Zabbix Certified Specialist
Expanded Exam-Focused Study Guide — Zabbix 7.0
Scope: Independently authored practice material based on the public structure of the supplied Stuvia bundle and the official Zabbix Certified
Specialist training outline. It is not a reproduction of paid material and does not claim to contain leaked or actual certification questions.
Core mental model: source → collection → preprocessing → item value → trigger/event → action → notification/operation →
visualization/reporting.
Zabbix Certified Specialist — Expanded Study Guide Page 1
, Official Topic Map
Training area Key focus
Architecture & Components Zabbix server, frontend, database, agents, proxies and monitoring flow
Hosts, Items & Keys Hosts, item types, keys, update intervals, passive/active checks and utilities
Triggers, Events & Alerting Trigger expressions, problem/recovery events, severity and dependencies
Templates, Macros & Tags Reusable configuration, inheritance, user macros, tags and overrides
Preprocessing & Dependent Items Transformation, validation, master items and dependent-item design
HTTP, Web, Logs & SNMP HTTP agent, synthetic web monitoring, log monitoring and SNMP
Proxies & Distributed Monitoring Remote sites, network boundaries, collection distribution and proxy design
Users, Roles, LDAP & SAML Groups, roles, least privilege and just-in-time provisioning
Actions & Notifications Actions, conditions, media types, operations and remote commands
Maintenance, Services & SLA Planned maintenance, service monitoring, SLAs and inventory
Low-Level Discovery Dynamic resources, discovery macros and overrides
Visualization & Dashboards Graphs, maps, dashboards and operational presentation
Reporting & Performance History, trends, workload, tuning, audit and administrative settings
Java & Database Monitoring Java monitoring, database observability and meaningful metrics
Troubleshooting & Releases Version awareness and systematic troubleshooting
Integrated Scenario Drills Architecture and configuration decisions in realistic monitoring scenarios
Zabbix Certified Specialist — Expanded Study Guide Page 2
, Architecture & Components
Zabbix server, frontend, database, agents, proxies and monitoring flow
Q1. What is the main role of the Zabbix server?
Answer: It centrally processes monitoring data, evaluates trigger logic, manages events and coordinates actions.
Exam note: Do not confuse the server with the web frontend.
Q2. What is the Zabbix frontend?
Answer: The web interface used for configuration, visualization, dashboards, problems, users and administration.
Exam note: Frontend is presentation/configuration, not the monitoring engine.
Q3. What is an item?
Answer: A definition for collecting or receiving a monitoring value.
Exam note: Item = measurement; trigger = logic.
Q4. What is a trigger?
Answer: A logical expression that evaluates item data to identify a problem condition.
Exam note: A trigger does not collect the raw metric.
Q5. What is a passive agent check?
Answer: The server or proxy initiates the request and the agent returns the value.
Exam note: Passive = Zabbix asks.
Q6. What is an active agent check?
Answer: The agent obtains its configuration and sends collected values to the server or proxy.
Exam note: Active = agent sends.
Q7. What is zabbix_get?
Answer: A utility for testing or retrieving a value from a Zabbix agent.
Exam note: get = query an agent.
Q8. What is zabbix_sender?
Answer: A utility for pushing values to Zabbix, commonly to trapper items.
Exam note: sender = push.
Q9. Why use templates?
Answer: They provide reusable monitoring configuration that can be linked to many hosts.
Exam note: Templates improve consistency and scalability.
Q10. What are user macros?
Answer: Reusable variables that substitute environment-specific values in supported configuration fields.
Exam note: Macros reduce hard-coded duplication.
Q11. A remote site has many monitored systems and limited WAN bandwidth. What architecture is appropriate?
Answer: A proxy-based design can collect locally and forward monitoring data to the central server.
Exam note: Remote + many endpoints + constrained link is a classic proxy scenario.
Q12. One API response contains several metrics. How can repeated collection be reduced?
Answer: Collect the response once and derive multiple dependent items using preprocessing.
Exam note: One payload → master item + dependent items.
Q13. A single outage causes hundreds of downstream alerts. What should be considered?
Answer: Model the upstream cause and use trigger dependencies and selective alerting to reduce symptom noise.
Exam note: One cause + many symptoms → dependency design.
Q14. Hundreds of similar hosts need identical monitoring. What should be preferred?
Answer: Use templates rather than manually duplicating configuration.
Exam note: Repeated configuration → template.
Zabbix Certified Specialist — Expanded Study Guide Page 3
, Q15. A custom application must push a metric into Zabbix. What pattern fits?
Answer: Use a trapper item and a sender mechanism such as zabbix_sender.
Exam note: Push model → trapper + sender.
Zabbix Certified Specialist — Expanded Study Guide Page 4
Expanded Exam-Focused Study Guide — Zabbix 7.0
Scope: Independently authored practice material based on the public structure of the supplied Stuvia bundle and the official Zabbix Certified
Specialist training outline. It is not a reproduction of paid material and does not claim to contain leaked or actual certification questions.
Core mental model: source → collection → preprocessing → item value → trigger/event → action → notification/operation →
visualization/reporting.
Zabbix Certified Specialist — Expanded Study Guide Page 1
, Official Topic Map
Training area Key focus
Architecture & Components Zabbix server, frontend, database, agents, proxies and monitoring flow
Hosts, Items & Keys Hosts, item types, keys, update intervals, passive/active checks and utilities
Triggers, Events & Alerting Trigger expressions, problem/recovery events, severity and dependencies
Templates, Macros & Tags Reusable configuration, inheritance, user macros, tags and overrides
Preprocessing & Dependent Items Transformation, validation, master items and dependent-item design
HTTP, Web, Logs & SNMP HTTP agent, synthetic web monitoring, log monitoring and SNMP
Proxies & Distributed Monitoring Remote sites, network boundaries, collection distribution and proxy design
Users, Roles, LDAP & SAML Groups, roles, least privilege and just-in-time provisioning
Actions & Notifications Actions, conditions, media types, operations and remote commands
Maintenance, Services & SLA Planned maintenance, service monitoring, SLAs and inventory
Low-Level Discovery Dynamic resources, discovery macros and overrides
Visualization & Dashboards Graphs, maps, dashboards and operational presentation
Reporting & Performance History, trends, workload, tuning, audit and administrative settings
Java & Database Monitoring Java monitoring, database observability and meaningful metrics
Troubleshooting & Releases Version awareness and systematic troubleshooting
Integrated Scenario Drills Architecture and configuration decisions in realistic monitoring scenarios
Zabbix Certified Specialist — Expanded Study Guide Page 2
, Architecture & Components
Zabbix server, frontend, database, agents, proxies and monitoring flow
Q1. What is the main role of the Zabbix server?
Answer: It centrally processes monitoring data, evaluates trigger logic, manages events and coordinates actions.
Exam note: Do not confuse the server with the web frontend.
Q2. What is the Zabbix frontend?
Answer: The web interface used for configuration, visualization, dashboards, problems, users and administration.
Exam note: Frontend is presentation/configuration, not the monitoring engine.
Q3. What is an item?
Answer: A definition for collecting or receiving a monitoring value.
Exam note: Item = measurement; trigger = logic.
Q4. What is a trigger?
Answer: A logical expression that evaluates item data to identify a problem condition.
Exam note: A trigger does not collect the raw metric.
Q5. What is a passive agent check?
Answer: The server or proxy initiates the request and the agent returns the value.
Exam note: Passive = Zabbix asks.
Q6. What is an active agent check?
Answer: The agent obtains its configuration and sends collected values to the server or proxy.
Exam note: Active = agent sends.
Q7. What is zabbix_get?
Answer: A utility for testing or retrieving a value from a Zabbix agent.
Exam note: get = query an agent.
Q8. What is zabbix_sender?
Answer: A utility for pushing values to Zabbix, commonly to trapper items.
Exam note: sender = push.
Q9. Why use templates?
Answer: They provide reusable monitoring configuration that can be linked to many hosts.
Exam note: Templates improve consistency and scalability.
Q10. What are user macros?
Answer: Reusable variables that substitute environment-specific values in supported configuration fields.
Exam note: Macros reduce hard-coded duplication.
Q11. A remote site has many monitored systems and limited WAN bandwidth. What architecture is appropriate?
Answer: A proxy-based design can collect locally and forward monitoring data to the central server.
Exam note: Remote + many endpoints + constrained link is a classic proxy scenario.
Q12. One API response contains several metrics. How can repeated collection be reduced?
Answer: Collect the response once and derive multiple dependent items using preprocessing.
Exam note: One payload → master item + dependent items.
Q13. A single outage causes hundreds of downstream alerts. What should be considered?
Answer: Model the upstream cause and use trigger dependencies and selective alerting to reduce symptom noise.
Exam note: One cause + many symptoms → dependency design.
Q14. Hundreds of similar hosts need identical monitoring. What should be preferred?
Answer: Use templates rather than manually duplicating configuration.
Exam note: Repeated configuration → template.
Zabbix Certified Specialist — Expanded Study Guide Page 3
, Q15. A custom application must push a metric into Zabbix. What pattern fits?
Answer: Use a trapper item and a sender mechanism such as zabbix_sender.
Exam note: Push model → trapper + sender.
Zabbix Certified Specialist — Expanded Study Guide Page 4