Data Security Platforms
Research preview. Based on public sources, not deployment testing.
← All platforms

Zscaler DSPM

Compare with…

Zscaler documents different scan methods by store, including APIs, snapshots, exports and sampled queries. A supported connector does not establish that every row or object is inspected. [1]

Capabilities

Discovery & classification [1]

Sources reviewed 2 sources

Data coverage

Read the scope beside each mark. Support for an environment does not establish every capability in every store.

Microsoft 365
Unconfirmed
AWS
Partial

S3 uses APIs, EBS uses snapshots and DynamoDB uses S3 exports. RDS methods include full and sampled scans. [1]

Google Cloud
Partial

Cloud Storage, Compute disks, Cloud SQL and BigQuery are listed. BigQuery scans use sampling. [1]

Snowflake and Databricks
Partial

Snowflake and Databricks are supported through sampled queries. Confirm cloud and region limits. [1]

On-prem shares
Unconfirmed
SaaS apps
Unconfirmed

Unconfirmed means the reviewed sources do not establish coverage. How coverage is assessed

Deployment and cost

How it runs

Collection methods vary by data store. [1]

Methods
The support matrix specifies API access, snapshots, exports or sampled queries.
Evaluation
Request the scanner placement and temporary-storage lifecycle for the proposed deployment.

Pricing and operating workload are not published in the reviewed sources.

Questions for the vendor

  1. What sampling rate and exclusions apply to each store?
  2. Where are snapshots and exports processed, and when are they deleted?

Sources

  1. help.zscaler.com
  2. help.zscaler.com