VMware Workspace ONE 21.X Advanced Integration Specialist Free Sample Questions

20 free sample questions228 in the full practice test Other version: 5V0-61.19(278)

Try simulator

5V0-61-22 Sample Questions

  1. Question 1

    A financial services firm is integrating Salesforce as a SAML application in Workspace ONE Access. The firm's security policy requires that user accounts in Salesforce are created automatically upon first login, but only for users in the 'Sales' Active Directory group. Furthermore, the user's employee ID and department must be passed as attributes in the SAML assertion. Which configuration is required to meet all these requirements?

    Answer and explanation

    Correct answer: B

    This is the complete and correct solution. The access policy correctly restricts access (and therefore provisioning) to the 'Sales' group. Enabling JIT handles the automatic account creation, and attribute mapping ensures the employee ID and department are passed in the assertion, fulfilling all stated requirements.

  2. Question 2

    Multiple answers

    An organization wants to implement passwordless authentication for its developers using FIDO2-compliant security keys (e.g., YubiKey) to access internal web applications through Workspace ONE Access. Which THREE of the following components or configurations are essential for this solution to function correctly? (Select THREE)

    Answer and explanation

    Correct answers: A, C, D

    This is the primary step required to make the FIDO2 (WebAuthn) authentication method available for use in access policies.

    Simply enabling the method is not enough. An access policy must be created or modified to apply this authentication method to the targeted users and applications.

    FIDO2 authentication relies on the WebAuthn browser API. Without a supported browser (like Chrome, Firefox, Edge, or Safari), the security key cannot communicate with the web service.

  3. Question 3

    During UAT testing for a new SAML integration, users report receiving an 'Invalid Signature on SAML Response' error from the service provider. The Workspace ONE Access administrator confirms that the correct signing certificate is uploaded to the service provider and has not expired. The service provider is a multi-tenant SaaS application. What is the most likely cause of this error?

    sequenceDiagram participant User participant Browser participant Access as Workspace ONE Access participant SP as Service Provider User->>Browser: Access SP URL Browser->>Access: Redirect with SAML Request Access->>Access: Authenticate User Access->>Browser: Generate Signed SAML Response Browser->>SP: POST SAML Response SP->>SP: Validate Signature (FAILS) SP-->>Browser: Error: Invalid Signature
    Answer and explanation

    Correct answer: D

    This is a common cause for signature validation failures. If Workspace ONE Access signs the SAML response using a stronger algorithm like RSA-SHA256, but the Service Provider is configured to expect an older algorithm like RSA-SHA1, the signature validation will fail even if the correct certificate is used. The algorithms must match on both the Identity Provider and Service Provider.

  4. Question 4

    When deploying Workspace ONE Access in an on-premises environment to integrate with an existing Active Directory forest, what is the primary function of the Workspace ONE Access Connector?

    Answer and explanation

    Correct answer: B

    The Workspace ONE Access Connector is installed on-premises and acts as a bridge. It contains services like the Directory Sync Service, User Auth Service, and Kerberos Auth Service that securely connect to Active Directory and sync user/group information to the Access service without exposing the directory to the internet.

  5. Question 5

    A university is implementing a BYOD program for students and wants to ensure that personal devices accessing university resources are secure. They are using Workspace ONE UEM and have integrated it with a Mobile Threat Defense (MTD) solution. The security team wants to automatically block access to university email if the MTD solution detects malware on a device. What is the most effective way to configure this?

    Answer and explanation

    Correct answer: A

    This is the standard and most direct method. The MTD solution reports the threat level (e.g., 'Malware detected') to UEM. A compliance policy in UEM can then be triggered by this status, with a defined action such as removing the managed email profile, thereby blocking access as required.

  6. Question 6

    Case Study

    A global investment bank, FinSecure, uses Workspace ONE as its digital workspace platform. They are integrating Microsoft 365 and have extremely strict security requirements. The Chief Information Security Officer (CISO) has mandated a risk-based conditional access model.

    Current Environment:

    • Workspace ONE Access is federated with Azure AD.
    • Workspace ONE UEM manages all corporate-owned iOS and Windows 10 devices.
    • Workspace ONE Intelligence is deployed and collecting data from UEM and Access.
    • The primary user directory is on-premises Active Directory, synchronized to both Azure AD and Workspace ONE Access.

    Requirements:

    1. Users on UEM-managed and compliant devices must be granted seamless single sign-on to Microsoft 365 applications.
    2. Users on unmanaged devices or devices with a 'High' risk score in Workspace ONE Intelligence must be blocked from accessing Microsoft 365.
    3. Users on managed but non-compliant devices (e.g., outdated OS) must be prompted for VMware Verify MFA.
    4. The solution must be centrally managed and leverage the existing VMware and Microsoft investments.

    Which solution design meets all of FinSecure's requirements?

    Answer and explanation

    Correct answer: C

    This is the correct and most robust design. It leverages each platform's strengths. Workspace ONE (Access, UEM, Intelligence) acts as the source of truth for device posture and user risk. This data is passed as claims to Azure AD. Azure AD's Conditional Access engine then acts as the policy enforcement point for Microsoft 365, using the trusted claims from Workspace ONE to make granular access decisions (grant, block, require MFA). This meets all requirements.

  7. Question 7

    An administrator is configuring Mobile SSO for iOS devices to allow seamless access to internal web applications. This configuration relies on Kerberos authentication. When creating the iOS device profile in Workspace ONE UEM, which certificate is essential to upload to facilitate the Kerberos authentication process?

    Answer and explanation

    Correct answer: C

    The iOS device must trust the Key Distribution Center (KDC), which is typically a domain controller in Active Directory, to request a Kerberos ticket. Uploading the KDC server's root or intermediate certificate into the SSO profile ensures the device establishes this trust and the Kerberos process can proceed securely.

  8. Question 8

    After configuring directory synchronization with Active Directory, an administrator notices that users who are members of nested groups (e.g., a user is in 'Group A', which is a member of 'Group B') are not being synchronized into Workspace ONE Access when only 'Group B' is added to the sync rule. What is the most likely reason for this issue?

    Answer and explanation

    Correct answer: B

    By default, for performance reasons, Workspace ONE Access does not recursively sync members of nested groups. To include these users, the administrator must explicitly enable the 'Sync Nested Group Members' option for the directory configuration within the Workspace ONE Access console.

  9. Question 9

    A security operations team wants to forward audit and system logs from Workspace ONE Access to their Splunk SIEM for threat correlation. They require the logs to be in a structured, key-value pair format for easy parsing in Splunk. Which syslog format should the administrator configure on the Workspace ONE Access appliance?

    Answer and explanation

    Correct answer: D

    LFV, also known as LEEF (Log Event Extended Format) in some contexts, is specifically designed to output logs as key-value pairs (e.g., 'usr=admin cat=AUDIT'). This format is ideal for SIEMs like Splunk and QRadar because it allows for automatic field extraction and easy parsing, meeting the security team's requirement.

  10. Question 10

    True or False: When using Just-in-Time (JIT) provisioning with a third-party SAML identity provider, the Workspace ONE Access Connector is required to create the user accounts in the Workspace ONE Access service directory.

    Answer and explanation

    Correct answer: B

    This statement is false. JIT provisioning creates a user account in the Workspace ONE Access local directory based on the attributes received in the SAML assertion from the trusted third-party IdP. The Workspace ONE Access Connector is not involved in this process, as it is used for syncing with on-premises directories like Active Directory.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 506 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon