T Techclick ← All lessons
Zscaler · DSPM · Interactive lesson

DSPM discover then posture

Ticket: ZIA DLP is green. Nobody uploaded a PAN this week. Finance still found card files in a public S3 bucket. Inline DLP never sees data that is already sitting in a store. Zscaler DSPM is the at-rest job: discover the store, classify the files with DLP engines synced from Internet & SaaS, then score posture (public exposure, encryption, logging, over-privilege, AI-service access). Proof is Resource Inventory plus a rescan — not a green DLP tile.

16 min read · L2 primary · Quiz at end

After this page you can

Lessons · ZIA DLP · DSPM

This page vs inline DLP

This lesson is data at rest: onboarded cloud/on-prem stores, agentless scan, classification, posture. Inline inspect, dictionary match on upload/download, and block/allow live on ZIA DLP. Do not merge them into “data protection.”

ZIA DLP · DLP + CASB (batch 11)

Hero · stores go through scan, then class and posture
Cloud store, database and file cabinet feeding a scan cube, then class and posture lanes
Mood, not a wiring diagram. DSPM scans supported stores (S3, RDS, blobs, VMs, on-prem DBs/file servers). Classification and posture are two outputs of that scan. Exact path is in the SVG.
Quick answer

Zscaler DSPM is agentless data-at-rest security for onboarded AWS / Azure / GCP accounts plus supported on-prem stores. It discovers data stores, classifies sensitive data with DLP engines and dictionaries synced from Internet & SaaS (ZIA), then contextualizes posture — public exposure, encryption, logging, over-privileged access, AI-service exposure. Data Posture Policies (predefined NIST / GDPR / PCI plus custom query-builder rules) generate alerts. Proof is Resource Inventory: Last Completed Scan, Latest Scan Status, Open Alerts, posture labels, and a rescan after the owner change. Lab: lab-finance-exports (PCI files, public, logging off) vs lab-marketing-assets (public images, not sensitive).

Why a green DLP tile is not “data is safe”

ZIA DLP inspects a transaction that is already on the wire. DSPM inspects a store that is already in the account. If card files landed in S3 last quarter via a pipeline, there is no upload for DLP to match this week. The ticket looks like “DLP is fine” until someone lists the bucket.

Three silent-zero states look identical from the DLP dashboard (no incidents):

Do not rank by Public Exposure alone

Two buckets can share the same posture label. One holds product images. One holds PCI files with logging off. DSPM’s job is sensitivity plus exposure plus access — not “every public object is Critical.” Confirm class, reachability, and owner before you page the cloud team.

Discover, classify, posture — three jobs

Discover is inventory of supported stores after the account is onboarded and a scan rule is enabled. DSPM uses an agentless scanner (orchestrator in a designated account; CloudFormation / Terraform templates: Tree Discovery, Orchestrator, Monitoring Scope, Evidence, Data Events on AWS). It does not install an agent on every bucket.

Classify is DLP engines and dictionaries synced from Internet & SaaS. You view them under Data Classification Settings; you edit engines in ZIA. ML document categories (Financial, Health, HR, Legal, …) land on files in storage and VMs — not inside database rows the same way. OCR covers image files and images embedded in PDF / Office.

Posture is the store’s security state: publicly accessible, encryption, logging, retention, exposed to AI services, over-privileged IAM. Data Posture Policies evaluate that state against sensitive data and raise alerts. Remediation guidance is on the alert; closure is a rescan, not a status dropdown.

Path · discover, classify, posture, then rescan
Four glass panels labeled Discover, Classify, Posture, Rescan
Feel of the order. Classification without a discovered store is empty. Posture without class is just a public-bucket colour. Rescan is the close.

Discover

Onboard AWS org / Azure tenant / GCP org. Scan rule on the resource type (S3, blob, RDS, VM, on-prem DB). Enable the rule. Inventory fills.

Classify

DLP engines from ZIA. Scan Scope picks which engines run. Sensitivity settings and enable/disable evaluation live on Data Classification Settings.

Posture

Labels on the resource: public exposure, encryption, logging, AI. Policies (predefined + custom query) turn a bad combination into an alert.

Proof

Resource Inventory: Last Completed Scan, Latest Scan Status, Open Alerts, Access tab (entity, Read/Edit/Full). Rescan after the IaC change.

Say this out loud

Discover the store. Classify the files with the same DLP engines ZIA already owns. Score how the store is exposed. Fix the template, then rescan. DLP never saw this because nothing moved.

How a store becomes a finding

Nothing classifies until a scan rule is enabled against an onboarded account. Full / incremental / historical / sampling are scan methods, not policy actions. After the scan, Resource Inventory shows the store, matched engines, document category, posture labels, and open alerts. A Data Posture Policy is a query: primary resource type plus predicates such as Publicly Accessible, Has Data / Is Sensitive, Encrypted, Logging.

Flow 1 · lab bucket lab-finance-exports
1 Onboard AWS org · templates 2 Scan rule S3 · enabled 3 Discover lab-finance-exports 4 Classify ZIA DLP engines 5 Posture public · no logging 6 Data Posture Policy match → alert S3 Bucket · Publicly Accessible = true · Has Data / Is Sensitive = true Inventory: Open Alerts > 0 · document category Financial · Access tab shows who can Read/Full Miss at step 2: scan rule disabled. Empty inventory. No class. No posture. DLP still green. Enable the rule. Do not add a ZIA block for s3.amazonaws.com to “fix” at-rest data. After the owner change: on-demand or scheduled rescan. Last Completed Scan must be newer than the fix. Open Alerts drop. Source: Zscaler Help — What is DSPM; About Scan Settings; About Data Posture Policies; About Resource Inventory.

Read left → right, then the gold bar. Discover is not classification. Classification is not a block. The alert is the policy hit; the rescan is the close.

ObjectLab valueIf missing
Cloud accountAWS organization onboarded; regions include ap-south-1No stores. Connection / orchestrator status failed → fix templates, not DLP.
Scan ruleCloud Type AWS · Cloud Storage · S3 · enabled · full scan on lab bucketsInventory empty. Latest Scan Status never moves.
Scan ScopeDLP engines that cover PCI / PII enabled in ZIA and selected hereStore found, class blank, posture has no sensitive-data correlation.
Store Alab-finance-exports — CSV with test PANs, public ACL, logging offThis is the finding you want first.
Store Blab-marketing-assets — public product images, no sensitive classPublic Exposure yes. Priority no. Do not page on colour alone.
PolicyPredefined PCI / public-sensitive, or custom: Publicly Accessible + Is SensitiveClassification exists; no alert. Investigation query still works.
ProofLast Completed Scan after the IaC fix; Open Alerts = 0 on that resourceConsole ACL click without rescan is not closure.

DSPM vs DLP vs CASB/SSPM

Pick the plane the ticket actually sits on. Mixing them is the usual “we have data protection, why did the bucket leak?” interview miss.

Flow 2 · public is not the same as leak
lab-marketing-assets Public Exposure = true Is Sensitive = false Watch · do not page lab-finance-exports Public Exposure = true Is Sensitive = true · no logging Page · owner + IaC fix Private RDS + PAN Public = false Over-privilege / no encrypt Still a DSPM finding DSPM ranks sensitivity + posture + access. Public-alone is a label, not a priority. ZIA DLP would only see a download of those CSVs. CASB/SSPM is SaaS app posture, not the IaaS bucket. Custom policy query: Publicly Accessible = true AND Has Data / Is Sensitive = true. Marketing misses. Finance hits. Source: Query Builder for Policies and Investigation; About Data Posture Policies; Understanding Data Classification.

Three columns, three tickets. Do not toggle a ZIA DLP block to “fix” an S3 ACL.

NeedUseSkip
Find PAN files sitting in S3 / blobs / RDSDSPM: onboard + scan + classify + postureZIA DLP. Nothing is in motion.
Stop a user uploading a PAN through the proxyZIA DLP engine / dictionary on the transactionDSPM scan rule. DSPM does not inline-block.
SaaS app misconfig (sharing, SSPM)CASB / SaaS security posture — different planeTreating DSPM Resource Inventory as the SaaS admin.
Same dictionaries everywhereEdit engines in Internet & SaaS; DSPM consumes the syncInventing a second dictionary only inside DSPM.

Runbook Side A / B / C

Side A is onboard and scan (discover). Side B is classification and Data Posture Policies. Side C is inventory, owner change, rescan. Do not start at C.

Admin paths below are from Zscaler Help (2026 unified console). Legacy DSPM UI also documents Administration › Scan Settings for scan rules. If your tenant still shows the legacy left nav, use that Help article — do not guess a third menu.

Side A — onboard then scan

  1. Onboard the cloud account

    Policies › Common Configuration › DSPM › Cloud Accounts. AWS organization, Azure tenant, or GCP organization. Deploy the published templates (AWS: Tree Discovery, Orchestrator, Monitoring Scope, Evidence, Data Events). Check Roles and Templates; DSPM Connection Status must not sit on failed. Source: About Cloud Accounts; Viewing Roles and Templates.

  2. Scan rule + enable

    Policies › Common Configuration › DSPM › Scan Settings → Scan Rules. Cloud Type AWS, resource category Cloud Storage, resource type S3 (Azure: Blob Containers). Scope the lab buckets. Enable the rule — a disabled rule does not scan. Scan methods: full, incremental, historical, sampling. Source: Configuring Scan Settings / Enabling or Disabling a Scan Rule.

admin.zscaler.com · Policies › Common Configuration › DSPM › Scan Settings › Scan Rules
Training mock · not live

Policies › Common Configuration › DSPM › Scan Settings › Add Scan Rule

lab-s3-full

AWS
Cloud Storage
S3 buckets
Full scan
lab-finance-exports, lab-marketing-assets
Enabled

Source: Zscaler Help — Configuring Scan Settings; Enabling or Disabling a Scan Rule. The enable toggle is the discover gate. Finish without enable = no inventory.

Side B — classify then posture policy

  1. DLP engines (view in DSPM, edit in ZIA)

    Policies › Data Protection › Policy › Data Classification Settings. Confirm the engines DSPM will evaluate; set sensitivity; enable evaluation. Change dictionary logic in Internet & SaaS. Then Scan Settings › Scan Scope: attach those engines to the scan rule. A disabled engine cannot be selected in Scan Scope. Source: About Data Classification Settings; Configuring Scan Scope.

  2. Data Posture Policies

    Policies › Data Protection › Policy › Data Posture Policies. Start with predefined (NIST / GDPR / PCI). Custom: primary resource type S3 Bucket, query Publicly Accessible = true AND Has Data / Is Sensitive = true. Severity Critical/High/Medium/Low. You cannot edit or delete predefined policies. Disable = no new alerts; existing alerts stay. Source: About Data Posture Policies; Managing Policies; Query Builder.

admin.zscaler.com · Policies › Data Protection › Policy › Data Posture Policies › Create Policy
Training mock · not live

Policies › Data Protection › Policy › Data Posture Policies › Create Policy

lab-s3-public-sensitive

AWS
S3 Bucket
Publicly Accessible = true AND Has Data / Is Sensitive = true
High

Source: Query Builder for Policies and Investigation (Publicly Accessible, Has Data / Is Sensitive); About Data Posture Policies (primary resource types include S3 Bucket). This query misses lab-marketing-assets on purpose.

Side C — inventory, fix, rescan

  1. Read Resource Inventory

    Analytics › Data Security › DSPM › Data Discovery (widgets drill into inventory) or Analytics › Resource Inventory. On lab-finance-exports you want: document category Financial, posture publicly exposed + no logging, Open Alerts > 0, Last Completed Scan populated, Latest Scan Status not Failed. Access tab: entity type, Read / Edit / Full, policy ARN. Source: Viewing the Data Discovery Dashboard; About Resource Inventory; Viewing the Access Levels.

  2. Change the store, not only the finding

    Owner fixes the IaC that still grants public (bucket policy / ACL in the template). Console-only ACL is a reopen. Investigation → New Investigation can confirm Publicly Accessible after the change. Source: Creating a New Investigation.

  3. Rescan is the close

    On-demand or wait for the schedule. Last Completed Scan must be after the template deploy. Open Alerts on that resource drop. Disabling the policy hides new alerts; it does not prove the bucket is private. Source: Enabling or Disabling a Scan Rule; Managing Policies (disable ≠ close).

Evidence pack to paste in the ticket (fields from Resource Inventory)
resource: lab-finance-exports
type: S3 Bucket · region: ap-south-1
class: DLP engines matched · document category Financial
posture: publicly exposed, no logging
access: list entity + Access Level (Read / Edit / Full)
alerts: Open Alerts count · policy name (predefined or lab-s3-public-sensitive)
scan: Last Completed Scan = <after-fix timestamp>
status: Latest Scan Status = completed (not Failed / Unsupported)
close: Open Alerts = 0 on this resource after rescan
do-not-close-on: AWS console ACL screenshot with no new Last Completed Scan
Green proof

Inventory row for lab-finance-exports shows a Last Completed Scan newer than the IaC change, posture no longer publicly exposed (or policy query no longer matches), Open Alerts = 0. That is the close — not “DLP had no hits.”

One finding after go-live

Account is onboarded. Scan rule lab-s3-full enabled. Engines covering PCI are in Scan Scope. Full scan lists both buckets. Classification marks CSVs in lab-finance-exports as sensitive / Financial; lab-marketing-assets has no sensitive class. Posture labels public on both; logging off only on finance. Policy lab-s3-public-sensitive alerts finance only. Owner updates the stack that still set a public ACL. Rescan. Last Completed Scan moves. Open Alerts on that resource go to zero.

If the stack is not updated, the next scan reopens the same alert. That is not a DSPM bug.

Proof · rescan is a new Last Completed Scan, not a dashboard vibe
Analyst reviewing an inventory scan complete card with a verification check
Ops feel. Artwork labels are not the Admin Console. Real fields: Last Completed Scan, Latest Scan Status, Open Alerts, posture labels, Access tab.

Traps + proof

SymptomLikely causeProof
DLP green, public PAN in S3At-rest data. Inline DLP never saw a transaction.Resource Inventory class + Public Exposure. No ZIA DLP incident expected.
Inventory empty after onboardScan rule missing or disabled. Orchestrator / connection failed.Scan Enable toggle. Latest Scan Status. Cloud Accounts connection status. Roles and Templates.
Stores listed, class blankEngines disabled, or Scan Scope omitted them, or file type not scanned (DB vs object store).Data Classification Settings enable/disable. Scan Scope. Help: file types scanned in storage/VMs, not the same in databases.
Every public bucket is CriticalPolicy query is Publicly Accessible only. No Is Sensitive.lab-marketing-assets vs lab-finance-exports. Add Has Data / Is Sensitive.
ACL fixed in console, alert returnsIaC / CloudFormation still grants public. Next scan is correct.Template diff. Last Completed Scan after the stack update. Investigation Publicly Accessible.
Alert vanished, bucket still publicPolicy disabled or custom query edited (DSPM closes old alerts and opens new ones on query change).Managing Policies: disable = no new alerts; query edit closes existing. Inventory posture still public.
Scan Failed / UnsupportedPermissions, region, unsupported store, or network mode (automated vs custom/BYON).Hover error on Latest Scan Status (timestamp, resource ID, reason). Roles and Templates vs cloud IAM.
Do not close by disabling the policy

Disable stops new alerts. Existing alert state does not prove the store is private. Fix the resource, rescan, then read Open Alerts and posture on that row.

Pilot checklist

Knowledge check

Six judgment items. Submit once. Reasons point back at the section to re-read.

Q1

ZIA DLP has no incidents this week. Card files sit in a public S3 bucket. What job is missing?

Correct: b. Inline DLP never sees data that is already in the store. Re-read Why a green DLP tile is not “data is safe.”
Q2

What is the correct order of DSPM jobs?

Correct: a. Empty inventory means nothing to classify. Class-blank means posture cannot correlate sensitive data. Re-read Discover, classify, posture and Flow 1.
Q3

Two buckets are public. lab-marketing-assets is product images. lab-finance-exports has PCI files and logging off. DSPM priority?

Correct: c. Public is a posture label. Priority is class + exposure + logging/access. Re-read Flow 2 and How to choose.
Q4

AWS is onboarded. Resource Inventory is empty. First check?

Correct: b. Discover requires an enabled scan rule against a healthy onboard. Re-read Side A and Traps.
Q5

The AWS console ACL is private. The next DSPM scan still alerts public. First move?

Correct: d. Console ACL without a template change is a reopen. Rescan is the proof. Re-read Side C and Traps.
Q6

Where do you change a DLP engine that DSPM uses to classify files?

Correct: a. Engines sync from ZIA. DSPM consumes them via Scan Scope. Re-read Classify in the mental model and Side B.

Sources

Related: ZIA DLP · DLP + CASB · Risk360 exposure scoring