5V0-61-22 Sample Questions

5V0-61-22 Sample Questions & Answers

Integrating applications, productivity suites and directory services carries the most weight, next to hooking up identity providers and access policies, staying compliant and blocking threats, basic platform architecture, and troubleshooting authentication issues.

Launch the full 5V0-61-22 simulator →

Showing 10 of 20 free samples.

  1. Question 1Advanced

    Integrations · Productivity Suite Integration

    Case Study

    A global investment bank, FinSecure, uses Workspace ONE as its digital workspace platform. They are integrating Microsoft 365 and have extremely strict security requirements. The Chief Information Security Officer (CISO) has mandated a risk-based conditional access model.

    Current Environment:

    • Workspace ONE Access is federated with Azure AD.
    • Workspace ONE UEM manages all corporate-owned iOS and Windows 10 devices.
    • Workspace ONE Intelligence is deployed and collecting data from UEM and Access.
    • The primary user directory is on-premises Active Directory, synchronized to both Azure AD and Workspace ONE Access.

    Requirements:

    1. Users on UEM-managed and compliant devices must be granted seamless single sign-on to Microsoft 365 applications.
    2. Users on unmanaged devices or devices with a 'High' risk score in Workspace ONE Intelligence must be blocked from accessing Microsoft 365.
    3. Users on managed but non-compliant devices (e.g., outdated OS) must be prompted for VMware Verify MFA.
    4. The solution must be centrally managed and leverage the existing VMware and Microsoft investments.

    Which solution design meets all of FinSecure's requirements?

    Show answer & explanation

    Correct answer: C

    This is the correct and most robust design. It leverages each platform's strengths. Workspace ONE (Access, UEM, Intelligence) acts as the source of truth for device posture and user risk. This data is passed as claims to Azure AD. Azure AD's Conditional Access engine then acts as the policy enforcement point for Microsoft 365, using the trusted claims from Workspace ONE to make granular access decisions (grant, block, require MFA). This meets all requirements.

  2. Question 2Intermediate

    Authentication Technologies · Certificate-Based Authentication

    An administrator is configuring Mobile SSO for iOS devices to allow seamless access to internal web applications. This configuration relies on Kerberos authentication. When creating the iOS device profile in Workspace ONE UEM, which certificate is essential to upload to facilitate the Kerberos authentication process?

    Show answer & explanation

    Correct answer: C

    The iOS device must trust the Key Distribution Center (KDC), which is typically a domain controller in Active Directory, to request a Kerberos ticket. Uploading the KDC server's root or intermediate certificate into the SSO profile ensures the device establishes this trust and the Kerberos process can proceed securely.

  3. Question 3Intermediate

    Troubleshooting · Directory Sync Troubleshooting

    After configuring directory synchronization with Active Directory, an administrator notices that users who are members of nested groups (e.g., a user is in 'Group A', which is a member of 'Group B') are not being synchronized into Workspace ONE Access when only 'Group B' is added to the sync rule. What is the most likely reason for this issue?

    Show answer & explanation

    Correct answer: B

    By default, for performance reasons, Workspace ONE Access does not recursively sync members of nested groups. To include these users, the administrator must explicitly enable the 'Sync Nested Group Members' option for the directory configuration within the Workspace ONE Access console.

  4. Question 4Intermediate

    Integrations · SIEM Integration

    A security operations team wants to forward audit and system logs from Workspace ONE Access to their Splunk SIEM for threat correlation. They require the logs to be in a structured, key-value pair format for easy parsing in Splunk. Which syslog format should the administrator configure on the Workspace ONE Access appliance?

    Show answer & explanation

    Correct answer: D

    LFV, also known as LEEF (Log Event Extended Format) in some contexts, is specifically designed to output logs as key-value pairs (e.g., 'usr=admin cat=AUDIT'). This format is ideal for SIEMs like Splunk and QRadar because it allows for automatic field extraction and easy parsing, meeting the security team's requirement.

  5. Question 5Beginner

    Authentication Technologies · Identity Provider Integration

    True or False: When using Just-in-Time (JIT) provisioning with a third-party SAML identity provider, the Workspace ONE Access Connector is required to create the user accounts in the Workspace ONE Access service directory.

    Show answer & explanation

    Correct answer: B

    This statement is false. JIT provisioning creates a user account in the Workspace ONE Access local directory based on the attributes received in the SAML assertion from the trusted third-party IdP. The Workspace ONE Access Connector is not involved in this process, as it is used for syncing with on-premises directories like Active Directory.

  6. Question 6Intermediate

    Digital Workspace Technologies · Workspace ONE Platform Architecture

    A consultant is designing a highly available deployment for VMware Unified Access Gateway (UAG) to support Horizon and web reverse proxy services. The design requires that the failure of a single UAG appliance does not interrupt user sessions. Which load balancing configuration is required to achieve this?

    graph TD subgraph DMZ LB[Load Balancer] UAG1[UAG Appliance 1] UAG2[UAG Appliance 2] UAG3[UAG Appliance 3] end Users((Users)) --> LB LB --> UAG1 LB --> UAG2 LB --> UAG3
    Show answer & explanation

    Correct answer: B

    This is the correct configuration. Source IP persistence (or cookie persistence) ensures that all traffic from a single user session is consistently sent to the same UAG appliance. Health monitors allow the load balancer to detect if a UAG appliance fails and automatically redirect traffic to the remaining healthy appliances, thus maintaining service availability.

  7. Question 7Advanced

    Endpoint Security Technologies · Data Loss Prevention

    A company's security policy prohibits employees from uploading corporate documents from their managed Windows 10 laptops to personal cloud storage services like Dropbox and Google Drive. However, access to these sites for other purposes is permitted. Which Workspace ONE feature should be used to enforce this specific Data Loss Prevention (DLP) control?

    Show answer & explanation

    Correct answer: C

    This is the most precise solution. Workspace ONE Tunnel, when configured with Device Traffic Rules, can inspect network traffic at a granular level. By creating a rule to block HTTP POST requests (which are used for file uploads) to specific domains like dropbox.com and drive.google.com, the policy can effectively prevent uploads while still allowing users to browse and view content (using GET requests).

  8. Question 8Intermediate

    Integrations · API and Custom Integrations

    A human resources department needs to automate the process of granting access to a set of specific applications in the Workspace ONE catalog for all new hires. The company uses an HRIS system that can trigger a webhook on a 'New Hire' event. What is the most efficient way to automate this entitlement process using the Workspace ONE platform's capabilities?

    Show answer & explanation

    Correct answer: B

    This is the most efficient and native solution. Workspace ONE Intelligence can act as a webhook listener. An automation workflow can be created to parse the new hire data from the webhook payload and then use the 'Workspace ONE UEM - Add User to User Group' action. By pre-assigning the required applications to that target user group, the entitlement process becomes fully automated.

  9. Question 9Advanced

    Authentication Technologies · Identity Provider Integration

    A consultant is integrating Workspace ONE Access with a legacy on-premises application that uses PingFederate as its identity provider. PingFederate requires the SAML NameID format to be a custom attribute called 'LegacyAppID'. This attribute exists for users in Active Directory. How should the consultant configure Workspace ONE Access to meet this requirement?

    Show answer & explanation

    Correct answer: A

    This is the correct procedure. The NameID format itself can be set to 'Unspecified' or another standard format, but the crucial step is to change the 'Name ID Value' field from a standard variable like ${user.userName} to the specific custom attribute required, which is ${user.legacyAppID}. This ensures the correct value is sent in the NameID element of the assertion.

  10. Question 10Intermediate

    Troubleshooting · Integration Troubleshooting

    An organization has successfully integrated Workspace ONE with Horizon and configured True SSO. However, users are reporting that when they launch a Horizon desktop from the Intelligent Hub, they are still being prompted for their Active Directory password. The administrator has verified that the True SSO enrollment server is healthy and certificates are being issued. What is a likely misconfiguration causing this issue?

    Show answer & explanation

    Correct answer: C

    True SSO is not enabled globally by default; it must be explicitly enabled on a per-pool basis within the Horizon Administrator console. If this setting is missed for a specific desktop pool, Horizon will fall back to requiring AD credentials, even if the underlying True SSO infrastructure is healthy.

Ready for the real thing?

The full 5V0-61-22 simulator has every exam-style question, timed mode, and instant scoring.