Font size
WorksheetsWorkspace
Total questions: 60
Worksheet time: 5hrs 0mins
As a Workspace ONE administrator, you have been tasked with creating a custom visualization for management that shows device statistics, trust network threats, and application adoption metrics in a single view.Which feature of Workspace ONE can be used?
Workspace ONE Intelligence Dashboards
Workspace ONE Access Application View
Workspace ONE Intelligence Automations
Workspace ONE UEM Device List View
Which Workspace ONE UEM feature can assist in sending event log information to a Security Information and Event Management (SIEM) tool?
Syslog Integration
Relay Server Integration
Certificate Authority Integration
File Storage Integration
Which two steps would an administrator complete to enable auto-discovery for their Workspace ONE UEM environment? (Choose two.)
Enter the email domain when installing the AirWatch Cloud Connector.
Verify the domain by accepting the link in the email that registered auto-discovery.
Register email domain within Workspace ONE UEM.
Enter the email domain when establishing directory services.
Email auto-discovery@workspaceone.com with the domain the administrator wants to register.
What two features of Hub Services can be enabled without enabling Workspace ONE Access and having the authentication mode set to Workspace ONE UEM?(Choose two.)
enable SSO for applications
enable People Search
notifications for iOS and Android
Hub Virtual Assistant Chatbot
Hub Catalog layout
Where is Hub Services component co-located?
Workspace ONE Intelligence
B. Workspace ONE Access
C. Workspace ONE Airlift
D. Workspace ONE UEM
Which two Workspace ONE UEM core components are required for all on-premises environments? (Choose two.)
A. Device Services
B. AirWatch Cloud Connector
C. Unified Access Gateway
D. Secure Email Gateway
E. Console Services
An administrator would like to track these details for all Windows desktops managed by Workspace ONE UEM:✑ driver details for a mouse driver✑ warranty information for OS✑ registry value of internal appsWhich Workspace ONE UEM utility can the administrator use?
A. Create LGPO and assign to Windows devices.
B. Create sensors and assign to Windows devices.
C. Create an OEM update profile and assign to Windows devices.
D. Create Application Control profile and assign to Windows devices.
When using Workspace ONE 20.x and higher, which three ways can an administrator using UEM automatically move devices into specified organization groups?(Choose three.)
A. user group mappings
B. device type mappings
C. location based mappings
D. IP-based mappings
E. device ownership mappings
What product from Workspace ONE needs to be enabled to provide administrators a flexible method for alerting and informing end-users?
A. AirWatch Cloud Connector
B. Workspace ONE Intelligence
C. Workspace ONE Hub Services
D. VMware Tunnel
What component of the Hub Services can be integrated with Physical Access Control Systems to allow the Workspace ONE Intelligent app on mobile devices to act as digital badge?
Which administrative console is used to change to an organization logo (branding) in the Intelligent Hub Catalog?
A. Workspace ONE Access
B. Workspace ONE Hub Services
C. Workspace ONE
D. Workspace ONE UEM
Which is true about Workspace ONE compatibility when deploying content across different device types?
A. Content cannot be distributed to iOS devices.
B. Content cannot be distributed by Workspace ONE.
C. Content can be distributed to devices types including iOS, Android, Windows, and MacOS.
D. Content can be distributed to devices types including iOS, Android, and Windows.
A Workspace ONE UEM administrator is migrating collections, applications, and policies from SCCM to Workspace ONE.When using AirLift, which three of the following must the administrator allow AirLift to access on the ConfigMgr server? (Choose three.)
A. Port 443 or specified TLS port if Secure Connection is configured
B. WinRM port (typically 5985)
C. Port 3268 or the specified Global Catalog port
D. Port 389 for Active Directory
E. Interactive Login Permissions
Which protocol does Workspace ONE use to communicate with third party Identity Providers?
SAML
Kerberos
RADIUS
OAuth
Which three Workspace ONE Edge Services are included in Unified Access Gateway? (Choose three.)
A. AirWatch Cloud Connector
B. Content Gateway
C. Secure Email Gateway
D. Workspace ONE Intelligence Connector
E. VMware Tunnel
An administrator is tasked with determining the root cause for a recent outage where devices were not able to authenticate. An investigation revealed a singleAirWatch Cloud Connector (ACC) server that had a disk error which caused it to be completely unresponsive.Which VMware resiliency recommendation would have prevented this outage?
Which of the following authentication methods is needed to be enabled/configured for an administrator to leverage Day Zero Onboarding?
A. Token Auth Adapter
B. Workspace ONE UEM External Access Token
FIDO2
D. Certificate-based authentication
E. Verify (Intelligent Hub)
When configuring a Certificate Authority in Workspace ONE, which three protocols are supported? (Choose three.)
ADCS
SCEP
EST
PKI
CMP
Which feature of Workspace ONE UEM can be configured to allow reports to run on a schedule and have them delivered to a subset of administrators?
A. Windows Scheduled Tasks
B. Report Subscriptions
C. Timed Report Execution
D. SQL Server Reporting Services
A customer has decided to use VMware Workspace ONE as their primary SAAS solution for endpoint management. The customer's security team requires all infrastructure to support High Availability (HA).Which two components of Workspace ONE will need to be maintained by the customer? (Choose two.)
A. AirWatch Cloud Connector
B. Workspace ONE Database
C. Console Services Servers
D. Unified Access Gateway
E. Device Services Server
A company has BYOD iOS devices and would like to give them access to internal sites in VMware Web without requiring full device management.Which VMware best practice configuration is needed to enable this?
A. Configure Tunnel for VMware Tunnel in the SDK settings.
B. Configure Tunnel for VMware Tunnel Proxy in the SDK settings.
C. Configure a VPN Profile for VMware Tunnel.
D. Configure a VPN Profile for VMware Tunnel Proxy.
Which three are features of the Workspace ONE Content Gateway service? (Choose three.)
A. Encrypted communications using SSL/TLS.
B. Secure access to internal repositories.
C. Provides health status on external repositories.
D. Support for most corporate file servers.
E. Provides email notification for Exchange mail.
Which is used to authenticate and encrypt traffic from individual applications on compliant devices to internal resources?
A. VMware Tunnel
B. Device Compliance
C. Workspace ONE Intelligence
D. Email Notification Service
Which three options are supported by Workspace ONE Access? (Choose three.)
A. Configuring Per-App VPN.
B. Configuring conditional access.
C. Configuring network segmentation.
D. Configuring Mobile SSO.
E. Configuring unified application catalog.
An administrator would like to customize their admin consoles default branding to include the company logo and reflect the company's text color and background.How would the administrator accomplish this task?
A. Navigate to UEM Console, All Settings, System, Branding. Click Branding and edit the settings in the Branding page as appropriate.
B. Navigate to the Configurations tab on the console. Click Branding. Edit the settings in the Branding page as appropriate.
C. Navigate to the Hub Service console Home page. Click Branding. Edit the settings in the Branding page as appropriate.
D. Navigate to UEM Console, All Settings, Hub Services. Click Branding and edit the settings in the Branding page as appropriate.
Which two statements are true about Content Gateway and Tunnel on Unified Access Gateway? (Choose two.)
A. Both can be configured with the same hostname on port 8443.
B. Both can be configured with the same hostname on different ports.
C. Both can be configured on port 8443 with different hostnames.
D. Both can be configured with the same hostname on port 443.
E. Both can be configured on port 443 with different hostnames.
An administrator has set up an iOS compliance policy for unwanted apps.Which of the following is the expected behavior when Workspace ONE UEM receives the app sample indicating the presence of the unwanted app?
A. After 1 day, end user will receive the push notification.
B. The concerned device will be marked as Non-compliant immediately.
C. The concerned device will be unenrolled.
D. After 2 days, all managed apps will be blocked/removed from the concerned device.
Which two configuration steps must be performed when managing iOS devices? (Choose two.)
A. Obtain an Apple Server Certificate.
B. Obtain an Apple ID.
C. Obtain an APNS certificate.
D. Obtain an Apple Developer ID.
E. Obtain an iCloud Account.
Which of the following is a prerequisite to deploy VMware Unified Access Gateway OVF?
DRAG DROP -Drag and drop the device operating system on the left into the box associated with its third party messaging solution.Select and Place:
IOS - APNS
Android WNS
Windows FCM
IOS - APNS
Windows - WNS
Android - FCM
IOS - WNS
Android - FCM
Windows APNS
Which three can be used to enforce conditional access in Workspace ONE? (Choose three.)
A. device ownership type
B. device enrollment method
C. device platform
D. application specific
E. network range
A customer intends to implement Android device management in their environment.Which three enrollment options would result in an end-user experience in which a dedicated container is created on the device for only business applications and contents? (Choose three.)
A. Knox Container
B. Device Enrollment Program (DEP)
C. Work Managed Device
E. Corporate Owned Personally Enabled (COPE)
F. Work Profile
Which Security Assertion Markup Language (SAML) configuration item is a pre-requisite to creating a third party identity provider in Workspace ONE Access?
An administrator is preparing to setup email management for Office 365 in UEM.Which is VMware's recommended email deployment model for this scenario?
VPN
B. Proxy
C. Indirect
D. Direct
Which type of design is a diagram that includes network zones, network components, server locations, and hardware recommendations?
Which three features within Hub Services can an administrator leverage when Workspace ONE Access is configured and integrated with Workspace ONE UEM?(Choose three.)
A. Email Notification
B. Mobile Flows
C. AirLift
D. Virtual Assistant
E. People
An administrator is concerned with data loss on Workspace ONE managed endpoints.Which three configurations should be enabled to further improve the device security posture? (Choose three.)
A. Configure compliance policies to monitor rooted and jailbroken devices.
B. Configure compliance policies to monitor Roaming Cell Data Usage.
C. Enable device-level data encryption.
E. Enable verbose logging.
F. Enable Data Loss Prevention policies.
An organization has purchased a SaaS Workspace ONE solution and wants to implement these:✑ integration with back-end resources like Active Directory from Microsoft to sync users and groups✑ Kerberos authentication✑ integration with Virtual Desktops and Applications from services (Horizon 7, Horizon Cloud, or Citrix)✑ third party integration with RSA SecureID, RADIUS for authenticationWhich Workspace ONE component is required?
A. VMware AirWatch Cloud Connector
B. VMware Workspace ONE Access Connector
C. VMware Workspace ONE Assist
D. VMware Workspace Unified Access Gateway
A customer is managing only iOS devices using Workspace ONE. They would like to begin managing Android devices.What would be the first step an administrator needs to complete to begin managing Android Devices?
A. Download and deploy Workspace ONE Unified Access Gateway.
B. Complete Android EMM registration from Workspace One Console.
C. Download and deploy Workspace ONE Access Connectors for Android devices.
D. Configure a Workspace ONE AirLift Server-side Connector.
For federal clients, FIPS 140-2 and AES 256-bit encryption are applied to which three areas? (Choose three.)
A. data in use
B. data in flying
C. data in pace
D. data in rest
E. data in transit
An administrator has received complaints from end-users not receiving consistent email notifications on their iOS devices. Email is configured on the end-users devices using only the VMware Boxer email client. Boxer is only configured from Workspace ONE to use Office 365.What can the administrator do to resolve the inconsistent email notifications?
A. Configure VMware ENS v2 to provide consistent notification experience.
B. Configure SEG v2 to provide a better notification experience.
C. Configure Mobile SSO for VMware Boxer to prevent users from entering credentials.
D. Configure VPN tunnel with a Boxer configuration, so that it is able to connect to the internal network.
You are an administrator configuring custom reports in Workspace ONE Intelligence.What is the maximum number of custom reports you can create per Organization Group (OG)?
An administrator wants to leverage the Workspace ONE Web application to allow end-user credentials to be passed to specific internal sites.Which security policy in Workspace ONE UEM must be configured?
A. Offline Access
B. Single Sign-On
C. Network Access Control
D. Integrated Authentication
Which three are features of the ENS v2? (Choose three.)
A. Supports most existing corporate file servers.
B. Provides email notification for Exchange Active Sync.
C. Secures access to internal content repositories.
D. Updates the badge count for an unread email.
E. Triggers a background sync on Workspace ONE Boxer.
An administrator noticed after syncing sAMAccountName as EnrollmentUser and syncing in an administrator group, that users are unable to log in with sAMAccountName.What could be the cause of the issue?
A. Admins need to apply <domain>\fullName as their username.
B. Admins need to apply <domain>\sAMAccountName as their username.
C. Admins need to have the role admin to be allowed to log in.
D. Admins need to sign in with their UPN as their username.
What is the purpose of the Workspace ONE UEM Security Pin?
A. Serves as a second layer of security for administrators while preventing inadvertent commands.
B. Provides a second factor of authentication for administrators during console login.
C. Provides multi-factor authentication for users during device enrollment.
D. Serves as a second layer of security for end users while preventing inadvertent commands.
Which three are features in the branding section of the Workspace ONE Access console? (Choose three.)
A. Uploading a favicon to display in the browser address bar.
B. Adjusting the name of the Intelligent Hub application on devices.
C. Adjusting the background color.
D. Uploading a logo for sign-in screens.
E. Adjusting the URL of the Access console.
A company using Mobile SSO would like to avoid deploying an additional connector for Workspace ONE. They currently do not have a use case for Virtual Apps or advanced authentication such as kerberos, RDA SecureID or Radius.Which configuration can be used to sync users and groups with a single connector of Workspace ONE?
A. Directory Sync from Workspace ONE UEM to Workspace ONE Access
B. Directory Sync from Workspace ONE Assist to Workspace ONE Access
C. Directory Sync from Workspace ONE Access to Workspace ONE Unified Access Gateway
D. Directory Sync from Workspace ONE Intelligence to Workspace ONE Access
Which two Workspace ONE edge services on Unified Access Gateway does VMware require to use 3rd party SSL certificates? (Choose two.)
A. Content Gateway
B. Tunnel Per-App VPN
C. Device Services
D. Tunnel Proxy
E. Secure Email Gateway
An administrator would like to import Public Applications acquired from the Microsoft Store for Business.Which configuration is required?
A. LDAP Active Directory Integration
B. SAML Authentication
C. Two Factor Authentication
D. Azure Active Directory Integration
When creating third party identity providers in Workspace ONE Access, which two SAML assertion components can be used to identify the user? (Choose two.)
A. NameID Element
B. SAML Attribute
C. SAML EntityID
D. NameID Signature
E. SAML Issuer
During an enrollment attempt, a user enters their email address in the initial field in the Intelligent Hub. The user receives an error stating, `Something went wrong with discovery`.Which configuration setting can be enabled to allow end users to enter an email address instead of a Server URL?
A. Autodiscovery Enrollment
B. Pre-Register devices
C. Allow only known users
D. Enrollment Token
IT management has announced all traffic from the DMZ will be blocked unless it passes through a newly configured proxy, effective immediately. Administrators notice that SEGv2 is unable to contact the Workspace ONE API Service in their SaaS environment.Which configuration will the administrators need to amend and apply to the SEGv2 servers?
An administrator requires a report on the chassis type of their Windows desktop devices. The information is currently not showing as a table entry in WorkspaceONE Intelligence.What does the administrator need to create to have this information show in Workspace ONE Intelligence?
A customer has a Workspace ONE SAAS environment. None of the administrators are able to log in to the console using their Active Directory (AD) credentials.They are able to log in using a basic administrator account provided to them when they deployed Workspace ONE.What could be cause for this issue?
A. AirWatch Connector is not running.
B. Workspace ONE Enterprise Integration Services is not running.
C. Workspace ONE Access connector is not running.
Device Services is not running.
An administrator would like to configure SSO for Workspace ONE UEM console login.Which catalog setting from Workspace ONE Access need to be configured?
Which of the following explains the differences between Workspace ONE UEM reports and Workspace ONE Intelligence Custom Reports?
A. Workspace ONE Intelligence Reports uses an on-premises reporting database to push data to a reports cloud service as Workspace ONE UEM Reports extracts data from your Workspace ONE UEM environment.
B. Workspace ONE Intelligence Reports uses a separate service to push data to a reports cloud service and Workspace ONE UEM Reports extracts data from your WS ONE UEM environment.
C. Workspace ONE Intelligence Reports use the same an API service to push data to a reports cloud service as Workspace ONE UEM Reports.
D. Workspace ONE Intelligence Reports use the same service to push data to a reports cloud service as Workspace ONE UEM Reports.
An administrator must ensure enrolled corporate owned Android Enterprise devices do not update during the holiday season.Which is VMware's recommended best practice to accomplish this?
A. Deliver ג€˜System Updatesג€™ profile with change freeze payload.
B. Deliver ג€˜System Updatesג€™ profile that defers updates up to 30 days.
C. Deliver ג€˜Restrictionsג€™ profile that disables chrome on devices.
D. Deliver ג€˜Restrictionsג€™ profile that disables Play Store on devices.
Which is required during installation of the Workspace ONE Intelligence Connector service?
A. Workspace ONE Intelligence Connector service must be installed on the AWCM Server.
B. Workspace ONE Intelligence Connector must be installed on the Console Server.
C. Workspace ONE Intelligence Connector service must be installed on the Device Services Server.
D. Workspace ONE Intelligence Connector must be installed on its own server.
Which is required to deliver a Check In, Check Out experience on an Android Device?
A. Block open enrollment into Workspace ONE UEM.
B. Enable VMware Workspace ONE Intelligence.
C. Deliver Launcher profile to the end-user.
D. Use a basic user as a staging account.
