ZSCALER EDU 200 QUESTIONS AND ANSWERS
What is used to detect if a SAML assertion was modified after being issued? - Answers
:Digital Signatures
How is a SAML assertion delivered to Zscaler? - Answers :The IdP sends it via the
user's browser to the SP
(Uses a form POST submitted via JavaScript)
In what way does Zscaler's Identity Proxy enable authentication to SaaS applications? -
Answers :Issuing SAML assertions
How does Zscaler Internet Access authenticate users? (Select 3)
Options:
- SAML
- SCIM
- LDAP
- Hosted Database - Answers :SAML, LDAP, Hosted Database
How does Zscaler Private Access authenticate end users? - Answers :SAML
Which services can coexist on an Application Segment? - Answers :Isolation, Browser
Access, and Inspection
How often does the Zscaler Client Connector check for software updates? - Answers
:Every 2 hours
Which check guarantees identification of a corporate-managed device by the Zscaler
Client Connector? - Answers :Client Certificate & Non-Exportable private key
You want Zscaler Client Connector to automatically redirect to your corporate SAML
IDP on launch. Which installer options should you configure to do so? (Select 2) -
Answers :cloudName
userDomain
Where is the control to prevent a user from exiting Zscaler Client Connector? - Answers
:In the Application Profile
When moving from an Explicit Proxy to a Tunneled/Transparent Proxy - what, if any,
effects will be seen on the client? (Select 3)
Options:
- No Effect
- The client will always resolve DNS
, - The client browser needs re-configuration
- Authenticated websites may no longer work
- An Explicit Proxy and a Transparent Proxy are the same thing - Answers :The client
will always resolve DNS
The client browser needs re-configuration
Authenticated websites may no longer work
What benefits does a Zscaler Tunnel have over other forwarding mechanisms for
Zscaler Client Connector? - Answers :Tunnels encapsulate traffic and authenticate to
the Zero Trust Exchange
Browser Based Access enables what kinds of applications to be published? - Answers
:HTTP and HTTPS
Why is Z-Tunnel 2.0 superior to Z-Tunnel 1.0? (Select 3)
Options:
- Provides a control channel to update device
- Faster transport mechanism
- Allows multicast traffic
- Enables Cloud Firewall
- Z-Tunnel 1.0 is no longer supported - Answers :Provides a control channel to update
device
Faster transport mechanism
Enables Cloud Firewall
What conditions exist for Trusted Network Detection? - Answers :DNS Search Domain,
DNS Server, Hostname Resolution
A server group maps _____ to ____? - Answers :App Connectors Groups to Application
Segments
Why is SSL/TLS inspection critical in a security architecture? - Answers :85-90% of all
internet traffic is SSL/TLS encrypted (including threats), as protocols such as HTTP/2
are only delivered over TLS; SSL/TLS inspection allows you to inspect the connection
and look at the full payload, including HTTP headers, which is important to be able to
block malicious traffic and prevent sensitive data from leaking out of an organization
What is the fastest way to change a user's access entitlements? - Answers :Send
different attributes via SCIM
In order for Zscaler to enforce policy based on accessing devices, what method is best
used by IdPs to share information about a user's accessing device? - Answers :SAML
Privileged Remote Access supports which protocols? (Select 2)
What is used to detect if a SAML assertion was modified after being issued? - Answers
:Digital Signatures
How is a SAML assertion delivered to Zscaler? - Answers :The IdP sends it via the
user's browser to the SP
(Uses a form POST submitted via JavaScript)
In what way does Zscaler's Identity Proxy enable authentication to SaaS applications? -
Answers :Issuing SAML assertions
How does Zscaler Internet Access authenticate users? (Select 3)
Options:
- SAML
- SCIM
- LDAP
- Hosted Database - Answers :SAML, LDAP, Hosted Database
How does Zscaler Private Access authenticate end users? - Answers :SAML
Which services can coexist on an Application Segment? - Answers :Isolation, Browser
Access, and Inspection
How often does the Zscaler Client Connector check for software updates? - Answers
:Every 2 hours
Which check guarantees identification of a corporate-managed device by the Zscaler
Client Connector? - Answers :Client Certificate & Non-Exportable private key
You want Zscaler Client Connector to automatically redirect to your corporate SAML
IDP on launch. Which installer options should you configure to do so? (Select 2) -
Answers :cloudName
userDomain
Where is the control to prevent a user from exiting Zscaler Client Connector? - Answers
:In the Application Profile
When moving from an Explicit Proxy to a Tunneled/Transparent Proxy - what, if any,
effects will be seen on the client? (Select 3)
Options:
- No Effect
- The client will always resolve DNS
, - The client browser needs re-configuration
- Authenticated websites may no longer work
- An Explicit Proxy and a Transparent Proxy are the same thing - Answers :The client
will always resolve DNS
The client browser needs re-configuration
Authenticated websites may no longer work
What benefits does a Zscaler Tunnel have over other forwarding mechanisms for
Zscaler Client Connector? - Answers :Tunnels encapsulate traffic and authenticate to
the Zero Trust Exchange
Browser Based Access enables what kinds of applications to be published? - Answers
:HTTP and HTTPS
Why is Z-Tunnel 2.0 superior to Z-Tunnel 1.0? (Select 3)
Options:
- Provides a control channel to update device
- Faster transport mechanism
- Allows multicast traffic
- Enables Cloud Firewall
- Z-Tunnel 1.0 is no longer supported - Answers :Provides a control channel to update
device
Faster transport mechanism
Enables Cloud Firewall
What conditions exist for Trusted Network Detection? - Answers :DNS Search Domain,
DNS Server, Hostname Resolution
A server group maps _____ to ____? - Answers :App Connectors Groups to Application
Segments
Why is SSL/TLS inspection critical in a security architecture? - Answers :85-90% of all
internet traffic is SSL/TLS encrypted (including threats), as protocols such as HTTP/2
are only delivered over TLS; SSL/TLS inspection allows you to inspect the connection
and look at the full payload, including HTTP headers, which is important to be able to
block malicious traffic and prevent sensitive data from leaking out of an organization
What is the fastest way to change a user's access entitlements? - Answers :Send
different attributes via SCIM
In order for Zscaler to enforce policy based on accessing devices, what method is best
used by IdPs to share information about a user's accessing device? - Answers :SAML
Privileged Remote Access supports which protocols? (Select 2)