T Techclick ← All lessons
Zscaler · Batch 11 · Lesson 14 · Interview + exam

ZDTA cert + interview — blueprint, then tickets

You cleared the course. The hiring manager does not ask “what is ZDTA?” They drop a production ticket: SSL broke a bank app, or a developer wants *.internal.corp on all ports. This page maps the official six-domain ZDTA blueprint back to lessons 01–13, then drills eight scenario answers you can say out loud.

~22 min read · L2 primary · Quiz at end

⚡ Quick Answer

ZDTA interview and exam prep: official six-domain blueprint, study map back to lessons 01–13, eight production scenario answers (direct / production / weak / strong), scored quiz. No invented exam percentages.

After this page you can

Quick answer (say this out loud)

ZDTA is the proctored exam at the end of Zscaler for Users — Administrator (EDU-200). The current public blueprint is six domains: Policy & Security 29%, User & Device 18%, Platform 18%, Monitoring 13%, Troubleshooting 13%, Integration 9%. It lists 60 questions / 90 minutes. Zscaler does not publish a cut score. Study by mapping those domains back to lessons 01–13, then practice tickets: expected flow, config object, log field, safe fix, proof. Current catalog after ZDTA is ZDTE (EDU-202) or ZDXA — not retired ZCCA-IA / ZCCA-PA names.

1. Why this page exists

A recruiter searches for the string ZDTA. A hiring manager who has run a ZIA rollout does not. They ask which engine blocked the URL after URL Filtering said Allowed, or what you do when half the fleet fails posture after a Windows update.

Paper certification dies in the first follow-up. The cert is a forcing function to study. The interview is a ticket. This lesson is the join: official blueprint on one side, production answers on the other.

Hero · six domains, one exam
Study desk with six domain nodes feeding a Zero Trust cloud
Notice: Policy is the heaviest official slice. The exam is not a feature list — it is “deploy, secure internet, set policy, connect private apps, monitor.”
Do not quote old blogs as the blueprint

Older posts (including a prior version of this page) listed seven domains such as “Cyber Security Services 20% / Basic Connectivity 20%” and an “80% pass mark.” Those numbers are not on the current official ZDTA blueprint PDF. If a JD still says ZCCA-IA or ZCCA-PA, translate it to ZDTA + day-job depth — do not invent a current “EDP / ZCCP” ladder unless Zscaler publishes it again.

2. Mental model — two exams

Treat prep as two different tests that share the same lab stories.

Exam A · ZDTA

Closed-book, proctored, timed. You prove you can administer the Zero Trust Exchange across identity, platform, policy, logs, incidents, and integrations. Authority = current blueprint + study guide.

Exam B · interview

Open-ended ticket. You prove you can pick a first check, name a log field, and refuse the unsafe shortcut. Authority = a story you actually ran in lessons 01–13.

Flow 1 · study vs interview
Official ZDTA blueprint Split Study map Domain % → lessons 01–13 Lab story + official practice exam Re-read the weak domain, not everything Interview ticket Direct → production → evidence Name the log / object / first check Refuse bypass-the-engine answers

Read top → down. Diamond = is this a timed item or a spoken ticket? Same lab story feeds both.

Say this out loud

I study the current blueprint, not a dump. I map each domain to a lesson I can reopen. In an interview I start with the first check and the evidence field — not the product slogan.

3. Official blueprint → lesson map

Primary source: Zscaler Digital Transformation Administrator blueprint (public PDF). It is a professional-level exam, 60 questions, 90 minutes, recommended after EDU-200 course and lab, with a suggested background of hands-on Zscaler time plus broader network/security experience.

The EDU-200 marketing page currently says “90 minutes to answer 50 questions.” Treat the exam blueprint as the exam authority and re-check both the day you book. The same PDF says topics are guidelines and may change without notice.

Decision · blueprint first
Blueprint diamond splitting into a study map path and an interview path
If the hours do not match Policy 29% + User/Platform 18% each, you are studying a different exam than the one Zscaler published.
Flow 2 · official domain weights
ZDTA blueprint (public PDF) — do not invent other % Policy & Security Configuration 29% User & Device Management 18% Platform Management 18% Monitoring, Reporting & Analytics 13% Troubleshooting & Incident Response 13% Integration & Optimization 9% Heaviest single domain = policy. User + Platform together = 36%. Do not under-study logs or incidents (26% combined). Source: digital-transformation-admin-blueprint.pdf · re-download before you book

Bar length tracks the published weight. Policy is almost a third of the exam.

Official domainWeightRe-read these lessonsWhat “ready” looks like
Policy & Security Configuration 29% 05 URL + Cloud App, 06 SSL + File Type, 07 Threat, 08 DLP + CASB, 11 ZPA policies, 12 CBI + SIPA You can say which engine fires, and you can name a scoped bypass instead of “turn it off.”
User & Device Management 18% 04 Auth + ZCC, Entra SAML + SCIM gold Provision then authenticate. Username appears in the web log. IdP / ACS are exempt from the tunnel.
Platform Management 18% 01 Foundation, 02 ZIA architecture, 03 Forwarding, 09 ZPA architecture, 10 Connectors CA / Public Service Edge / Nanolog. GRE vs IPSec vs ZCC. Connector egress 443, no inbound VIP.
Monitoring, Reporting & Analytics 13% 13 Logs, ZDX, troubleshoot Insights vs ZDX vs NSS. Green ZDX score is not the same as a slow transaction.
Troubleshooting & Incident Response 13% 13 + traps in 04, 06, 10 First check, not reboot. Quote the field that closes the ticket.
Integration & Optimization 9% 04 (SAML/SCIM), 03 (forwarding), 13 (NSS / SIEM) One IdP as the Zscaler front door. NSS gap is a data-loss incident, not “restart Splunk and leave.”

Academy outcomes (not extra invented domains) sit across that table: deploy the Exchange, secure user-to-internet traffic, enable basic policy, connect private apps via Client Connector, monitor experience. The expansive objective list lives in the ZDTA study guide — download the current file; do not memorize a third-party dump.

4. How to choose the next cert

Zscaler’s public certification catalog (FAQ last updated 30 Jul 2026) lists three proctored exams: ZDTA, ZDTE, ZDXA. Each attempt is US$300, non-refundable. Credentials are valid two years; recertify by passing the current exam, starting 90 days before expiry.

CredentialPathPick it whenDo not pick it when
ZDTA EDU-200 Administrator You need the platform admin badge hiring screens for. Do this first. You only want a LinkedIn badge and have never opened Insights.
ZDTE EDU-202 Engineer Day-job is advanced identity, connectivity, Private Service Edge, deeper ZIA/ZPA services. You have not yet administered a tenant. Engineer assumes the admin path.
ZDXA Digital Experience Administrator Your tickets are “Teams is choppy” and hop-by-hop proof, not policy design. You have never run a ZDX probe or compared it to a real Web Insights row.
Z-Badges Academy specializations You already hold a cert and need a product-depth complement. A JD asked for ZDTA and you try to substitute a badge.
Old names you will still see on JDs

ZCCA-IA / ZCCA-PA (and older ZIA Admin / ZPA Admin wording) are retired administrator tracks. If a recruiter uses those strings, answer with ZDTA plus the matching day-job depth (ZIA policy vs ZPA connectors). Do not invent a current “EDP” or “ZCCP” sequence unless you have a live Academy page in front of you.

5. Study + exam-day runbook

Four weeks is enough if lessons 01–13 are already done. Less than that is memorization. More than six without labs is decay. Source for exam mechanics: Certification Exam FAQs.

Side A — Academy / external

  1. Create the Cyber Academy account

    Required before you can schedule. Customer, partner, and public-sector portals differ. You will get a Zscaler Client Candidate ID (ZCID) for Pearson VUE.

  2. Download the current blueprint + study guide

    Do this the week you book, not from a screenshot in a WhatsApp group. Confirm domain names and the 60 / 90 numbers still match.

  3. Sit the official ZDTA practice exam

    It is a familiarization tool, not a guarantee. Group misses by blueprint domain. A practice pass is not a certification result.

Side B — this course (product)

  1. Week 1 — User 18% + Platform 18%

    Re-read 01–04 and 09–10. Lab: ip.zscaler.com, one forwarding method, one SAML login that shows a username in Web Insights, one Connector that is outbound 443 only.

  2. Week 2 — Policy 29%

    Re-read 05–08, 11–12. Lab: one URL rule, one SSL host bypass, one threat/sandbox story, one DLP dictionary that you tighten instead of disable, one narrow App Segment.

  3. Week 3 — Monitor 13% + Troubleshoot 13%

    Re-read 13. Lab: one Insights vs ATP mismatch, one ZDX hop story, one posture-fail first check. Write the evidence field before the fix.

  4. Week 4 — Integration 9% + spoken tickets

    Re-read the eight scenarios below out loud. Time yourself. If a domain from the practice exam is weak, reopen that lesson — do not reread the whole course.

Side C — exam day + proof

  1. Schedule Pearson VUE or OnVUE

    US$300 per attempt. Cancel a test-center seat at least 48 hours ahead. OnVUE: personal PC preferred, Windows 10 / macOS 13+, one display, 6 Mbps down / 2 Mbps up, government photo ID, arrive/login 15 minutes early. Breaks are not permitted. Work laptops often fail the secure browser.

  2. Do not invent a target percentage

    Official FAQ: Zscaler does not reveal the cut score or how many items you must get right. Pass/fail is on-screen immediately. Failures get a breakdown by blueprint area. Passers get Pass only — no item review.

  3. After a pass

    Accept the Credly badge, download the certificate from Share. Recert window opens 90 days before the two-year mark. Same US$300 exam fee.

Primary source for this block

Zscaler Certification Exam FAQs (30 Jul 2026) + ZDTA blueprint PDF + ZDTA Academy page (US$300, English).

6. Interview loop after you pass

The loop is the same every time: ticket → first check → object → log → scoped fix → proof. That is also how you should have studied weeks 2–4.

Ops · proof, not slogans
Operations desk with abstract health checks and interview cards
Close with a log field and a scoped change. “We use Zero Trust” is not evidence.

What they listen for

Order. You name the engine, the object (rule / segment / posture check), and the page that proves it.

What fails you

Disable the engine, open *.internal.corp on all ports, or argue with a user because ZDX is green.

7. Eight scenario answers

Each stem is a production ticket. Answer in this order: direct line, why production cares, the weak trap, the sentence you actually say, the evidence field.

Q1 · Scenario — 50-branch forwarding

A 50-branch bank asks you to pick GRE, IPSec, PAC, and Zscaler Client Connector for ZIA. They want one default.

Direct answer
Default branch transport is IPSec IKEv2. PAC is the exception path (lab / unmanaged). ZCC is mandatory for every laptop that leaves the branch. GRE only if the CPE already does clean GRE keepalives and you have MTU under control.
Why production cares
Branch tunnels stop the moment the user is on hotel Wi-Fi. PAC never sees non-browser traffic. GRE’s MTU/keepalive tax shows up as “Zscaler is slow.”
Weak answer / trap
“PAC file for the whole company.” Or “GRE everywhere because the blueprint said connectivity is 20%.” That weight is not on the current exam PDF, and PAC is not a fleet design.

Strong framing (say this)

IPSec at the branch, ZCC on every roaming device, PAC as a scoped override. I can show the location object and the ZCC App Profile that match that sentence.

Evidence to name

Lesson 03 forwarding; Admin → Locations; ZCC App Profile / forwarding profile; ip.zscaler.com from a branch PC and from a home laptop.

Q2 · Troubleshoot — SSL breaks a bank app

One user group cannot open a partner banking site after you enabled SSL Inspection. Everyone else is fine.

Direct answer
Confirm certificate pinning or a missing Zscaler Root CA on that device class. If it is pinning, add an SSL Inspection bypass for that host and document it. Do not disable the inspection policy.
Why production cares
Bypass is one host. Disable is every site that group touches. Auditors will ask which one you chose.
Weak answer / trap
“Turn off SSL Inspection.” Or “reinstall ZCC for the org.”

Strong framing (say this)

I filter Insights on user + URL, look for a TLS error versus a 403 after decrypt, then I either push the root CA or bypass the pinned host.

Evidence to name

Lesson 06 SSL; Insights Web — policy / SSL columns; SSL Inspection bypass list; device cert store.

Q3 · Unsafe shortcut — wildcard App Segment

A developer asks for Application Segment *.internal.corp on all TCP ports “so we can move fast.”

Direct answer
Push back. Ask for specific FQDNs and ports. Split into narrower segments. A temporary, reviewed wildcard is only acceptable with a tight Access Policy (group + posture) and an expiry.
Why production cares
That wildcard is every reachable internal host. Zero Trust becomes “VPN with extra steps.”
Weak answer / trap
“Sure, we can lock it with MFA later.” Or “ZPA implicit deny will save us.” Implicit deny does not help if the allow policy matches the wildcard.

Strong framing (say this)

App Segment is the what — FQDN and ports. I will not publish all ports on a star domain. Give me the list or we schedule discovery.

Evidence to name

Lessons 09 / 11; Application Segment definition; Access Policy that would match that segment.

Q4 · Architecture — two ZPA policies, allow and deny

The user is in two groups. For the same App Segment, one Access Policy allows and one denies. Which fires?

Direct answer
Top-down, first match wins, evaluation stops. If nothing matches, ZPA is implicit deny — there is no implicit allow.
Why production cares
GUI order is the control plane. A leftover broad allow above a new deny is why “I wrote the deny” does nothing.
Weak answer / trap
“Most specific wins, like a firewall.” Or “deny always wins.” Those are different products.

Strong framing (say this)

I screenshot the policy order, say which rule number hit, and I keep an explicit deny-log at the bottom so default deny is visible.

Evidence to name

Lesson 11 ZPA policies; Access Policy list order; ZPA diagnostics / user activity for the matched policy name.

Q5 · Evidence — URL Filtering says Allowed

The user is blocked. Insights Web shows URL Filtering: Allowed. Where do you look next?

Direct answer
Another engine. Check Advanced Threat / sandbox, File Type, DLP, Cloud App Control, and SSL errors. ZIA is not a single verdict.
Why production cares
Helpdesk will keep cloning URL rules while ATP or DLP is the actual block. You waste a change window.
Weak answer / trap
“Add the URL to the allow list again.” Or “disable URL Filtering to test.”

Strong framing (say this)

I open the same transaction and read every policy column. Allowed in URL Filtering is not the ticket closer.

Evidence to name

Lessons 05, 07, 08, 13; Insights Web full row; which policy name is Block.

Q6 · Compare — what do you sit after ZDTA?

You passed ZDTA. Your week is URL, SSL, DLP, and NSS into Splunk. A peer says “go EDP-ZIA or ZCCP next.”

Direct answer
Open the live catalog. Today that is ZDTE if you want engineer-depth platform work, or a Z-Badge that matches the product. ZDXA only if the job is experience monitoring. I will not quote retired ZCCA / invented EDP names as current exams.
Why production cares
Managers budget US$300 and study time. Sending someone at the wrong exam wastes a quarter.
Weak answer / trap
“ZIA Admin, then ZCCP, then architect.” That ladder is not what the July 2026 FAQ lists.

Strong framing (say this)

ZDTA first. Next exam matches the tickets I already own. I will screenshot the Academy page in the interview if the JD is stale.

Evidence to name

Academy certification page; FAQ (ZDTA / ZDTE / ZDXA); your last 20 tickets tagged ZIA vs ZPA vs ZDX.

Q7 · Troubleshoot — posture fails after an OS upgrade

Half the Windows fleet fails the ZPA posture check (AV running + disk encryption) the morning after a feature update.

Direct answer
Do not loosen posture for the company. Identify which check failed on the new build (renamed service, moved signal). Fix the detection. A time-boxed warn is only for a confirmed transient, with a comms note.
Why production cares
A Saturday “set posture to none” is a security regression that outlives the Windows bug.
Weak answer / trap
“Disable posture so people can work.” Or “reimage the fleet.”

Strong framing (say this)

I pull ZCC / ZPA diagnostics for one failed device, name the failing check, then I update that check — not the entire Zero Trust policy.

Evidence to name

Lessons 04 / 11; posture profile; Z-App diagnostic; one before/after device.

Q8 · Scenario — DLP false-positive flood

After a dictionary update, DLP incidents explode. The CISO wants the noise gone before lunch.

Direct answer
Group last-day incidents by rule and dictionary. Read matched substrings. Tighten the pattern or add a proximity keyword. Move that one rule to alert while you tune. Leave the rest of DLP on.
Why production cares
Disabling the engine is a data-exfil window. Auditors will ask for the hours it was off.
Weak answer / trap
“Disable DLP, we’ll put it back Friday.” Or “raise the company-wide threshold to 99.”

Strong framing (say this)

I isolate the dictionary that broke, I do not touch the other rules, and I can show the incident count dropping after the tighten.

Evidence to name

Lesson 08 DLP + CASB; DLP incident viewer; dictionary / engine; rule action alert vs block.

8. Traps + proof checklist

TrapWhat it looks likeSafer path
Invented blueprint “Seven domains, 80% to pass, connectivity 20%.” Open the current PDF. Six domains. Cut score unpublished.
Retired cert names Studying ZCCA-IA dumps, or quoting EDP/ZCCP as live exams. ZDTA → ZDTE or ZDXA from the live Academy page.
Bypass vs disable SSL / DLP / posture turned off for the org. Host, rule, or check scoped. Document the exception.
One-engine thinking URL Filtering Allowed, so “Zscaler is broken.” Read ATP, File Type, DLP, Cloud App, SSL on the same row.
Practice exam = cert Stopping study after a green practice score. Use misses to reopen one lesson. The real exam is proctored and unpaid-for-refund.
Green ZDX vs angry user “Score 92, you’re wrong.” RUM / Web Insights for that user’s transactions, then the endpoint.
Pilot checklist — lesson 14 is green when

Knowledge check

Six judgment items. Same traps as the runbook and interview block. Check answers, then reset if you miss any.

Q1

You have four weeks. Using the current official ZDTA blueprint, where do the most hours go?

Correct: c. Re-read Official blueprint → lesson map. The public PDF is six domains. Option b is the retired/invented seven-domain list. Identity is not a 4% domain on the current sheet.
Q2

A study group says you need 80% (48 of 60) to pass ZDTA. What is the accurate statement?

Correct: b. Re-read Side C — exam day. FAQ: no specific cut score; passers get Pass only; failures get a domain breakdown. Do not invent 70% or 80%.
Q3

SSL Inspection breaks one pinned banking host for one group. What is the first production fix?

Correct: a. Re-read interview Q2 and lesson 06. Bypass ≠ disable. Blast radius is the whole difference.
Q4

Same user, same ZPA App Segment: policy 3 allows, policy 7 denies. The user is in both groups. What happens?

Correct: c. Re-read interview Q4 and lesson 11. Order in the GUI is the control. Implicit deny, not implicit allow.
Q5

You hold ZDTA. You want the current engineer-level platform exam. Which official name do you book?

Correct: d. Re-read How to choose the next cert. Public catalog: ZDTA, ZDTE, ZDXA. ZCCA / EDP / ZCCP are not the live names on that page.
Q6

Insights Web: URL Filtering = Allowed. The user still cannot open the site. First move?

Correct: b. Re-read interview Q5 and lesson 13. One Allowed column is not a full verdict. Do not change forwarding or ZPA for an internet URL until the log row is read.

Sources

Related: 01 Foundation · 03 Forwarding · 04 Auth + ZCC · Entra SAML + SCIM · 06 SSL · 08 DLP + CASB · 11 ZPA policies · 13 Logs + ZDX