Skip to content

OCE-W Workspace ONE Engineer Practice Questions

Prepare for OCE-W with more than an answer.

216 questions in the full set16 sample questionsUpdated Mar 12, 2026

Unlock the full exam and previous versions

  • v1Workspace ONE Engineer 216 questions Current
  • OCE-W-EXTLegacy Workspace ONE Engineer - Extended 20 questions Locked
Exam fee
$250 USD
Time limit
135 minutes
Questions on the exam
65
Passing score
275 (scale 100-500)
Level
Engineer
Valid for
3 years
Domains covered on the exam 8
  1. Infrastructure Planning and Management12.5%
  2. Device and Policy Management12.5%
  3. Identity and Access Management12.5%
  4. Application and Patch Management12.5%
  5. Troubleshooting12.5%
  6. Security and Compliance12.5%
  7. Monitoring and Health12.5%
  8. Automation and Integration12.5%
  1. 1

    A user's device becomes non-compliant in Workspace ONE UEM, but they can still access Microsoft 365 apps for about 15 minutes.

    What is the primary reason for this delay in enforcement?

    Show answer details

    Correct answer: A

    Workspace ONE UEM sends the status to Entra ID, but there is inherent latency. Furthermore, if the user has a valid access token (PRT/Session Token), they maintain access until that token expires or is revoked/refreshed, which causes the delay in blocking.

  2. 2

    You have integrated Carbon Black with Workspace ONE Intelligence. You want to automatically tag a device as 'At Risk' in UEM when Carbon Black reports a high-severity threat.

    Which Intelligence feature enables this?

    Show answer details

    Correct answer: B

    Create an Intelligence automation (workflow) with a Trust Network (Carbon Black Threats) trigger filtered on a high 'Carbon Black Severity Score', and add the Workspace ONE UEM action 'Add Tag to Device' with the 'At Risk' tag. Dashboards and reports only display data, and ingestion alone does not act on it.

  3. 3

    Analyze the following Compliance Policy workflow:

    graph TD Start([Check Compliance]) --> IsCompromised{Is Compromised?} IsCompromised -->|Yes| Action1[Block Email] IsCompromised -->|Yes| Action2[Notify User] Action2 --> Wait[Wait 24 Hours] Wait --> CheckAgain{Still Compromised?} CheckAgain -->|Yes| Action3[Enterprise Wipe]

    What happens to a device that is detected as 'Compromised' (Jailbroken/Rooted) with this policy?

    Show answer details

    Correct answer: D

    The workflow shows immediate actions (Block Email, Notify) followed by a tiered action (Wait 24h -> Enterprise Wipe). This gives the user a chance to fix it (unlikely for compromised, but follows the logic) before data removal.

  4. 4

    SafetyNet Attestation (now the Play Integrity check) is enabled for Android devices in Workspace ONE UEM. One device is reported as Compromised because it failed attestation.

    Which of the following is a valid reason for this?

    Show answer details

    Correct answer: C

    SafetyNet Attestation, now the Play Integrity check, is a Google API that validates a device's software and hardware integrity to show whether it has been tampered with. A custom ROM, an unlocked bootloader or root access fails this check, and Workspace ONE UEM reports the device as compromised. Battery level, a wrong username or a missing Hub app are not integrity failures.

  5. 5

    What is the primary purpose of the 'Escrow Gateway' (EG) component when interacting with the Unified Access Gateway (UAG) in a Workspace ONE environment?

    Show answer details

    Correct answer: D

    The Escrow Gateway is a specific component (often hosted on UAG or separate) used to retrieve S/MIME private keys/certs from an internal source and deliver them securely to the Boxer mail client for email encryption/signing.

  6. 6

    True or False: In a Workspace ONE UEM SaaS environment, the customer is responsible for manually upgrading the database schema when a new version of the console is released.

    Show answer details

    Correct answer: B

    In a SaaS (Cloud) environment, Omnissa (the vendor) manages all backend infrastructure updates, including the database schema. The customer is only responsible for updating their on-prem connectors (ACC, UAG).

  7. 7

    An administrator needs to identify which administrator account changed the 'Device Inactivity' setting in the UEM Console last week.

    Which specific log/report should they check?

    Show answer details

    Correct answer: C

    Console events record actions taken in the Workspace ONE UEM console, including login sessions, failed logins, admin actions and system settings changes. A change to a device setting therefore appears there with the admin who made it. The path is Monitor > Events and Logs > Console Events. Device events record MDM commands and device responses.

  8. 8

    A user's device is 'Enterprise Wiped'. Which of the following data is REMOVED from the device?

    Show answer details

    Correct answer: C

    An Enterprise Wipe only removes corporate data (managed apps, profiles, certs, email) leaving personal photos, contacts, and unmanaged apps intact. A Device Wipe (Factory Reset) removes everything.

Create an account to continue.