ZDTE – ZSCALER DIGITAL TRANSFORMATION ENGINEER LATEST
VERSION EXAM PREP - VERIFIED QUESTIONS AND ANSWERS -
COMPLETE COVERAGE 2026
1. What are the three foundational layers of Zscaler's architecture? Central
Authority (control plane), Enforcement Nodes (Public Service Edges), and
Logging Services (logging plane)
2. What is the role of the Central Authority? Manages authentication, policy
orchestration, availability, and directs users to the best Service Edge
3. What is the function of Public Service Edges? Enforce security policies in
real-time and process user traffic
4. What is the role of the Logging Services plane? Stores encrypted,
compressed, and obfuscated logs for visibility and compliance
5. What does single-scan, multi-action processing mean? A packet is scanned
once but evaluated by multiple security engines simultaneously
6. Which protocol does Z-Tunnel 1.0 support? HTTP and HTTPS only (ports
80/443)
7. Which Zscaler tunnel mode captures all traffic including non-web
protocols? Z-Tunnel 2.0
8. What is the max throughput per GRE tunnel without NAT? 1 Gbps
9. What is the max throughput per GRE tunnel behind NAT? 250 Mbps
10. How can you achieve 2 Gbps GRE throughput? Deploy two primary and
two backup GRE tunnels with unique public IPs
11. What is the main purpose of Source IP Anchoring? To preserve a
consistent source IP for apps requiring IP-based allowlisting
12. What is a Zscaler Subcloud? A subset of Public Service Edges defined to
restrict user traffic to specific nodes
, 13. What DNS hostname is used when connecting to a subcloud?
gateway.subcloud.zscaler.net
14. What is the default hostname for ZIA Public Service Edge connections?
gateway.zscaler.net
15. What Zscaler service provides licensed connectivity inside China? China
Premium Access
16. Which two telecoms dominate internet traffic inside China? China
Telecom and China Unicom
17. What maximum throughput is supported per GRE tunnel according to
Zscaler best practice? 1 Gbps
18. What is the main difference between Forwarding PAC and App Profile
PAC? Forwarding PAC decides proxy routing; App Profile PAC decides which
Zscaler node processes traffic
19. What Zscaler tool streams logs to SIEM in near real-time? Log
Streaming Service (LSS)
20. What service compresses and streams logs efficiently? Nanolog
Streaming Service (NSS)
21. What is the order of policy enforcement in ZIA? Exceptions →
Malicious URL check → Cloud App Control → URL filtering → Browser
control → Country restrictions → IPS → Bandwidth controls → DLP
22. Which Zscaler product provides clientless browser-based access to
apps? Browser Access
23. What Zscaler service simplifies workload-to-workload and workload-
to-internet connectivity in cloud VPCs/VNets? Zscaler Cloud Connector
24. What Zscaler product securely connects IoT/OT devices at branch
sites? Zscaler Branch Connector
25. Which Zscaler platform service is customer-deployed for private
enforcement? ZIA/ZPA Private Service Edge
26. What is the purpose of Public Service Edges? Globally distributed
enforcement nodes for internet and SaaS traffic inspection
27. Which Zscaler service enforces DNS security? Zscaler DNS Control
28. What is Tenant Restrictions used for? To control which SaaS tenants
users can authenticate into (e.g., restrict Microsoft 365 logins)
VERSION EXAM PREP - VERIFIED QUESTIONS AND ANSWERS -
COMPLETE COVERAGE 2026
1. What are the three foundational layers of Zscaler's architecture? Central
Authority (control plane), Enforcement Nodes (Public Service Edges), and
Logging Services (logging plane)
2. What is the role of the Central Authority? Manages authentication, policy
orchestration, availability, and directs users to the best Service Edge
3. What is the function of Public Service Edges? Enforce security policies in
real-time and process user traffic
4. What is the role of the Logging Services plane? Stores encrypted,
compressed, and obfuscated logs for visibility and compliance
5. What does single-scan, multi-action processing mean? A packet is scanned
once but evaluated by multiple security engines simultaneously
6. Which protocol does Z-Tunnel 1.0 support? HTTP and HTTPS only (ports
80/443)
7. Which Zscaler tunnel mode captures all traffic including non-web
protocols? Z-Tunnel 2.0
8. What is the max throughput per GRE tunnel without NAT? 1 Gbps
9. What is the max throughput per GRE tunnel behind NAT? 250 Mbps
10. How can you achieve 2 Gbps GRE throughput? Deploy two primary and
two backup GRE tunnels with unique public IPs
11. What is the main purpose of Source IP Anchoring? To preserve a
consistent source IP for apps requiring IP-based allowlisting
12. What is a Zscaler Subcloud? A subset of Public Service Edges defined to
restrict user traffic to specific nodes
, 13. What DNS hostname is used when connecting to a subcloud?
gateway.subcloud.zscaler.net
14. What is the default hostname for ZIA Public Service Edge connections?
gateway.zscaler.net
15. What Zscaler service provides licensed connectivity inside China? China
Premium Access
16. Which two telecoms dominate internet traffic inside China? China
Telecom and China Unicom
17. What maximum throughput is supported per GRE tunnel according to
Zscaler best practice? 1 Gbps
18. What is the main difference between Forwarding PAC and App Profile
PAC? Forwarding PAC decides proxy routing; App Profile PAC decides which
Zscaler node processes traffic
19. What Zscaler tool streams logs to SIEM in near real-time? Log
Streaming Service (LSS)
20. What service compresses and streams logs efficiently? Nanolog
Streaming Service (NSS)
21. What is the order of policy enforcement in ZIA? Exceptions →
Malicious URL check → Cloud App Control → URL filtering → Browser
control → Country restrictions → IPS → Bandwidth controls → DLP
22. Which Zscaler product provides clientless browser-based access to
apps? Browser Access
23. What Zscaler service simplifies workload-to-workload and workload-
to-internet connectivity in cloud VPCs/VNets? Zscaler Cloud Connector
24. What Zscaler product securely connects IoT/OT devices at branch
sites? Zscaler Branch Connector
25. Which Zscaler platform service is customer-deployed for private
enforcement? ZIA/ZPA Private Service Edge
26. What is the purpose of Public Service Edges? Globally distributed
enforcement nodes for internet and SaaS traffic inspection
27. Which Zscaler service enforces DNS security? Zscaler DNS Control
28. What is Tenant Restrictions used for? To control which SaaS tenants
users can authenticate into (e.g., restrict Microsoft 365 logins)