Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
Content inspection of encrypted content at scale is widely available on most network-based security platforms, such as firewalls, to deploy.
The correct answer is B. False. In Zero Trust architecture, inspection of encrypted traffic is a major requirement because most internet traffic is now encrypted, and threats frequently hide inside TLS/SSL sessions. However, Zscaler's TLS/SSL inspection reference guidance explains that this type of inspection is not widely available at scale on most traditional network-based security platforms. Conventional security appliances typically experience a major reduction in effective traffic-handling capacity when decryption is enabled, which is one of the main reasons many legacy environments only inspect a limited subset of encrypted traffic.
This limitation is important in Zero Trust because selective inspection creates blind spots. If encrypted traffic is not inspected broadly, malware delivery, command-and-control activity, risky application behavior, and data exfiltration can bypass security controls. Zscaler's architecture is designed to move this function to a cloud-delivered inline security model so inspection can occur more consistently and at scale. Therefore, the statement is false because traditional firewalls and similar appliances have historically struggled to provide encrypted content inspection broadly and efficiently enough for modern Zero Trust needs.
How is risky behavior controlled in a Zero Trust architecture?
The correct answer is B. In Zero Trust architecture, risky behavior is controlled through continuous evaluation and policy-based response, not through static network constructs such as VLAN quarantine or dependence on standalone appliances. Zscaler's Zero Trust guidance emphasizes granular, context-based policies that evaluate the user, device, application, and surrounding conditions before and during access. In the ZPA architecture material, Zscaler states that applications should remain inaccessible unless the user is authorized, and policy should be independent of IP address or location.
The strongest architecture match is option B, because Zscaler documentation describes security outcomes such as inline prevention, deception, and threat isolation for compromised or risky users. That means when behavior becomes suspicious, later access attempts can be restricted, misdirected, or blocked based on updated policy context. This is fundamentally different from a legacy response such as placing a device permanently in a VLAN, which remains network-centric and coarse-grained. Logging alone also does not control risk, and simply deploying security appliances does not deliver Zero Trust by itself. Zero Trust controls risky behavior by dynamically adjusting enforcement based on observed context and threat posture, which best aligns with option B.
Should policy enforcement apply to all traffic, including from authorized initiators?
The correct answer is A. In Zero Trust architecture, policy enforcement applies to every access request, including requests from users who may ultimately be authorized. Zscaler documentation explains that when a user requests access, the platform evaluates context such as identity, posture, location, group membership, and application conditions, then enforces the matching policy. This means that authorized users are not exempt from policy; rather, policy is what determines whether they are authorized for that specific request.
ZPA guidance also states that access policies use explicit logic based on application segments, SAML attributes, client type, and posture profiles, and that traffic that does not match a policy is automatically blocked. This is fully consistent with the principle that no access should occur outside authorization and policy control.
Option A is the only choice that matches that Zero Trust principle, even though its wording is broader than the question. Options B, C, and D are incorrect because they either exclude authorized users from enforcement or imply unnecessary visibility to destinations. In Zero Trust, all traffic is subject to policy, and nothing should be allowed without authorization.
How are services protected in a legacy scenario when they are discoverable on the public Internet? (Select all that apply)
The correct answers are A, C, and D. In a legacy architecture, applications that are exposed and discoverable on the public Internet are usually protected by building a DMZ (demilitarized zone) and placing multiple security technologies in front of the service. This commonly includes a large security stack made up of separate appliances or services for functions such as load balancing, firewalling, distributed denial-of-service (DDoS) protection, and related edge security controls. A web application firewall (WAF) is also a standard protective element in these public-facing designs because it adds inspection and protection for web-based attack patterns and internet-originated abuse.
Option B, DAST, is not a correct answer because Dynamic Application Security Testing is a testing and assessment method, not a live architectural protection control that sits inline to defend exposed services in production. Zero Trust architecture contrasts with this legacy model by removing direct public discoverability and reducing dependence on a complex exposed edge stack. Instead of defending openly exposed applications with layered perimeter tools, Zero Trust aims to make applications less discoverable and access more identity- and policy-driven.
Connections approved by the Zero Trust Exchange must then enable permanent network-level access for at least 30 days.
The correct answer is B. False. Zero Trust architecture is specifically designed to avoid giving users broad, lasting network-level access after a connection is approved. Zscaler's Universal ZTNA guidance states that users connect directly to applications, not the network, which minimizes attack surface and eliminates lateral movement. This means approval is tied to the specific access request and the relevant context at that moment, not to an ongoing entitlement to the underlying network.
The idea of granting network-level access for 30 days is much closer to a legacy VPN model, where a user is placed onto a routable network and may retain broad reachability beyond the immediate business need. Zero Trust does the opposite. It verifies identity and context, evaluates policy, and then enforces a specific control outcome for that request. If the user's context changes, the policy outcome can also change. That is why Zero Trust is often described as dynamic and per-access, rather than static and persistent. A connection approved by the Zero Trust Exchange does not imply a long-term network privilege; it enables only the necessary application access under current policy conditions.
75 questions covering all exam domains, starting from $20
Exam domains verified against: Official Zscaler ZTCA exam guide, last checked September 2026.
Understand the shift from perimeter-based defense to continuous verification and the foundational principles of zero trust security. Learn how to establish zero trust connections and explore establishing zero trust connections through identity verification, content and access control, and policy enforcement.
Preparation for deeper technical learning on zero trust architecture implementation. This section sets the foundation for what you will encounter in the subsequent technical sections.
Examine the three elements of verifying identity and context: who is connecting (user and device identity), what is the access context (device security state and user behavior), and where the connection is going (destination and risk assessment). Learn architectural best practices and what Zscaler does for each element.
Sample question from this domain above: Q2
Master the three elements of controlling access and content: assess risk through adaptive control, prevent compromise through threat protection, and prevent data loss through data protection policies. Understand why each matters and what Zscaler solutions provide.
Learn how to enforce policies consistently across all access decisions and connections to applications. Understand why policy enforcement is important and how Zscaler implements policy enforcement in zero trust architectures.
Recap and consolidate learning throughout the zero trust journey. Review the complete architecture from identity verification through policy enforcement to reinforce concepts for successful exam preparation.
Common questions about the exam itself