OCA-W Sample Questions

OCA-W Sample Questions & Answers

Checks your knowledge of administering the Workspace ONE UEM console, which edges out everything else in weight, device enrollment and compliance profiles, deploying apps through the catalog, certificate security and conditional access, and support troubleshooting.

Launch the full OCA-W simulator →

Showing 8 of 16 free samples.

  1. Question 1Advanced

    Device Lifecycle Management · Platform-Specific Enrollment

    Case Study:

    A large retail chain, 'GlobalMart', is deploying 5,000 Android Zebra rugged devices for its warehouse staff. The devices will be shared among workers across three shifts. Each worker must log in at the start of their shift to access a specific set of applications, including an inventory scanner and a messaging app. At the end of the shift, the device must be wiped of the previous user's session data and be ready for the next worker. The devices are managed in a dedicated 'Warehouse' Organization Group (OG).

    Requirements:

    1. Devices must be locked to a specific set of authorized work applications.
    2. User sessions must be isolated, and all session data must be cleared upon logout.
    3. Enrollment must be as streamlined as possible, requiring minimal interaction from the warehouse setup team.
    4. The solution must use Android Enterprise (not Android legacy) management.

    Which combination of Workspace ONE UEM features and configurations should the administrator implement to meet all of GlobalMart's requirements?

    Show answer & explanation

    Correct answer: A

    Zebra StageNow barcode enrollment is a supported bulk method for Android Enterprise Fully Managed devices and needs minimal interaction. Enrolling with a multi-user staging account (Android Shared Device Mode = Launcher) turns on shared-device check-in/check-out in Workspace ONE Launcher: the device is locked to the authorized apps, each worker logs in to receive only their assigned resources, and the session is cleared at check-in so the device is ready for the next worker. Work Profile is for BYOD, and scheduled enterprise wipes would unenroll the devices.

  2. Question 2Intermediate

    Integration, Monitoring, and Troubleshooting · System Logging and SIEM Integration

    A security team wants to forward all Workspace ONE UEM console events to their central SIEM platform for correlation and analysis. The SIEM platform ingests data via Syslog over TCP on port 514. The administrator has navigated to Groups & Settings > All Settings > System > Enterprise Integration > Syslog, set Protocol to TCP and Port to 514. What should be entered in the Host Name field?

    Show answer & explanation

    Correct answer: B

    The Syslog General tab has separate fields: Host Name (the SIEM address, for example siem.company.com), Protocol (UDP, TCP or Secure TCP) and Port. Enter siem.company.com as the Host Name, choose TCP as the Protocol, and enter 514 as the Port. The protocol and port are not written into the Host Name value.

  3. Question 3Intermediate

    Device Lifecycle Management · Ownership Types and Management Modes

    A consulting firm is implementing a BYOD program and wants to manage corporate applications and data on employee-owned Android devices without accessing personal data. The primary goals are to containerize corporate data, prevent data leakage to personal apps, and have the ability to wipe only corporate data if an employee leaves. Which Android Enterprise enrollment method is the best practice for this scenario?

    Show answer & explanation

    Correct answer: C

    The Android Enterprise Work Profile (Profile Owner) mode is specifically designed for BYOD scenarios. It creates a secure, encrypted container on the device that isolates corporate apps and data from the user's personal space. Administrators have full control over the work profile, including the ability to wipe it remotely, but have no visibility or control over the personal side of the device, thus preserving user privacy.

  4. Question 4Beginner

    Workspace ONE UEM Administration and Architecture · Organization Groups (OG) Management

    True or False: In a multi-level Organization Group (OG) hierarchy, a VPN profile created at a child OG will automatically override a VPN profile with the same name that was inherited from its parent OG.

    Show answer & explanation

    Correct answer: B

    False. Device profiles do not override each other by name. Each profile is a separate resource with its own Managed By OG and assignments. A profile managed at the parent OG stays assigned to the devices it targets and is read-only for child-OG administrators. A profile created at the child OG is simply another profile, so both are delivered if both are assigned. To change what child devices receive, change the assignments (for example, exclude the child devices from the parent profile) rather than relying on a same-name 'override'.

  5. Question 5Intermediate

    Application Management · Public App Store Applications

    An organization uses Apple's Volume Purchase Program (VPP) to manage paid iOS application licenses. An employee with several VPP-licensed apps installed on their device leaves the company, and their device is unenrolled from Workspace ONE UEM. What happens to the VPP licenses that were assigned to that user?

    Show answer & explanation

    Correct answer: C

    When a device is unenrolled or an app is uninstalled, Workspace ONE UEM automatically sends a command to revoke the VPP license. The license is then returned to the available pool associated with the VPP token in the UEM console. This allows the license to be reclaimed and reassigned to another user or device, preventing license loss and unnecessary repurchasing.

  6. Question 6Advanced

    Access Control and Security · Single Sign-On (SSO) Configuration

    A company is troubleshooting a Mobile SSO issue for iOS devices. Authentication fails, and analysis shows the device is not presenting its client certificate to Omnissa Access during the authentication attempt. The environment uses SCEP to deliver identity certificates, and the administrator has confirmed that a valid identity certificate is installed on the affected devices. Which step in the authentication flow is most likely failing?

    sequenceDiagram participant Device participant App participant UEM participant Access as Omnissa Access participant IdP App->>Device: User requests access Device->>Access: Initiates authentication Access->>Device: Responds with certificate challenge Note right of Device: Fails to find/present certificate Device-->>Access: Fails to respond with cert Access-->>App: Authentication Failed
    Show answer & explanation

    Correct answer: D

    Mobile SSO (for iOS) requires the administrator to upload the certificate authority issuer certificate (Root and Intermediate CA Certificate, PEM or DER) in the Mobile SSO (for iOS) authentication method in Omnissa Access. Without the issuing CA uploaded, Omnissa Access has no trusted issuer for the device's SCEP-issued identity certificate, so certificate-based Mobile SSO fails even though the certificate is present on the device.

  7. Question 7Intermediate

    Device Lifecycle Management · Device Configuration and Profiles

    An administrator pushed a new Restrictions profile to a Smart Group of iOS devices. While most devices received and applied the profile successfully, five devices in the group show 'Not Now' in the Command Status column for the profile installation. The devices are online and checking in with the UEM console. What is a common reason for the 'Not Now' status?

    Show answer & explanation

    Correct answer: B

    The View Devices screen's Command Status column shows 'Not Now' when the device is locked or otherwise occupied. The device received the command but cannot process it at the moment, so it defers the command and handles it on a later check-in. An expired APNs certificate would stop commands reaching the device at all. A restart is not required.

  8. Question 8Intermediate

    Workspace ONE UEM Administration and Architecture · Role-Based Access Control (RBAC)

    A university wants to create a custom administrator role for its student help desk staff. The staff need to be able to perform basic troubleshooting actions like clearing a device passcode and sending messages to devices. However, they must be explicitly prevented from performing any type of wipe command (device or enterprise) and from creating or editing configuration profiles. Which is the most effective way to configure this role in Workspace ONE UEM?

    Show answer & explanation

    Correct answer: B

    Least privilege: start from a clean slate, either with Add Role or by copying a role and setting the All category to None. Then enable only what the job requires: Read on the device list resources (for example, Device Management > Devices List View > Devices) and Edit only on the individual Clear Passcode and Send Message resources, which you can find with Search Resources. Wipe and profile resources remain unchecked. Assigning a built-in role unchanged grants remote actions and other functions beyond the requirement.

Ready for the real thing?

The full OCA-W simulator has every exam-style question, timed mode, and instant scoring.

Go to the OCA-W simulator →