
Zscaler Digital Transformation Administrator - ZDTA Exam Questions
QUESTION NO: 1
A sanctioned SaaS application is allowed in Cloud App Control but appears to be blocked by URL Filtering.
Which configuration would permit access through a controlled bypass that follows policy precedence?
A sanctioned SaaS application is allowed in Cloud App Control but appears to be blocked by URL Filtering.
Which configuration would permit access through a controlled bypass that follows policy precedence?
Correct Answer: D
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).
QUESTION NO: 2
For a deployment using both ZIA and ZPA set of services, what is the best authentication solution?
For a deployment using both ZIA and ZPA set of services, what is the best authentication solution?
Correct Answer: C
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).
QUESTION NO: 3
As technology that exists for a very long period of time, has URL Filtering lost its effectiveness?
As technology that exists for a very long period of time, has URL Filtering lost its effectiveness?
Correct Answer: A
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).
QUESTION NO: 4
Which Advanced Threats policy can be configured to protect users against a credential attack?
Which Advanced Threats policy can be configured to protect users against a credential attack?
Correct Answer: C
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).
QUESTION NO: 5
The Zscaler platform can protect against malicious files, URLs and content based on a number of criteria including reputation type. What type of checking is virus scanning?
The Zscaler platform can protect against malicious files, URLs and content based on a number of criteria including reputation type. What type of checking is virus scanning?
Correct Answer: B
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).
QUESTION NO: 6
A tenant's Cloud App Control policy permits Webmail globally. Security requires members of the Sales group to receive a CAUTION prompt when accessing personal Webmail, while all other groups must continue to receive unrestricted access.
Sales users and other groups are currently matched by a Cloud App Control rule that allows all Webmail.
Which action should the administrator take to meet the requirement for the Sales group?
A tenant's Cloud App Control policy permits Webmail globally. Security requires members of the Sales group to receive a CAUTION prompt when accessing personal Webmail, while all other groups must continue to receive unrestricted access.
Sales users and other groups are currently matched by a Cloud App Control rule that allows all Webmail.
Which action should the administrator take to meet the requirement for the Sales group?
Correct Answer: A
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).
QUESTION NO: 7
Malicious File Protection exclusions can be configured for which type of file?
Malicious File Protection exclusions can be configured for which type of file?
Correct Answer: C
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).
QUESTION NO: 8
Which proprietary technology does Zscaler use to calculate risk attributes dynamically for websites?
Which proprietary technology does Zscaler use to calculate risk attributes dynamically for websites?
Correct Answer: A
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).
QUESTION NO: 9
Which Risk360 key focus area observes a broad range of event, security configurations, and traffic flow attributes?
Which Risk360 key focus area observes a broad range of event, security configurations, and traffic flow attributes?
Correct Answer: A
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).
QUESTION NO: 10
An executive summary correlates Risk360 category-contribution views with audit commitments: identity risk has decreased, but data-loss risk is trending upward; business-unit mean time to remediate (MTTR) variance suggests uneven remediation; and leadership requests board-ready evidence of continuous improvement mapped to the NIST Cybersecurity Framework (CSF).
What is the appropriate next step based on this summary and goal?
An executive summary correlates Risk360 category-contribution views with audit commitments: identity risk has decreased, but data-loss risk is trending upward; business-unit mean time to remediate (MTTR) variance suggests uneven remediation; and leadership requests board-ready evidence of continuous improvement mapped to the NIST Cybersecurity Framework (CSF).
What is the appropriate next step based on this summary and goal?
Correct Answer: A
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).
QUESTION NO: 11
A contractor team in a regional lab must upload ZIP archives to an approved code repository but must not upload archives or executables to generic file-sharing sites. A sudden increase in renamed executables, such as an .exe file disguised with a .jpg extension, complicates monitoring.
Which action best applies the correct file-type policy to this team while aligning with security requirements?
A contractor team in a regional lab must upload ZIP archives to an approved code repository but must not upload archives or executables to generic file-sharing sites. A sudden increase in renamed executables, such as an .exe file disguised with a .jpg extension, complicates monitoring.
Which action best applies the correct file-type policy to this team while aligning with security requirements?
Correct Answer: D
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).
QUESTION NO: 12
An administrator is provisioning new App Connectors in Microsoft Azure. A new egress policy enforces TLS inspection for outbound traffic from the workload subnets.
Which action should the ZPA administrator take to prevent App Connector registration failures?
An administrator is provisioning new App Connectors in Microsoft Azure. A new egress policy enforces TLS inspection for outbound traffic from the workload subnets.
Which action should the ZPA administrator take to prevent App Connector registration failures?
Correct Answer: C
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).




