ZSCALER ZDTA PRACTICE
EXAM 60 QUESTIONS
Question 1: A company wants user and group accounts created in Zscaler
automatically while keeping authentication at its corporate identity provider. Which combination best follows Zscaler's recommended identity design?
Choices:
1) SAML for provisioning and SCIM for authentication 2) SCIM for provisioning and SAML for authentication 3) LDAP for provisioning and local passwords for authentication 4) OIDC for provisioning and PAC les for authentication
Correct Answer: SCIM for provisioning and SAML for authentication
Explanation: Zscaler recommends SCIM to provision and synchronize users and groups and SAML to authenticate users through the identity provider. SCIM handles lifecycle data; SAML handles federated sign-on.
Question 2: An IdP sends the attributes Department=Finance and
EmploymentType=Employee for Maria. Zscaler policy grants the Finance- Page 1
Employees group access to a nance SaaS app. What must occur for Maria to receive that policy?
Choices:
1) Her source IP must be added to a static location 2) Her browser must use an explicit proxy on port 80 only 3) Her IdP attributes must map her into the Finance-Employees group used by the policy 4) Her device must be placed in an App Connector group Correct Answer: Her IdP attributes must map her into the Finance-Employees group used by the policy Explanation: Identity attributes from the IdP are used to place users into the relevant Zscaler groups. When the policy references that group, Maria receives the policy after her identity/ group mapping is available to Zscaler.
Question 3: An administrator creates a new ZIdentity group for contractors and
wants only that group to receive a restricted access policy. What is the most important policy-side step?
Choices:
1) Reference the new contractor group in an enabled policy rule with the intended access criteria 2) Convert the group into a trusted network 3) Assign the group an App Connector provisioning key 4) Add every contractor's public IP to a destination group Correct Answer: Reference the new contractor group in an enabled policy rule with the intended access criteria Explanation: Creating the identity group alone does not dene resource access. The administrator must use that group as a criterion in the appropriate enabled policy rule so the intended controls are actually enforced.Page 2
Question 4: A security manager suspects that an administrator granted themselves broader privileges shortly before a policy was changed. Which Zscaler record should be reviewed rst?
Choices:
1) Web Insights 2) Sandbox report 3) Cloud Path history 4) Administrator Audit Log
Correct Answer: Administrator Audit Log
Explanation: The Administrator Audit Log records administrative actions and is the primary evidence source for investigating role changes, conguration changes, and possible unauthorized privilege escalation.
Question 5: A contractor uses an unmanaged personal laptop and needs access to
one internal HTTPS application. The company will not install endpoint software on contractor devices. Which approach best ts least privilege?
Choices:
1) Give the contractor a full-tunnel VPN 2) Publish the internal subnet through a GRE tunnel 3) Use ZPA Browser Access for the specic web application 4) Create a static ZIA location for the contractor's home network Correct Answer: Use ZPA Browser Access for the specic web application Explanation: ZPA Browser Access can provide controlled browser-based access to supported private web applications without requiring Zscaler Client Connector on the unmanaged device, avoiding network-level access.Page 3