2V0-62-23 Sample Questions & Answers
Topics include Workspace ONE's platform architecture and enterprise integrations, planning the solution and security architecture, navigating and administering the console, enrolling endpoints, deploying applications, and diagnosing common issues.
Launch the full 2V0-62-23 simulator →Showing 10 of 20 free samples.
- Question 1Advanced
Plan and Design the VMware Solution · Holistic Workspace ONE Solution Design
Case Study:
A multinational logistics company,
ShipFast, is modernizing its device management with VMware Workspace ONE. The environment consists of 10,000 corporate-owned Android Zebra devices for package scanning, 2,000 corporate-owned Windows 11 laptops for managers, and a BYOD program for 5,000 employees using personal iOS and Android devices.Current Situation:
The Zebra devices are running an older Android version and are managed via a legacy Android (non-Enterprise) configuration. The Windows laptops are currently managed by SCCM, butShipFastwants to co-manage them with Workspace ONE UEM to leverage modern management capabilities. The BYOD program is new, and the primary concern is securing corporate data within applications like Boxer and Content without managing the entire personal device.Requirements:
- Zebra Devices: Must be fully locked down to a single package scanning application. A streamlined, zero-touch enrollment process is required for deploying new devices in warehouses globally. Devices must be provisioned with specific Wi-Fi settings and a device root certificate.
- Windows Laptops: Must be moved to a co-management model.
ShipFastwants to use UEM for deploying Win32 applications, managing BitLocker encryption, and enforcing OS patch levels via Baselines. SCCM will continue to handle OS imaging for now. - BYOD Devices: Must use Workspace ONE Intelligent Hub with the 'Registered Mode' to provide access to a catalog of productivity apps (Boxer, Content). Data Loss Prevention (DLP) policies must be enforced to prevent copy/paste of corporate data to personal apps. Full MDM enrollment must be blocked for BYOD devices.
Constraints:
- The company uses Azure AD as its primary identity provider.
- A minimal on-premises footprint is preferred.
- The solution must be scalable across different regions with varying network conditions.
Which combination of Workspace ONE features and configurations best addresses all of
ShipFast's requirements?Show answer & explanation
Correct answer: B
This option correctly addresses all requirements. 'Work Managed' mode is the modern standard for fully corporate-owned Android devices. StageNow is Zebra's tool for creating barcodes for zero-touch enrollment. A Launcher profile provides the required kiosk functionality. Co-management for Windows is correctly initiated via Azure AD join and GPO-driven enrollment, allowing UEM and SCCM to coexist. For BYOD, 'Unmanaged' mode (also known as Registered Mode) provides MAM-only control, allowing DLP policies to be applied to Workspace ONE apps without full device management, which aligns perfectly with the requirement to block MDM enrollment.
- Question 2Intermediate
Install, Configure, Administrate the VMware Solution · SAML Configuration in Workspace ONE Access
An administrator is configuring Workspace ONE Access as the identity provider for a third-party SaaS application that supports SAML 2.0. The SaaS provider requires the SAML assertion to contain a user's UPN as the NameID and their department as an attribute named 'userDepartment'. The department information is synced from Active Directory. Where in the Workspace ONE Access console would the administrator map the Active Directory 'department' attribute to the 'userDepartment' SAML attribute?
Show answer & explanation
Correct answer: D
SAML attribute mapping is configured on a per-application basis within Workspace ONE Access. After adding the SaaS application to the catalog, the administrator must edit its configuration. Within the app's settings, the 'Custom Attribute Mapping' section allows the administrator to define which Workspace ONE user attributes (synced from AD) are sent in the SAML assertion and what the outgoing attribute names should be. This is where
${user.department}would be mapped to the name 'userDepartment'. - Question 3Intermediate
Plan and Design the VMware Solution · Content Gateway Architecture
An organization is using Workspace ONE Content and has configured several on-premises repositories using the Content Gateway. To improve performance for users in a remote office, they have deployed a new Content Gateway server in that office's local data center. How should the administrator configure Workspace ONE UEM to ensure users in the remote office connect to their local Content Gateway server instead of the central one?
Show answer & explanation
Correct answer: C
Workspace ONE UEM supports mapping Content Gateway servers to specific network ranges (IP addresses). When a device running the Content app attempts to connect, UEM checks the device's public IP address against the configured ranges. If the device's IP falls within a range associated with a specific gateway, UEM directs the device to that gateway. This is the designed method for providing geographically local gateway access.
- Question 4IntermediateSelect 2
Install, Configure, Administrate the VMware Solution · Compliance Policy Actions
A new administrator is reviewing the Workspace ONE UEM environment and finds a critical compliance policy that sends a 'Wipe Device' command if a device is compromised. The administrator is concerned about accidental data loss and wants to implement a less destructive, intermediate step. The goal is to first remove all corporate data and access profiles from the device, but leave personal data untouched. Which two compliance actions should be configured to run before the 'Wipe Device' action? (Select TWO)
Show answer & explanation
Correct answers: B, D
The 'Enterprise Wipe' command is designed specifically for this purpose. It removes all corporate content, applications, and configurations delivered by UEM, while leaving the device's personal data, apps, and settings intact. It effectively de-provisions the device from a corporate standpoint without performing a full factory reset.
While an Enterprise Wipe is the most comprehensive single action, explicitly removing all assigned profiles is another key step. This ensures that configurations like Wi-Fi, VPN, and email profiles granting access to corporate systems are immediately revoked from the device.
- Question 5Intermediate
Troubleshoot and Optimize the VMware Solution · Apple Business Manager (DEP) Troubleshooting
After configuring the integration between Workspace ONE UEM and Apple Business Manager (ABM), an administrator notices that newly purchased devices are appearing in the UEM console, but the assigned profiles and applications are not being installed automatically upon device activation. The devices stop at the iOS Setup Assistant and require manual intervention. What is the most likely cause of this issue?
Show answer & explanation
Correct answer: B
For a zero-touch enrollment experience with ABM (formerly DEP), a 'Default Staging User' must be configured in the DEP profile within UEM. This setting allows the device to automatically authenticate and receive its assigned profiles and applications without requiring end-user credentials during the Setup Assistant. If this is not configured, the device will halt the process, waiting for user input, which prevents the automated deployment.
- Question 6Beginner
Install, Configure, Administrate the VMware Solution · Workspace ONE Boxer Configuration
True or False: Workspace ONE Boxer can be configured with a K-V pair in its application configuration to disable the 'Report Phishing' add-in for a specific group of users, even if the add-in is enabled globally at the tenant level.
Show answer & explanation
Correct answer: A
This is true. Workspace ONE Boxer's functionality can be finely controlled using Application Configuration Key-Value Pairs (K-VPs) pushed from Workspace ONE UEM. A specific key, such as
AppPhishingAddinDisabled, can be set totrueand assigned to a specific smart group. This assignment will override the global setting for those users, disabling the add-in only for them. This allows for granular policy control. - Question 7Beginner
Install, Configure, Administrate the VMware Solution · Device Grouping and Assignment
A system administrator needs to create a dynamic device collection in Workspace ONE UEM based on a device's reported OS version and a value from a custom attribute. Specifically, the collection should include all Windows 11 devices that have a custom attribute named 'Department' set to 'Engineering'. What is the most appropriate Workspace ONE UEM feature to accomplish this?
Show answer & explanation
Correct answer: C
Smart Groups are the primary feature in Workspace ONE UEM for creating dynamic device collections based on a wide range of criteria. The rule engine for Smart Groups allows for complex logic combining multiple attributes, including platform, OS version, device model, and custom attributes. This scenario is a perfect use case for a Smart Group.
- Question 8Intermediate
Install, Configure, Administrate the VMware Solution · Workspace ONE Intelligence Dashboards
A Workspace ONE administrator is using Workspace ONE Intelligence to create a new dashboard. The goal is to visualize the adoption rate of a newly deployed internal application on iOS devices. The dashboard should display a historical trend of the application's install count over the last 90 days. Which Intelligence feature should be used to create this specific visualization?
Show answer & explanation
Correct answer: B
Workspace ONE Intelligence dashboards are composed of customizable Widgets. To create the required visualization, the administrator would add a new widget, select the 'Application' data source, filter by the specific application name and iOS platform, and then choose a 'Historical' trend view (like a line chart) with a time range of 'Last 90 Days'. This is the standard method for creating historical trend visualizations in Intelligence.
- Question 9Intermediate
IT Architectures, Technologies, Standards · Windows Enrollment with Azure AD
An organization wants to simplify the enrollment process for their corporate-owned Windows 11 devices that are not yet in Autopilot. The goal is for users to enter their corporate email address during the Out-of-Box Experience (OOBE), which should then redirect them to the Workspace ONE enrollment screen after Azure AD authentication. Which configuration is a prerequisite for this workflow to succeed?
Show answer & explanation
Correct answer: C
This enrollment method is known as 'Azure AD-driven MDM enrollment'. It requires configuring the MDM settings within the Azure AD portal (Mobility (MDM and MAM)). The administrator must specify the Workspace ONE UEM Discovery URL and Terms of Use URL. Additionally, the 'MDM user scope' must be set to 'All' or a specific group of users who are allowed to enroll. When a user in scope signs in with their Azure AD credentials during OOBE, Azure AD redirects the device to the specified UEM URLs to complete MDM enrollment.
- Question 10Beginner
IT Architectures, Technologies, Standards · Workspace ONE UEM Architecture
What is the primary function of the 'Device Services' component in a Workspace ONE UEM on-premises installation?
Show answer & explanation
Correct answer: B
The Device Services (DS) server is the core component that handles all MDM communications. Enrolled devices check in to the DS server to receive commands, profiles, and applications. It also processes incoming data from devices, such as inventory samples and compliance status, and writes this information to the UEM database. It is the primary endpoint for all managed devices.
Ready for the real thing?
The full 2V0-62-23 simulator has every exam-style question, timed mode, and instant scoring.