🎤 ZPA — Interview Q&A

❓ زیرو ٹرسٹ کے تین اصول کون سے ہیں؟Zero Trust ke teen principles kaun se hain?What are the three principles of Zero Trust?

کبھی بھروسہ نہ کرو، ہمیشہ تصدیق کرو؛ least privilege رسائی؛ micro-segmentation۔Never trust, always verify; least privilege access; micro-segmentation.Never trust, always verify; least privilege access; micro-segmentation.

❓ ZTNA vs VPN — فرق کیا ہے؟ZTNA vs VPN — farq kya hai?ZTNA vs VPN — what is the difference?

VPN پوری نیٹ ورک رسائی دیتا ہے اور IPs ظاہر کرتا ہے۔ ZTNA صرف per-app رسائی دیتا ہے، internal IPs چھپاتا ہے، اور کوئی ان باؤنڈ پورٹ نہیں کھولتا۔VPN poori network access deta hai aur IPs zahir karta hai. ZTNA sirf per-app access deta hai, internal IPs chhupata hai, aur koi inbound port nahi kholta.VPN gives full network access and exposes IPs. ZTNA gives per-app access only, hides internal IPs, and opens no inbound ports.

❓ App Connector کیا ہے؟App Connector kya hai?What is an App Connector?

ایپس کے پاس ایک VM جو ZPA کلاؤڈ کی طرف آؤٹ باؤنڈ اونلی ٹنل بناتی ہے اور user requests اندر پہنچاتی ہے۔Apps ke paas ek VM jo ZPA cloud ki taraf outbound-only tunnel banati hai aur user requests andar pahunchati hai.A VM next to the apps that opens an outbound-only tunnel to the ZPA cloud and delivers user requests inward.

❓ Application Segment کیا ہے؟Application Segment kya hai?What is an Application Segment?

یہ publish ہونے والی unit کو define کرتا ہے: ایپ کے FQDNs، IP ranges، ports، اور server groups جو اسے serve کرتے ہیں۔Ye publish hone wali unit ko define karta hai: app ke FQDNs, IP ranges, ports, aur server groups jo ise serve karte hain.It defines a publishable unit: the app's FQDNs, IP ranges, ports, and the server groups that serve it.

❓ ZPA میں IdP کیا ہے اور کیا کرتا ہے؟ZPA mein IdP kya hai aur kya karta hai?What is an IdP in ZPA and what does it do?

وہ trusted identity source (Okta, Entra ID, Google) جو SAML سے جڑتا ہے؛ ZPA اسے login, groups, SSO اور MFA کے لیے استعمال کرتا ہے۔Woh trusted identity source (Okta, Entra ID, Google) jo SAML se jurta hai; ZPA ise login, groups, SSO aur MFA ke liye istemal karta hai.The trusted identity source (Okta, Entra ID, Google) connected via SAML; ZPA uses it for login, groups, SSO, and MFA enforcement.

❓ Browser Access کیا ہے اور کب استعمال ہوتا ہے؟Browser Access kya hai aur kab istemal hota hai?What is Browser Access and when is it used?

یہ اندرونی ایپس کو Zscaler سرٹیفیکیٹ سے براؤزر میں کھولتا ہے — contractors یا BYOD کے لیے بغیر client agent انسٹال کیے۔Ye internal apps ko Zscaler certificate se browser mein kholta hai — contractors ya BYOD ke liye bina client agent install kiye.It opens internal apps in a browser using a Zscaler certificate — for contractors or BYOD with no client agent installed.

❓ User ایپ تک نہیں پہنچ سکتا — اپنی troubleshooting order بتائیں؟User app tak nahi pahunch sakta — apni troubleshooting order batayein.A user cannot reach an app — walk me through your troubleshooting order.

Client (sign-in, ZPA module on) → policy (کون سا rule لگا، Analytics > Logs میں دیکھیں) → segment (FQDN/port) → connector health۔Client (sign-in, ZPA module on) → policy (kaun sa rule laga, Analytics > Logs mein dekhein) → segment (FQDN/port) → connector health.Client (sign-in, ZPA module on) → policy (which rule matched, see Analytics > Logs) → segment (FQDN/port) → connector health.