Skip to content

Horizon Engineer Practice Questions

Prepare for OCE-H with more than an answer.

211 questions in the full set16 sample questionsUpdated Mar 12, 2026

Unlock the full exam and previous versions

  • v1Horizon Engineer 211 questions Current
  • OCE-H-EXTLegacy Horizon Engineer - Extended 135 questions Locked
Exam fee
$250 USD
Time limit
135 minutes
Questions on the exam
65
Passing score
275 (scale scaled)
Level
Engineer
Valid for
2 years
Domains covered on the exam 7
  1. Infrastructure Planning and Management25%
  2. Desktop, Application, and Profile Management15%
  3. Monitoring and Optimization15%
  4. Troubleshooting20%
  5. Security and Compliance15%
  6. Scale and Recovery15%
  7. Automation and Integration10%
  1. 1

    A customer requires that all USB mass storage devices be blocked in their VDI environment, but they want to allow a specific model of encrypted USB drive used by the finance team.

    How can this be achieved?

    Show answer details

    Correct answer: C

    Horizon Client evaluates USB filter settings in this order (highest first): Exclude Path, Include Path, Exclude Vid/Pid Device, Include Vid/Pid Device, Exclude Device Family, Include Device Family, the Allow family settings, then Exclude All Devices. Because Include Vid/Pid Device outranks Exclude Device Family, you can exclude the storage family and still include the one approved drive by its VID/PID.

  2. 2

    You want to automate the process of creating a new manual desktop pool using PowerShell.

    Which PowerCLI module must be imported to access the Horizon specific cmdlets?

    Show answer details

    Correct answer: C

    The Omnissa.Horizon.Helper PowerShell module extends Omnissa.VimAutomation.HorizonView (which provides Connect-HVServer and Disconnect-HVServer) with high-level functions such as New-HVPool, New-HVEntitlement and Set-HVMachine. You load it with Import-Module -Name Omnissa.Horizon.Helper. Before the Omnissa rebrand the equivalent module was called VMware.Hv.Helper.

  3. 3

    You are integrating Horizon 8 with Omnissa Access to provide a unified application catalog.

    Which configuration step is performed in the Horizon Console so that the Connection Server trusts launches initiated from Omnissa Access?

    Show answer details

    Correct answer: B

    Integrating a Horizon pod with Omnissa Access has two parts. In the Access console you create a virtual apps collection, which syncs resources. In Horizon Console you configure a SAML authenticator on the Connection Server, always using the Omnissa Access FQDN and its metadata, so that the Connection Server trusts Access-issued SAML assertions when users launch desktops and apps.

  4. 4

    A user is experiencing poor audio quality in a Horizon Blast session. The network team confirms that a firewall on the WAN path blocks UDP, so a UDP connection between the client and the agent cannot be established.

    Which protocol behavior should the administrator expect to see in Horizon Performance Tracker?

    Show answer details

    Correct answer: B

    Blast Extreme uses UDP by default. If it has problems making its connection over UDP, for example because a firewall blocks UDP, it automatically uses TCP for the session. Horizon Performance Tracker shows the transport type (UDP or TCP) in each direction, so it would show TCP.

  5. 5

    A consultant is reviewing a Horizon architecture where a Load Balancer is placed between the Unified Access Gateways (UAGs) and the Connection Servers. The consultant recommends removing the Load Balancer and configuring a 1:1 mapping between each UAG and a specific Connection Server URL.

    What is the primary technical justification for this recommendation?

    Show answer details

    Correct answer: C

    Omnissa/VMware best practices recommend a 1:1 ratio because the UAG acts as a smart proxy. If a Load Balancer sits between them, the UAG might send traffic to the LB VIP, which routes to a healthy server even if the specific server the UAG is 'paired' with is down. However, for session affinity and accurate status reporting in the dashboard, a direct 1:1 link allows the UAG to detect if its specific backend broker is down and mark itself as unavailable to the external load balancer, ensuring cleaner failover.

  6. 6

    During the installation of the first (standard) Horizon Connection Server in a new pod, the installer prompts for a data recovery password.

    What is the specific function of this password in the context of the Horizon LDAP (AD LDS/ADAM) database?

    Show answer details

    Correct answer: A

    The data recovery password (1-128 characters) is set when you install the first, standard Connection Server. Horizon backs up its LDAP (AD LDS) configuration as encrypted LDIF data, and you must supply this password to decrypt and restore that backup, for example with vdmimport -d -p -f backup.LDF > decrypted.LDF followed by vdmimport -f decrypted.LDF. It is not used for JMS, vCenter communication or console logon.

  7. 7

    When planning a Horizon deployment using Instant Clones, which specific vCenter Server privilege is required for the Horizon vCenter service account so that the guest customization (ClonePrep) of the clones can complete successfully?

    Show answer details

    Correct answer: C

    The vCenter Server user that Horizon uses for instant clones needs Virtual machine > Provisioning privileges, including Customize, Clone virtual machine, Deploy template and Read customization specifications, along with inventory, configuration and snapshot privileges. Global > Settings, Host > System Management and Guest Operations > Execute are not the required privilege for guest customization.

  8. 8

    You are troubleshooting a failed Horizon Connection Server installation. The installer log indicates that the creation of the ADAM instance failed.

    Which of the following is the most likely cause?

    Show answer details

    Correct answer: B

    The Horizon Connection Server installs a lightweight directory service (ADAM/LDS) which listens on standard LDAP ports (389 for standard, 636 for SSL). If another service (like a local AD Domain Controller role or another LDAP tool) is binding to port 389, the ADAM instance creation will fail.

Create an account to continue.