Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Zscaler ZTCA Exam - Topic 2 Question 15 Discussion

Sometimes authorized and allowed initiators may request malicious access to services. What would be the best policy enforcement for an enterprise?
C) Conditionally block (Deceive).
A) Allow access only during business hours.
B) Allow untethered access.
D) Conditionally allow access and have a resource from Network Security review based on logs later.

Zscaler ZTCA Exam - Topic 2 Question 15 Discussion

Actual exam question for Zscaler's ZTCA exam
Question #: 15
Topic #: 2
[All ZTCA Questions]

Sometimes authorized and allowed initiators may request malicious access to services. What would be the best policy enforcement for an enterprise?

Show Suggested Answer Hide Answer
Suggested Answer: C

The correct answer is C. Conditionally block (Deceive). In Zero Trust architecture, authorization alone is not enough to guarantee that a request is safe. An otherwise authorized user, device, or workload can still generate malicious, compromised, or suspicious access attempts. For that reason, Zero Trust policy enforcement must remain contextual and adaptive, even after identity and access have already been validated. Zscaler's architecture emphasizes that access policies are based on the entire user context, including device, location, and compliance, and that different policy outcomes can be enforced based on those values.

A deception-based conditional block is the strongest answer because it both prevents harmful access and gives defenders insight into attacker behavior by redirecting suspicious activity away from the real service. This is more effective than simply allowing access during business hours or allowing the activity and reviewing logs later, because those approaches do not stop the potentially malicious action in real time. Zero Trust is built around preventive, policy-driven enforcement, not delayed review. Therefore, if an authorized initiator behaves maliciously, the best enforcement is to conditionally block with deception.


Contribute your Thoughts:

0/2000 characters

Currently there are no comments in this discussion, be the first to comment!


Save Cancel