A financial services firm is deploying VMware Workspace ONE Tunnel for per-app VPN access to internal resources. The security team mandates that only corporate-approved applications on compliant iOS devices can establish a tunnel. An administrator has configured the Tunnel profile in Workspace ONE UEM and assigned it. However, users report that while the Tunnel application installs, it fails to connect. The UEM compliance engine shows the devices as compliant. Which configuration step in Workspace ONE Access is most likely missing?
Answer and explanation
Correct answer: B
For VMware Tunnel to function correctly in a UEM-integrated environment, Workspace ONE Access requires a specific access policy for the Tunnel application itself. This policy must be configured to use the 'Device Enrollment' authentication method, which verifies that the connection attempt is coming from a device managed by Workspace ONE UEM. Without this policy, Access will reject the authentication request from the Tunnel client, even if the device is compliant in UEM.
Question 2
Multiple answers
A retail company is using Workspace ONE UEM to manage shared Android devices in its stores. The devices are configured in Kiosk Mode using a Launcher profile. The IT team needs to ensure that if a device's battery level drops below 15% or if it has not synced with the UEM server in over 24 hours, specific actions are taken. Which two features must be configured to meet these requirements? (Select TWO)
Answer and explanation
Correct answers: B, E
The 'Last Seen' rule within a compliance policy directly addresses the requirement to take action if a device has not synced within a specified time frame, such as 24 hours.
The Event/Action engine (formerly known as Telecom Management for some features) in Workspace ONE UEM allows administrators to create rules based on real-time device telemetry, including battery level. This is the correct feature to use for triggering actions based on battery percentage.
Question 3
True or False: When using Workspace ONE UEM to deploy Windows Updates via Baselines, the feature relies on devices being able to reach Microsoft's public Windows Update for Business (WUfB) services, and it cannot source update payloads from an on-premises WSUS server.
Answer and explanation
Correct answer: A
This is true. The Baselines feature in Workspace ONE UEM is an orchestration layer on top of the native Windows Update for Business (WUfB) client-side targeting capabilities. It tells the device which updates to install and when, but the device itself must download the actual update payloads from Microsoft's public content delivery network (CDN). It does not integrate with or pull updates from a local WSUS server.
Question 4
A hospital is leveraging Freestyle Orchestrator in Workspace ONE to automate complex onboarding workflows for clinician-used iPads. A new requirement is to deploy a specific set of clinical applications ONLY after confirming that the device has been successfully encrypted. The workflow should also notify the security team via a webhook if the encryption check fails. The administrator has built the following logical workflow:
┌───────────────────┐
│ Trigger: │
│ Device Enrolled │
└────────┬──────────┘
│
▼
┌───────────────────┐
│ Condition: │
│ Is Encrypted? │
└────────┬──────────┘
│
┌───────┴───────┐
│ Yes │ No
▼ ▼
┌──────────┐ ┌───────────────────┐
│ Install │ │ Send Webhook to │
│ App Set A│ │ Security Team │
└──────────┘ └───────────────────┘
During testing, the administrator observes that for newly enrolled iPads, the workflow immediately branches to the 'No' path and sends the webhook, even though the devices report as encrypted in the UEM console a few minutes later. What is the most likely cause of this behavior?
Answer and explanation
Correct answer: C
The issue is a race condition. The 'Device Enrolled' trigger fires immediately upon successful enrollment. However, it can take a few moments for the device to process the encryption command, perform the encryption, and report its encrypted status back to the UEM server. The workflow is checking the condition before the device's encrypted status has been updated in the UEM database. Adding a 'Wait' step (e.g., 5 minutes) after the trigger would allow time for the device state to be reported correctly before the condition is evaluated.
Question 5
The command Get-WorkspaceONEGroup -Search 'Finance' is executed using the Workspace ONE UEM PowerShell module. What is the expected output of this command?
Answer and explanation
Correct answer: C
The Get-WorkspaceONEGroup cmdlet from the official PowerShell module is used to retrieve User Group objects from Workspace ONE UEM. The -Search parameter filters the results to return user groups whose names contain the specified string. Therefore, it will return the User Group objects (including name, ID, etc.) for groups like 'Finance', 'Corporate Finance', etc.
Question 6
Case Study:
A multinational logistics company, ShipFast, is modernizing its device management with VMware Workspace ONE. The environment consists of 10,000 corporate-owned Android Zebra devices for package scanning, 2,000 corporate-owned Windows 11 laptops for managers, and a BYOD program for 5,000 employees using personal iOS and Android devices.
Current Situation: The Zebra devices are running an older Android version and are managed via a legacy Android (non-Enterprise) configuration. The Windows laptops are currently managed by SCCM, but ShipFast wants to co-manage them with Workspace ONE UEM to leverage modern management capabilities. The BYOD program is new, and the primary concern is securing corporate data within applications like Boxer and Content without managing the entire personal device.
Requirements:
Zebra Devices: Must be fully locked down to a single package scanning application. A streamlined, zero-touch enrollment process is required for deploying new devices in warehouses globally. Devices must be provisioned with specific Wi-Fi settings and a device root certificate.
Windows Laptops: Must be moved to a co-management model. ShipFast wants to use UEM for deploying Win32 applications, managing BitLocker encryption, and enforcing OS patch levels via Baselines. SCCM will continue to handle OS imaging for now.
BYOD Devices: Must use Workspace ONE Intelligent Hub with the 'Registered Mode' to provide access to a catalog of productivity apps (Boxer, Content). Data Loss Prevention (DLP) policies must be enforced to prevent copy/paste of corporate data to personal apps. Full MDM enrollment must be blocked for BYOD devices.
Constraints:
The company uses Azure AD as its primary identity provider.
A minimal on-premises footprint is preferred.
The solution must be scalable across different regions with varying network conditions.
Which combination of Workspace ONE features and configurations best addresses all of ShipFast's requirements?
Answer and explanation
Correct answer: B
This option correctly addresses all requirements. 'Work Managed' mode is the modern standard for fully corporate-owned Android devices. StageNow is Zebra's tool for creating barcodes for zero-touch enrollment. A Launcher profile provides the required kiosk functionality. Co-management for Windows is correctly initiated via Azure AD join and GPO-driven enrollment, allowing UEM and SCCM to coexist. For BYOD, 'Unmanaged' mode (also known as Registered Mode) provides MAM-only control, allowing DLP policies to be applied to Workspace ONE apps without full device management, which aligns perfectly with the requirement to block MDM enrollment.
Question 7
An administrator is configuring Workspace ONE Access as the identity provider for a third-party SaaS application that supports SAML 2.0. The SaaS provider requires the SAML assertion to contain a user's UPN as the NameID and their department as an attribute named 'userDepartment'. The department information is synced from Active Directory. Where in the Workspace ONE Access console would the administrator map the Active Directory 'department' attribute to the 'userDepartment' SAML attribute?
Answer and explanation
Correct answer: D
SAML attribute mapping is configured on a per-application basis within Workspace ONE Access. After adding the SaaS application to the catalog, the administrator must edit its configuration. Within the app's settings, the 'Custom Attribute Mapping' section allows the administrator to define which Workspace ONE user attributes (synced from AD) are sent in the SAML assertion and what the outgoing attribute names should be. This is where ${user.department} would be mapped to the name 'userDepartment'.
Question 8
An organization is using Workspace ONE Content and has configured several on-premises repositories using the Content Gateway. To improve performance for users in a remote office, they have deployed a new Content Gateway server in that office's local data center. How should the administrator configure Workspace ONE UEM to ensure users in the remote office connect to their local Content Gateway server instead of the central one?
Answer and explanation
Correct answer: C
Workspace ONE UEM supports mapping Content Gateway servers to specific network ranges (IP addresses). When a device running the Content app attempts to connect, UEM checks the device's public IP address against the configured ranges. If the device's IP falls within a range associated with a specific gateway, UEM directs the device to that gateway. This is the designed method for providing geographically local gateway access.
Question 9
Multiple answers
A new administrator is reviewing the Workspace ONE UEM environment and finds a critical compliance policy that sends a 'Wipe Device' command if a device is compromised. The administrator is concerned about accidental data loss and wants to implement a less destructive, intermediate step. The goal is to first remove all corporate data and access profiles from the device, but leave personal data untouched. Which two compliance actions should be configured to run before the 'Wipe Device' action? (Select TWO)
Answer and explanation
Correct answers: B, D
The 'Enterprise Wipe' command is designed specifically for this purpose. It removes all corporate content, applications, and configurations delivered by UEM, while leaving the device's personal data, apps, and settings intact. It effectively de-provisions the device from a corporate standpoint without performing a full factory reset.
While an Enterprise Wipe is the most comprehensive single action, explicitly removing all assigned profiles is another key step. This ensures that configurations like Wi-Fi, VPN, and email profiles granting access to corporate systems are immediately revoked from the device.
Question 10
After configuring the integration between Workspace ONE UEM and Apple Business Manager (ABM), an administrator notices that newly purchased devices are appearing in the UEM console, but the assigned profiles and applications are not being installed automatically upon device activation. The devices stop at the iOS Setup Assistant and require manual intervention. What is the most likely cause of this issue?
Answer and explanation
Correct answer: B
For a zero-touch enrollment experience with ABM (formerly DEP), a 'Default Staging User' must be configured in the DEP profile within UEM. This setting allows the device to automatically authenticate and receive its assigned profiles and applications without requiring end-user credentials during the Setup Assistant. If this is not configured, the device will halt the process, waiting for user input, which prevents the automated deployment.