ENGINEER FINAL PAPER 2026 FULL QUESTIONS
AND CORRECT ANSWERS GRADED A+
◉ What do we do if a customer changes the default risk score of an
application? Answer: We immediately readjust that risk score for
that specific tenant, for that specific customer.
◉ What does OneAPI use for authentication? Answer: OAuth
◉ How does OneAPI simplify API integration? Answer: By providing
a single-entry point for accessing multiple APIs.
◉ Where does the API Gateway reside? Answer: The Central
Authority
◉ How do you deploy GRE tunnels? Answer: Configure two tunnels
per site - primary and a backup to optimal DCs.
◉ What is the maximum bandwidth for each GRE tunnel? Answer: 1
Gbps if not behind NAT. 250 Mbps if behind NAT.
, ◉ How do you configure IPsec tunnels? Answer: Configure two
tunnels per ISP per site - primary and a backup to optimal DCs.
◉ What is the maximum bandwidth for each IPsec tunnel? Answer:
400 Mbps
◉ How many IKEv2 SAs per IPsec tunnel? Answer: No more than 8.
◉ What are the two Index Tools? Answer: Exact Data Match (EDM)
and Index Data Match (IDM)
◉ How do DLP Dictionaries, Engines, and Policies work together?
Answer: Engines are made of Dictionaries.
Policies are made of Engines.
◉ Which capabilities are not available on standard firewall
subscription? Answer: DNS Tunneling, IPS Control, and non-
standard traffic redirection.
◉ How many apps and attributes are in the Shadow IT database?
Answer: 45,000 apps and 75 attributes.
◉ What is the most significant metric when calculating a ZDX score?
Answer: Page Fetch Time