A global logistics firm is restructuring its Workspace ONE UEM environment. They have three major regions: Americas, EMEA, and APAC, each with its own IT team. The corporate IT team needs to enforce a global security policy, including a complex passcode and device encryption, that cannot be altered by regional administrators. However, regional teams must be able to deploy their own region-specific Wi-Fi profiles and applications. Which Organization Group (OG) configuration strategy meets these requirements?
Answer and explanation
Correct answer: B
Create the global security profiles at the top-level OG (Managed By = top-level OG) and assign them to all devices below it. Regional administrators whose roles are scoped to their child OG see these profiles as read-only ('this profile is being managed at a higher organization group and cannot be edited'). They can still create and assign their own Wi-Fi profiles and apps, managed at their own child OG, and those reach only that branch. Sibling OGs stay isolated from each other.
Question 2
An administrator is configuring a device profile to automatically provision corporate Wi-Fi settings to newly enrolled iOS devices. The network security team requires certificate-based authentication using a unique device certificate for each connection. The company has a Microsoft Certificate Authority integrated with Workspace ONE UEM. Which payload must be configured within the Wi-Fi profile to meet this requirement?
Answer and explanation
Correct answer: C
A unique per-device certificate is delivered by adding a SCEP (or Credentials) payload whose Credential Source is Defined Certificate Authority, selecting the integrated Microsoft CA and its certificate template. In the Wi-Fi payload, choose an enterprise security type (for example WPA/WPA2 Enterprise with EAP-TLS) and select that certificate as the Identity Certificate. A Credentials payload containing only the CA root certificate provides trust, not a unique client certificate.
Question 3
Multiple answers
An administrator needs to deploy a legacy Win32 application to the engineering department. The installation process is complex: it requires a specific registry key to be set before installation, the main MSI installer to be run, and a post-installation script to be executed to apply a license file. Which components must be configured in a Freestyle Orchestrator workflow to successfully automate this deployment? (Select THREE)
Answer and explanation
Correct answers: A, C, D
Freestyle Orchestrator workflows sequence resources that are already in inventory: applications, profiles and scripts. Scripts need Advanced, Enterprise or Desktop Essentials. Here, a script action sets the registry key, an application action installs the MSI (deployed through Software Distribution), and a second script action after the install applies the license file. Steps run in order, and each step must finish before the next starts. Compliance policies are not workflow steps, and a device profile does not perform these installation tasks.
Question 4
A financial services company uses an Omnissa Access policy that chains the Device Compliance (with Workspace ONE UEM) authentication method so that only Android devices that are compliant in Workspace ONE UEM can access internal applications. Several users report being denied access although their devices show as compliant in the Workspace ONE UEM console and in the Intelligent Hub app. The device compliance check in Omnissa Access fails for these users. What is the most likely cause of this discrepancy?
Answer and explanation
Correct answer: B
Omnissa Access checks compliance by calling Workspace ONE UEM through the Device Compliance (with Workspace ONE UEM) authentication method, which is pre-populated with the UEM console URL, the UEM Admin API key and the AirWatch Cloud Connector certificate. Omnissa documents that this method does not work when Workspace ONE UEM is unreachable, and that if the UEM service details change the UEM configuration in Omnissa Access must be updated, otherwise the method might fail. A broken or outdated API connection therefore makes the compliance check fail even though UEM itself shows the device as compliant.
Question 5
Case Study:
A large retail chain, 'GlobalMart', is deploying 5,000 Android Zebra rugged devices for its warehouse staff. The devices will be shared among workers across three shifts. Each worker must log in at the start of their shift to access a specific set of applications, including an inventory scanner and a messaging app. At the end of the shift, the device must be wiped of the previous user's session data and be ready for the next worker. The devices are managed in a dedicated 'Warehouse' Organization Group (OG).
Requirements:
Devices must be locked to a specific set of authorized work applications.
User sessions must be isolated, and all session data must be cleared upon logout.
Enrollment must be as streamlined as possible, requiring minimal interaction from the warehouse setup team.
The solution must use Android Enterprise (not Android legacy) management.
Which combination of Workspace ONE UEM features and configurations should the administrator implement to meet all of GlobalMart's requirements?
Answer and explanation
Correct answer: C
Zebra StageNow barcode enrollment is a supported bulk method for Android Enterprise Fully Managed devices and needs minimal interaction. Enrolling with a multi-user staging account (Android Shared Device Mode = Launcher) turns on shared-device check-in/check-out in Workspace ONE Launcher: the device is locked to the authorized apps, each worker logs in to receive only their assigned resources, and the session is cleared at check-in so the device is ready for the next worker. Work Profile is for BYOD, and scheduled enterprise wipes would unenroll the devices.
Question 6
A security team wants to forward all Workspace ONE UEM console events to their central SIEM platform for correlation and analysis. The SIEM platform ingests data via Syslog over TCP on port 514. The administrator has navigated to Groups & Settings > All Settings > System > Enterprise Integration > Syslog, set Protocol to TCP and Port to 514. What should be entered in the Host Name field?
Answer and explanation
Correct answer: A
The Syslog General tab has separate fields: Host Name (the SIEM address, for example siem.company.com), Protocol (UDP, TCP or Secure TCP) and Port. Enter siem.company.com as the Host Name, choose TCP as the Protocol, and enter 514 as the Port. The protocol and port are not written into the Host Name value.
Question 7
A consulting firm is implementing a BYOD program and wants to manage corporate applications and data on employee-owned Android devices without accessing personal data. The primary goals are to containerize corporate data, prevent data leakage to personal apps, and have the ability to wipe only corporate data if an employee leaves. Which Android Enterprise enrollment method is the best practice for this scenario?
Answer and explanation
Correct answer: B
The Android Enterprise Work Profile (Profile Owner) mode is specifically designed for BYOD scenarios. It creates a secure, encrypted container on the device that isolates corporate apps and data from the user's personal space. Administrators have full control over the work profile, including the ability to wipe it remotely, but have no visibility or control over the personal side of the device, thus preserving user privacy.
Question 8
True or False: In a multi-level Organization Group (OG) hierarchy, a VPN profile created at a child OG will automatically override a VPN profile with the same name that was inherited from its parent OG.
Answer and explanation
Correct answer: B
False. Device profiles do not override each other by name. Each profile is a separate resource with its own Managed By OG and assignments. A profile managed at the parent OG stays assigned to the devices it targets and is read-only for child-OG administrators. A profile created at the child OG is simply another profile, so both are delivered if both are assigned. To change what child devices receive, change the assignments (for example, exclude the child devices from the parent profile) rather than relying on a same-name 'override'.