Skip to content

ZDTA Practice Questions

Prepare for ZDTA with more than an answer.

204 questions in the full set20 sample questionsUpdated Aug 11, 2025
Exam fee
$300 USD
Level
Professional
Valid for
Not specified
Domains covered on the exam 7
  1. Identity Services22%
  2. Connectivity Services20%
  3. Access Control Services15%
  4. Cyberthreat Protection Services20%
  5. Data Protection Services13%
  6. Zscaler Digital Experience7%
  7. Zero Trust Automation3%
  1. 1

    True or False: Zscaler Browser Isolation executes web content in a remote, disposable container in the Zscaler cloud and streams only safe pixels to the end-user's browser, completely isolating the user's device from direct exposure to web-based threats.

    Show answer details

    Correct answer: A

    This statement is true. This process is the core concept of Zscaler's Browser Isolation. It creates an 'air gap' between the user's endpoint and the internet, ensuring that any malicious code (like malware or ransomware) is executed in the isolated cloud container and never reaches the user's device, thus preventing compromise.

  2. 2

    A company is migrating from a traditional hub-and-spoke network with VPN to a Zero Trust architecture with Zscaler. The primary goal is to provide users with fast, direct access to both SaaS applications and internal applications hosted in Azure, regardless of user location. Which two Zscaler products are fundamental to achieving this transformation? (Select TWO)

    Show answer details

    Correct answer: A, B

    ZIA is the Secure Web Gateway component that provides secure, direct-to-internet access for users connecting to SaaS and public web applications. It replaces the need to backhaul internet traffic through a central data center.

    ZPA is the Zero Trust Network Access (ZTNA) solution that replaces legacy VPN. It provides secure access to internal applications hosted in data centers or public clouds like Azure, without placing users on the network.

  3. 3

    An administrator notices that the ZDX score for Microsoft Teams is consistently low for users in the Asia-Pacific region. They need to understand if the performance issue is caused by the users' local Wi-Fi, their ISP, the Zscaler infrastructure, or Microsoft's network. What is the most effective ZDX view for this root cause analysis?

    sequenceDiagram participant User as User Device participant WiFi as Local WiFi participant ISP participant Zscaler as Zscaler Cloud participant Microsoft as Microsoft Network User->>WiFi: Teams Traffic WiFi->>ISP: ISP->>Zscaler: Zscaler->>Microsoft: Note over User, Microsoft: ZDX measures latency at each hop
    Show answer details

    Correct answer: C

    The ZDX CloudPath view is specifically designed to visualize the end-to-end network path from the user's device to the application. It breaks down the path into distinct segments: User, WiFi, LAN, ISP, Zscaler, and Application. By examining the latency and packet loss metrics for each segment in the CloudPath view, the administrator can immediately identify which part of the journey is introducing the performance degradation for the users in that region.

  4. 4

    To comply with data residency regulations, a German company must ensure that all of its employees' web traffic, including policy enforcement and logging, is processed exclusively within data centers located in the European Union. Which Zscaler configuration is essential to meet this requirement?

    Show answer details

    Correct answer: B

    Zscaler operates multiple, separate cloud infrastructures to meet data sovereignty and residency requirements. The zscaler.de cloud is specifically for customers who require their data to be processed and stored within Germany, in compliance with strict regulations like GDPR. By having their tenant provisioned on this specific cloud, the company ensures that all administration, policy enforcement, and logging occur within the designated jurisdiction.

  5. 5

    A security architect is designing a ZPA deployment for high availability. They have two data centers, DC1 and DC2. They need to ensure that if all App Connectors in DC1 fail, users can still access applications hosted in DC1. What is the recommended design to achieve this?

    graph TD subgraph User ZCC[Zscaler Client Connector] end subgraph ZscalerCloud[Zscaler Cloud] ZPA end subgraph DC1[Data Center 1] App1[(App 1)] CG1[Connector Group 1] end subgraph DC2[Data Center 2] CG2[Connector Group 2] end ZCC --> ZPA ZPA --> CG1 ZPA --> CG2 CG1 --> App1 CG2 -.-> App1
    Show answer details

    Correct answer: B

    ZPA's high availability model allows App Connectors from different physical locations (and different Connector Groups) to service the same Server Group, provided they have network connectivity to the application servers. By creating a Server Group for DC1 applications and associating it with a Connector Group that includes connectors from both DC1 and DC2, ZPA can automatically failover traffic to the connectors in DC2 if the ones in DC1 become unavailable.

  6. 6

    A financial services firm is deploying Zscaler Private Access (ZPA) and must ensure that developers connecting from unmanaged personal devices (BYOD) can only access a specific set of non-sensitive development tools. Access from corporate-managed devices should be unrestricted. The firm uses Okta for identity management. Which ZPA feature is the most precise and secure mechanism to enforce this policy?

    Show answer details

    Correct answer: B

    Device Posture Profiles within Zscaler Client Connector are the designed mechanism for differentiating access rights based on the security state and ownership of a device. By creating a posture profile that checks for a corporate-issued certificate, an administrator can create a ZPA Access Policy that grants different levels of access to users on managed versus unmanaged devices. This is more secure and scalable than managing separate application segments or relying on IdP groups alone, which don't verify the device state.

  7. 7

    A global logistics company is using Zscaler Internet Access (ZIA) with SSL inspection enabled. The finance department uses a legacy desktop application that communicates with a third-party payment processing service. This application ceases to function correctly for all finance users. Initial troubleshooting reveals the application uses certificate pinning. What is the most appropriate and secure way to restore functionality without compromising the company's overall security posture?

    Show answer details

    Correct answer: C

    Certificate pinning forces an application to only trust a specific server certificate. SSL inspection breaks this by design. The most secure and precise method to resolve this is to bypass SSL inspection only for the specific FQDNs used by the application, and only for the users who need it (the Finance department). Using FQDNs is more reliable than IP addresses, which can change. Disabling inspection for the entire group or globally would create a significant security gap.

  8. 8

    A manufacturing company wants to prevent engineers from accidentally leaking proprietary CAD designs to their personal cloud storage accounts (e.g., Google Drive, Dropbox) while still allowing them to access corporate-sanctioned cloud applications. Which combination of Zscaler features should an administrator configure to enforce this policy effectively? (Select TWO)

    Show answer details

    Correct answer: B, C

    Tenant Restriction is a specific feature within Cloud App Control that allows administrators to permit access to SaaS applications like Google Drive but restrict logins to specific corporate tenants, effectively blocking personal accounts.

    DLP is essential for inspecting the content of uploads. By configuring it to identify CAD file types and proprietary design patterns, it can block the exfiltration of sensitive data, even if the user is attempting to upload to a permitted site.

  9. 9

    A DevOps engineer is troubleshooting a ZPA deployment where an application segment for a new microservice is unreachable. The App Connector group has been provisioned in AWS and shows as healthy in the ZPA Admin Portal. The Server Group is configured with the correct FQDN of the microservice. The engineer confirms that the security groups in AWS allow traffic from the App Connector's IP to the microservice. What is the most likely remaining cause of the connectivity failure?

    Show answer details

    Correct answer: C

    A common ZPA deployment issue is DNS resolution. The App Connector itself must be able to resolve the FQDNs of the applications it is serving. If the App Connector is using a generic public DNS server, it will likely fail to resolve internal, private FQDNs. The App Connector's underlying OS must be configured to use an internal DNS server (like Amazon Route 53 Resolver for a VPC) that can resolve the application's address.

  10. 10

    A security team observes alerts from Zscaler's Deception feature indicating that a user workstation has attempted to connect to a decoy server configured as a file share. This action is a strong indicator of a compromised host attempting lateral movement. What Zscaler feature can provide the most immediate, rich context about the user's other recent activities, both malicious and benign, across internet and SaaS applications to aid the investigation?

    Show answer details

    Correct answer: C

    ZIA's Web Insights Logs provide a detailed, real-time record of every web transaction for a specific user. After a Deception alert, an analyst can pivot directly to the Web Insights Logs, filter by the user involved, and see all their recent web activity, including URLs visited, cloud applications used, threat categories triggered, and data exfiltration attempts. This provides the richest context for understanding the scope of the compromise.

Create an account to continue.