Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Zscaler ZDTA Exam - Topic 2 Question 21 Discussion

What is the recommended default rule for the cloud-gen firewall configuration when deploying a new ZIA tenant?
A) Block all traffic
B) Permit all traffic
C) Disable the firewall
D) Allow only web traffic (ports 80/443)

Zscaler ZDTA Exam - Topic 2 Question 21 Discussion

Actual exam question for Zscaler's ZDTA exam
Question #: 21
Topic #: 2
[All ZDTA Questions]

What is the recommended default rule for the cloud-gen firewall configuration when deploying a new ZIA tenant?

Show Suggested Answer Hide Answer
Suggested Answer: A

For a new cloud-gen firewall configuration, a default block posture is the safer baseline. Administrators should explicitly permit required business traffic and preserve required Zscaler service rules instead of leaving a broad default allow that weakens least-privilege design. Option A (Block all traffic) is correct because block all traffic is the recommended default-deny stance.

Why the other options are incorrect:

B . Permit all traffic: Permit-all firewall posture lets unexpected services leave the network until later rules stop them.

C . Disable the firewall: Disabling the firewall removes the enforcement layer instead of creating a safe default rule set.

D . Allow only web traffic (ports 80/443): Allowing only ports 80/443 would ignore valid non-web business traffic that may need explicit firewall rules.


Contribute your Thoughts:

0/2000 characters
Rhea
12 hours ago
I remember practicing a question like this, and I think it was about permitting all traffic by default. That seems risky though.
upvoted 0 times
...
Beatriz
6 days ago
I think the default should be to block all traffic, but I’m not entirely sure if that’s the best approach for every situation.
upvoted 0 times
...

Save Cancel