Skip to main content

Introduction

Zenith Live 2026 · Hands-On Lab

Discover · Protect · Investigate

Explore the data security lifecycle — one fictional company, three personas, nine complementary labs.

⏱ ~4 Hours🗂 3 Modules · 9 Labs👤 3 Personas🖥 2 Tenants🏢 Dataparity Inc.

Workshop Overview

Dataparity Inc. is a fictional financial services firm assessing sensitive data across SaaS, endpoints, and AI tools. Alex explores existing findings and builds detection and enforcement policies, Kevin tests web, endpoint, and preconfigured browser controls, and Priya reviews existing incidents and response workflows. The company and personas connect these complementary exercises, not a single file or incident. Allow approximately four hours, including introductions, discussion, breaks, and setup.

Learning Path

🔍
Discover
Module 1 · Labs 1–4
Explore SaaS posture, endpoint data, user activity, apps, devices, and Copilot readiness.
→
🛡
Protect
Module 2 · Labs 5–8
Build web and endpoint policies in Labs 5–7; test preconfigured browser controls in Lab 8.
→
🔎
Investigate
Module 3 · Lab 9
Review existing incident evidence, notification history, actions, and workflow previews.

Module Overview

Module 1
Visibility
⏱ ~60 min · Enterprise Tenant · Read-Only
Lab 1Shadow IT & App Visibility
20 min
Lab 2SaaS Posture & App Governance
15 min
Lab 3Endpoint Data Visibility
15 min
Lab 4Copilot Readiness
10 min
Module 2
Protection
⏱ ~90 min · Lab Tenant · Read/Write
Lab 5Detection Logic
15 min
Lab 6Inline DLP
25 min
Lab 7Endpoint DLP
25 min
Lab 8Browser DLP
25 min
Module 3
Investigation
⏱ ~30 min · Enterprise Tenant · Read-Only
Lab 9ZWA SOC Triage
20 min
ReviewKnowledge Check
10 min

Review Evidence · Explore Actions · Preview Workflows

Meet the Team

🛡
Alex
Security Administrator
Modules 1 + 2

Dataparity's security admin. Alex reviews SaaS and endpoint findings in Module 1, then builds detection logic and web/endpoint policies in Labs 5–7. Browser policies in Lab 8 are preconfigured.

👤
Kevin
End User · Customer Success
Module 2 (Test Steps)

A busy employee testing convenient tools. Kevin tries a web upload, local file access and clipboard paste, then browser masking, sensitive-download blocking, and watermarking.

🔍
Priya
SOC Analyst · Tier-1
Module 3 (Full Lab)

Dataparity's SOC analyst. Priya reviews a pre-populated incident queue, evidence, existing notifications and state changes, available actions, and workflow previews — without changing records.

📊
The Narrative Thread
One company, complementary activities

Labs 6 and 7 reuse Dataparity_Q2_2025_Workforce_Financial_Summary.docx and the Lab 5 detection engine. Lab 8 uses supplied customer text, a sensitive sample PDF from DLP Test, and a browser-viewed document with preconfigured controls. Labs 3, 4, and 9 explore independent pre-populated records — not the student's file or incident.

Labs 3–4 — VisibilityLab 6 — Upload BlockLab 7 — File Read & Paste BlockLab 8 — Mask, Block, WatermarkLab 9 — Existing Incident Review

Lab Tenants

🏢
Enterprise Tenant
Tenant 1 · Read-Only
Modules 1 + 3

Pre-populated with production-like data for read-only exploration. Sign in using CloudShare → Credentials → SDC Credentials for Modules 1 and 3. No configuration or incident-response actions are performed.

⚗️
Lab Tenant
Tenant 2 · Read/Write
Module 2 Only

Use CloudShare → Credentials → Zscaler Tenant / Student Admin for Module 2. Build detection and web/endpoint policies in Labs 5–7; Lab 8 uses preconfigured browser controls and its separate extension login. Allow 15 minutes for Module 2 prerequisites, including VM/Client Connector setup and SSL inspection verification.

🎓
Lab Assistant
Zenith Live 2026 · Dataparity
Introduction
Browse all topics