Instructions and covered skills
Read each scenario carefully before selecting a response. Focus on the access decision, the protected application, and the conditions described. Do not rely on assumptions that are not stated in the question. Stay focused and turn off notifications while completing the test. Review each selected response for policy scope and least-privilege implications. Choose the response that best supports secure, reliable remote application access.
Key Areas
This test measures the ability to apply Zero Trust Network Access (ZTNA) controls to remote application access. It focuses on creating policies that grant access to named applications rather than exposing broad network segments. Candidates should understand how identity provider groups, application inventories, device posture signals, geographic context, authentication strength, and session risk can influence an access decision.
Strong performance requires recognizing the roles of users, devices, ZTNA brokers, application connectors, and protected applications. The test also covers least-privilege design, including separating policies by application sensitivity and using narrowly scoped identity groups. Candidates should be able to distinguish an authentication issue from a device-compliance issue, connector availability problem, policy conflict, or application-side authorization failure.
Logging and operational review are included because ZTNA policies must be monitored after deployment. Relevant evidence includes user identity, device identifier, matched policy, requested application, authentication method, source context, connector status, decision outcome, and session timestamps. Candidates should understand how this evidence supports incident investigation and policy tuning without unnecessarily collecting unrelated personal data.
Recommended Preparation
Review a ZTNA product's policy evaluation flow and terminology, including applications, connectors, identity groups, posture checks, access rules, session controls, and audit logs. Practice mapping sample business roles to only the applications they need. Examine how managed-device status, operating system updates, endpoint protection, disk encryption, and certificate presence can become posture requirements.
Study common remote-access scenarios involving employees, contractors, administrators, and third parties. Consider how stronger authentication, time-limited access, geographic restrictions, and step-up verification may be applied to sensitive applications. Practice reading access logs and tracing a denied request from identity authentication through policy matching and connector reachability. When reviewing any access design, prioritize explicit application authorization, narrowly scoped rules, prompt removal of obsolete entitlements, and documented exceptions.