No more typing reviews! Try our Samantha, our new voice AI agent.

VMware Carbon Black App Control vs Zscaler Zero Trust Exchange Platform comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Feb 8, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

VMware Carbon Black App Con...
Ranking in Application Control
7th
Average Rating
9.2
Reviews Sentiment
6.8
Number of Reviews
8
Ranking in other categories
No ranking in other categories
Zscaler Zero Trust Exchange...
Ranking in Application Control
4th
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
67
Ranking in other categories
Data Loss Prevention (DLP) (5th), Cloud Access Security Brokers (CASB) (8th), ZTNA as a Service (1st), Secure Access Service Edge (SASE) (2nd), Remote Browser Isolation (RBI) (1st)
 

Mindshare comparison

As of May 2026, in the Application Control category, the mindshare of VMware Carbon Black App Control is 11.0%, down from 24.1% compared to the previous year. The mindshare of Zscaler Zero Trust Exchange Platform is 11.1%, up from 8.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Application Control Mindshare Distribution
ProductMindshare (%)
Zscaler Zero Trust Exchange Platform11.1%
VMware Carbon Black App Control11.0%
Other77.9%
Application Control
 

Featured Reviews

AS
Security Administrator at EJADA
We can isolate problem machines and limit their access
We use App Control to scan the network for virtual machines that have unauthorized applications. We can isolate the problem VMs and control application access.  More than two years. I rate Carbon Black App Control 10 out of 10 for stability. I rate App Control six out of 10 for scalability.…
Vibin Thomas - PeerSpot reviewer
Team Lead, Technical Content Security at Valuepoint Systems
Zero trust access has transformed remote connectivity and now simplifies secure app usage
Zscaler Zero Trust Exchange Platform, especially Zscaler Private Access, is very strong, though there are a few areas where improvements can be made. One challenge observed is around initial troubleshooting and visibility. While Zscaler Private Access provides logs, it can sometimes take time to pinpoint the exact cause of access issues, especially in complex environments with multiple policies and identity integration. Another area is the dependency on identity and connector health. Since Zscaler Private Access is heavily reliant on app connectors and identity providers, any issues with these components can impact user access, making proper monitoring critical. During the initial setup, policy configuration and application onboarding require careful planning, especially for larger environments with many applications. These challenges are manageable with proper design and monitoring. Overall, the platform delivers strong security and user experience. I would recommend a few improvements, especially around user interface, reporting, and troubleshooting experience. From a user interface perspective, while the platform is powerful, the policy configuration and navigation can feel complex, especially for new users. A more simplified and intuitive layout for policy mapping and application access would help reduce the learning curve. In terms of reporting, Zscaler Private Access provides logs, but having more built-in customizable dashboards and analytics would be very helpful. Better visibility into user access patterns, application performance, and real-time troubleshooting insights would improve operational efficiency. From a support and troubleshooting standpoint, it would be beneficial to have more granular centralized visibility, allowing for quick end-to-end tracing of a user request from authentication to application access without switching between multiple views. These improvements would make the platform even more efficient, especially for large-scale enterprise environments.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It offers a sense of security where anything that comes in, regardless of what it is, unless you approve it manually, it's not going to run."
"We have been dealing with VMware Carbon Black App Control for one year, and during this time we have already made sure that this is the best solution to protect our user machines and servers."
"All the functions within VMware Carbon Black App Control are valuable."
"The visibility, reporting, and the ability to stop or prevent malicious or undesired applications from being installed are the most valuable features."
"The API integration is good."
"I use the console to check for threats and I find it to be very user-friendly."
"The visibility, reporting, and the ability to stop or prevent malicious or undesired applications from being installed are the most valuable features."
"The effectiveness of application whitelisting is very good."
"The initial setup is easy."
"Subsequently, after this, there is a huge reduction, as the vulnerabilities, especially the security bugs that were coming prior to Zscaler Zero Trust Exchange Platform, were about 20,000 to 22,000 and have come down more than 40 percent, which is definitely an advantage over the previous product."
"The scalability by definition is kind of intrinsically built-in."
"The VPN is great for the stability on offer and for the cloud updates and insights you can get."
"The most valuable aspect of Zscaler Cloud DLP is its automatic DLP feature."
"I would recommend Zscaler Cloud DLP to others because it's the best proxy product in the market at the moment."
"Zscaler's technical support is quite good."
"I like the web filtering capabilities, which are very good, and it offers sound internet security notifications with a stable, scalable solution and an easy-to-use user interface."
 

Cons

"Its initial setup is very complex. We got help from their implementation team because if it is not set up properly, you can really hinder the operation of your environment and things won't execute or run."
"Another issue is that even sometimes if you approve, for example, Adobe as a publisher, you say any product or anything that's from Adobe has to run. It generally runs, but especially in a large environment and with a lot of users, sometimes, due to some certification validation issues or some other issue, it might stop the process from running."
"The reporting is not good and needs to be improved."
"I would like to see the addition of some more features that are in other, similar solutions."
"I would like to see the addition of some more features that are in other, similar solutions."
"The initial setup is somewhat complex."
"The initial setup is somewhat complex."
"Carbon Black does not use the database for identifying the file, the fields, or malware."
"The only issue with Zscaler Cloud DLP is that it only gives you DLP protection from web traffic, which is flowing out, while a full-blown DLP solution such as Forcepoint or Symantec gives you DLP coverage for multiple channels. Zscaler Cloud DLP doesn't give you coverage for email, fax, and USB channels, and this is the only challenge or room for improvement in the solution. It's just an extension on top of what you're buying on the proxy, so it's just an added layer, and it doesn't cover DLP on a very broad level. I'm unsure if Zcaler is in the business of competing with a full-blown DLP solution, and if there's a plan to expand the features of Zscaler Cloud DLP beyond the web channel because you'll have to deploy a full-blown agent for it. I'm unsure if this is on the cards because the solution is just an added layer that you get with your proxy. I've asked the Zcaler team whether there's a plan to go full DLP in the future, but I didn't get a positive response. There isn't any feature I'd like added to Zscaler Cloud DLP currently, because anything you could think of that should be in cloud or SaaS solutions is already there, except for machine learning, as it's the only functionality that seems to be lacking in the solution. Machine learning is an additional policy available in other DLP solutions in the market, but my team didn't find it in Zscaler Cloud DLP."
"Sometimes applications crash on some machines, and we’d like Zscaler to give us some information as to why that may have happened. We’d like more detailed reports."
"From a user interface perspective, while the platform is powerful, the policy configuration and navigation can feel complex, especially for new users."
"We'd like to have two-factor authentication that is quite simple."
"There could be additional ways to define proximity. Additionally, they should provide some exclusion options for specific policies and an ability to control the DLP engine."
"There is some issue while accessing the portal. It takes too long."
"There aren't really any missing features that I have witnessed."
"The connectivity monitoring part should be included in the core license without any extra charges."
 

Pricing and Cost Advice

"The pricing for this product is competitive and our customers who told us that often, Carbon Back is the cheaper solution."
"We pay a fee for support, which is renewed annually."
"Its price is reasonable and what is expected for these types of products."
"The technical support is good."
"Pricing for Zscaler Private Access is moderate. It's acceptable, though I can't give you the exact price currently. It's not too expensive, and on a scale of one to five, I would rate it a four out of five in terms of pricing."
"As per industry leads, Zscaler CASB is an expensive solution."
"Zscaler DLP solution is expensive, with a fixed pricing structure that is billed annually and monthly. There are no additional costs for licenses."
"The pricing is expensive and on the higher end. Honestly, in my opinion, it is not worth the price."
"The product has reasonable pricing."
"Zscaler Cloud DLP is moderately priced. We pay around 2 million rupees per year."
"Zscaler Private Access is extremely expensive."
report
Use our free recommendation engine to learn which Application Control solutions are best for your needs.
893,244 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
23%
Computer Software Company
9%
Government
8%
Healthcare Company
7%
Financial Services Firm
12%
Manufacturing Company
10%
Computer Software Company
9%
Insurance Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business4
Large Enterprise4
By reviewers
Company SizeCount
Small Business16
Midsize Enterprise12
Large Enterprise44
 

Questions from the Community

Ask a question
Earn 20 points
What is the better solution - Prisma Access or Zscaler Private Access?
We looked into Prisma Access before choosing Zscaler Private Access (ZPA). Palo Alto’s Prisma Access is a secure access service edge (SASE) designed to deliver network security in a cloud-deliver...
What needs improvement with Zscaler SASE?
The solution needs to improve a lot of aspects.
What is your primary use case for Zscaler SASE?
We are using Zscaler Zero Trust Exchange for its Zscaler Internet Access service. It provides web security, DLP, data protection, prevention, and lots more features.
 

Also Known As

CB Protection, Carbon Black CB Protection
Zscaler SASE, Zscaler DLP, Zscaler CASB, Zscaler CSPM, Zscaler Browser Isolation, Zscaler Posture Control
 

Overview

 

Sample Customers

Kaas Tailored, Core-Mark, Indeed, Hologic, Landmark Credit Union, Project Worldwide
Siemens, AutoNation, GE, NOV
Find out what your peers are saying about VMware Carbon Black App Control vs. Zscaler Zero Trust Exchange Platform and other solutions. Updated: April 2026.
893,244 professionals have used our research since 2012.