What is the duration of Zscaler ' s short-lived issuing CA for SSL Inspection?
A.
7-day expiry with 0-day rotation
B.
14-day expiry with 7-day rotation
C.
30-day expiry with 7-day rotation
D.
21-day expiry with 14-day rotation
The Answer Is:
B
This question includes an explanation.
Explanation:
Answer B is correct. Zscaler’s official TLS/SSL Inspection reference architecture states that the ZIA Service Edge intermediate CA is used for seven days and remains valid for fourteen days. In other words, it has a 14-day expiry with a 7-day rotation. The overlap lets a newly issued intermediate become active while the previous certificate is still valid, supporting continuity across service edges. ZIA uses this short-lived intermediate to sign on-demand certificates presented to endpoints during SSL inspection. Its private key is retained in the Zscaler CA database and Service Edge memory and is not written to disk at the edge. Therefore, 7/0, 30/7, and 21/14 do not match the documented lifecycle. See Zscaler’s TLS/SSL Inspection reference architecture.
ZDTA PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 70% Discount on All Products,
Use Coupon: "coponace"