Summer Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

Zscaler Zero Trust Cyber Associate

Last Update 4 hours ago Total Questions : 75

The Zscaler Zero Trust Cyber Associate content is now fully updated, with all current exam questions added 4 hours ago. Deciding to include ZTCA practice exam questions in your study plan goes far beyond basic test preparation.

You'll find that our ZTCA exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these ZTCA sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any Zscaler Zero Trust Cyber Associate practice test comfortably within the allotted time.

Question # 11

Zero Trust is about controlling initiator access. This is based on validating the identity of the user, and that is the sole attribute used to control access.

A.

True

B.

False

Question # 12

Identifying and proving the who value, that is, who is the initiating entity, is usually a function of a government agency.

A.

True

B.

False

Question # 13

What is the cause of performance issues for some VPN connections?

A.

A split tunnel VPN where you break out traffic destined for certain IP addresses to go direct.

B.

VPN vendors throttle network traffic on the overlay by default to reduce overhead on the VPN headend.

C.

Hairpinning cloud application traffic through a data center bottleneck.

D.

Interoperability issues between IPSec standards like IKEv1 and IKEv2.

Question # 14

What is the security risk inherent in creating a split tunnel VPN, where some traffic is routed over the VPN tunnel and the rest over a direct internet connection?

A.

The VPN traffic is exempted from any security policies configured on the direct internet uplink router or appliance.

B.

You no longer have the visibility required to make decisions on those traffic flows that are going directly out to the internet.

C.

A split ACL list, which means only half the rules will be enforced.

D.

An issue between the built-in client VPN agent on most modern operating systems and a third-party VPN gateway upstream.

Question # 15

Data center applications are moving to:

A.

The branch.

B.

Castle and moat type architectures.

C.

The DMZ.

D.

The cloud.

Question # 16

What are the three main sections that the elements of Zero Trust are grouped into?

A.

Verify Identity and Context, Control Content and Access, and Enforce Policy.

B.

VPNs, firewalls, and legacy architectures.

C.

Castle-and-moat security architectures, with the data center and inbound DMZ being key.

D.

Routers, switches, and wireless access points.

Question # 17

What is the ultimate goal of policy enforcement?

A.

State a conditional allow or a conditional block.

B.

Issue a log that can be interpreted in a modern SOC.

C.

Designate an initiator as always trustworthy or always untrustworthy.

D.

Track network bandwidth utilization across destination application categories.

Question # 18

The initial section of Zero Trust, Verify Identity and Context, includes three elements; the first is:

A.

Who is connecting.

B.

Device posture-based determinations of quarantine.

C.

Integration with third-party threat intelligence feeds.

D.

ML-based application discovery as part of a microsegmentation implementation.

Question # 19

Which of the following actions can be included in a conditional “block” policy? (Select 2)

A.

Quarantine: Ensure access is stopped and assessed.

B.

Deceive: Direct any malicious attack to a restricted decoy.

C.

Firehose: Send TCP resets to the initiator.

D.

Allow the connection.

Question # 20

In a Zero Trust architecture, what is required to apply the first levels of control policy decisions?

A.

Inspection of SSL/TLS connections.

B.

Local breakout so that traffic goes directly to SaaS applications from branches.

C.

Context and Identity.

D.

Segmenting an OT network so that it is air-gapped from the IT environment.

Go to page: