Weekend Sale Special Limited Time 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = drift75

Pass the Zscaler Digital Transformation Administrator ZDTA Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam ZDTA Premium Access

View all detail and faqs for the ZDTA exam


809 Students Passed

84% Average Score

92% Same Questions
Viewing page 9 out of 9 pages
Viewing questions 81-90 out of questions
Questions # 81:

How does a Zscaler administrator troubleshoot a certificate pinned application?

Options:

A.

They could look at SSL logs for a failed client handshake.

B.

They could reboot the endpoint device.

C.

They could inspect the ZIA Web Policy.

D.

They could look into the SaaS application analytics tab.

Questions # 82:

Which three levels of inspection are used by Zscaler for File Type Identification?

Options:

A.

Mime type, file extension and file size

B.

File extension, content type and file size

C.

Magic bytes, mime type and file extension

D.

Magic bytes, mime type and MS Office version

Questions # 83:

A regional hospital must provide a vendor with intermittent access to a legacy device-management application hosted on two on-premises servers. The vendor’s previous VPN caused noisy port scans to appear in logs and exposed nearby subnets to probing.

Which action should the administrator take to constrain access to the application while reducing lateral movement?

Options:

A.

Create ZPA Application Segments for the device-management FQDNs and ports, and enforce identity- and posture-based policies for the vendor group

B.

Configure DNS sinkholes to divert off-port vendor traffic and apply URL Filtering to suppress non-application flows

C.

Deploy a dedicated VLAN and a jump host near the application, and restrict traffic with subnet ACLs that limit the vendor to the jump host’s IP address

D.

Implement host-based firewall rules on both servers and advertise a reduced VPN route set to the vendor client

Questions # 84:

How can we protect the Zscaler Client Connector from unauthorized alterations to its files and registry settings?

Options:

A.

StrictEnforcement CLI Parameter of ZCC installation file

B.

TamperProofing options in Forwarding Profile

C.

AntiTampering CLI Parameter of ZCC installation file

D.

DisableTampering options in Forwarding Profile

Questions # 85:

A network team needs to prevent recurring congestion while meeting performance goals for critical applications. The team has several months of application-usage and bandwidth data across multiple sites.

What approach is most appropriate for avoiding congestion?

Options:

A.

Defer policy changes until user complaints stabilize, then adjust application classes based on the most recent incident set

B.

Analyze multiweek trends by location to identify consistently congested circuits and plan targeted capacity upgrades before peak periods

C.

Convert several high-usage business applications to the Silver class to distribute utilization more evenly across queues

D.

Relax quality-of-service constraints to reduce strict queue boundaries that may be causing packet drops

Questions # 86:

An organization mandates strict BYOD controls and does not permit endpoint agents on personal devices. Which Zscaler deployment approach aligns with this requirement while maintaining data protection for access to corporate applications?

Options:

A.

Adopt agentless access by combining Browser Isolation for SaaS applications and clientless ZPA for private applications

B.

Require self-enrollment in Zscaler Client Connector across personal endpoints to enforce forwarding profiles

C.

Depend on location-based rules and user agents to shape traffic from home and public networks

D.

Use per-application Zscaler Client Connector tunnels for unmanaged devices to segment private application access

Questions # 87:

Which API architectural style is used by Zscaler for Zero Trust Automation?

Options:

A.

JSON-RPC

B.

SOAP

C.

GraphQL

D.

REST

Questions # 88:

The Security Alerts section of the Alerts dashboard has a graph showing what information?

Options:

A.

Top 5 Malware Programs Detected

B.

Top 5 Viruses by Region

C.

Top 5 Threats by Systems Impacted

D.

Top 5 Unified Threat Yara Options

Questions # 89:

Malicious File Protection exclusions can be configured for which type of file?

Options:

A.

Files sent using the PPTP protocol

B.

Files sent using the SCP protocol

C.

Files sent using the RTSP protocol

D.

Password-encrypted files

Questions # 90:

A company observes risky uploads from unmanaged devices connecting over public Wi-Fi to cloud storage. The devices intermittently fail posture checks, and logs show inconsistent category enforcement.

Which action places the stricter control where it will be applied consistently to off-network traffic?

Options:

A.

Attach tenant-restriction profiles to a limited set of users in CASB and rely on inherited group mappings to constrain cloud activity

B.

Add connector-level ZPA policies that restrict FQDNs for storage endpoints and deny remote TCP ports used by synchronization clients

C.

Create a ZIA rule set scoped to roaming users and unauthenticated sessions, positioned early in the policy order to enforce stronger Cloud App Control and URL Filtering

D.

Deploy branch bandwidth classes that shape storage traffic in sublocations to reduce large upload attempts from remote users

Viewing page 9 out of 9 pages
Viewing questions 81-90 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.