OCA-W Workspace ONE Administrator Practice Questions
Prepare for OCA-W with more than an answer.
Unlock the full exam and previous versions
- v1Workspace ONE Administrator 187 questions Current
- OCA-W-EXTLegacy Workspace ONE Administrator - Extended 180 questions Locked
- Level
- Administrator
- Valid for
- 2-3 years (TBD)
Domains covered on the exam 5
- Workspace ONE UEM Administration and Architecture30%
- Device Lifecycle Management28%
- Application Management18%
- Access Control and Security16%
- Integration, Monitoring, and Troubleshooting8%
- 1
A healthcare organization needs to ensure that only authorized and healthy iOS devices can access patient data in their Office 365 tenant. Their security policy requires devices to be managed by UEM, be compliant with all security profiles, and use certificate-based authentication. Which combination of components is required to build this Zero Trust solution? (Select THREE)
Show answer details
Correct answer: A, B, C
Three pieces are needed: (1) a Workspace ONE UEM compliance policy that defines device health; (2) an Omnissa Access access policy that chains a certificate-based method (Mobile SSO for iOS / Certificate) with Device Compliance (with Workspace ONE UEM), so non-compliant devices are denied; and (3) Office 365 configured in Omnissa Access with Omnissa Access as the federated identity provider for the Microsoft 365 (Entra ID) domain, so Office 365 sign-ins are sent to Access where the policy is enforced. Per-app Tunnel and per-app Office 365 profiles are not required for this access control.
Three pieces are needed: (1) a Workspace ONE UEM compliance policy that defines device health; (2) an Omnissa Access access policy that chains a certificate-based method (Mobile SSO for iOS / Certificate) with Device Compliance (with Workspace ONE UEM), so non-compliant devices are denied; and (3) Office 365 configured in Omnissa Access with Omnissa Access as the federated identity provider for the Microsoft 365 (Entra ID) domain, so Office 365 sign-ins are sent to Access where the policy is enforced. Per-app Tunnel and per-app Office 365 profiles are not required for this access control.
Three pieces are needed: (1) a Workspace ONE UEM compliance policy that defines device health; (2) an Omnissa Access access policy that chains a certificate-based method (Mobile SSO for iOS / Certificate) with Device Compliance (with Workspace ONE UEM), so non-compliant devices are denied; and (3) Office 365 configured in Omnissa Access with Omnissa Access as the federated identity provider for the Microsoft 365 (Entra ID) domain, so Office 365 sign-ins are sent to Access where the policy is enforced. Per-app Tunnel and per-app Office 365 profiles are not required for this access control.
- 2
What is the primary function of the Workspace ONE SDK when integrated into an internal mobile application?
Show answer details
Correct answer: C
The Workspace ONE SDK (Software Development Kit) is a library of code that developers can embed in their apps. Its primary purpose is to enable Mobile Application Management (MAM) capabilities. This allows the UEM console to manage the app itself, applying policies like data encryption, DLP (copy/paste restrictions), integrated authentication, and per-app tunneling, often without needing the entire device to be under MDM control.
- 3
An administrator is developing a script to automate device queries using the Workspace ONE UEM REST API. The script sends a GET request to
/api/mdm/devices/searchbut consistently receives anHTTP 401 Unauthorizedresponse. The administrator has confirmed the API key is correct and has been generated for a dedicated API administrator account. What is the most likely missing component in the API request header?Show answer details
Correct answer: B
An
HTTP 401 Unauthorizederror specifically points to an authentication failure. For Workspace ONE UEM REST API calls, authentication requires two key headers: theAuthorizationheader (typically for user credentials or tokens) and theaw-tenant-codeheader, which contains the API key. Even if other authentication headers are present, omitting theaw-tenant-codewill result in a 401 error because the system cannot identify which tenant's API key is being used. - 4
Case Study:
A wealth management firm, 'FinSecure', is developing an in-house iOS application for its financial advisors to access sensitive client portfolio data on their corporate-managed iPads. The firm's CISO has mandated a stringent set of security controls for this application.
Company Background:
FinSecure has a mature Workspace ONE UEM and Omnissa Access deployment. All iPads are supervised and fully managed. Advisors often use their iPads in public locations like cafes and airports.Security Requirements:
- All application traffic must be routed through a secure gateway in the corporate datacenter, regardless of the network the iPad is on.
- The application's data must be encrypted at rest on the device.
- Users must be prevented from copying portfolio data out of the application and pasting it into personal apps like Mail or Notes.
- The application must not be backed up to iCloud or iTunes.
- The solution must not require any modification to the application's source code.
Which combination of Workspace ONE UEM features should be implemented to satisfy all of FinSecure's security requirements?
Show answer details
Correct answer: D
App Wrapping injects Workspace ONE SDK functionality into a compiled internal app, so the source code is not modified. An App Wrapping Profile can enable App Tunnel (per-app traffic through Workspace ONE Tunnel) and the DLP copy/paste restrictions. For iOS, the wrapping engine does not add DAR encryption; data at rest is protected by iOS Data Protection once a device passcode is enforced. Wrapped apps do not support the DLP Data Backup setting, so iCloud backup is blocked with the managed app's Prevent Application Backup option. The SDK option needs source-code changes, and device-wide profiles do not meet the per-app requirements.
- 5
A global logistics firm is restructuring its Workspace ONE UEM environment. They have three major regions: Americas, EMEA, and APAC, each with its own IT team. The corporate IT team needs to enforce a global security policy, including a complex passcode and device encryption, that cannot be altered by regional administrators. However, regional teams must be able to deploy their own region-specific Wi-Fi profiles and applications. Which Organization Group (OG) configuration strategy meets these requirements?
Show answer details
Correct answer: D
Create the global security profiles at the top-level OG (Managed By = top-level OG) and assign them to all devices below it. Regional administrators whose roles are scoped to their child OG see these profiles as read-only ('this profile is being managed at a higher organization group and cannot be edited'). They can still create and assign their own Wi-Fi profiles and apps, managed at their own child OG, and those reach only that branch. Sibling OGs stay isolated from each other.
- 6
An administrator is configuring a device profile to automatically provision corporate Wi-Fi settings to newly enrolled iOS devices. The network security team requires certificate-based authentication using a unique device certificate for each connection. The company has a Microsoft Certificate Authority integrated with Workspace ONE UEM. Which payload must be configured within the Wi-Fi profile to meet this requirement?
Show answer details
Correct answer: D
A unique per-device certificate is delivered by adding a SCEP (or Credentials) payload whose Credential Source is Defined Certificate Authority, selecting the integrated Microsoft CA and its certificate template. In the Wi-Fi payload, choose an enterprise security type (for example WPA/WPA2 Enterprise with EAP-TLS) and select that certificate as the Identity Certificate. A Credentials payload containing only the CA root certificate provides trust, not a unique client certificate.
- 7
An administrator needs to deploy a legacy Win32 application to the engineering department. The installation process is complex: it requires a specific registry key to be set before installation, the main MSI installer to be run, and a post-installation script to be executed to apply a license file. Which components must be configured in a Freestyle Orchestrator workflow to successfully automate this deployment? (Select THREE)
Show answer details
Correct answer: B, C, D
Freestyle Orchestrator workflows sequence resources that are already in inventory: applications, profiles and scripts. Scripts need Advanced, Enterprise or Desktop Essentials. Here, a script action sets the registry key, an application action installs the MSI (deployed through Software Distribution), and a second script action after the install applies the license file. Steps run in order, and each step must finish before the next starts. Compliance policies are not workflow steps, and a device profile does not perform these installation tasks.
Freestyle Orchestrator workflows sequence resources that are already in inventory: applications, profiles and scripts. Scripts need Advanced, Enterprise or Desktop Essentials. Here, a script action sets the registry key, an application action installs the MSI (deployed through Software Distribution), and a second script action after the install applies the license file. Steps run in order, and each step must finish before the next starts. Compliance policies are not workflow steps, and a device profile does not perform these installation tasks.
Freestyle Orchestrator workflows sequence resources that are already in inventory: applications, profiles and scripts. Scripts need Advanced, Enterprise or Desktop Essentials. Here, a script action sets the registry key, an application action installs the MSI (deployed through Software Distribution), and a second script action after the install applies the license file. Steps run in order, and each step must finish before the next starts. Compliance policies are not workflow steps, and a device profile does not perform these installation tasks.
- 8
A financial services company uses an Omnissa Access policy that chains the Device Compliance (with Workspace ONE UEM) authentication method so that only Android devices that are compliant in Workspace ONE UEM can access internal applications. Several users report being denied access although their devices show as compliant in the Workspace ONE UEM console and in the Intelligent Hub app. The device compliance check in Omnissa Access fails for these users. What is the most likely cause of this discrepancy?
Show answer details
Correct answer: B
Omnissa Access checks compliance by calling Workspace ONE UEM through the Device Compliance (with Workspace ONE UEM) authentication method, which is pre-populated with the UEM console URL, the UEM Admin API key and the AirWatch Cloud Connector certificate. Omnissa documents that this method does not work when Workspace ONE UEM is unreachable, and that if the UEM service details change the UEM configuration in Omnissa Access must be updated, otherwise the method might fail. A broken or outdated API connection therefore makes the compliance check fail even though UEM itself shows the device as compliant.
