2026 Exams
1. What is used to detect if a SAML assertion was Digital Signatures
modified after being issued?
Options:
- XML
- Digital Signatures
- Attributes
- Tokens
2. How is a SAML assertion delivered to Zscaler? The IdP sends it via the user's
browser to the SP
Options: (Uses a form POST submitted
- The IdP sends it via an HTTP post directly to the via JavaScript)
SP via a backend API
- The SP sends it via an HTTP post directly to the
IdP via a backend API
- The IdP sends it via the user's browser to the SP
- The SP sends it via a trusted authority to the IdP
3. In what way does Zscaler's Identity Proxy enable Issuing SAML assertions
authentication to SaaS applications?
Options:
- Injecting identity headers into the HTTP request
- SSL Inspection
- Browser Isolation
- Issuing SAML assertions
4. How does Zscaler Internet Access authenticate SAML, LDAP, Hosted Database
users? (Select 3)
Options:
, Zscaler EDU 200 - Essentials - ZDTA Study Guide
2026 Exams
- SAML
- SCIM
- LDAP
- Hosted Database
5. How does Zscaler Private Access authenticate end SAML
users?
Options:
- Username and Password in a form-based auth
- Hosted DB
- SAML
- SCIM
6. What is the fastest way to change a user's access Send ditterent attributes via
entitlements? SCIM
7. In order for Zscaler to enforce policy based on SAML
accessing devices, what method is best used by
IdPs to share information about a user's accessing
device?
Options
- Kerberos
- SAML
, Zscaler EDU 200 - Essentials - ZDTA Study Guide
2026 Exams
- Header Injection
- Mobile Device Management
8. Privileged Remote Access supports which proto- SSH, RDP
cols? (Select 2)
Options:
- SSH
- RDP
- CIFS
- HTTP/HTTPS
9. Which services can coexist on an Application Seg- Isolation, Browser Access, and
ment? Inspection
Options:
- Isolation, Browser Access, and Inspection
- RDP, SSH, and Inspection
- Inspection, Isolation, and RDP
- CIFS, RDP, and SSJ
10. How often does the Zscaler Client Connector check Every 2 hours
for software updates?
Options:
- Every 2 hours
- Every 6 hours
- Every 12 hours
- Every 24 hours
11. Which check guarantees identification of a corpo- Client Certificate & Non-Ex-
rate-managed device by the Zscaler Client Connec- portable private key
tor?
, Zscaler EDU 200 - Essentials - ZDTA Study Guide
2026 Exams
12. You want Zscaler Client Connector to automatical- --cloudName
ly redirect to your corporate SAML IDP on launch. --userDomain
Which installer options should you configure to do
so? (Select 2)
13. Where is the control to prevent a user from exiting In the Application Profile
Zscaler Client Connector?
Options:
- It's a ZCC Installer option
- In the Forwarding Profile
- In the Application Profile
- Under Administration, Advanced Settings
14. When moving from an Explicit Proxy to a Tun- The client will always resolve
neled/Transparent Proxy - what, if any, effects will DNS
be seen on the client? (Select 3) The client browser needs
re-configuration
Options: Authenticated websites may no
- No Effect longer work
- The client will always resolve DNS
- The client browser needs re-configuration
- Authenticated websites may no longer work
- An Explicit Proxy and a Transparent Proxy are the
same thing
15. What benefits does a Zscaler Tunnel have over Tunnels encapsulate traflc and
other forwarding mechanisms for Zscaler Client authenticate to the Zero Trust
Connector? Exchange