Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Zscaler ZDTA Exam - Topic 1 Question 17 Discussion

How does a Zscaler administrator troubleshoot a certificate pinned application?
A) They could look at SSL logs for a failed client handshake.
B) They could reboot the endpoint device.
C) They could inspect the ZIA Web Policy.
D) They could look into the SaaS application analytics tab.

Zscaler ZDTA Exam - Topic 1 Question 17 Discussion

Actual exam question for Zscaler's ZDTA exam
Question #: 17
Topic #: 1
[All ZDTA Questions]

How does a Zscaler administrator troubleshoot a certificate pinned application?

Show Suggested Answer Hide Answer
Suggested Answer: A

Certificate pinning prevents SSL interception by validating a server's certificate against known values. When ZIA performs SSL inspection, it substitutes the certificate with one signed by Zscaler's CA. This causes the handshake to fail for pinned applications. To troubleshoot, an administrator should review SSL logs to identify handshake failures, which indicate certificate pinning issues. Logs will show the TLS negotiation details, including any disruptions.


Contribute your Thoughts:

0/2000 characters
Martha
4 days ago
I think A is the best choice. SSL logs show handshake issues.
upvoted 0 times
...
Thomasena
9 days ago
Agreed, A) is the best option here!
upvoted 0 times
...
Carma
14 days ago
D) Wait, can you really troubleshoot from the SaaS analytics? Sounds odd.
upvoted 0 times
...
Sheldon
19 days ago
C) makes sense, gotta check the policies first.
upvoted 0 times
...
Taryn
24 days ago
I think B) is a waste of time, doesn't really help with cert issues.
upvoted 0 times
...
Georgiann
30 days ago
A) is definitely the way to go! SSL logs are super helpful.
upvoted 0 times
...
Delsie
1 month ago
I vaguely recall something about the SaaS application analytics tab being useful for troubleshooting, but I can't remember if it directly relates to certificate pinning.
upvoted 0 times
...
Elinore
1 month ago
I feel like rebooting the device, option B, is a bit of a stretch for this scenario. It seems too basic for a certificate pinning issue.
upvoted 0 times
...
Isaiah
2 months ago
I remember practicing a question about troubleshooting SSL issues, and I think inspecting the ZIA Web Policy could be relevant too, maybe option C?
upvoted 0 times
...
Alfreda
2 months ago
I think option A makes sense since SSL logs can show issues with the handshake, but I'm not entirely sure how to access those logs.
upvoted 0 times
...

Save Cancel