Q: 16
A user is accessing a private application through Zscaler with SSL Inspection enabled. Which
certificate will the user see on the browser session?
Options
Discussion
D . Practice material and the official guide are clear that Zscaler does MITM SSL and issues its own cert to the browser. Real server cert only shows up if inspection is off, so D should be right here.
D In practice exams and docs, Zscaler always presents its own MITM cert to the browser during SSL inspection, not the original server one. Pretty sure that's right but let me know if you've seen different!
Seen this in a few practice sets. It's D because with SSL inspection on, Zscaler sits in the middle and issues its own cert to the user's browser. The real server cert gets replaced in transit. Pretty sure about this but open if someone has other thoughts.
Option B, Had something like this in a mock and B was correct there.
D imo
C trips people up but I’m pretty sure it’s not correct. D, Zscaler MITM cert is shown when inspection’s on.
You'll see the Zscaler generated MITM Certificate. That's what shows up since Zscaler proxies and reissues the cert during SSL inspection. Similar question popped up in exam reports. D.
Be respectful. No spam.