A defense contractor requires that all administrative actions within the Workspace ONE UEM console be logged and forwarded to an external Splunk SIEM for audit compliance. The security team mandates that the transmission of these logs must be encrypted.
Which configuration satisfies this requirement?
Answer and explanation
Correct answer: C
To ensure encrypted transmission of logs, Syslog must be configured to use TCP with SSL/TLS enabled. Standard TCP/UDP on port 514 transmits data in clear text. Secure Syslog typically uses port 6514.
Question 2
An administrator is designing the Organization Group (OG) hierarchy for a multinational retail corporation. The requirement is to allow regional administrators to manage devices and users within their specific region (North America, EMEA, APAC) without having visibility or control over other regions. However, a central IT team must retain the ability to push global compliance policies that cannot be removed by regional admins.
Which OG structure and permission model best supports this?
Answer and explanation
Correct answer: B
This structure utilizes the hierarchical inheritance of Workspace ONE UEM. By defining policies at the parent and assigning admins to children, you enforce global standards while providing regional autonomy. Scoping admins to child OGs restricts their visibility to only their region.
Question 3
A new systems engineer needs programmatic access to the Workspace ONE UEM environment to automate device tagging based on an external HR database. The engineer should NOT have access to view user data or perform device wipes.
Which combination of actions creates the most secure API access configuration?
Answer and explanation
Correct answer: B
Least privilege principle requires creating a custom role with only the necessary permissions (REST API access and the specific action required, tagging). A dedicated account and unique API key ensure auditability and isolation.
Question 4
While investigating a connectivity issue, an administrator notices that the 'Device Services' log in the UEM console is showing repeated 401 Unauthorized errors for a specific device attempting to check in.
What is the most likely cause of this error?
Answer and explanation
Correct answer: B
A 401 Unauthorized error during device check-in (Sync) typically indicates that the device's authentication token (HMAC) is rejected by the server. This happens if the device record was deleted or un-enrolled on the server side, but the device still thinks it is enrolled.
Question 5
A company is deploying a large fleet of rugged handheld devices to field workers. These devices will be shared among shifts. The requirement is to minimize user friction during shift changes while ensuring user-specific data (like email) is removed between users.
Which enrollment and management strategy is optimal?
Answer and explanation
Correct answer: B
Staging allows the device to be enrolled once by IT. The Launcher's Check-in/Check-out (CICO) feature allows users to sign in for their shift, applying their profile settings, and sign out at the end, clearing user data without re-enrolling the device.
Question 6
An administrator creates a Smart Group with the criteria: Platform: Android AND Ownership: BYOD. This group is assigned to a Compliance Policy that removes all managed applications if the device is rooted.
What happens if an employee enrolls a rooted Android device but selects 'Corporate - Dedicated' during enrollment by mistake?
Answer and explanation
Correct answer: B
Smart Groups operate on strict boolean logic. Since the ownership criterion is 'BYOD' and the device is enrolled as 'Corporate - Dedicated', it falls outside the scope of the Smart Group and thus the compliance policy is never evaluated against it.