ZDTA EXAM || MOST RECENT EXAM ACTUAL
COMPLETE REAL VERIFIED EXAM QUESTIONS AND
CORRECT ANSWERS (VERIFIED ANSWERS)
ALREADY GRADED A+!!! NEWEST EXAM!!!
What conditions exist for Trusted Network Detection? -
Answer-DNS Search Domain, DNS Server, Hostname
Resolution
A server group maps _____ to ____? - Answer-App
Connectors Groups to Application Segments
Why is SSL/TLS inspection critical in a security
architecture? - Answer-85-90% of all internet traffic is
SSL/TLS encrypted (including threats), as protocols such
as HTTP/2 are only delivered over TLS; SSL/TLS
inspection allows you to inspect the connection and look at
the full payload, including HTTP headers, which is
important to be able to block malicious traffic and prevent
sensitive data from leaking out of an organization
How much of an organization's traffic can Zscaler perform
SSL/TLS inspection on? - Answer-Zscaler inspects and
decrypts 100% of TLS traffic without constraints
,2|Page
What address translation options are available in the
Firewall policy? (Select 3)
Options:
- Destination Port Translation
- Source IP Translation to static IP
- Destination IP Translation to static IP
- Source Port Translation
- Destination IP Translation to FQDN - Answer-Destination
Port Translation
Destination IP Translation to static IP
Destination IP Translation to FQDN
What is the purpose of the Client Forwarding policy? -
Answer-It defines which Application Segments definitions
are downloaded by the Zscaler Client Connector
In Zscaler Private Access policy, which criteria can be
used to control access? (Select 3)
,3|Page
Options
- Zero Trust Exchange data center
- SAML or SCIM Attribute
- Client Connector Posture and Trusted Network
- Client Type
- Zscaler Internet Access Enabled - Answer-SAML or
SCIM Attribute
Client Connector Posture and Trusted Network
Client Type
Which are the acceptable actions for Firewall policy?
(Select 3)
Options:
- Allow
- Block/Drop
- Block/Reset
- Block/FIN+ACK
- Redirect - Answer-Allow
Block/Drop
Block/Reset
, 4|Page
What options for TLS Inspection Certificates are available?
(Select 2)
Options:
- Zscaler Root Certificate Authority
- Customer Root Certificate Authority
- Verisign Root CA
- Microsoft Azure Certificate Authority - Answer-Zscaler
Root Certificate Authority
Customer Root Certificate Authority
Do most organizations around the world inspect 100% of
all SSL/TLS encrypted traffic? - Answer-The reality is more
nuanced - certain traffic exclusions for healthcare and
financial websites may be required depending on the
organization's choice - that is why the Zscaler platform has
the ability to bypass SSL inspection for certain categories
of websites. Furthermore certain types of latency sensitive
traffic such as UCaaS should be bypassed, so
organizations rarely inspect of all traffic
TLS Inspection provides what functionality? (Select 3)