Skip to content

5V0-62-22 Workspace ONE 21.X UEM Troubleshooting Specialist Practice Questions

Prepare for 5V0-62-22 with more than an answer.

204 questions in the full set20 sample questionsUpdated Mar 13, 2026
Exam fee
$250 USD
Level
Specialist
Valid for
2 years
Domains covered on the exam 3
  1. Architectures and Technologies5%
  2. Troubleshooting and Repairing85%
  3. Administrative and Operational Tasks10%
  1. 1

    When troubleshooting Workspace ONE UEM, an administrator needs to understand the flow of a command sent from the console to an iOS device. What is the correct sequence of communication for a command, such as 'Request Device Log'?

    sequenceDiagram participant UEM as UEM Console participant DS as Device Services participant AWCM participant APNs as Apple Push Notification Service participant iOS as iOS Device

    Show answer details

    Correct answer: C

    The correct flow is: 1. Admin initiates command in UEM Console. 2. The Console sends the command to Device Services. 3. Device Services queues the command and sends a notification request to AWCM. 4. AWCM sends a push notification payload to Apple's APNs. 5. APNs delivers the push notification to the iOS device. 6. The device, upon receiving the push, checks in with the Device Services server to retrieve the actual command.

  2. 2

    An administrator is troubleshooting a PowerShell script deployed via Workspace ONE UEM to Windows 10 devices. The script is intended to create a folder on the C: drive. The script execution history in the UEM console shows the command as 'Processed' but the folder is never created on the device. The administrator has confirmed that the script runs successfully when executed manually on a test device. What is a common cause for this issue?

    Show answer details

    Correct answer: C

    In Workspace ONE UEM, PowerShell scripts can be deployed to run in either the 'System' or 'User' context. Writing to the root of the C: drive requires administrative privileges. If the script is deployed to run in the 'User' context, it will execute with the permissions of the logged-in user, which typically does not include the right to create folders at the root of C:. The script fails silently on the device, and UEM only reports that the command was processed. Rerunning the script deployment in the 'System' context would resolve this.

  3. 3

    A user with an Android Enterprise Work Profile device reports that they are unable to access internal websites using VMware Web. Other managed applications on the device can access internal resources correctly via the VMware Tunnel. What is the first and most critical item to verify in the Workspace ONE UEM console to troubleshoot this issue?

    Show answer details

    Correct answer: C

    For Per-App VPN to function, each application that needs to use the tunnel must be explicitly added to the VPN profile's application list. Since other managed apps are working, the Tunnel itself is functional. The problem is specific to VMware Web, making it highly likely that it was simply omitted from the list of apps authorized to use the VPN connection.

  4. 4

    An administrator is troubleshooting an issue where devices are not receiving commands from the UEM console in a timely manner. The administrator suspects an issue with the AirWatch Cloud Messaging (AWCM) service. Which of the following are valid troubleshooting steps to investigate AWCM connectivity and functionality? (Select TWO)

    Show answer details

    Correct answer: A, C

    Navigating to the /awcm/status endpoint on the AWCM server is a standard health check. It provides a status page indicating if the service is running and can connect to its dependencies, which is a key first step in troubleshooting.

    The AWCM.log file is the primary source of detailed information for the AWCM service. It will contain entries for every connection attempt from devices and every push notification request from Device Services, along with any corresponding errors.

  5. 5

    An organization has configured their Workspace ONE UEM environment to use the Self-Service Portal (SSP) to allow users to perform basic management tasks on their own devices. A user reports that they are unable to see the 'Enterprise Wipe' action for their old device in the SSP, even though they can see other actions like 'Lock Device'. The administrator's role has permissions to enterprise wipe devices. What is the most likely reason the action is missing for the user?

    Show answer details

    Correct answer: B

    The actions available in the SSP are controlled by two things: the administrator's permissions and the SSP's own configuration. The SSP settings allow an administrator to define which actions are available to end-users on a per-role basis. Even if an admin has the permission, the action must also be explicitly enabled for that user's role within the SSP configuration page (Groups & Settings > All Settings > System > Self-Service Portal).

  6. 6

    An administrator is troubleshooting a fleet of corporate-owned Android Enterprise devices that are failing to receive application configurations for the VMware Web client. The devices are successfully enrolled and receiving other profiles. The administrator confirmed the application is assigned with the correct configuration, but the 'Application List' sample from the devices does not show the configuration as applied. Which log file on the Workspace ONE UEM server is the most critical to review first to diagnose why the application configuration is not being sent to the devices?

    Show answer details

    Correct answer: C

    The Interrogator.log on the UEM Console server processes and queues application-related commands, including application configurations. If the configuration is assigned but not being sent, this log will contain entries showing the processing status, queueing for the device, and any errors encountered that prevent it from being sent. AWCM.log is for push notifications, Tunnel.log is for VPN connectivity, and EntitySync.log is for directory service synchronization.

  7. 7

    A financial services company is using a third-party Certificate Authority (CA) integrated via D/COM with their on-premises Workspace ONE UEM environment. After a recent Windows security patch was applied to the server hosting the AirWatch Cloud Connector (ACC), new iOS device enrollments are failing. Existing devices cannot renew their Wi-Fi certificates. The ACC server logs show 'Access Denied' errors when communicating with the CA. Which TWO actions are the most likely to resolve this issue? (Select TWO)

    Show answer details

    Correct answer: B, D

    Windows security patches can often reset or tighten DCOM permissions. The ACC service account requires specific DCOM 'Launch and Activation' and 'Access' permissions to communicate with the CA. 'Access Denied' errors point directly to a permissions issue at this layer.

    This built-in group is specifically designed to grant the necessary DCOM permissions for certificate services. Adding the ACC service account to this group is a standard and effective way to restore the required permissions after they have been altered by a patch or misconfiguration.

  8. 8

    A new junior administrator at the 'Sales' Organization Group (OG) reports they cannot create or edit compliance policies. A senior administrator confirms the junior admin has a custom role with all permissions for 'Compliance Policies' enabled. However, when investigating the OG hierarchy, the senior administrator notes a setting at the parent 'Global' OG. Which setting at the 'Global' OG would prevent the junior administrator from managing compliance policies at the 'Sales' OG, even with the correct role permissions?

    Show answer details

    Correct answer: D

    In the Workspace ONE UEM OG hierarchy, a parent OG can lock a setting. By choosing 'Override' and unchecking 'Allow children to inherit/override', the 'Global' OG effectively locks the compliance policy settings for all child OGs. This restriction takes precedence over any role-based permissions an administrator has at a lower OG.

  9. 9

    True or False: When troubleshooting a VMware Tunnel Per-App VPN connection issue, the vpnd.log on the Unified Access Gateway (UAG) appliance is the primary log to analyze for detailed traffic flow and policy enforcement decisions for the VPN tunnel.

    Show answer details

    Correct answer: A

    The statement is true. The vpnd.log on the UAG contains the most detailed information regarding the VMware Tunnel service, including device connection attempts, session establishment, traffic routing decisions based on network traffic rules, and any errors encountered during the VPN session. It is the definitive log for troubleshooting Per-App VPN issues.

  10. 10

    An administrator is using Workspace ONE Assist to remotely troubleshoot an issue on a user's Windows 11 device. The administrator needs to modify a registry key located in HKEY_LOCAL_MACHINE\SOFTWARE. During the remote session, the administrator is unable to access or modify keys in this hive, but can successfully modify keys in HKEY_CURRENT_USER. What is the most likely cause for this behavior?

    Show answer details

    Correct answer: B

    Workspace ONE Assist sessions run in the context of the logged-on user by default. Modifying the HKEY_LOCAL_MACHINE hive requires administrative privileges. To perform this action, the administrator must use the 'Run as Administrator' feature within the Assist session to elevate the tool (like Registry Editor) before they can make system-wide changes. The ability to modify HKEY_CURRENT_USER confirms the session is active but lacks elevation.

Create an account to continue.