configuration would enable access while respecting how policies are evaluated?
A help desk receives intermittent Microsoft 365 latency complaints after local Internet breakout was enabled at several sites. The problem increases during peak collaboration windows and dies down unpredictably.
Which action should an administrator take to capture diagnostic information, determine where path issues emerge, and attach evidence to the incident workflow?
When configuring Zscaler Private Access, what is the function of the Server Group?
A network team needs to prevent recurring congestion while meeting performance goals for critical applications. The team has several months of application-usage and bandwidth data across multiple sites.
What approach is most appropriate for avoiding congestion?
Zscaler forwards the server SSL/TLS certificate directly to the user ' s browser session in which situation?
A Gold-class SaaS application performs poorly even though its bandwidth class has a generous minimum and moderate maximum. Usage dashboards show available capacity during incidents, and other applications are not saturating the link.
What is the most defensible next step to prevent recurring degradation?
A device meets VPN-trusted-network criteria where existing corporate controls apply, and administrators want to minimize unnecessary tunneling while relying on application and IP bypasses in the Application Profile for selected low-latency traffic.
Which Forwarding Profile action aligns with this approach for the VPN-trusted context?
Which of the following statements most accurately describes Zero Trust Connections?
Which Advanced Threat Protection feature restricts website access by geographic location?
When a SAML IDP returns an assertion containing device attributes, which Zscaler component consumes the attributes first, for policy creation?
Zscaler Advanced Threat Protection (ATP) is a key capability within Zscaler Internet Access (ZIA), protecting users against attacks such as phishing. Which of the following is NOT part of the ATP workflow?
Which Platform Service enables visibility into the headers and payload of encrypted transactions?
What is the scale used to represent a users Zscaler Digital Experience (ZDX) score?
Logs indicate traffic to an internal hostname was permitted and not inspected, despite a posture-based access policy that should have blocked the session.
Which statement best explains this outcome?
What is the purpose of Browser Access in relation to Zscaler Private Access (ZPA)?
A company must grant engineers and finance staff access to different private resources. After rollout, all users have access to both sets of resources.
Which action should the administrator take to tighten least privilege while keeping access operational?
Which Zscaler forwarding mechanism creates a loopback address on the machine to forward the traffic towards Zscaler cloud?
What is Zscaler ' s rotation policy for intermediate certificate authority certificates?
A Zscaler Client Connector App Profile is configured to apply a Forwarding Profile that forwards all traffic to the Zero Trust Exchange using Z-Tunnel 2.0. If a change is made to the Logout password in the App Profile, how long will it be before the new logout password is in effect?
A firewall policy set evaluates rules from top to bottom and stops at the first match. Rule 1 allows Marketing users outbound TCP 80/443 to any destination. Rule 2 blocks the Anonymizers network-application category globally. Rule 3 blocks all traffic to 203.0.113.0/24.
What outcome and risk are most likely when a Marketing user accesses an anonymizer over HTTPS?
The Zscaler Gen AI Security Report gives visibility and insight into an organization ' s use of generative AI applications. What kind of log will include Prompt for administrators to view for different prompts entered by users in those applications?
A team plans to deploy ZPA App Connectors as virtual machines in two data centers and one AWS VPC.
Which information should be communicated upfront to align network placement and access controls with Zero Trust principles?
A contractor team in a regional lab must upload ZIP archives to an approved code repository but must not upload archives or executables to generic file-sharing sites. A sudden increase in renamed executables, such as an .exe file disguised with a .jpg extension, complicates monitoring.
Which action best applies the correct file-type policy to this team while aligning with security requirements?
A macOS desktop application connecting to api.vendor.com fails during the TLS handshake whenever SSL/TLS Inspection is enabled. The application uses certificate pinning, and users intermittently connect through networks that prefer Google QUIC.
Which action should the security administrator take to restore functionality while retaining inspection for unrelated traffic?
A tenant’s Cloud App Control policy permits Webmail globally. Security requires members of the Sales group to receive a CAUTION prompt when accessing personal Webmail, while all other groups must continue to receive unrestricted access.
Sales users and other groups are currently matched by a Cloud App Control rule that allows all Webmail.
Which action should the administrator take to meet the requirement for the Sales group?
A sequence in the Administrator Audit Log shows several failed sign-ins from an unfamiliar location, followed by a successful administrator sign-in and a near-immediate role upgrade on the same identity.
Which entry combination constitutes the clearest escalation indicator requiring a containment step?
A branch wants to block unmanaged devices from a private HR web application while allowing managed devices to work. The branch egress IP is configured as a trusted network. A Client Forwarding Policy currently bypasses the HR application for traffic on that trusted network, causing inconsistent enforcement for devices tunneling through the site.
What change should be made to achieve the intended outcome?
Live logs show a global DLP rule that blocks uploads of regulated financial data and a departmental override that allows uploads for Finance when device posture is compliant. A Finance user on a compliant device successfully uploads a spreadsheet containing regulated data to a generic file-sharing application, despite expectations that the upload would be blocked. The departmental allow rule appears before the global block rule.
Which conclusion and next step best address the issue?
A Cloud Sandbox detonation shows a document beaconing through obfuscated scripts and spawning child processes that attempt network calls to newly registered domains. The desired outcome is to prevent users from downloading or accessing similar suspicious files across web and SaaS channels.
What action should be taken next?
What does Zscaler Advanced Firewall support that Zscaler Standard Firewall does not?
An operations team relies on API-driven exports of ZDX scores and Firewall Insights to track application performance over time. The team encounters periodic HTTP 429 errors during peak hours, and performance regressions are missed when exports fail.
Which mitigation best reduces blind spots that contribute to preventable performance issues?
A security team suspects that data exfiltration is occurring through encrypted channels to attackers.
To assess the company’s posture before tuning controls, which next step should be taken to validate whether existing protections cover this behavior?
Administrators report that some non-compliant devices can still reach private applications. A broad Allow rule precedes device-posture checks in the policy set.
What is the most appropriate next step to satisfy the compliance-before-access requirement?
Layered defense throughout an organization security platform is valuable because of which of the following?
What enables zero trust to be properly implemented and enforced between an originator and the destination application?
Cross-Site Scripting (XSS) attacks are a type of injection, in which malicious scripts are injected into otherwise benign and trusted websites. XSS includes which of the following?
Zscaler Platform Services works upon unencrypted data from encrypted communications due to which of the following?
A global URL Filtering rule blocks Newly Registered Domains and Anonymizers. Marketing has a rule that allows Social Media with a Caution action, and specific group-based rules appear above broader global rules. A user who belongs to both Marketing and Contractors attempts to access a social-media subdomain that is newly registered and classified under both Social Media and Newly Registered Domains.
What enforcement outcome is most consistent with the rule hierarchy and category matching?
Which Advanced Threats policy can be configured to protect users against a credential attack?
An executive summary correlates Risk360 category-contribution views with audit commitments: identity risk has decreased, but data-loss risk is trending upward; business-unit mean time to remediate (MTTR) variance suggests uneven remediation; and leadership requests board-ready evidence of continuous improvement mapped to the NIST Cybersecurity Framework (CSF).
What is the appropriate next step based on this summary and goal?
Policy troubleshooting identifies inconsistent enforcement across web and private-application channels for a regulated data type. The inconsistency causes inefficient investigations and intermittent blocking.
Which action would most plausibly improve platform performance under this policy framework?
A regional data center experiences intermittent loss of access to an internal ERP application through ZPA during maintenance windows. The site runs two virtual-machine App Connectors mapped to the ERP segment. Maintenance affects one hypervisor at a time, and support tickets show that sessions drop sporadically but recover.
Which change should the ZPA administrator request to improve continuity within the site’s constraints?
Which action should be taken during a regional policy-tuning effort that requires evidence of egress-control effectiveness by correlating rule-hit counts and application usage across locations under network-layer enforcement?
An investigation requires reviewing administrator entitlement changes from nine months ago to confirm suspected privilege escalation.
ZIdentity’s default portal retention period has already elapsed.
Which approach helps preserve and access the required audit trail for governance and forensic analysis?
A company must enforce least-privileged access to private applications when contractors connect from varying locations using devices with inconsistent security posture. The security team wants decisions to use identity and per-session context instead of broad network assumptions.
Which approach best meets the requirement?
When the Zscaler Client Connector launches, which portal does it initially interact with to understand the user ' s domain and identity provider (IdP)?
To design an update-governance process that reduces disruption and supports reporting, which practice aligns with continuous improvement and defensible decision-making?
An administrator must apply file-type controls to a subset of users while ensuring evasion-resistant detection.
Which configuration most directly maps a file-type policy to a user group and role-based security requirements?
When users are authenticated using SAML, what are the two most efficient ways of provisioning the users?
An organization wants to let a contractor group reach a single internal web application while restricting access to all other private resources. The team needs the policy to reflect contractor group-membership changes during normal operations and to ensure device risk is accounted for per session.
Which configuration most effectively enforces least privilege in this case?
Which of the following is unrelated to the properties of ' Trusted Networks ' ?
Which of the following is a common use case for adopting Zscaler’s Data Protection?
A log review shows requests to a sanctioned application being allowed despite a later rule intended to restrict access by time of day.
The rule set is:
Allow the sanctioned application for All Employees
Block the sanctioned application outside business hours for All Employees
Log restricted-access hits
Which cause and risk are most consistent with this behavior?
A user authenticates through an IdP. The SAML assertion and SCIM provisioning return different group memberships.
Which placement and policy-evaluation outcome ensures the most consistently up-to-date results?
A microsegmentation policy set contains a broad “allow employees to internal applications” rule before more specific controls. An incident review found SMB access from non-finance hosts to a finance file share.
Which refinement best addresses the unintended access while improving the internal security posture?
Which of the following DLP Notification methods can be used to forward a copy of the data that triggered the DLP policy to the auditor?
Company A acquires Company B. Users from both companies require reliable access to internet and SaaS services and to each other’s private applications across overlapping RFC1918 address ranges. A legacy VPN retained temporarily for a third-party integration causes intermittent route conflicts and noticeable latency.
Which action should the administrator prioritize to stabilize access and minimize network-level collisions?
Zscaler Client Connector checks for software updates automatically at which interval?
Does the Cloud Firewall detect evasion techniques that would allow applications to communicate over non-standard ports to bypass its controls?
What is the name of the feature that allows the platform to apply URL filtering even when a Cloud App control policy explicitly permits a transaction?