OCE-W Sample Questions & Answers
Ranges across enrollment strategy and configuration profiles, directory services paired with the AirWatch Cloud Connector, conditional access and authentication, patch and application automation, troubleshooting, security policies, and health monitoring.
Launch the full OCE-W simulator →Showing 8 of 16 free samples.
- Question 1Advanced
Infrastructure Planning and Management · Enterprise Service Component Integration
In an on-premises Workspace ONE UEM deployment with 20,000 devices, what is the function of integrating Memcached?
Show answer & explanation
Correct answer: D
Memcached is a third-party distributed data caching application for Workspace ONE UEM. Before querying the database, UEM checks Memcached for stored results, which reduces the database workload. It is aimed at installations with 5,000+ devices, is available for SaaS and on-premises, and is configured at Groups & Settings > All Settings > Installation > Cache Settings (port 11211). It is not a form of backup or redundancy.
- Question 2IntermediateSelect 2
Identity and Access Management · Authentication Methods
An administrator wants an Omnissa Access policy rule that verifies device compliance with Workspace ONE UEM by chaining an authentication method with 'Device Compliance (with Workspace ONE UEM)'.
Which two authentication methods can be chained with Device Compliance? (Select two)
Show answer & explanation
Correct answers: C, D
The built-in identity provider authentication methods that can be chained with Device Compliance (with Workspace ONE UEM) are Mobile SSO (for iOS), Mobile SSO (for Android), and Certificate (Cloud Deployment). The authentication method must come before the device compliance method in the rule.
The built-in identity provider authentication methods that can be chained with Device Compliance (with Workspace ONE UEM) are Mobile SSO (for iOS), Mobile SSO (for Android), and Certificate (Cloud Deployment). The authentication method must come before the device compliance method in the rule.
- Question 3Intermediate
Identity and Access Management · Authentication Methods
You are integrating a third-party Identity Provider (e.g., Okta) with Omnissa Access. You want users to be redirected to Okta for authentication when they access the Workspace ONE portal.
After configuring the IDP in the Access console, what is the final step to enforce this flow?
Show answer & explanation
Correct answer: B
Simply adding the Identity Provider makes it available, but not active. You must update the Access Policies to use this new authentication method (e.g., 'Okta Auth') as the primary or fallback method for the relevant network ranges or apps.
- Question 4Intermediate
Security and Compliance · Risk Scoring with Intelligence
Which component is primarily responsible for calculating the 'User Risk Score' used in Conditional Access policies within Omnissa Access?
Show answer & explanation
Correct answer: C
Workspace ONE Intelligence aggregates data from UEM, Access, and Trust Network partners to calculate User and Device Risk Scores. Omnissa Access then consumes these scores to make conditional access decisions.
- Question 5Advanced
Application and Patch Management · Application Deployment
You need to retire an internally developed iOS application (v1.0) and replace it with v2.0 for all users. You want to ensure v1.0 is uninstalled before v2.0 is installed to prevent data conflicts.
Which strategy in Workspace ONE UEM best supports this requirement?
Show answer & explanation
Correct answer: D
Use Add Version on the existing internal app record so UEM manages v2.0 as an update of the same app (iOS upgrades in place). If a clean install is required, first remove v1.0 from the devices (for example by removing its assignment or sending a removal command), then deploy v2.0.
- Question 6Advanced
Application and Patch Management · Device Email Management
A customer is deploying the Secure Email Gateway (SEG) V2 model. They want to understand the traffic flow for email attachments.
Which statement accurately describes the SEG V2 architecture regarding attachments?
graph TD Device -->|HTTPS| UAG_SEG UAG_SEG -->|EAS| ExchangeShow answer & explanation
Correct answer: C
SEG V2 sits in the ActiveSync path and applies email security policies inline. Its content-transformation feature can encrypt attachments of selected file types with a key unique to the device and user, so they can be opened only in Workspace ONE Content (Content Locker), and it can transform hyperlinks. It does not send attachments to the UEM console, and it encrypts at the gateway, not on the Exchange server.
- Question 7Advanced
Troubleshooting · Troubleshooting Tools
When initiating a Workspace ONE Assist session to a Windows 10 device, the connection stays at 'Connecting...' and eventually times out. The device is online and checking in to UEM.
Which specific URL/Port requirement is likely blocked?
Show answer & explanation
Correct answer: B
Assist remote sessions connect through the Assist Connection Proctor (CP) service. Its default port is 8443, or 443 when CP runs on a separate server, and both are customizable. If the device cannot reach CP, the session stays at Connecting even though the device checks in to UEM through the normal device services path. T10 is the API certificate/user used between UEM and Assist.
- Question 8Intermediate
Security and Compliance · Risk Scoring with Intelligence
In Workspace ONE Intelligence Risk Analytics, which factor contributes to the 'Login Risk' score?
Show answer & explanation
Correct answer: A
Login risk scores are built from Omnissa Access login data. Machine learning models consider historical login requests and the user's login location to judge whether an attempt is anomalous. Each login gets Low, Medium or High in real time, with a grace period of about one month while the user's pattern is learned.
Ready for the real thing?
The full OCE-W simulator has every exam-style question, timed mode, and instant scoring.