Zscaler for Users - Advanced (EDU-202)
Network and security administrators, engineers, and architects
Zscaler for Users – Advanced is designed to provide you with a deep dive of the Zscaler for Users solution as well as help you deploy and provision the advanced features and functionality of the Zscaler Zero Trust Exchange™.
Integrate with advanced identity services
Configure advanced connectivity options for sending traffic to the Zero Trust Exchange
Deploy Zscaler Private Service Edge
Configure advanced cybersecurity services such as DNS security, firewall, private app segmentation, AppProtection, browser isolation, deception, and data loss prevention
Explore advanced digital experience monitoring
Course Outline
Zscaler for Users - Advanced Overview
- Recap of Zscaler for Users - Essentials (EDU-200)
- Introduction to Zscaler for Users - Advanced (EDU-202)
Zscaler Architecture
- A Foundational Overview
- Unmatched Protection and Performance
- Additional Capabilities (Sub Clouds)
Advanced Identity Services
- LDAP Authentication
- Hosted User Database Authentication
- Zscaler as an Identity Proxy
- Configuration Guidance
Advanced Connectivity Services
- Connectivity Services–Forwarding Profile PAC vs. App Profile PAC
- ZIA
- Tunnel Mode
- Browser Access
- SD-WAN / Any Router
- GRE Tunnel Options
- IPsec Options
- Zscaler Cloud Connector
Advanced Platform Services
- Policy Framework Demos
- Zscaler Private Service Edges
- ZPA Private Service Edges
- Private Internet Service Edge
- Analytics and Reporting
- Traffic Forwarding: Source IP Anchoring
Advanced Zscaler Digital Experience
- ZDX Metrics
- Probes
- Deep Tracing (Diagnostics)
- Alerts and Rules
- Device, Software, and Process Inventory
- Integration with Microsoft Intune
- Integration with ServiceNow
- Role-Based Administration
- Getting Help from Zscaler
- ZDX Dashboard
- ZDX Copilot
- Analytics
- Hosted Monitoring
- Applications Overview Dashboard
- Call Quality Monitoring Dashboard
- Users Dashboard
- Device, Software, and Process Inventory Information
- Deep Tracing (Diagnostics) Session Results
- Alerts Page
- Configuring Applications
- Configuring Call Quality Monitoring
- Configuring Probes
- Configuring Deep Tracing (Diagnostics)
- Configuring Alerts
- Configuring Role-Based Administration
- Configuring Self Service Settings
- Configuring Data Explorer Views
- Configuring Inventory Settings
Advanced Access Control Services
- Zscaler Cloud Firewall
- Zscaler Cloud Firewall Architecture
- Adaptive Policies for Remote Workforce
- Intrusion Prevention System (IPS)
- APIs for Cloud Firewalls
- Destination and Access Control Policies
- Logging and Reporting
- DNS Control Features, Capabilities, Performance, and Security
- Resolvers and Traffic Forwarding
- DNS Configuration and Best Practices
- DNS Demonstration
- Tenant Restriction
- Tenant Restriction Demonstration
- Cloud App Instances/ Cloud App Control Policy
- Configuring Private Application Access
- Zscaler Private Access Application Segmentation Demonstration
Advanced Cybersecurity Services
- What is Cybersecurity?
- Advanced Threat Protection
- Intrusion Prevention System (IPS)
- Cloud Sandbox
- Browser Isolation
- Private Access AppProtection
- Zscaler Deception
Advanced Data Protection Services
- What is Zscaler Data Protection?
- Inline Data Protection
- Data Loss Prevention
- Secure SaaS and BYOD
- Out-of-Band Data Protection and SSPM
- Out-of-Band CASB Demo
- Third-Party App Security (AppTotal)
- Incident Management
Hands-On Lab Details
Prerequisites
Zscaler for Users - Advanced (EDU-202) E-Learning
Proficiency
Advanced
Description
The Zscaler for Users - Advanced (EDU-202) lab builds on the Zscaler for Users - Advanced (EDU-202) e-learning by helping students practice the skills learned in the e-learning portion.
Duration
1 day | 8 hours
Type
Instructor Led Training (ILT)
Completion criteria
Complete all lab tasks
Price per seat
US $1,200 (4 EDU credits)
Lab Outline
Connect to the Virtual Lab
Test Your Lab Access and Start Your Environment
Join the Corp: Client PC to the Student FQDN on Microsoft Entra ID
Test Zscaler Admin Portal SSO Access
Identity Services–Configure ZIA User Authentication
Add an Application and Configure SAML SSO in Azure
Add Azure as an IdP to the Zscaler Service
Identity Services–Configure ZIA SCIM Authorization
Enable ZIA IdP for SCIM Provisioning
Configure the Azure Enterprise Application for Zscaler Internet Access SCIM
Identity Services–Configure ZPA User Authentication
Add Azure as ZPA IdP and Download SP Metadata for the IdP
Configure Azure IdP for ZPA
Complete the IdP Configuration in the ZPA Admin Portal
Identity Services–Configure ZPA SCIM Authorization
Enable ZPA IdP for SCIM Provisioning
Configure the Azure Enterprise Application for Zscaler Private Access SCIM
Connectivity Services–Configure Browser Access for 3rd Parties
- Provision App Connector
Info: Troubleshooting App Connector Enrollment
Create HVAC Application Web Server Certificate
Create HVAC Application and Access Policy for Browser Access
Create DNS CNAME Record for the HVAC Application
Test Browser Access to the HVAC Application
Platform Services–Configure Log Streaming
Provision Dedicated App Connector for Log Streaming
Add Log Receiver
Add SSH Access to SIEM Server in Private Data Center
Verify Log Feed
Zscaler Digital Experience–Configure Alerts & Diagnostics
Enroll Device for Digital Experience Monitoring
Create an Alert Rule
Configure a Deep Tracing Session
Access Control Services–Configure & Examine Firewall Policies
Verify Client Connector Forwarding to Firewall
Verify Tunnel Version v2.0 DTLS Forwarding on User's Device
Test Non-Web Traffic with Firewall Default Block
Configure Firewall Policies
Examine Firewall Traffic
Check Firewall Filtering Rule Log Data
Cyberthreat Protection Services–Configure Sandbox File Inspection
Configure a Sandbox Policy to Inspect All Files
Configure Sandbox Policy to Allow Specific Downloads
View Sandbox Activity Reports
Cyberthreat Protection Services–Browser Isolation
Build Isolation Profile
Implement Isolation Policy
Test Browser Isolation User Experience & Threat Prevention Capabilities
Cyberthreat Protection Services–Deception-Based Active Defense
Generate Recon Activity
Investigate Deception Alerts
Data Protection Services–Explore Application and Data Visibility
Check Visibility for all SaaS Applications, Including AI- & ML-Based Apps
Discover Apps with Potential API (oAuth2) Access to Corporate Sanctioned Apps
View AI- & ML-Based Auto Data Discovery Dashboard
View Data at Rest Discovery for Sanctioned Apps
View Security Posture Management (SSPM)
Data Protection Services–Data Classification
View Predefined Dictionaries
View Custom Dictionaries–Regex and Phrases
View Custom Dictionaries–Microsoft Information Protection Labels
View Custom Dictionaries–Advanced Classifications EDM/IDM
View Predefined and Custom DLP Engines
Data Protection Services–Manage Incidents with Zscaler Workflow Automation (ZWA)
Enroll with Zscaler Client Connector
Test PII Information Protection in Unsearchable PDF and Images Using OCR for Data in Motion
View Current DLP Incidents
Modify Incident Metadata
Test User Notification/Coaching & Escalation Workflow
Configure Automated Workflows
Certification Exam Details
Prerequisites
Zscaler for Users - Advanced E-Learning and Hands-On Lab
Duration
90 minutes
Test format
60 multiple choice questions
Available language(s)
English
Price per attempt
US $300 (1 EDU credit)