Broadcom’s ZTNA exam does not ask what zero trust means. It never defines the model, never compares it with perimeter security, and never asks you to argue for it. Every one of its eleven topics is a place in a console or a decision you make inside one.
The Symantec ZTNA certification is the Technical Specialist credential for Symantec ZTNA Complete, coded 250-583: 75 questions in 90 minutes at a 70 percent bar, with a syllabus that publishes eleven topic names and not a single percentage beside them.
Table of Contents
- What is the Symantec ZTNA certification?
- Why does Broadcom test the console rather than the concept?
- How is the 250-583 exam delivered and scored?
- What does the syllabus actually list?
- Agentless or agent based, and why the exam splits them
- Where ZTNA sits inside the wider SASE stack
- What does Broadcom expect you to have done first?
- How does the Technical Specialist track work?
- How should you prepare for 250-583?
- Frequently Asked Questions
- Conclusion
What is the Symantec ZTNA certification?
The Symantec ZTNA certification is Broadcom’s intermediate-level credential for administrators of Symantec ZTNA Complete, formally titled Broadcom Symantec ZTNA Complete R1 Technical Specialist and carrying the exam code 250-583. It is a 75 question paper covering eleven topic areas, from the administration portal and authentication through to application publishing, policy, integrations and reporting.
Broadcom classifies the badge as a certification at intermediate level rather than as a foundational or expert one. That placement is honest about the audience: the exam assumes you can already find your way around the product, and spends its questions on what you do once you are there.
The product itself has a second name that turns up constantly in the material. Symantec ZTNA was previously Secure Access Cloud, and Broadcom’s own badge text still uses that older name. Anyone reading around this exam will meet both, and they refer to the same thing.
Why does Broadcom test the console rather than the concept?
Read the eleven topic names in order and the pattern is unmistakable. Symantec ZTNA Portal, Authentication, Network Security Boundary, Agentless Application Configuration, Policy Configuration, Agent Based Application Configuration, Integrations, Role Based Admin Control, Logging and Reporting, Planning. Ten of the eleven describe an administrative task. Only the first, SASE Solution Overview, is conceptual at all.
That design has a consequence worth saying plainly: reading about zero trust will not prepare you for this exam. The architecture is well documented, and the reference most organisations work from is NIST Special Publication 800-207, which sets out the policy engine, policy administrator and policy enforcement point model that products like this one implement. It is genuinely useful background. It will not tell you which screen in the Symantec portal creates a connector. Vendor-neutral practitioner material from the Zero Trust working group is useful for the same reason, because it describes the deployment decisions without assuming any one product.
The productive way to use that document is as a translation layer. When the syllabus says Network Security Boundary, it is talking about enforcement points. When it says Policy Configuration, it is talking about the policy engine. Knowing the abstract model helps you understand why the product is shaped the way it is, but the exam scores you on the shape.
The quickest way to calibrate is to work a set of exam-style items and see how many are locational rather than conceptual. CertFun’s 250-583 practice questions make the difference obvious within the first handful, and that is a cheaper diagnosis than discovering it during the real sitting.
How is the 250-583 exam delivered and scored?
250-583 is 75 questions in 90 minutes, priced at $250 USD, with a 70 percent pass mark, and it is scheduled through Broadcom rather than through a third-party test aggregator. The recommended training is Broadcom’s own Symantec Zero Trust Network Access Administration R1 course. Passing issues a Broadcom Technical Specialist badge through Credly.
| Field | Value |
|---|---|
| Credential name | Broadcom Symantec ZTNA Complete R1 Technical Specialist |
| Exam code | 250-583 |
| Level | Intermediate |
| Questions | 75 |
| Duration | 90 minutes |
| Passing score | 70 percent |
| Price | $250 USD |
| Topic areas | 11, with no published weightings |
| Recommended course | Symantec Zero Trust Network Access Administration R1 |
| Scheduling | Broadcom |
Seventy five questions in 90 minutes is 72 seconds each, which is tight by the standards of vendor product exams. It is roughly a third less time per question than a 50 item, 75 minute paper allows, so the pacing itself is part of the challenge rather than an afterthought.
A 70 percent bar on 75 questions means 53 correct answers and a margin of 22. That sounds generous, and it is the reason the missing weightings matter less than they might: with eleven topics and no published distribution, the safest assumption is that no single topic can be skipped, and a 22 item allowance is enough to absorb one genuinely weak area but not two.
What does the syllabus actually list?
Eleven topic areas, published as names and objectives with no percentage beside any of them. That is unusual and it changes how you should plan. Without weightings there is no way to rank topics by exam value, so the defensible approach is to treat coverage as flat and work through every one rather than gambling on which will dominate.
| Topic | What the objectives describe |
|---|---|
| SASE Solution Overview | The benefits of the Symantec SASE solution and of ZTNA within it |
| Symantec ZTNA Portal | Navigating the admin portal and administering tenant admins |
| Authentication | Configuring and administering authentication |
| Network Security Boundary | Implementing and administering sites and connectors |
| Agentless Application Configuration | Implementing and administering agentless applications |
| Policy Configuration | Implementing and administering policies on configured applications |
| Agent Based Application Configuration | Agent based applications, plus integrating Cloud SWG and DNS servers |
| Integrations | Integration with Cloud Data Loss Prevention and Threat Intelligence Services |
| Role Based Admin Control | Using RBAC with ZTNA sites and with collections |
| Logging and Reporting | Log shipping, health checks and notifications |
| Planning | Planning and deploying ZTNA in an organisation |
Two of these are easy to underestimate. Planning is a single objective and reads like a throwaway, but it is the only topic that asks you to think about a whole deployment rather than a single setting, which makes it the most likely home for scenario-shaped questions. Logging and Reporting looks administrative and covers health checks and notifications, which are the mechanisms by which a broken connector becomes visible.
Role Based Admin Control deserves a second look too, because it is explicitly tested in two different scopes: against sites and against collections. Those are different objects with different inheritance behaviour, and a question that names one when you are thinking of the other is a straightforward way to lose a mark.
Agentless or agent based, and why the exam splits them
The syllabus gives agentless and agent based application configuration two separate topics rather than one, which is the clearest structural signal it offers. They are different publishing models with different capabilities, and the exam wants you to know which one a described requirement calls for.

Agentless publishing puts the service in front of a web application and brokers the session without anything installed on the user’s device. It is the model that makes third-party and unmanaged-device access workable, because there is nothing to deploy to a machine you do not control.
Agent based publishing installs a client and can therefore reach applications that are not web based, handling protocols a browser cannot broker. The syllabus attaches two integrations to this topic specifically: Cloud Secure Web Gateway and DNS servers. That pairing is not decorative. Once a client is on the device, web traffic and name resolution both become things the platform can influence, which is why those integrations belong here rather than in the general integrations topic.
This is also where the comparison people actually search for gets answered. The practical difference between this model and a traditional remote access tunnel is that a tunnel grants network reachability and this grants application reachability, one published application at a time. A candidate who understands that distinction will find most of the policy questions follow from it.
Where ZTNA sits inside the wider SASE stack
The first topic on the syllabus is the SASE Solution Overview, and it exists because ZTNA Complete is not sold or deployed alone. Broadcom’s Symantec ZTNA product page positions it inside a wider network protection portfolio, and the exam’s integration objectives reflect exactly that.
Three named integrations run through the syllabus. Cloud Secure Web Gateway handles outbound web traffic. Cloud Data Loss Prevention inspects what moves through the sessions ZTNA brokers. Threat Intelligence Services supplies the reputation and threat context that policy decisions can act on.
Understanding those as a set rather than as three unrelated checkboxes is what the overview topic is really testing. A question about why a policy references DLP is answerable from the architecture; it is not answerable by memorising the name of a menu item.
It is worth knowing which parts of the portfolio are separately certified, too. Broadcom runs Technical Specialist exams across the Symantec line, including web protection, endpoint and messaging products, so the ZTNA credential is one node in a set rather than a standalone qualification.
What does Broadcom expect you to have done first?
Broadcom states its expectation on the badge record rather than on the syllabus page, and it is specific: three to six months of experience working with Symantec ZTNA in production or in a lab, alongside completing eLearning and instructor-led training. There is no formal prerequisite certification, but there is a clear experience assumption.
That detail is the most useful thing a candidate can find before booking, and it is easy to miss because it lives on the badge page rather than with the exam specifications. A reader who has been using the product for a fortnight now knows the honest answer to whether they are ready.
There is one administrative step in the same list that catches people out. Earning the badge requires accepting Broadcom’s Software Certification Agreement, which is not an academic requirement at all, but it is part of the process and it is worth doing before results day rather than after. The Broadcom ZTNA badge record lists all four requirements together.
How does the Technical Specialist track work?
Technical Specialist is a tier in Broadcom’s certification programme rather than a single qualification, and it runs across the whole Symantec and CA software portfolio. Each product line has its own exam in the 250 series, each is scoped to that product, and none of them is a prerequisite for another.
That structure explains why the credential is narrow on purpose. It is not trying to establish that you understand network security generally. It is establishing that you can run one named product, which is precisely what a partner or a customer wants to verify before letting someone near a production tenant. Broadcom describes the programme structure on its software certification programme page.
Anyone building a Symantec profile will find the exams share a shape more than they share content. The Symantec Messaging Gateway specialist exam sits in the same tier and follows the same console-first logic, which means preparation habits transfer even though nothing on the syllabus does.
The same numbering scheme runs across the wider portfolio, well beyond the Symantec security line, so a 250 series code on its own tells you the tier rather than the subject.
How should you prepare for 250-583?
Preparation for 250-583 should be flat rather than weighted, because the syllabus publishes no percentages. Cover all eleven topics, spend the extra time on the two application-publishing topics and on policy, and rehearse the pace, because 72 seconds a question is the constraint most candidates underestimate.

- Check your experience honestly against Broadcom’s own expectation of three to six months working with Symantec ZTNA, and if you fall short, get lab time before you book rather than after you fail.
- Work through the Symantec Zero Trust Network Access Administration R1 course, since Broadcom names it as the recommended training and the syllabus follows its structure.
- Publish one application each way, agentless and agent based, so that the two separate topics become two distinct experiences rather than a single blurred memory.
- Attach policies to both published applications and change them, because policy configuration is tested against configured applications rather than in isolation.
- Configure the three named integrations, Cloud Secure Web Gateway, Cloud Data Loss Prevention and Threat Intelligence Services, so the architecture questions rest on something you have wired rather than read.
- Set up role based admin control twice, once scoped to sites and once scoped to collections, since the syllabus explicitly tests both and they behave differently.
- Break a connector deliberately and follow it through log shipping, health checks and notifications, which turns the reporting topic into a diagnosis you have actually performed.
- Finish with timed sets at 75 questions in 90 minutes until the pace feels routine, and accept the Broadcom Software Certification Agreement before exam day so the badge issues cleanly.
Four to six weeks is a sensible window for an administrator already working with the platform. The breadth is the work here, not the depth, because eleven topics with no weightings leaves nowhere safe to be thin.
The habit of preparing in the console rather than from notes carries across the tier. Broadcom’s workload automation line follows the same pattern, and the AutoSys 250-613 exam is another Technical Specialist paper built entirely around a single product’s administration surface.
Frequently Asked Questions
How many questions are on the 250-583 exam?
Seventy five questions in 90 minutes, which works out at about 72 seconds each. That is tighter than most vendor product exams and the pacing is worth rehearsing.
What is the passing score for the Symantec ZTNA certification?
Seventy percent, which on 75 questions means 53 correct answers and a margin of 22. Broadcom does not publish a scaled score for this exam.
How much does Broadcom 250-583 cost?
$250 USD. Scheduling is through Broadcom rather than a third-party aggregator.
Are the topics weighted?
No. The syllabus publishes eleven topic names with objectives under each and no percentages at all. Without a distribution, the safe plan is to treat coverage as flat rather than guess which topic dominates.
Do I need experience before taking this exam?
Broadcom sets no formal prerequisite certification, but its own badge record expects three to six months of hands-on work with Symantec ZTNA in production or a lab, alongside eLearning and instructor-led training.
What is the difference between agentless and agent based publishing here?
Agentless brokers access to web applications with nothing installed on the device, which is what makes unmanaged-device access workable. Agent based installs a client, reaches non-web applications, and is where the Cloud Secure Web Gateway and DNS integrations attach.
Does the exam test zero trust theory?
Barely. Only the SASE Solution Overview topic is conceptual, and even that is framed around the benefits of Symantec’s own solution. The other ten topics are administration tasks.
Is Symantec ZTNA the same as Secure Access Cloud?
Yes. Secure Access Cloud is the former name, and Broadcom’s badge text still uses it, so both names appear across the documentation and refer to the same product.
Which integrations does the syllabus name?
Three: Cloud Secure Web Gateway and DNS servers under the agent based topic, and Cloud Data Loss Prevention plus Threat Intelligence Services under the integrations topic.
Does the credential expire?
Broadcom states no expiry or validity period on the badge record. Because the exam is tied to release R1 of the product, its practical currency is likely to follow the product rather than a fixed clock.
Conclusion
250-583 is a broad, console-first product exam with an unusually bare syllabus: eleven topics, no weightings, 75 questions in 90 minutes, and a 70 percent bar. The missing percentages are the defining feature, because they remove any safe place to be thin and make even coverage the only defensible plan.
Take Broadcom’s own three to six month experience expectation seriously, publish an application both ways, wire the three named integrations, and practise at the pace the clock actually demands. Then book it, accept the certification agreement in advance, and treat the badge as proof you can run this one product well rather than as a general zero trust qualification.
