ZDTA
Zscaler Digital Transformation Administrator (ZDTA)
Part of Zscaler Digital Transformation Administrator
Independent study aid built from the public exam blueprint. Not affiliated with, authorized by, or endorsed by zscaler. Objectives are transcribed and mapped by hand, so this page may contain mistakes or may have fallen behind the vendor's current material: exam objectives, versions, numbering and availability all change without notice. Treat zscaler's own certification portal as the source of truth and verify against it before you book anything.
User & Device Management (18%) and Platform Management (18%)
ZDTA-A.01 Given a scenario including a user's attributes from the IdP, identify the groups they will be placed into, and the policies that will be applied.
ZDTA-A.02 Identify the steps to assign users to the appropriate groups with the appropriate access using ZIdentity.
ZDTA-A.03 Given a scenario including creating or modifying a user group in Zscaler Zidentity, identify the next step to ensure policies apply to that group.
ZDTA-A.04 Given an Administrator Audit Log, interpret the activity or identify unauthorized activity in the Administrator Audit Logs.
ZDTA-A.05 Given a scenario including an organization that has strict BYOD policies, identify the appropriate ZCC deployment option that should be used.
ZDTA-A.06 Given a scenario about an exfiltration, identify the next step that should be taken to check the company's posture.
ZDTA-A.07 Given a scenario including an organization goal to ensure user devices are compliant before enabling access to the internet or private application, identify the next step that should be taken.
ZDTA-A.08 Given a scenario in which an organization requires more stringent access control on traffic originating from off of the corporate network, identify the most logical place to put that policy.
ZDTA-A.09 Given a scenario where an administrator needs to connect to Zscaler a location that requires a certain bandwidth and requirements and no need for HA, identify the type of tunnels that should be used and the minimal amount needed to cover the requisites.
On this site: VPN Fundamentals: What Tunnels Protect, and What They Don't, GRE Tunnels: The Simplest Envelope in Networking, IPsec and IKE: How Encrypted Tunnels Negotiate Themselves, Tunnel Overhead, MTU, and MSS: The Byte Math Every Tunnel Owes, Zscaler Tunnel Types: Z-Tunnel, GRE, and IPsec, With the Numbers, TLS Inspection in ZIA: The Policy, the Bypasses, and the Bill, Locations and Sublocations: Teaching the Cloud Where Your Sites AreZDTA-A.10 Given a merger and acquisition use case, identify the appropriate configurations necessary to ensure seamless access to internet and private applications.
ZDTA-A.11 Given a scenario with an example of misordered firewall rules, identify how the rule set will be executed and identify any unintended risks associated with the rule set order.
On this site: ZIA Cloud Firewall: Rule Order Is the Whole BallgameZDTA-A.12 Given a scenario to deploy ZPA App Connectors in VMs or Containerized environments, identify the necessary information to be communicated to the team.
Policy & Security Configuration (29%)
ZDTA-B.01 Given a scenario including requirements, identify the appropriate assets where SSL bypass can be implemented.
ZDTA-B.02 Given a scenario including an application that needs to be accessed, identify the bypass that would allow the application to be accessed in this situation.
ZDTA-B.03 Given a scenario and an example of a log, identify why access is being allowed despite an expected policy violation.
ZDTA-B.04 Given a scenario about creating and modifying a custom URL category, identify how to achieve a given goal.
ZDTA-B.05 Given a scenario about applying URL filtering rules to users/groups, identify how to achieve a given goal.
ZDTA-B.06 Given a sandbox scenario including a desired outcome, identify the next action that should be taken.
ZDTA-B.07 Given an example sandbox report and organizational requirements, identify the trends in malicious activity over a specific timeframe.
ZDTA-B.08 Given a scenario about file type control, identify how to ensure a given category is prioritized correctly.
ZDTA-B.09 Given a scenario about applying file type policies and a specific user or group, identify how to apply the correct file type policy based on the roles and security needs.
ZDTA-B.10 Given a scenario where various users need to access different applications, identify the App Segments that enable proper least privileged access.
ZDTA-B.11 Given a scenario where various users need to access different applications, identify the proper access policies to enforce least privileged access.
ZDTA-B.12 Given a scenario including a content inspection rule, analyze the outcome of the rule, identify the appropriate actions to take, or communicate who should take appropriate actions.
ZDTA-B.13 Given a scenario including DLP notification, block actions, and a user uploading sensitive data, identify the notification method that should be used.
ZDTA-B.14 Given a scenario including problems with unauthorized SaaS Applications in an organization, identify where to find Risky Assets / Potential Shadow IT in the portal.
ZDTA-B.15 Given a scenario about enforcing granular controls, identify the outcome of an action.
ZDTA-B.16 Given an image of rules in a specific order in the platform, identify how a group's access is impacted.
On this site: ZIA Cloud Firewall: Rule Order Is the Whole BallgameZDTA-B.17 Given a scenario about least privilege access, identify the most effective way to achieve the outcome.
ZDTA-B.18 Given a scenario about the need for defining network segmentation for a private application, identify the most effective network segmentation strategy that should be used.
ZDTA-B.19 Given a scenario including a micro-segmentation policy and internal applications, identify how to refine the policy to enhance the security posture for internal applications.
ZDTA-B.20 Given a scenario including specific requirements for client forwarding policies with client connector, identify the Client Connector Forwarding Profile action that will meet the requirements.
ZDTA-B.21 Given a scenario including requirements for trusted network bypass rules, identify the proper set of client forwarding policies that bypass applications when on a specific network.
ZDTA-B.22 Given a scenario about applying posture-based access criteria to enforce device compliance, identify the outcome of the criteria.
Monitoring, Reporting & Analytics (13%), Troubleshooting & Incident Response (13%), and Integration & Optimization (9%)
ZDTA-C.01 Given a scenario about the need for specific information from web and firewall logs, identify the log type that should be used.
ZDTA-C.02 Given an example audit log, identify indicators of privilege escalation.
ZDTA-C.03 Given a scenario including an executive security summary and a desired goal, identify the appropriate next step given the information in the summary.
ZDTA-C.04 Given a scenario about tracking application usage over time and performance goals, identify methods to prevent the performance issues.
On this site: The ZDX Score: What the Probes Measure and How the Number Is Made, Reports and Executive Summaries: Turning the Nanolog Into Sentences Leadership ReadsTools: zdx-score-factor-explainerZDTA-C.05 Given a scenario including a goal about connectivity, identify the ZDX diagnostics that should be used to address the goal.
On this site: The ZDX Score: What the Probes Measure and How the Number Is Made, Troubleshooting Client Connector: The Diagnostics Menu and the First Four ChecksTools: zdx-score-factor-explainerZDTA-C.06 Given a scenario including a screenshot of a policy rule and the hierarchy, identify the unintended policy interactions.
On this site: ZIA Cloud Firewall: Rule Order Is the Whole BallgameZDTA-C.07 Given a scenario including policy logic and configuration information, identify how to improve the overall platform performance.
On this site: ZIA Cloud Firewall: Rule Order Is the Whole BallgameZDTA-C.08 Given a scenario including information on known threat actor groups, identify how to block the malicious domains or IPs in Zscaler policies to prevent further compromise.
ZDTA-C.09 Given a scenario where a private application is intermittently working for the same user, identify a likely cause and solution.
ZDTA-C.10 Given a scenario and information about a system that need updates, identify the steps needed to deploy updates to the system including to the broader user base efficiently and with minimal disruption.
Public sources, used in good faith
These guides are independent study aids built from publicly available material: published exam blueprints, official product documentation, and vendor training catalogues. Product names, exam codes, and trademarks belong to their owners and are used only to identify the subject being taught. This site is not affiliated with or endorsed by any vendor named here. If you hold rights in material published on this page and believe it should be removed or corrected, please send the exact URL and a short note on the issue through the contact page; requests are reviewed promptly and in good faith. Read the full disclaimer →