VMware 5v0-62-19 practice test

VMware Workspace ONE Advanced Integration andDesign Specialist Exam

Last exam update: May 12 ,2024
Page 1 out of 4. Viewing questions 1-15 out of 63

Question 1

Refer to the ACME Financials design use case.
ACME Financials Design Use Case
1. Introduction
1.1 Business Overview
ACME Financials is an investment firm that has established itself as a leader in USA's fast-moving
financial asset management market and has around 1000 employees.
ACME plans to transform its end-user computing resources to the digital workspace. ACME wants a
secure platform that is available from any device and from anywhere, as well as a solution that
reduces operating costs.
ACME's major business driver for the digital workplace is to enable employees to work remotely, and
to enable the secure access to all of its resources from anywhere and any device while enhancing
security with multi-factor authentication. The solution should support its BYOD strategy and let
remote employees use their own laptop, desktop, or mobile device to access the resources from any
location.
ACME also wants to remove the need to supply and manage desktop hardware to external
contractors. Because financial data is highly sensitive, the firm needs a technology that would protect
customer and other critical information - even when accessed on a mobile device. ACME is looking to
improve the security of the desktop and application platforms across the enterprise. In addition to
using endpoint security tools and multi-factor authentication, ACME insists on using additional
security and controls to provide the highest level of security and protection to services and
applications.
ACME currently uses a VPN-based remote access solution. ACME would like to remove additional
components that add support or management complexity, and device dependence for remote access
users. ACME is looking to achieve the same access to virtual desktops and Windows 10 or mobile
applications, both inside and outside of the ACME enterprise network.
ACME is very keen on enforcing standardization to keep the IT infrastructure as consistent as
possible. IT wants to use standardized versions of Windows (Windows 10), consistent configurations,
and application delivery from a central source. All while maintaining the compliance of every device
that requires encryption, password and PIN protection, as well as update -and anti-virus control.
To simplify and standardize desktop and application delivery, ACME wants to offer a service catalog
based approach based on ACME IT standards. This will allow ACME to effectively deliver and manage
resources, allowing IT to deliver device and application services that meet business and technical
needs, while maximizing the use of shared IT computing resources.
Additional Facts
Speaking to the developers revealed that most apps are standardized apps from public app-stores,
but ACME uses some their in-house developed, critical mobile apps, where some of the developers
have already left the company, so that they cannot be rewritten in a short amount of time.
To reduce operating costs, ACME has already moved to Office 365 and is currently running a few
migrations from on-premises to the cloud for other applications.
ACME's IT says that it is a Microsoft Windows only shop, but the assessment shows that currently
most of the managers are using Apple devices.
ACME currently uses directory services and two-factor authentication mechanisms (Radius) for
internal and external access. ACME requires to support Single Sign-On (SSO) integration with their
current authentication solutions. They also require to use SSO whenever possible, as they do not
believe in having multiple user accounts and passwords for their end users.
ACME wants the solution to provide mechanisms to provide a secure e-mail solution to any device
that complies to global security standards even for BYO devices.
1.2 High Level User Classification
680 Office workers (call center, corporate and office administrators) use standardized PCs or Thin-
Clients to access ACME's core apps and tools.
240 Remote-office workers use the company's CYOD initiative and use these devices (Notebooks,
Convertibles, Tablets, Android phones) to access their apps and tools from remote.
30 Executives use Apple Mac Books as well as iPhones and iPads to work on- and off-premises.
80 IT -admins and software developers are using high-end workstations with administrative access.
1.3 High Level Application Assessment
ACME currently has 261 applications, of which 186 are based on Microsoft Windows.
Today, users are allocated applications via AD group membership.
75 applications are either web-based or SaaS-based, including Office 365.
A major incident recently meant sales workers were disappearing suddenly along with their data
and laptops on some new colonies.
Any external access should require multi-factor authentication. Access from the internal network
should work seamlessly with SSO for the core applications. High-security applications also require
MFA from internal access.
The address ranges of the HQ datacenter are as follows:
172.16.0.0/16 internal
80.34.57. external
2. Initial Stakeholder Interview Findings
In addition to the goals summarized in the previous section, the following are findings from initial
interviews with the key stakeholders and an analysis of their service level agreements.
The design must use the F5 Loadbalancer and should be as redundant as possible.
Qualified IT personal is hard to find these days. If possible, reduce operational costs and try to
automate or outsource basic IT-tasks.
ACME is very particular about meeting the go-live date. If there are unforeseen delays, the project
may not be delivered for the required go-live date.
After the successful deployment of Workspace ONE, ACME plans to move their virtual desktop
infrastructure to Horizon on AWS. But there are still Web apps and file services which will run in the
on-premises datacenter.
Which two components are still needed in the on-premises datacenter? (Choose two.)

  • A. Content gateway
  • B. PowerShell host for e-mail
  • C. Layer 2 connection between Horizon on AWS on the ACME datacenter
  • D. AWS Storage
  • E. Identity bridging
Answer:

C,E

User Votes:
A
50%
B
50%
C
50%
D
50%
E
50%
Discussions
vote your answer:
A
B
C
D
E
0 / 1000

Question 2

What is the purpose of network ranges in conditional access policies?

  • A. Network ranges are a fallback authentication method for an application.
  • B. Network ranges limit access to an application depending of the source IP address.
  • C. All applications are using the new network range by default.
  • D. Network ranges limit access to an application depending of the destination IP address.
Answer:

B

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 3

What are three requirements for a device that is already joined to Azure AD to enroll into Workspace
ONE UEM? (Choose three.)

  • A. No Azure AD account configured on the device.
  • B. Windows 10 OS build 14393.82 and above.
  • C. KB update КВ3176934 installed.
  • D. No MDM managed.
  • E. User must be a member of the Console Admin Group.
  • F. Windows Update services not started.
Answer:

B,C,D

User Votes:
A
50%
B
50%
C
50%
D
50%
E
50%
F
50%
Discussions
vote your answer:
A
B
C
D
E
F
0 / 1000

Question 4

Which settings need to be prepared when planning a Workspace ONE AirLift installation?

  • A. Identity Manager Tenant URL
  • B. IDP.XML
  • C. SSO Domain
  • D. System Center Configuration Manager (SCCM) Site Code
Answer:

D

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 5

Which certificate is needed during profile configuration when configuring an iOS Mobile SSO profile
within Workspace ONE UEM?

  • A. The Workspace ONE UEM Device root certificate
  • B. KDC certificate
  • C. Valid Webserver certificate from a Devices Server
  • D. APNS certificate
Answer:

B

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 6

Which two are possible authentication methods for a third-party integrated Identity Provider (iDP)?
(Choose two.)

  • A. Device-based certificate
  • B. Windows authentication
  • C. PIN code
  • D. SAML password
  • E. SAML-based certificate
Answer:

B,D

User Votes:
A
50%
B
50%
C
50%
D
50%
E
50%
Discussions
vote your answer:
A
B
C
D
E
0 / 1000

Question 7

An administrator wants to add the Workspace ONE Identity Manager as an Identify Provider in Okl
a. What is the correct entityID (Issuer URI)?
A.
https://tenant.vmwareidentity.com/SAAS/API/1.0/GET/metadata/idp.xml
B.
https://tenant.vmwareidentity.com/API/1.0/GET/metadata/sp.xml
C.
https://tenant.vmwareidentity.com/SAAS/API/1.0/GET/metadata/sp.xml
D.
https://tenant.vmwareidentity.com/API/l.0/GET/metadata/idp.xml

Answer:

C

User Votes:
Discussions
vote your answer:
0 / 1000

Question 8

Refer to the ACME Financials design use case.
ACME Financials Design Use Case
1. Introduction
1.1 Business Overview
ACME Financials is an investment firm that has established itself as a leader in USA's fast-moving
financial asset management market and has around 1000 employees.
ACME plans to transform its end-user computing resources to the digital workspace. ACME wants a
secure platform that is available from any device and from anywhere, as well as a solution that
reduces operating costs.
ACME's major business driver for the digital workplace is to enable employees to work remotely, and
to enable the secure access to all of its resources from anywhere and any device while enhancing
security with multi-factor authentication. The solution should support its BYOD strategy and let
remote employees use their own laptop, desktop, or mobile device to access the resources from any
location.
ACME also wants to remove the need to supply and manage desktop hardware to external
contractors. Because financial data is highly sensitive, the firm needs a technology that would protect
customer and other critical information - even when accessed on a mobile device. ACME is looking to
improve the security of the desktop and application platforms across the enterprise. In addition to
using endpoint security tools and multi-factor authentication, ACME insists on using additional
security and controls to provide the highest level of security and protection to services and
applications.
ACME currently uses a VPN-based remote access solution. ACME would like to remove additional
components that add support or management complexity, and device dependence for remote access
users. ACME is looking to achieve the same access to virtual desktops and Windows 10 or mobile
applications, both inside and outside of the ACME enterprise network.
ACME is very keen on enforcing standardization to keep the IT infrastructure as consistent as
possible. IT wants to use standardized versions of Windows (Windows 10), consistent configurations,
and application delivery from a central source. All while maintaining the compliance of every device
that requires encryption, password and PIN protection, as well as update -and anti-virus control.
To simplify and standardize desktop and application delivery, ACME wants to offer a service catalog
based approach based on ACME IT standards. This will allow ACME to effectively deliver and manage
resources, allowing IT to deliver device and application services that meet business and technical
needs, while maximizing the use of shared IT computing resources.
Additional Facts
Speaking to the developers revealed that most apps are standardized apps from public app-stores,
but ACME uses some their in-house developed, critical mobile apps, where some of the developers
have already left the company, so that they cannot be rewritten in a short amount of time.
To reduce operating costs, ACME has already moved to Office 365 and is currently running a few
migrations from on-premises to the cloud for other applications.
ACME's IT says that it is a Microsoft Windows only shop, but the assessment shows that currently
most of the managers are using Apple devices.
ACME currently uses directory services and two-factor authentication mechanisms (Radius) for
internal and external access. ACME requires to support Single Sign-On (SSO) integration with their
current authentication solutions. They also require to use SSO whenever possible, as they do not
believe in having multiple user accounts and passwords for their end users.
ACME wants the solution to provide mechanisms to provide a secure e-mail solution to any device
that complies to global security standards even for BYO devices.
1.2 High Level User Classification
680 Office workers (call center, corporate and office administrators) use standardized PCs or Thin-
Clients to access ACME's core apps and tools.
240 Remote-office workers use the company's CYOD initiative and use these devices (Notebooks,
Convertibles, Tablets, Android phones) to access their apps and tools from remote.
30 Executives use Apple Mac Books as well as iPhones and iPads to work on- and off-premises.
80 IT -admins and software developers are using high-end workstations with administrative access.
1.3 High Level Application Assessment
ACME currently has 261 applications, of which 186 are based on Microsoft Windows.
Today, users are allocated applications via AD group membership.
75 applications are either web-based or SaaS-based, including Office 365.
A major incident recently meant sales workers were disappearing suddenly along with their data
and laptops on some new colonies.
Any external access should require multi-factor authentication. Access from the internal network
should work seamlessly with SSO for the core applications. High-security applications also require
MFA from internal access.
The address ranges of the HQ datacenter are as follows:
172.16.0.0/16 internal
80.34.57. external
2. Initial Stakeholder Interview Findings
In addition to the goals summarized in the previous section, the following are findings from initial
interviews with the key stakeholders and an analysis of their service level agreements.
The design must use the F5 Loadbalancer and should be as redundant as possible.
Qualified IT personal is hard to find these days. If possible, reduce operational costs and try to
automate or outsource basic IT-tasks.
ACME is very particular about meeting the go-live date. If there are unforeseen delays, the project
may not be delivered for the required go-live date.
There is a requirement of having F5 as a primary load balancer.
Which two components are part of the logical design behind the load balancer? (Choose two.)

  • A. Secure E-Mail Gateway (SEG)
  • B. Workspace ONE UEM Device Servers
  • C. VMware Universal Access Gateway (UAG)
  • D. Active Directory Domain Controllers
  • E. VMware NSX Manager
Answer:

D,E

User Votes:
A
50%
B
50%
C
50%
D
50%
E
50%
Discussions
vote your answer:
A
B
C
D
E
0 / 1000

Question 9

What are two prerequisites to integrate Ping into VMware Workspace ONE? (Choose two.)

  • A. PingFederate must have Service Provider role enabled.
  • B. PingFederate must have remote authentication enabled.
  • C. PingFederate must be enabled as remote IdP.
  • D. PingFederate must be enabled as Built-in IdP.
  • E. PingFederate must have Identity Provider role enabled.
Answer:

A,E

User Votes:
A
50%
B
50%
C
50%
D
50%
E
50%
Discussions
vote your answer:
A
B
C
D
E
0 / 1000

Question 10

An administrator configured Okta as an identity provider for Workspace ONE. Users complain that
they still cannot authenticate via Okta.
What is most likely the issue?

  • A. The connector is down.
  • B. The Active Directory sync has failed.
  • C. The Okta IDP authentication method has not been selected in the access policies.
  • D. Okta authentication method for built-in identity providers is disabled.
Answer:

C

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 11

What are the requirements to configure Kerberos for VMware Identity Manager?

  • A. Add the authentication method in Workspace ONE UEM.
  • B. Assign the user to the Active Directory group for Kerberos.
  • C. Enter the account attribute that contains the SID of the user.
  • D. Enable Windows Authentication.
Answer:

D

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 12

An architect is planning for a cloud-hosted implementation of VMware Identity Manager to integrate
with an existing implementation of Workspace ONE UEM. The solution will include the following
authentication methods:
Username/Password (Cloud Deployment)
VMware Verify
RADIUS (Cloud Deployment)
Device Compliance
Workspace ONE UEM is also cloud hosted, however, the Active Directory and RADIUS servers are
deployed on-premises.
Which two design elements are required to ensure all authentication methods are highly available?
(Choose two.)

  • A. IdP Hostname set to load-balancer FQDN
  • B. Connectors configured for Legacy Mode
  • C. Enable Redirect configured on each Connector
  • D. Associate connectors with Build-In IdP
  • E. Enable authentication methods on all connectors
Answer:

C,D

User Votes:
A
50%
B
50%
C
50%
D
50%
E
50%
Discussions
vote your answer:
A
B
C
D
E
0 / 1000

Question 13

An administrator has created a new VMware Horizon desktop pool and added the entitlement within
the Horizon Administrator. The Horizon environment is properly connected to VMware Identity
Manager.
What are the next steps in the VMware Identity Manager admin console to make the desktop pool
available to users?

  • A. There are no additional steps needed.
  • B. Create a new entitlement in the VMware Identity Manager.
  • C. Create a new assignment in the VMware Identity Manager.
  • D. Create a new entitlement in the VMware Workspace ONE UEM.
Answer:

C

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 14

What statement is true about OAuth2?

  • A. It is lighter than SAML, it is XML-based rather than JSON.
  • B. It is heavier than SAML, it is JSON-based rather than XML.
  • C. It is lighter than SAML, it is JSON-based rather than XML.
  • D. It is heavier than SAML, it is XML-based rather than JSON.
Answer:

C

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 15

What are three requirements before beginning work on a VMware Workspace ONE and Okta
Integration? (Choose three.)

  • A. An Okta tenant: Role required: System or Console Administrator
  • B. A Workspace ONE UEM tenant: Role required: Console Administrator
  • C. A VMware Identity Manager tenant: Role required: System Administrator
  • D. A VMware Identity Manager tenant: Role required: Console Administrator
  • E. An Okta tenant: Role required: Super or Org Administrator
  • F. A Workspace ONE UEM tenant: Role required: System Administrator
Answer:

C,E,F

User Votes:
A
50%
B
50%
C
50%
D
50%
E
50%
F
50%
Discussions
vote your answer:
A
B
C
D
E
F
0 / 1000
To page 2