Practice SCAZT Network And Cloud Security questions with full explanations on every answer.
Start practicing
Network And Cloud Security — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
You need to ensure that all web traffic from a branch office is inspected by the Umbrella SIG. Which configuration step is mandatory on your perimeter router?
2You are implementing Cisco Secure Access and want to use PAC files for browsers. Where must the PAC file be hosted for automatic proxy configuration?
3You are configuring Cisco Umbrella to protect roaming users. Which component must be installed on the endpoint to ensure consistent policy enforcement when the user is off-VPN?
4A user on a corporate laptop is unable to reach a specific SaaS application that is blocked by the Cisco Secure Access SIG. How can you verify the specific rule causing this block?
5In Cisco Secure Access, you need to configure a Global Policy to block access to specific cloud applications based on risk levels. Where do you define this logic?
6You are troubleshooting an Umbrella SIG tunnel connection. The IPsec tunnel is up, but users report timeouts. What is the most likely cause if the tunnel MTU is not adjusted correctly?
7You are deploying Umbrella Virtual Appliances (VAs) in a local Active Directory environment. What is the primary purpose of the VA in this deployment?
8When configuring a SIG tunnel in Umbrella, which protocol is typically used to establish the encrypted connection between the branch office firewall and the Umbrella data center?
9What is the function of an Umbrella 'Integrations' key?
10Which Cisco Umbrella feature allows you to categorize destinations and apply custom block or allow lists?
11Which report in Cisco Umbrella provides the most direct view of security threats identified in your environment?
12You are analyzing a 'Domain Blocked' event in Umbrella. The explanation says 'Proxy'. What does this imply?
13When deploying the Cisco Secure Access AnyConnect module, what is the primary role of the Umbrella DNS module within it?
14You are setting up cloud network segmentation. In the context of Secure Access, how are groups of resources isolated from each other?
15You want to ensure that users are warned before visiting a newly registered domain. Which feature in Cisco Umbrella handles this?
16Which component is required to allow Umbrella to perform SSL decryption on web traffic?
17What is the main advantage of using a Secure Internet Gateway (SIG) over a traditional on-premises firewall?
18What is the primary benefit of the Cisco Umbrella 'Global Network' architecture?
19You notice that some of your users are bypassing the Umbrella SIG by using a personal VPN. What is the most effective way to prevent this with Cisco products?
20You are seeing 'SSL Inspection Error' in your logs. What is the most likely cause?
21When using Umbrella's 'Selective Proxy', how is the determination made to route traffic through the proxy vs. direct to destination?
22Where do you manage the Umbrella Roaming Client deployment configuration?
23You are integrating Cisco Secure Access with an IdP. What protocol is used to facilitate this authentication?
24What is the purpose of 'Internal Networks' in the Umbrella dashboard?
25You have a branch office with a static IP. You want to secure it without a local virtual appliance. What is the best method?
26In Secure Access, how are 'Traffic Forwarding' profiles used?
27What is the role of a 'Policy' in Cisco Umbrella?
28Which component is required to enable Active Directory integration with Umbrella for user-level reporting?
29You have a requirement to perform 'File Analysis' on downloads. Which Umbrella product component must be enabled?
30When troubleshooting DNS queries in Umbrella, which command is most useful on a local machine to see if it is using the Umbrella resolvers?
31Which method is the most secure way to authenticate users for Cisco Secure Access?
32A user is experiencing 'SSL Certificate Mismatch' errors. You suspect it is caused by the Umbrella proxy. How do you resolve this permanently?
33Which TWO of the following are primary benefits of Cisco Umbrella DNS-layer security?
34You want to restrict access to specific cloud apps (e.g., Dropbox). Which Umbrella feature is used?
35What does the 'Umbrella dashboard' allow you to do regarding DNS security?
36When migrating from an explicit proxy to the Umbrella SIG, what is the primary challenge for legacy applications?
37Which TWO methods can be used to identify internal clients in Cisco Umbrella reports?
38Which TWO features are part of the Cisco Secure Access suite for remote users?
39Which THREE items must be configured to successfully implement an Umbrella SIG tunnel?
40Which THREE factors are evaluated by the Umbrella policy engine when processing a DNS request?
41Which TWO logging methods can be used to export Umbrella logs for SIEM analysis?
42Which THREE types of traffic are typically protected by a SIG?
43Which THREE pieces of information are displayed in the Umbrella 'Activity Search' report?
44Which THREE components are critical for a successful cloud network segmentation strategy?
45Which TWO conditions must be met for a user to be effectively managed by the Umbrella Roaming Client?
46Which TWO pieces of information are required for a 'Network Identity' in Umbrella?
47Which THREE actions can be taken in an Umbrella policy based on content categories?
48Which THREE items are necessary for troubleshooting a failed 'Umbrella AD Connector' sync?
49Which TWO components are essential for a complete Cisco Umbrella deployment on end-user laptops?
50An administrator is configuring Cisco Umbrella for a branch office and needs to ensure that all DNS requests are inspected for malicious domains without requiring a client-side agent. Which configuration approach should the administrator implement?
51You are implementing Cisco Secure Access and need to configure a Global Policy that restricts access to unsanctioned SaaS applications based on their risk score. Where should this policy be applied in the Secure Access dashboard?
52An organization is migrating to a Secure Internet Gateway (SIG) architecture. They currently have an on-premises firewall blocking all traffic except for specific ports. What is the recommended method to forward traffic to the SIG while maintaining existing security policy consistency?
53In Cisco Umbrella, which component is used to associate internal IP addresses with Active Directory user identities for granular policy reporting?
54You are troubleshooting a scenario where users are unable to access a specific internal cloud resource after migrating to Cisco Secure Access. The traffic is being blocked by a default policy. How should you modify the traffic flow to ensure internal traffic stays off the SIG?
55A company wants to prevent users from bypassing security policies by using unauthorized VPNs or proxies. Which feature in Cisco Umbrella should be enabled to mitigate this risk?
56Which Cisco Umbrella report provides the most granular visibility into the specific security categories triggered by user traffic?
57Which THREE actions are required when configuring a new IPsec tunnel for the Cisco SIG (Secure Internet Gateway)?
58Which TWO settings must be correctly configured to ensure that Cisco Secure Access provides effective decryption and inspection of HTTPS traffic?
59Which THREE items are considered primary components of the Cisco Umbrella 'Identity' structure when creating security policies?
The Network And Cloud Security domain covers the key concepts tested in this area of the SCAZT exam blueprint published by Cisco. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all SCAZT domains — no account required.
The Courseiva SCAZT question bank contains 59 questions in the Network And Cloud Security domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Network And Cloud Security domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included