Summer Sale Limited Time 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = simple75

Pass the Zscaler Digital Transformation Administrator ZDTA Questions and answers with Dumpstech

Exam ZDTA Premium Access

View all detail and faqs for the ZDTA exam

Practice at least 50% of the questions to maximize your chances of passing.
Viewing page 6 out of 9 pages
Viewing questions 51-60 out of questions
Questions # 51:

Audit and access logs show that a user was able to access an application segment even though the user was recently moved into a restricted group referenced by a deny rule.

What is an accurate explanation for the discrepancy?

Options:

A.

URL Filtering precedence suppressed the access policy to prevent duplicate enforcement

B.

Posture profiles enforced an AND condition that masked identity checks at session start

C.

The policy relied on SAML group attributes that had not refreshed, so the session was evaluated against stale membership

D.

The deny rule matched but was downgraded because of location-group prioritization

Questions # 52:

How would an administrator retrieve the access token to use the Zscaler One API?

Options:

A.

The administrator needs to send a POST request along with the required parameters to ZIdentity " s token endpoint.

B.

The administrator needs to send a GET request along with the required parameters to ZIdentity ' s token endpoint.

C.

The administrator needs to logon to the ZIA portal to generate the access token with Super Admin role.

D.

The administrator needs to logon to the ZIA portal to generate the access token with API Admin role.

Questions # 53:

An administrator must brief a cross-functional team on the prerequisites for allowing a single App Connector group in AWS to serve applications in an on-premises data center over Direct Connect.

Which requirement is most critical to state to avoid reachability gaps and App Connector misbehavior?

Options:

A.

Confirm that internal routing permits the App Connector subnets to reach the on-premises application subnets and that App Connector egress to ZPA Service Edges remains outbound TLS over permitted paths

B.

Confirm that client microtunnels terminate on the AWS App Connectors through inbound firewall rules and that Direct Connect advertises public prefixes

C.

Confirm that the on-premises firewalls publish NAT to expose the application servers for App Connector probes and that reverse DNS is authoritative in AWS

D.

Confirm that ZPA control-plane addresses are reachable through inbound ACLs from the Zscaler cloud and that application probes are source-NATed at the data-center edge

Questions # 54:

Which of the following DLP components make use of Boolean Logic?

Options:

A.

DLP Rules

B.

DLP dictionaries

C.

DLP Engines

D.

DLP identifiers

Questions # 55:

The Security Alerts section of the Alerts dashboard has a graph showing what information?

Options:

A.

Top 5 Malware Programs Detected

B.

Top 5 Viruses by Region

C.

Top 5 Threats by Systems Impacted

D.

Top 5 Unified Threat Yara Options

Questions # 56:

The security exceptions allow list for Advanced Threat Protection apply to which of the following Policies?

Options:

A.

Sandbox

B.

URL Filtering

C.

File Type Control

D.

IPS Control

Questions # 57:

Zscaler Client Connector checks for software updates automatically at which interval?

Options:

A.

Every 6 hours

B.

Every 12 hours

C.

Every 2 hours

D.

Every 24 hours

Questions # 58:

A data center requires connectivity to Zscaler for traffic inspection without an encryption requirement. The site must support a defined bandwidth profile of 2.2 Gbps and has no high-availability requirement.

Which configuration uses the minimum number of tunnels while meeting the throughput requirement?

Options:

A.

Configure three GRE tunnels mapped to the same location and use equal-cost multipath routing to support the aggregate 2.2 Gbps throughput

B.

Configure one IPSec peer with Dead Peer Detection enabled and conservative cipher settings to reduce processing load on the edge device

C.

Configure two GRE tunnels to different Service Edges and apply strict MTU policing to reduce fragmentation

D.

Configure two IPSec peers with static routing to divide traffic while accepting the additional key-exchange processing

Questions # 59:

You recently deployed an additional App Connector to an existing app connector group. What do you need to do before starting the zpa-connector service?

Options:

A.

Copy the group provisioning key to /opt/zscaler/var/provision key

B.

Monitor the peak CPU and memory utilization of the AC

C.

Schedule periodic software updates for the app connector group

D.

Check the status of the new App Connector in the administration portal

Questions # 60:

Which of the following is the preferred method for authentication in a OneAPI environment?

Options:

A.

OIDC

B.

SCIM

C.

SAML

D.

EntraID

Viewing page 6 out of 9 pages
Viewing questions 51-60 out of questions