Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
Zscaler Data Protection supports custom dictionaries. What actions can administrators take with these dictionaries to protect data in motion?
Custom DLP dictionaries let administrators define the exact business-specific content that should be treated as sensitive. They can include keywords, phrases, patterns, and regex expressions that match regulated data, internal identifiers, or proprietary terms. Option A (Define specific keywords, phrases, or patterns relevant to their organization's sensitive data policy) is correct because those dictionary entries are what Zscaler uses to detect data in motion.
Why the other options are incorrect:
B . Define specific governance and regulations relevant to their organization's sensitive data policy: Governance and regulatory labels help describe policy intent. A custom dictionary needs the actual sensitive-data tokens: keywords, phrases, or patterns.
C . Define specific SaaS tenant relevant to their organization's sensitive data policy: A SaaS tenant value controls which tenant or instance users may access. Custom dictionaries define content patterns, not tenant boundaries.
D . Define specific file types relevant to their organization's sensitive data policy: File type definitions classify files such as executables or archives. Custom DLP dictionaries define sensitive words, phrases, regexes, or identifiers.
For a deployment using both ZIA and ZPA set of services, what is the best authentication solution?
For a deployment using both ZIA and ZPA, the cleanest authentication model is SAML for both services. A shared SAML IdP gives consistent identity, attributes, and group context for internet/SaaS access and private-application access. Option C (Configure Authentication using SAML on both ZIA and ZPA) is correct because using SAML on both ZIA and ZPA provides unified authentication.
Why the other options are incorrect:
A . Use forms Authentication in ZPA and SAML in ZIA: SAML provides browser-based federation by carrying signed assertions from the identity provider to the service provider.
B . Use forms Authentication in ZIA and SAML in ZPA: SAML provides browser-based federation by carrying signed assertions from the identity provider to the service provider.
D . Use forms Authentication for both ZIA and ZPA: Forms authentication is an application-login method. ZIA and ZPA authentication should be based on the supported identity integration model in the scenario, not generic forms auth.
A sequence in the Administrator Audit Log shows several failed sign-ins from an unfamiliar location, followed by a successful administrator sign-in and a near-immediate role upgrade on the same identity.
Which entry combination constitutes the clearest escalation indicator requiring a containment step?
Option D combines two high-confidence indicators: unexpected successful access to a privileged identity and an immediate increase in that identity's permissions. Zscaler records administrator login and configuration activity in audit data; its 2024 Audit Logs update states that the portal records the login name and IP address of administrators who sign in and add or modify configurations. Zscaler also supports restricting administrator access by source IP through Administrator Management settings. The temporal link between an untrusted source and role elevation therefore warrants containment, credential or session revocation, and investigation. The other choices contain either expected administrative maintenance, nonprivileged lockouts, or documented token and password events. They may merit review, but they do not demonstrate the same direct path from suspicious access to privilege escalation.
An administrator suspects that users in Europe are being routed to a distant service edge, inflating latency before traffic reaches a SaaS provider.
Which ZDX diagnostic provides evidence of inefficient client-to-service-edge routing?
CloudPath supplies path-level evidence rather than an indirect symptom. Zscaler's CloudPath evaluation documentation shows that the diagnostic presents the network path and reports latency, packet loss, and jitter across hops. Examining the early client-to-Zscaler portion reveals whether European users take an unexpectedly long route, encounter excessive hops, or accumulate latency before reaching the service edge. That directly tests the routing hypothesis and helps separate local, ISP, Zscaler-edge, and downstream SaaS segments. Alert thresholds can reveal that experience degraded but cannot prove the path was inefficient. CPU and memory telemetry tests endpoint-resource causes, not service-edge selection. Page Fetch Time confirms application slowness at a high level, yet many application, server, and network factors influence it. CloudPath is therefore the defensible diagnostic for locating where path delay begins.
Malicious File Protection exclusions can be configured for which type of file?
Comprehensive and Detailed 100 to 150 words of Explanation From Zscaler Digital Transformation Administrator topics:
Password-encrypted or password-protected files can be addressed through Malware Protection security exceptions, making D correct. Because the service cannot decrypt protected content without the password, it cannot inspect the internal payload in the same manner as an ordinary unencrypted file. ZIA therefore provides policy handling for this condition, allowing administrators to define the appropriate exception or control based on organizational risk. PPTP, SCP, and RTSP are network or application protocols; they are not file conditions used as the Malicious File Protection exclusion described in the question. Administrators should still treat password-protected files cautiously because attackers can use encryption to conceal malicious payloads from content inspection. Zscaler's official security-exception guidance explicitly includes password-protected files, confirming that option D identifies the supported file category.
What does the user risk score enable a user to do?
A user risk score is an adaptive signal used to tune security policy around individual user exposure. It does not by itself prove compromise, but it helps administrators identify risky users and apply stronger monitoring, access restrictions, or control requirements. Option C (Configure stronger user-specific policies to monitor & control user-level risk exposure) is correct because the value of the score is operational: it supports stronger user-specific policies and risk-based monitoring.
Why the other options are incorrect:
A . Compare the user risk score with other companies to evaluate users vs other companies: Benchmarking users against other companies would be an executive comparison metric. User risk score is used inside the tenant to tune user-level controls.
B . Determine whether or not a user is authorized to view unencrypted data: Access to unencrypted data is a data-handling and policy decision. User risk score measures user exposure and behavior risk; it is not a decryption authorization switch.
D . Determine if a user has been compromised: A high user risk score can indicate suspicious behavior, but it is not a definitive compromise verdict. Administrators use it to strengthen monitoring and policy first.
Exam domains verified against: Official Zscaler ZDTA exam guide, last checked October 2026.
Covers authentication and authorization through SAML, SCIM, OIDC, ZIdentity Administration, and policy and audit log management. Understand how to configure identity integration with the Zscaler Zero Trust Exchange and manage user access controls.
Sample question from this domain above: Q5
Addresses device posture, trusted networks, browser access, TLS/SSL inspection, and policy framework configuration for internet, private, and digital experience access. Master policy application across multiple connectivity scenarios and deployment models.
Focuses on Zscaler's platform services suite including device posture, TLS inspection, and policy framework for internet access, private access, and digital experience. Learn integration of platform capabilities with overall security architecture.
Covers cloud app control, URL filtering, file type control, bandwidth control, Microsoft 365 integration, private application access, segmentation, and firewall capabilities. Configure access policies that enforce granular application and network control.
Sample question from this domain above: Q2
Includes malware protection, advanced threat protection, command and control channel detection, deception, identity threat detection and response, intrusion prevention, private app protection, browser isolation, and detection and response capabilities. Implement multi-layered threat defenses across the platform.
Sample question from this domain above: Q4
Encompasses Zscaler data protection including AI-driven data discovery, secure data in motion, secure SaaS data, secure cloud and endpoint data, and secure BYOD. Apply data protection controls across cloud and on-premise data flows.
Covers Zscaler's comprehensive risk management suite including Zscaler Risk 360, unified vulnerability management, deception, identity protection, and breach predictor capabilities. Use risk scoring and dashboards to make informed security decisions.
Focuses on ZDX score, architecture, features, functionality, and use cases for monitoring and optimizing user experience. Leverage ZDX tools to measure and improve application and network performance metrics.
Addresses API capabilities and Zscaler APIs for automation and integration tasks. Understand how to use the One API approach for automating administrative and policy enforcement workflows.
Common questions about the exam itself