SEC536: Adversarial AI - Penetration Testing AI Systems

In this webcast, SANS will share results from an in-depth hands-on review of Zscaler Microsegmentation, revealing how it enables real-time asset discovery, granular policy enforcement, and unified Zero Trust controls across cloud and on-premises environments.

It's an extension of the Zscaler Private Access (ZPA) platform that provides real-time asset discovery, granular workload-level policy enforcement, and zero trust controls across both cloud and on-premises environments, deployed via an installed agent on each asset.
It discovers cloud assets using metadata tags or cloud attributes such as VPC or VNet identifiers, and discovers on-premises assets using IP addresses or network subnet definitions. In SANS testing, AWS-tagged assets were added to a dynamic resource group in under 30 seconds.
Sim Block is a policy action that allows traffic to pass through while still generating alerts, as if the traffic had been blocked. It's designed for testing and tuning, letting teams see what a stricter policy would catch before enforcing it.
The recommended timeline is four to six weeks, covering agent deployment, a monitoring period of at least one to two weeks to observe real traffic patterns, and a review of enforcement logs before moving from Allow/Sim Block policies to full Block enforcement.
The research notes that microsegmentation is one of the most sought-after zero trust capabilities but also one of the most difficult to implement and maintain, with many initiatives failing before they're fully underway, typically due to the operational burden of tracking policy and performance issues without a phased rollout plan.
Yes. The platform supports both physical and virtual systems, cloud APIs, and containers, allowing organizations to segment workloads across cloud and on-premises environments without relying solely on static IPs or manual rule creation, and it supports AWS, Azure, GCP, and on-premises deployment targets.