ZDTE Study Guide Questions and Answers
100% Correct
1. What technology can help in protecting users from websites running never
seen before malicious javascript? - ANSWER Browser Isolation can be used
to safely render websites through a pixelated stream eliminating any
malicious javascript from executing
2. What is the "Cloud Effect" as it pertains to Cloud Sandbox? - ANSWER The
MD5 hash of a file deemed malicious from Sandbox or threat feeds is
uploaded to the cloud so that at any time any customer sees the same file, it
will be blocked
3. DP: What do we do if a customer changes the default risk score of an
application? - ANSWER WE immediately readjust that risk score for that
specific tenant, for that specific customer.
4. DP: How does Shadow IT visibility influence your policy constructions? -
ANSWER Based on risk score all apps that are higher than risk 4 should be
auto blocked. Granular policy (ie all apps not PCI-certified cannot be used
by finance team).
5. DP: How does Zscaler classify the documents, and the data, automatically
without an admin creating any rules? - ANSWER We use AI/ML we
collected millions of docs, anonymized the data, and fed it to ALML
6. DP: What does cloud application control allow you to do? - ANSWER
Create excess control policies based on where the user is going and their
activities
7. DP: Which Zscaler capability protects your sensitive data contained in
images? - ANSWER OCR
8. DP: Which inline data protection capability differentiates between different
instances of the same tenant and enables us to apply very granular policies? -
ANSWER Posture management (WRONG?)
, 2
9. State whether the following statement is true or false: Zscaler can
automatically classify documents and data without a data protection admin
creating any rules, regex and policies. - ANSWER TRUE
10.Select options that are true regarding Zscaler Outbound Email DLP (Select
three). - ANSWER (1) Using outbound and inbound connectors, as well as
mail flow rules, the Exchange server sends email to, and receives email
from, the Zscaler smart host.
(2) The Zscaler smart host receives the email and sends it to the Zscaler DLP
service for inspection. The Zscaler DLP service then inspects the email
content for sensitive data, adding headers that define DLP actions to emails
that trigger outbound email policy.
(3) When the Exchange server receives inspected email from the Zscaler
smart host, it uses those headers to determine enforcement actions
11.DP :What is parallel processing? - ANSWER Even when there is a match,
we will continue to go down to the policy engine and be able to execute all
the policies before we stop.
12.DP at REST: WHat are the two focus areas of protecting data at rest? -
ANSWER (1) how to prevent data loss. (2) How to protect against known
and unknown threats?
13.DP: What is the first step in the process of data at rest scanning? - ANSWER
Ultize the same DLP policies you built for inline and identify those assets in
the cloud.
14.DP : What action does Zscaler take when it identifies an unknown content? -
ANSWER Completely unknown assets are sandboxed and wait for a verdict
from our cloud sandbox and trigger remediation actions
15.DP: What action does Zscaler take when it identifies malicious content? -
ANSWER Triggers quarantine
16.DP: While protecting against malware, what action will Zscaler take if an
external colloborator injected a PDF that happens to be a known malware? -
ANSWER Zscaler will identify that the PDF has malicious content and will
trigger quarantine action.
, 3
17.DP: As part of protection against malware, what action will Zscaler take
when it finds an asset that is completely unknown? - ANSWER Zscaler will
sandbox the unknown content, wait for the verdict from the cloud sandbox
and accordingly trigger a remediation action.
18.DP: State whether the following statement is true or false: Incident
Management is a policy protects your traffic from fraud, unauthorized
communication, and other malicious objects and scripts. - ANSWER
FALSE
19.When you do data loss prevention (DLP) for your data at rest scanning, why
do we utilize the same DLP policies that you have built for your in-line data
protection? - ANSWER We utilize those DLP policies to identify, analyze,
and resolve misconfigurations.[oddly worded I think I got this wrong]
20.What is Workflow Automation? - ANSWER It is a capability that allows
organizations to automate Incident Management in order to remediate data
protection incidents
21.State whether the following statement is true or false: In case of on -prem
incident receiver, you can setup a VM and deploy it to archive all the DLP
violations - ANSWER FALSE... maybe
22.State whether the following statement is true or false: Incident Management
is a policy protects your traffic from fraud, unauthorized communication,
and other malicious objects and scripts. - ANSWER TRUE
23.Whats a common feature of SD-WAN GRE Tunnels and IPSec Tunnels? -
ANSWER Provide secure communication between different network
segments
24.What are the challenges of extending legacy network and security to the
public cloud? - ANSWER Creating VPCs and VNETs add overhead.
Increases attach surface.
25.What are the use cases for ZT Cloud? - ANSWER Workload to internet,
intracloud, multi-cloud, hybrid?
26.What is the purpose of a GRE tunnel in the ZTE? - ANSWER To load
balance traffic properly