Question 1
A financial services firm is deploying Zscaler Private Access (ZPA) and must ensure that developers connecting from unmanaged personal devices (BYOD) can only access a specific set of non-sensitive development tools. Access from corporate-managed devices should be unrestricted. The firm uses Okta for identity management. Which ZPA feature is the most precise and secure mechanism to enforce this policy?
Answer and explanation
Correct answer: B
Device Posture Profiles within Zscaler Client Connector are the designed mechanism for differentiating access rights based on the security state and ownership of a device. By creating a posture profile that checks for a corporate-issued certificate, an administrator can create a ZPA Access Policy that grants different levels of access to users on managed versus unmanaged devices. This is more secure and scalable than managing separate application segments or relying on IdP groups alone, which don't verify the device state.