Skip to content

5V0-61-22 Workspace ONE 21.X Advanced Integration Specialist Practice Questions

Prepare for 5V0-61-22 with more than an answer.

228 questions in the full set20 sample questionsUpdated Mar 13, 2026

Unlock the full exam and previous versions

  • v1Version 1 228 questions Current
  • 5V0-61.19Legacy Workspace ONE Unified Endpoint Management Specialist 278 questions Locked
Exam fee
$250 USD
Level
Specialist
Valid for
2 years
Domains covered on the exam 5
  1. Digital Workspace Technologies13%
  2. Authentication Technologies20%
  3. Endpoint Security Technologies17%
  4. Integrations28%
  5. Troubleshooting22%
  1. 1

    Case Study

    HealthFirst, a large hospital network, is modernizing its mobile device strategy for clinical staff. They currently use an on-premises Microsoft Exchange server for email, which is exposed to the internet via a reverse proxy. They are concerned about the security of this setup and want to enhance it using Workspace ONE.

    Current Environment:

    • Workspace ONE UEM (SaaS) manages all corporate-owned iOS devices used by clinicians.
    • The on-premises Exchange 2016 server is in a private datacenter network.
    • Devices currently connect to Exchange ActiveSync directly through a firewall/reverse proxy.
    • Staff use the native iOS Mail client.

    Requirements:

    1. All mobile email traffic must be proxied through a secure gateway in the DMZ.
    2. The solution must prevent unmanaged or non-compliant devices from connecting to the Exchange server.
    3. The native iOS Mail client must continue to be supported.
    4. No direct inbound connections from the internet to the Exchange server should be allowed.

    Which solution design should the integration specialist propose?

    Show answer details

    Correct answer: C

    This design meets all requirements perfectly. The UAG with SEG acts as a secure proxy in the DMZ (Req 1, 4). It integrates with UEM to check device compliance, blocking unmanaged/non-compliant devices (Req 2). It proxies standard ActiveSync traffic, so the native iOS client is supported (Req 3). This is the standard, best-practice architecture for securing on-premises Exchange with Workspace ONE.

  2. 2

    In the context of the Workspace ONE platform, what is the primary role of Hub Services?

    Show answer details

    Correct answer: C

    Hub Services is the component responsible for the user-facing experience within the Intelligent Hub. It powers the unified application catalog, aggregates notifications from various sources, enables features like People Search, and allows administrators to customize the layout and branding of the Hub app.

  3. 3

    An administrator is creating a security policy for corporate-owned, dedicated-use Windows 10 devices. The goal is to enforce a strict security posture based on industry best practices. Which TWO of the following should be configured in Workspace ONE UEM to achieve this? (Select TWO)

    Show answer details

    Correct answer: B, D

    Baselines in Workspace ONE UEM allow administrators to apply industry-standard security configurations, such as those from the Center for Internet Security (CIS). This is a primary method for establishing a hardened security posture.

    While Baselines apply settings, Compliance Policies continuously monitor the state of the device. Creating a policy to ensure critical security features like disk encryption (BitLocker) and antivirus are active and healthy is essential for maintaining the security posture.

  4. 4

    A company needs to add a second factor of authentication for VPN access. The existing VPN concentrator supports the RADIUS protocol. The company uses Workspace ONE Access as its primary identity provider. How can the administrator leverage Workspace ONE to fulfill this requirement?

    Show answer details

    Correct answer: B

    This is the correct solution. The Workspace ONE Access Connector includes a RADIUS service. By enabling it and configuring the VPN as a RADIUS client, the connector can receive authentication requests. It then proxies these to Workspace ONE Access, which can enforce MFA policies (e.g., require VMware Verify push notification) before sending a RADIUS Access-Accept response back to the VPN.

  5. 5

    An administrator for a large enterprise with over 100,000 users and thousands of applications is experiencing slow performance when syncing the application catalog between Workspace ONE Access and the Intelligent Hub. Users report that new applications or changes to entitlements take several hours to appear. What is the most effective approach to optimize this process?

    Show answer details

    Correct answer: C

    This feature is specifically designed for large-scale environments to improve performance. Instead of syncing the entire massive catalog for all users, it syncs only a base set of common apps. A user's specific entitlements are then synced 'just-in-time' when they log in or refresh their Hub. This significantly reduces the load and time required for the background global sync.

  6. 6

    A financial services firm is integrating Salesforce as a SAML application in Workspace ONE Access. The firm's security policy requires that user accounts in Salesforce are created automatically upon first login, but only for users in the 'Sales' Active Directory group. Furthermore, the user's employee ID and department must be passed as attributes in the SAML assertion. Which configuration is required to meet all these requirements?

    Show answer details

    Correct answer: B

    This is the complete and correct solution. The access policy correctly restricts access (and therefore provisioning) to the 'Sales' group. Enabling JIT handles the automatic account creation, and attribute mapping ensures the employee ID and department are passed in the assertion, fulfilling all stated requirements.

  7. 7

    An organization wants to implement passwordless authentication for its developers using FIDO2-compliant security keys (e.g., YubiKey) to access internal web applications through Workspace ONE Access. Which THREE of the following components or configurations are essential for this solution to function correctly? (Select THREE)

    Show answer details

    Correct answer: A, C, D

    This is the primary step required to make the FIDO2 (WebAuthn) authentication method available for use in access policies.

    Simply enabling the method is not enough. An access policy must be created or modified to apply this authentication method to the targeted users and applications.

    FIDO2 authentication relies on the WebAuthn browser API. Without a supported browser (like Chrome, Firefox, Edge, or Safari), the security key cannot communicate with the web service.

  8. 8

    During UAT testing for a new SAML integration, users report receiving an 'Invalid Signature on SAML Response' error from the service provider. The Workspace ONE Access administrator confirms that the correct signing certificate is uploaded to the service provider and has not expired. The service provider is a multi-tenant SaaS application. What is the most likely cause of this error?

    sequenceDiagram participant User participant Browser participant Access as Workspace ONE Access participant SP as Service Provider User->>Browser: Access SP URL Browser->>Access: Redirect with SAML Request Access->>Access: Authenticate User Access->>Browser: Generate Signed SAML Response Browser->>SP: POST SAML Response SP->>SP: Validate Signature (FAILS) SP-->>Browser: Error: Invalid Signature
    Show answer details

    Correct answer: D

    This is a common cause for signature validation failures. If Workspace ONE Access signs the SAML response using a stronger algorithm like RSA-SHA256, but the Service Provider is configured to expect an older algorithm like RSA-SHA1, the signature validation will fail even if the correct certificate is used. The algorithms must match on both the Identity Provider and Service Provider.

  9. 9

    When deploying Workspace ONE Access in an on-premises environment to integrate with an existing Active Directory forest, what is the primary function of the Workspace ONE Access Connector?

    Show answer details

    Correct answer: B

    The Workspace ONE Access Connector is installed on-premises and acts as a bridge. It contains services like the Directory Sync Service, User Auth Service, and Kerberos Auth Service that securely connect to Active Directory and sync user/group information to the Access service without exposing the directory to the internet.

  10. 10

    A university is implementing a BYOD program for students and wants to ensure that personal devices accessing university resources are secure. They are using Workspace ONE UEM and have integrated it with a Mobile Threat Defense (MTD) solution. The security team wants to automatically block access to university email if the MTD solution detects malware on a device. What is the most effective way to configure this?

    Show answer details

    Correct answer: A

    This is the standard and most direct method. The MTD solution reports the threat level (e.g., 'Malware detected') to UEM. A compliance policy in UEM can then be triggered by this status, with a defined action such as removing the managed email profile, thereby blocking access as required.

Create an account to continue.