
Platform Services & Forwarding · Advanced ZIA Security · ZPA Private Access · Data Protection · Management, Logging & ZDX
60 questions · 90 min · 70% Techclick practice target
⚠️ Exam Rules
| Questions in this Techclick bank | 60 |
|---|---|
| Timer | 90 min |
| Techclick practice target | 70% |
| Official exam code | ZDTE |
An engineer must forward all TCP and UDP traffic from managed laptops to the Zscaler cloud, not just web ports. Which Zscaler Client Connector tunnel mode meets this requirement?
Correct: D. Z-Tunnel 2.0 carries all ports and protocols so non-web applications are inspected, whereas Z-Tunnel 1.0 is limited to web traffic on the standard ports. Tunnel with local proxy is a legacy web-only mode, and GRE is a site forwarding method rather than something an endpoint agent uses.
A branch office with a static public IP must forward traffic to Zscaler without deploying agents to guest devices. Which forwarding method is most appropriate?
Correct: C. GRE requires a static public address and forwards all traffic from the site regardless of device ownership, which is exactly the guest scenario. Installing agents on guest devices is not feasible, emailing PAC files is unenforceable, and source IP anchoring is a ZPA feature for preserving egress identity rather than a branch forwarding method.
An engineer is choosing between GRE and IPsec for a branch site. Select the TWO statements that correctly describe IPsec forwarding to Zscaler. (Choose TWO)
Correct: C and D. IPsec suits dynamic-address branches because the tunnel identity can be an FQDN rather than a fixed address, and it encrypts the transport unlike plain GRE. Static addressing is a GRE requirement rather than an IPsec one, IPsec tunnels typically have lower per-tunnel throughput than GRE, and a location object is still required for policy and reporting.
A company must exclude a payroll SaaS application from the Zscaler tunnel entirely because the provider blocks proxied connections. Which mechanism implements that exclusion for agent-based users?
Correct: A. Traffic must leave the tunnel entirely, which is a forwarding decision made by the client configuration rather than a policy decision inside the service. Allowing the category, exempting SSL inspection or permitting the port all still send the traffic through Zscaler, which is precisely what the provider rejects.
An engineer needs Zscaler policy to apply different rules to the Mumbai and Bengaluru offices, both forwarding by GRE. Which configuration element makes that distinction possible?
Correct: D. Location objects are the policy identity for site-forwarded traffic, so a distinct location per office allows differentiated rules, bandwidth control and reporting. Inspection profiles define how traffic is decrypted, administrator scoping controls who edits configuration, and NSS feeds export logs rather than differentiate policy.
Last updated:
Yes. You can start, finish and score it for free, and download the Techclick practice certificate.
This bank has 60 original scenario-based questions with a 90-minute timer and a 70% Techclick practice target.
The official exam code is ZDTE (Zscaler).
No. They are original practice questions written by Techclick. This is not the vendor's official exam and not leaked dumps.
Score 70% or higher to get a Techclick practice certificate and LinkedIn badge. It is not an official Zscaler certification.
Related practice tests: Zscaler ZCC-ADMIN, Zscaler ZIA-SIM, Zscaler ZSS, Zscaler ZDTA, Zscaler ZDXA, Zscaler ZCCA-IA (linked below).

You earned it — let the world know!
