Zscaler ZDTA Exam
Zscaler Digital Transformation Administrator (Page 5 )

Updated On: 7-Feb-2026

Can URL Filtering make use of Cloud Browser Isolation?

  1. No. Cloud Browser Isolation is a separate platform.
  2. No. Cloud Browser Isolation is only a feature of Advanced Threat Defense.
  3. Yes. After blocking access to a site, the user can manually switch on isolation.
  4. Yes. Isolate is a possible Action for URL Filtering.

Answer(s): D

Explanation:

Yes, URL Filtering can make use of Cloud Browser Isolation. Specifically, "Isolate" is an available action in URL Filtering policies that enables users to access potentially risky or untrusted websites in an isolated environment, preventing any malicious content from reaching the user's device. The study guide explains that integrating Cloud Browser Isolation into URL Filtering enhances security by isolating risky browsing activities directly from policy enforcement points.



What is the immediate outcome or effect when the Zscaler Office 365 One Click Rule is enabled?

  1. All traffic undergoes mandatory SSL inspection.
  2. Office 365 traffic is exempted from SSL inspection and other web policies.
  3. Non-Office 365 traffic is blocked.
  4. All Office 365 drive traffic is blocked.

Answer(s): B

Explanation:

When the Zscaler Office 365 One Click Rule is enabled, Office 365 traffic is exempted from SSL inspection and other web policies to optimize performance and user experience. This rule simplifies policy configuration by automatically identifying and excluding Office 365 cloud traffic from inspection, reducing latency and avoiding potential conflicts with Office 365 services. The study guide clarifies that this rule helps balance security with seamless cloud application usage.



The Forwarding Profile defines which of the following?

  1. Fallback methods and behavior when a DTLS tunnel cannot be established
  2. Application PAC file location
  3. System PAC file when off trusted network
  4. Fallback methods and behavior when a TLS tunnel cannot be established

Answer(s): A

Explanation:

The Forwarding Profile in Zscaler defines the fallback methods and behavior when a DTLS tunnel cannot be established. This profile governs how traffic should be forwarded if the preferred DTLS (Datagram Transport Layer Security) tunnel fails, ensuring continuity by falling back to alternative methods such as TLS or other configured options. It is critical to maintaining secure and resilient connectivity paths for traffic forwarding.
The study guide clarifies that this forwarding profile specifically addresses DTLS fallback behavior to maintain session reliability.



What is the default timer in ZDX Advanced for web probes to be sent?

  1. 1 minute
  2. 10 minutes
  3. 30 minutes
  4. 5 minutes

Answer(s): D



When configuring a ZDX custom application and choosing Type: 'Network' and completing the configuration by defining the necessary probe(s), which performance metrics will an administrator NOT get for users after enabling the application?

  1. Server Response Time
  2. ZDX Score
  3. Client Gateway IP Address
  4. Disk I/O

Answer(s): D

Explanation:

When a ZDX custom application is configured with the type set to 'Network', the administrator will not get Disk I/O metrics for users. Disk I/O metrics relate to local client device performance and are not part of network-type application probes which focus on network latency, server response, and other network-centric measurements.
The study guide notes that Disk I/O is part of endpoint-level monitoring and is not collected by network-type probes, unlike metrics such as Server Response Time or ZDX Score which are network related.






Post your Comments and Discuss Zscaler ZDTA exam prep with other Community members:

Join the ZDTA Discussion