Platform Services
In a dual-arm Virtual Service Edge deployment, what correctly describes
the traffic flow?
a) Ingress → LB VIP → Service Edge → Internet (DSR) → Client
b) Ingress → LB VIP → Service Edge → External IP → Internet → DSR →
Client
c) Ingress → External IP → Service Edge → LB VIP → Internet → Client
d) Ingress → Service Edge → External IP → Internet → LB VIP → Client -
Correct Answer ✔️✔️b) Ingress → LB VIP → Service Edge →
External IP → Internet → DSR → Client
A company needs to deploy Service Edges in their VMware
environment. Which combination of requirements must be met for
optimal performance?
,a) ESXi 6.7+, 8 vCPUs, 16GB RAM, SSL accelerator
b) vSphere 7.0+, 4 vCPUs, 32GB RAM, dual-arm configuration
c) ESXi 6.5+, 16 vCPUs, 8GB RAM, single-arm deployment
d) vSphere 6.7+, 8 vCPUs, 32GB RAM, dedicated NIC - Correct Answer
✔️✔️a) ESXi 6.7+, 8 vCPUs, 16GB RAM, SSL accelerator
An enterprise wants to implement dynamic routing based on user
location and network context. Which combination of configurations is
required?
a) PAC file with ${Source IP} variables and DNS resolution checks
b) SIPA with geo-localization and trusted networks
c) Direct Server Return with load balancer VIPs
d) App Connector groups with location-based routing - Correct
Answer ✔️✔️a) PAC file with ${Source IP} variables and DNS
resolution checks
, In a SIPA deployment, why is it crucial to exclude the application from
Client Forwarding Policy?
a) To prevent direct ZPA connections bypassing ZIA inspection
b) To enable Direct Server Return functionality
c) To maintain source IP preservation
d) To ensure proper load balancing - Correct Answer ✔️✔️a) To
prevent direct ZPA connections bypassing ZIA inspection
Which scenario would NOT be an appropriate use case for Source IP
Anchoring?
a) Office 365 step-up authentication bypass
b) Legacy application IP-based access control
c) Internal application access control
d) Geo-specific content delivery - Correct Answer ✔️✔️c)
Internal application access control