Summer Sale Limited Time 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = simple75

Pass the Zscaler Digital Transformation Administrator ZDTA Questions and answers with Dumpstech

Exam ZDTA Premium Access

View all detail and faqs for the ZDTA exam

Practice at least 50% of the questions to maximize your chances of passing.
Viewing page 9 out of 9 pages
Viewing questions 81-90 out of questions
Questions # 81:

What is the name of the feature that allows the platform to apply URL filtering even when a Cloud App control policy explicitly permits a transaction?

Options:

A.

Allow Cascading

B.

Allow and Quarantine

C.

Allow URL Filtering

D.

Allow and Scan

Questions # 82:

A pilot update is underway for Zscaler Client Connector in three regions to reduce known vulnerabilities. In one region, ZDX shows latency spikes and tunnel failures correlated with a specific operating-system build during the pilot.

Which action should the administrator take to proceed toward broader rollout with minimal disruption?

Options:

A.

Constrain the rollout to a pilot ring focused on the affected operating system and region, monitor the Client Connector dashboard and ZDX, and revert that segment if failures persist before expanding

B.

Backhaul traffic from the affected region to headquarters to reduce variability, accepting additional latency and potentially compounding user impact

C.

Tighten inspection policies across all pilot regions to constrain throughput, accepting degraded experience to stabilize failure patterns

D.

Accelerate the global rollout to close compliance gaps despite localized instability, relying on post-deployment remediation for the affected cohort

Questions # 83:

A user assigned to the Contractors group reaches an internal web app despite a rule to prevent contractor access.

Taking into consideration evaluation order and rule logic, which explanation best accounts for the access outcome?

Options:

A.

An inspection policy relaxed enforcement through HTTP method handling, leaving the session permitted despite the deny.

B.

A data protection engine recalibrated risk and weakened access control through orchestration overlaps in the stack.

C.

An earlier allow scoped to the application segment matched due to a trusted network condition, and the later catch-all deny did not evaluate.

D.

A client forwarding bypass reduced enforcement fidelity and triggered a secondary pass where the deny was sidelined.

Questions # 84:

Which of the following enables the discovery of newly observed domains within three minutes of the domain coming online?

Options:

A.

IP Chicken

B.

MXToolbox

C.

Farsight Feed

D.

Dig

Questions # 85:

Is SCIM required for ZIA?

Options:

A.

Depends

B.

Maybe

C.

No

D.

Yes

Questions # 86:

In which of the following SaaS apps can you protect data at rest via Zscaler ' s out-of-band CASB solution?

Options:

A.

Yahoo Mail

B.

Twitter.

C.

Google Drive.

D.

Facebook.

Questions # 87:

What does a DLP Engine consist of?

Options:

A.

DLP Policies

B.

DLP Rules

C.

DLP dictionaries

D.

DLP identifiers

Questions # 88:

Which attack type is characterized by a commonly used website or service that has malicious content like malicious JavaScript running on it?

Options:

A.

Watering Hole Attack

B.

Pre-existing Compromise

C.

Phishing Attack

D.

Exploit Kits

Questions # 89:

Which of the following are types of device posture?

Options:

A.

Detect Crowdstrike, Crowdstrike ZTA score, First name

B.

Certificate Trust, File Path, Full Disk Encryption

C.

Domain Joined, Process Check, Deception Check

D.

Unauthorized Modification, OS Version, License Key

Questions # 90:

Cloud Sandbox detonations begin returning indicators of compromise associated with TrickBot infrastructure, including domains and IP addresses. The SOC wants consistent enforcement in ZIA with less manual effort.

Which operational approach best fits this goal?

Options:

A.

Perform daily manual updates to a URL blocklist and a separate firewall address group for each new indicator, deferring changes during peak hours

B.

Switch IPS to detect-only mode to gather more evidence and postpone blocking until campaign indicators stabilize across multiple users

C.

Increase Advanced Threat Protection risk sensitivity and rely on page-risk analysis to identify newly observed destinations

D.

Use a SOAR workflow with Zscaler APIs to add domains to a custom URL category and IP addresses to a firewall destination group, with block policies applied automatically

Viewing page 9 out of 9 pages
Viewing questions 81-90 out of questions