A financial services company is deploying VMware Workspace ONE UEM to manage a fleet of corporate-owned, personally enabled (COPE) Android devices. The security team requires that all work-related applications and data be stored in a separate, encrypted container on the devices, isolated from personal apps. Which enrollment method must the administrator configure to meet this specific requirement?
Answer and explanation
Correct answer: B
The Android Enterprise - Work Profile enrollment method is specifically designed for COPE and BYOD scenarios. It creates a managed, encrypted container on the device to securely separate work applications and data from personal data, which directly fulfills the security team's requirement. Device Administrator is a legacy method with limited capabilities. Work Managed Device mode takes over the entire device and is for corporate-owned, single-use cases. A Closed Network enrollment is for devices without Google Play services.
Question 2
An administrator is configuring a VMware Horizon environment and needs to provide remote users with secure access to their virtual desktops without requiring a traditional VPN client. Which component is essential for brokering external connections and proxying the display protocol traffic?
Answer and explanation
Correct answer: B
The VMware Unified Access Gateway (UAG) is a hardened virtual appliance typically deployed in a DMZ. Its primary role is to provide secure remote access to internal resources, including Horizon desktops and applications. It proxies display protocols like Blast Extreme and PCoIP, eliminating the need for a traditional client-based VPN and enhancing the security posture.
Question 3
Multiple answers
A consultant is explaining the benefits of VMware App Volumes to a client. Which of the following are key advantages of using App Volumes for application delivery in a VDI environment? (Select TWO)
Answer and explanation
Correct answers: A, C
By decoupling applications from the OS and delivering them in real-time via AppStacks, App Volumes allows administrators to maintain a clean, generic 'golden' image. This drastically reduces the number of images to manage and simplifies patching and updates.
App Volumes attaches application containers (AppStacks) to virtual desktops after the user logs in, making applications appear as if they were natively installed. This on-demand delivery model provides flexibility and rapid provisioning of applications to users or groups.
Question 4
True or False: Workspace ONE Access can function as a standalone Identity Provider (IdP) and can also federate with third-party IdPs like Okta or Azure AD.
Answer and explanation
Correct answer: A
This statement is true. Workspace ONE Access is a flexible identity solution. It contains a built-in identity provider that can manage users and authentication. Additionally, it is designed to integrate with existing enterprise identity systems, allowing it to act as a service provider (SP) that trusts a third-party IdP for authentication via standards like SAML.
Question 5
A university wants to provide students with access to specialized engineering software from any device, including their personal laptops and tablets. The IT department has a limited budget and wants to minimize the hardware footprint in the data center. They need a solution that can serve applications to many concurrent users from a small number of Windows Server VMs. Which Horizon feature should they implement?
Answer and explanation
Correct answer: C
Published Applications using a Remote Desktop Session Host (RDSH) farm is the ideal solution. It allows multiple users to run sessions on a single Windows Server OS, which is highly efficient for both licensing and hardware resources. This model delivers just the application interface to the end-user's device, perfectly matching the university's need to serve many concurrent users with specialized software in a cost-effective manner.
Question 6
What is the primary function of the VMware Workspace ONE Intelligent Hub application on an end-user's device?
Answer and explanation
Correct answer: B
The Workspace ONE Intelligent Hub is the central application for end-users. Its primary function is to provide a unified catalog where users can access all their entitled applications (web, mobile, virtual) with single sign-on. It also offers self-service actions, notifications, and facilitates device enrollment and communication with the UEM server.
Question 7
A system administrator is troubleshooting an issue where a user's entitlements to a new SaaS application, configured in Workspace ONE Access, are not appearing in their Intelligent Hub catalog. The administrator has confirmed the user is in the correct Active Directory group. What is the most likely next step to resolve this issue?
sequenceDiagram
participant User
participant WS1_Access as Workspace ONE Access
participant AD as Active Directory
User->>WS1_Access: Login Request
WS1_Access->>AD: Authenticate User
AD-->>WS1_Access: Authentication OK
WS1_Access->>AD: Query Group Membership
AD-->>WS1_Access: Return Groups
WS1_Access-->>User: Display Entitled Apps (Problem Here)
Answer and explanation
Correct answer: C
Workspace ONE Access synchronizes with Active Directory at scheduled intervals. If a user is added to a group, the change in entitlement will not reflect until the next sync completes. The most direct way to resolve this is to manually trigger a directory sync from the Workspace ONE Access console to immediately pull in the updated group membership information.
Question 8
A retail company is deploying thousands of iOS devices for their store associates. To simplify the setup process, they want the devices to automatically enroll into Workspace ONE UEM with minimal user interaction right out of the box. Which program must the company utilize to achieve this streamlined enrollment experience?
Answer and explanation
Correct answer: D
Apple Business Manager (ABM), which incorporates the functionality of the former Device Enrollment Program (DEP), is Apple's framework for zero-touch deployment. By integrating Workspace ONE UEM with ABM, organizations can assign newly purchased devices to their UEM server. When the device is first powered on and connects to the internet, it automatically enrolls, applies configurations, and becomes managed without IT intervention.
Question 9
An administrator is creating a non-persistent virtual desktop pool using VMware Horizon Instant Clones. During the provisioning process, the '________' is powered on, and its virtual disk and memory state are used to rapidly create new desktops for users.
Answer and explanation
Correct answer: C
In the Instant Clone process, a Replica VM is created from the Golden Image. Then, for each host in the cluster, a Parent VM is created from the Replica. This Parent VM is powered on and its memory is 'forked' to create the running state for multiple desktop VMs (Instant Clones) on that host. This memory sharing is key to the speed and efficiency of the technology.
Question 10
Case Study
A global logistics company, GlobalShip, is modernizing its End-User Computing strategy. They have a diverse workforce, including office workers with corporate laptops, warehouse staff using rugged Android scanners, and a remote sales team using their own personal (BYOD) devices. The company's primary goal is to provide a consistent and secure user experience across all device types while simplifying IT management.
Current Situation: GlobalShip currently uses separate tools for managing different devices: Microsoft SCCM for Windows laptops, a legacy MDM for the Android scanners, and no management for BYOD devices. This has led to inconsistent security policies, a fragmented user experience, and high administrative overhead. Applications are a mix of legacy client-server apps hosted on-premises and newer SaaS applications like Salesforce and Office 365.
Requirements:
A single platform to manage all endpoints (Windows, Android, BYOD iOS/Android).
Single Sign-On (SSO) for all applications, both on-prem and cloud.
Secure containerization for corporate data on BYOD devices.
A unified application catalog for all users, regardless of their device.
Which combination of VMware products best fulfills all of GlobalShip's requirements?
Answer and explanation
Correct answer: B
This combination directly addresses all four requirements. Workspace ONE UEM provides a single platform for Unified Endpoint Management across Windows, Android (including rugged), and BYOD iOS/Android devices, fulfilling requirement #1. Workspace ONE Access delivers SSO for both SaaS and legacy applications, meeting requirement #2. UEM's support for Android Enterprise Work Profile and iOS User Enrollment enables secure containerization for BYOD, satisfying requirement #3. The Workspace ONE Intelligent Hub, powered by both UEM and Access, provides the unified application catalog, fulfilling requirement #4.