ZSCALER EDU 200 - ESSENTIALS -
ZDTA STUDY SET
What6is6used6to6detect6if6a6SAML6assertion6was6modified6after6being6issued?
Options:
-6XML
-6Digital6Signatures
-6Attributes
-6Tokens6-6ans--Digital6Signatures
How6is6a6SAML6assertion6delivered6to6Zscaler?
Options:
-6The6IdP6sends6it6via6an6HTTP6post6directly6to6the6SP6via6a6backend6API
-6The6SP6sends6it6via6an6HTTP6post6directly6to6the6IdP6via6a6backend6API
-6The6IdP6sends6it6via6the6user's6browser6to6the6SP
-6The6SP6sends6it6via6a6trusted6authority6to6the6IdP6-6ans--
The6IdP6sends6it6via6the6user's6browser6to6the6SP
(Uses6a6form6POST6submitted6via6JavaScript)
In6what6way6does6Zscaler's6Identity6Proxy6enable6authentication6to6SaaS6applications?
Options:
-6Injecting6identity6headers6into6the6HTTP6request
-6SSL6Inspection
-6Browser6Isolation
-6Issuing6SAML6assertions6-6ans--Issuing6SAML6assertions
How6does6Zscaler6Internet6Access6authenticate6users?6(Select63)
Options:
-6SAML
-6SCIM
-6LDAP
-6Hosted6Database6-6ans--SAML,6LDAP,6Hosted6Database
How6does6Zscaler6Private6Access6authenticate6end6users?
Options:
,-6Username6and6Password6in6a6form-based6auth
-6Hosted6DB
-6SAML
-6SCIM6-6ans--SAML
What6is6the6fastest6way6to6change6a6user's6access6entitlements?6-6ans--
Send6different6attributes6via6SCIM
In6order6for6Zscaler6to6enforce6policy6based6on6accessing6devices,6what6method6is6best6
used6by6IdPs6to6share6information6about6a6user's6accessing6device?
Options
-6Kerberos
-6SAML
-6Header6Injection
-6Mobile6Device6Management6-6ans--SAML
Privileged6Remote6Access6supports6which6protocols?6(Select62)
Options:
-6SSH
-6RDP
-6CIFS
-6HTTP/HTTPS6-6ans--SSH,6RDP
Which6services6can6coexist6on6an6Application6Segment?
Options:
-6Isolation,6Browser6Access,6and6Inspection
-6RDP,6SSH,6and6Inspection
-6Inspection,6Isolation,6and6RDP
-6CIFS,6RDP,6and6SSJ6-6ans--Isolation,6Browser6Access,6and6Inspection
How6often6does6the6Zscaler6Client6Connector6check6for6software6updates?
Options:
-6Every626hours
-6Every666hours
-6Every6126hours
-6Every6246hours6-6ans--Every626hours
Which6check6guarantees6identification6of6a6corporate-
managed6device6by6the6Zscaler6Client6Connector?6-6ans--Client6Certificate6&6Non-
Exportable6private6key
, You6want6Zscaler6Client6Connector6to6automatically6redirect6to6your6corporate6SAML6ID
P6on6launch.6Which6installer6options6should6you6configure6to6do6so?6(Select62)6-6ans----
cloudName
--userDomain
Where6is6the6control6to6prevent6a6user6from6exiting6Zscaler6Client6Connector?
Options:
-6It's6a6ZCC6Installer6option
-6In6the6Forwarding6Profile
-6In6the6Application6Profile
-6Under6Administration,6Advanced6Settings6-6ans--In6the6Application6Profile
When6moving6from6an6Explicit6Proxy6to6a6Tunneled/Transparent6Proxy6-
6what,6if6any,6effects6will6be6seen6on6the6client?6(Select63)
Options:
-6No6Effect
-6The6client6will6always6resolve6DNS
-6The6client6browser6needs6re-configuration
-6Authenticated6websites6may6no6longer6work
-6An6Explicit6Proxy6and6a6Transparent6Proxy6are6the6same6thing6-6ans--
The6client6will6always6resolve6DNS
The6client6browser6needs6re-configuration
Authenticated6websites6may6no6longer6work
What6benefits6does6a6Zscaler6Tunnel6have6over6other6forwarding6mechanisms6for6Zscal
er6Client6Connector?
Options:
-6Tunnels6are6the6only6mechanism6to6install6ZCC
-6Tunnels6enable6only6HTTP6and6HTTPS6traffic6to6be6forwarded6by6ZCC
-6Tunnels6enable6Zscaler6to6control6the6end6user6device
-6Tunnels6encapsulate6traffic6and6authenticate6to6the6Zero6Trust6Exchange6-6ans--
Tunnels6encapsulate6traffic6and6authenticate6to6the6Zero6Trust6Exchange
Browser6Based6Access6enables6what6kinds6of6applications6to6be6published?
Options:
-6HTTP6and6HTTPS
-6RDP6and6SSH
-6Telnet6and6RDP
-6HTTP,6HTTPS,6and6SSH6-6ans--HTTP6and6HTTPS
Why6is6Z-Tunnel62.06superior6to6Z-Tunnel61.0?6(Select63)
ZDTA STUDY SET
What6is6used6to6detect6if6a6SAML6assertion6was6modified6after6being6issued?
Options:
-6XML
-6Digital6Signatures
-6Attributes
-6Tokens6-6ans--Digital6Signatures
How6is6a6SAML6assertion6delivered6to6Zscaler?
Options:
-6The6IdP6sends6it6via6an6HTTP6post6directly6to6the6SP6via6a6backend6API
-6The6SP6sends6it6via6an6HTTP6post6directly6to6the6IdP6via6a6backend6API
-6The6IdP6sends6it6via6the6user's6browser6to6the6SP
-6The6SP6sends6it6via6a6trusted6authority6to6the6IdP6-6ans--
The6IdP6sends6it6via6the6user's6browser6to6the6SP
(Uses6a6form6POST6submitted6via6JavaScript)
In6what6way6does6Zscaler's6Identity6Proxy6enable6authentication6to6SaaS6applications?
Options:
-6Injecting6identity6headers6into6the6HTTP6request
-6SSL6Inspection
-6Browser6Isolation
-6Issuing6SAML6assertions6-6ans--Issuing6SAML6assertions
How6does6Zscaler6Internet6Access6authenticate6users?6(Select63)
Options:
-6SAML
-6SCIM
-6LDAP
-6Hosted6Database6-6ans--SAML,6LDAP,6Hosted6Database
How6does6Zscaler6Private6Access6authenticate6end6users?
Options:
,-6Username6and6Password6in6a6form-based6auth
-6Hosted6DB
-6SAML
-6SCIM6-6ans--SAML
What6is6the6fastest6way6to6change6a6user's6access6entitlements?6-6ans--
Send6different6attributes6via6SCIM
In6order6for6Zscaler6to6enforce6policy6based6on6accessing6devices,6what6method6is6best6
used6by6IdPs6to6share6information6about6a6user's6accessing6device?
Options
-6Kerberos
-6SAML
-6Header6Injection
-6Mobile6Device6Management6-6ans--SAML
Privileged6Remote6Access6supports6which6protocols?6(Select62)
Options:
-6SSH
-6RDP
-6CIFS
-6HTTP/HTTPS6-6ans--SSH,6RDP
Which6services6can6coexist6on6an6Application6Segment?
Options:
-6Isolation,6Browser6Access,6and6Inspection
-6RDP,6SSH,6and6Inspection
-6Inspection,6Isolation,6and6RDP
-6CIFS,6RDP,6and6SSJ6-6ans--Isolation,6Browser6Access,6and6Inspection
How6often6does6the6Zscaler6Client6Connector6check6for6software6updates?
Options:
-6Every626hours
-6Every666hours
-6Every6126hours
-6Every6246hours6-6ans--Every626hours
Which6check6guarantees6identification6of6a6corporate-
managed6device6by6the6Zscaler6Client6Connector?6-6ans--Client6Certificate6&6Non-
Exportable6private6key
, You6want6Zscaler6Client6Connector6to6automatically6redirect6to6your6corporate6SAML6ID
P6on6launch.6Which6installer6options6should6you6configure6to6do6so?6(Select62)6-6ans----
cloudName
--userDomain
Where6is6the6control6to6prevent6a6user6from6exiting6Zscaler6Client6Connector?
Options:
-6It's6a6ZCC6Installer6option
-6In6the6Forwarding6Profile
-6In6the6Application6Profile
-6Under6Administration,6Advanced6Settings6-6ans--In6the6Application6Profile
When6moving6from6an6Explicit6Proxy6to6a6Tunneled/Transparent6Proxy6-
6what,6if6any,6effects6will6be6seen6on6the6client?6(Select63)
Options:
-6No6Effect
-6The6client6will6always6resolve6DNS
-6The6client6browser6needs6re-configuration
-6Authenticated6websites6may6no6longer6work
-6An6Explicit6Proxy6and6a6Transparent6Proxy6are6the6same6thing6-6ans--
The6client6will6always6resolve6DNS
The6client6browser6needs6re-configuration
Authenticated6websites6may6no6longer6work
What6benefits6does6a6Zscaler6Tunnel6have6over6other6forwarding6mechanisms6for6Zscal
er6Client6Connector?
Options:
-6Tunnels6are6the6only6mechanism6to6install6ZCC
-6Tunnels6enable6only6HTTP6and6HTTPS6traffic6to6be6forwarded6by6ZCC
-6Tunnels6enable6Zscaler6to6control6the6end6user6device
-6Tunnels6encapsulate6traffic6and6authenticate6to6the6Zero6Trust6Exchange6-6ans--
Tunnels6encapsulate6traffic6and6authenticate6to6the6Zero6Trust6Exchange
Browser6Based6Access6enables6what6kinds6of6applications6to6be6published?
Options:
-6HTTP6and6HTTPS
-6RDP6and6SSH
-6Telnet6and6RDP
-6HTTP,6HTTPS,6and6SSH6-6ans--HTTP6and6HTTPS
Why6is6Z-Tunnel62.06superior6to6Z-Tunnel61.0?6(Select63)