2V0-62-23 Workspace ONE 22.X Professional Practice Questions
Prepare for 2V0-62-23 with more than an answer.
Unlock the full exam and previous versions
- v1Version 1 205 questions Current
- 2V0-61.20Legacy VMware Professional Workspace ONE Exam 77 questions Locked
- Exam fee
- $250 USD
- Level
- Professional
- Valid for
- 2 years
Domains covered on the exam 5
- IT Architectures, Technologies, Standards
- VMware Solution
- Plan and Design the VMware Solution
- Install, Configure, Administrate the VMware Solution
- Troubleshoot and Optimize the VMware Solution
- 1
A manufacturing company uses rugged Android devices on its factory floor. The devices are enrolled as Android Enterprise 'Work Managed' devices. The company needs to deploy a new in-house application (
.apkfile) to these devices without making it available on the public Google Play Store. Which three steps are required to achieve this? (Select THREE)Show answer details
Correct answer: B, C, E
The process for deploying private Android apps begins by uploading the signed
.apkfile to the Workspace ONE UEM console under the 'Internal Applications' section.After uploading the
.apkto UEM, the console facilitates publishing it as a private app to the organization's Managed Google Play Store. This makes the app available for assignment within the Android Enterprise framework but keeps it private to the organization.Once the app is published privately, it can be managed and assigned just like a public app. The administrator assigns it to the appropriate smart group of devices and sets the push mode to 'Auto' to ensure it is installed automatically without user interaction.
- 2
Case Study:
A healthcare organization,
WellCare, uses Workspace ONE to manage thousands of devices, including shared iPads for patient charting and corporate iPhones for doctors. They have a strict security policy enforced by Workspace ONE Intelligence. Recently, the security team has identified a new threat and needs to implement an immediate, automated response.Current Setup:
- Workspace ONE UEM is integrated with Workspace ONE Intelligence.
- A compliance policy in UEM marks devices with outdated OS versions as 'non-compliant'.
- A third-party security tool,
ThreatDetect, is integrated with Intelligence.ThreatDetectcan identify devices with malicious activity and reports a risk score to Intelligence.
New Requirement:
An automated workflow must be created in Workspace ONE Intelligence that triggers under two specific conditions:- If a device's risk score from
ThreatDetectis 'High'. - If a device is marked as 'non-compliant' in UEM due to an OS version that is more than two major versions old (e.g., running iOS 15 when iOS 17 is current).
When either of these conditions is met, the workflow must immediately perform two actions:
- Revoke all authentication tokens for the user of the device via Workspace ONE Access.
- Add a tag named 'High-Risk-Quarantine' to the device object in UEM.
Which components of Workspace ONE Intelligence are required to build this specific workflow?
Show answer details
Correct answer: B
This option correctly identifies all necessary components. The Automation engine is the core feature for this task. The workflow's trigger (filter) needs to combine data from two sources: the 'ThreatDetect' data source for the risk score and the 'UEM' data source for OS version and compliance status. A complex filter with 'OR' logic is needed to trigger if either condition is met. The required actions are performed by the pre-configured connectors: the 'Workspace ONE Access' connector has an action to 'Revoke All Tokens for User', and the 'Workspace ONE UEM' connector has an action to 'Add Device Tag'.
- 3
A consultant is designing a Workspace ONE UEM deployment for a client who requires high availability for their on-premises Device Services servers. The design includes two Device Services servers behind a load balancer. Which load balancer persistence method is required for proper function?
Show answer details
Correct answer: A
For Device Services servers, VMware recommends using Source IP persistence. This ensures that all requests from a single device (originating from the same IP address) are consistently sent to the same Device Services server for the duration of the session. This is important for maintaining session integrity during complex operations like enrollment or application deployment.
- 4
The help desk reports that multiple macOS users are unable to enroll their devices. During enrollment via Intelligent Hub, they receive an error immediately after authenticating, stating 'Profile Installation Failed'. The administrator confirms that the APNs certificate is valid and other device platforms are enrolling successfully. Which is the most likely cause of this specific macOS enrollment issue?
Show answer details
Correct answer: C
A common cause for the 'Profile Installation Failed' error specifically on macOS is a certificate trust issue. During enrollment, the device must download the initial MDM profile from the UEM server. If the SSL certificate securing the UEM server's public URL is not issued by a certificate authority that is trusted by default in the macOS trust store, or if the certificate chain is incomplete, macOS will refuse to install the profile, leading to this error. This is a more frequent issue with on-premises environments using internal CAs.
- 5
Which three components are required to configure Single Sign-On from a managed iOS device to a SAML-enabled web application, using Workspace ONE as the identity provider? (Select THREE)
sequenceDiagram participant Device participant App participant Hub as Intelligent Hub participant Access as Workspace ONE Access participant AppServer as Web App Device->>App: Launch App App->>Access: Initiate Auth (Redirect) Access->>Hub: Request Kerberos Ticket Hub->>Access: Provide Ticket Access->>AppServer: SAML Assertion AppServer-->>App: Grant AccessShow answer details
Correct answer: A, B, D
The Intelligent Hub acts as the Kerberos client on the iOS device, obtaining the Kerberos ticket required for authentication.
Workspace ONE Access includes a built-in KDC that issues the Kerberos tickets to the Intelligent Hub after validating the device's identity via its client certificate.
This profile configures the device to use the Intelligent Hub for Kerberos authentication and contains the list of applications and URLs that are permitted to use Mobile SSO.
- 6
A financial services firm is deploying VMware Workspace ONE Tunnel for per-app VPN access to internal resources. The security team mandates that only corporate-approved applications on compliant iOS devices can establish a tunnel. An administrator has configured the Tunnel profile in Workspace ONE UEM and assigned it. However, users report that while the Tunnel application installs, it fails to connect. The UEM compliance engine shows the devices as compliant. Which configuration step in Workspace ONE Access is most likely missing?
Show answer details
Correct answer: B
For VMware Tunnel to function correctly in a UEM-integrated environment, Workspace ONE Access requires a specific access policy for the Tunnel application itself. This policy must be configured to use the 'Device Enrollment' authentication method, which verifies that the connection attempt is coming from a device managed by Workspace ONE UEM. Without this policy, Access will reject the authentication request from the Tunnel client, even if the device is compliant in UEM.
- 7
A retail company is using Workspace ONE UEM to manage shared Android devices in its stores. The devices are configured in Kiosk Mode using a Launcher profile. The IT team needs to ensure that if a device's battery level drops below 15% or if it has not synced with the UEM server in over 24 hours, specific actions are taken. Which two features must be configured to meet these requirements? (Select TWO)
Show answer details
Correct answer: B, E
The 'Last Seen' rule within a compliance policy directly addresses the requirement to take action if a device has not synced within a specified time frame, such as 24 hours.
The Event/Action engine (formerly known as Telecom Management for some features) in Workspace ONE UEM allows administrators to create rules based on real-time device telemetry, including battery level. This is the correct feature to use for triggering actions based on battery percentage.
- 8
True or False: When using Workspace ONE UEM to deploy Windows Updates via Baselines, the feature relies on devices being able to reach Microsoft's public Windows Update for Business (WUfB) services, and it cannot source update payloads from an on-premises WSUS server.
Show answer details
Correct answer: A
This is true. The Baselines feature in Workspace ONE UEM is an orchestration layer on top of the native Windows Update for Business (WUfB) client-side targeting capabilities. It tells the device which updates to install and when, but the device itself must download the actual update payloads from Microsoft's public content delivery network (CDN). It does not integrate with or pull updates from a local WSUS server.
- 9
A hospital is leveraging Freestyle Orchestrator in Workspace ONE to automate complex onboarding workflows for clinician-used iPads. A new requirement is to deploy a specific set of clinical applications ONLY after confirming that the device has been successfully encrypted. The workflow should also notify the security team via a webhook if the encryption check fails. The administrator has built the following logical workflow:
┌───────────────────┐ │ Trigger: │ │ Device Enrolled │ └────────┬──────────┘ │ ▼ ┌───────────────────┐ │ Condition: │ │ Is Encrypted? │ └────────┬──────────┘ │ ┌───────┴───────┐ │ Yes │ No ▼ ▼ ┌──────────┐ ┌───────────────────┐ │ Install │ │ Send Webhook to │ │ App Set A│ │ Security Team │ └──────────┘ └───────────────────┘During testing, the administrator observes that for newly enrolled iPads, the workflow immediately branches to the 'No' path and sends the webhook, even though the devices report as encrypted in the UEM console a few minutes later. What is the most likely cause of this behavior?
Show answer details
Correct answer: C
The issue is a race condition. The 'Device Enrolled' trigger fires immediately upon successful enrollment. However, it can take a few moments for the device to process the encryption command, perform the encryption, and report its encrypted status back to the UEM server. The workflow is checking the condition before the device's encrypted status has been updated in the UEM database. Adding a 'Wait' step (e.g., 5 minutes) after the trigger would allow time for the device state to be reported correctly before the condition is evaluated.
- 10
The command
Get-WorkspaceONEGroup -Search 'Finance'is executed using the Workspace ONE UEM PowerShell module. What is the expected output of this command?Show answer details
Correct answer: C
The
Get-WorkspaceONEGroupcmdlet from the official PowerShell module is used to retrieve User Group objects from Workspace ONE UEM. The-Searchparameter filters the results to return user groups whose names contain the specified string. Therefore, it will return the User Group objects (including name, ID, etc.) for groups like 'Finance', 'Corporate Finance', etc.
