5V0-62-22 Sample Questions & Answers
Troubleshooting managed devices and applications dominates the weighting by far, next to how organization groups get restricted and configured, and how admin roles affect console and device events and log collection.
Launch the full 5V0-62-22 simulator →Showing 10 of 20 free samples.
- Question 1Advanced
Troubleshooting and Repairing · Objective 6.26 - Identify, understand, and troubleshoot common symptoms related to issues with applications.
A hospital is deploying shared iPads for nurses. During enrollment, the devices successfully receive Wi-Fi and passcode profiles, but the final step of installing the hospital's critical Electronic Health Record (EHR) application fails. The application is a VPP-licensed app assigned to a device-based smart group. The UEM console shows the command 'InstallApplication' has been queued but never progresses to 'Success'. All other device types are installing the app correctly. What is the most likely root cause of this specific failure on shared iPads?
Show answer & explanation
Correct answer: B
Device-based VPP app assignment on Shared iPads requires that the app is assigned to the device serial number, but the device must be able to communicate with Apple's VPP service to redeem the license. This communication often fails if there is no user context or if the App Store is restricted. The most common cause is that Shared iPads, by design, do not have a primary user Apple ID logged in, which can interrupt the license validation process unless specifically configured for it. The solution is often to ensure the device can reach Apple's VPP endpoints and that no profiles are blocking the App Store services.
- Question 2Intermediate
Administrative and Operational Tasks · Objective 7.4 - Describe the process of changing logging levels for troubleshooting Workspace ONE core services and components.
To troubleshoot intermittent connectivity issues with the Secure Email Gateway (SEGv2), an administrator needs to increase the verbosity of logging to capture detailed information about mail server connections. What is the correct value to modify in the
application.propertiesfile on the SEG server to enable DEBUG level logging?Show answer & explanation
Correct answer: B
The
application.propertiesfile for SEGv2 uses standard Spring Boot logging configuration. To change the logging level for the SEG application specifically, the administrator must set the property for the SEG's root package, which iscom.airwatch.seg, toDEBUG. Settinglogging.level.rootwould change it for all components, which is usually too verbose. - Question 3Intermediate
Administrative and Operational Tasks · Objective 7.2 - Understand the Console Events or Device Events settings
A retail company has deployed thousands of Android devices for their store associates. After a recent directory synchronization, a large number of these devices have been incorrectly enterprise wiped because their user accounts were moved to a different OU in Active Directory, which was not mapped to an enrollment OG in UEM. The administrator needs to quickly identify which admin user initiated the sync that caused this issue. Which event log in the Workspace ONE UEM console should be reviewed to find this information?
Show answer & explanation
Correct answer: B
Console Events track all administrative actions performed within the UEM console. A manual directory sync is an administrative action. The Console Events log will contain an entry for 'User Sync Started' or similar, which will include the username of the administrator who initiated the action and the timestamp. Device Events would show the resulting 'Enterprise Wipe' commands but not who initiated the sync.
- Question 4Advanced
Troubleshooting and Repairing · Objective 6.31 - Identify, understand, and troubleshoot common symptoms of VMware Tunnel related issues
Case Study:
A global logistics company, ShipFast, is modernizing its warehouse operations by deploying 5,000 Zebra rugged Android devices. The devices are enrolled via StageNow barcodes into a dedicated 'Warehouse' Organization Group (OG) in their on-premises Workspace ONE UEM 21.11 environment. The deployment requires a high-availability architecture for internal application access.
The current architecture consists of two UEM application servers (DS and Console on each), a standalone SQL Server, and a pair of Unified Access Gateway (UAG) 3.9 appliances in a load-balanced cluster. A Per-App VPN profile is configured to provide access to the internal Warehouse Management System (WMS) application. The WMS app is hosted on a server at 10.10.20.50.
Following the initial successful pilot of 100 devices, the company proceeded with a mass rollout. Shortly after, warehouse managers reported widespread failures. The Zebra devices cannot connect to the WMS application. Initial checks show the devices are online in the UEM console and have received the VPN profile. The WMS server is online and accessible from the internal network.
Troubleshooting reveals that the
vpnd.logon the UAGs is flooded with 'Packet dropped' messages for traffic destined for 10.10.20.50. The UEM Tunnel configuration in the console has 'Network Traffic Rules' defined to allow access to the 10.10.20.0/24 subnet. The administrator also notes that the UAG cluster's health checks are intermittently failing on the Tunnel service. Further investigation shows high CPU utilization on both UAG appliances.What is the most probable root cause of the connection failure?
Show answer & explanation
Correct answer: C
The combination of high CPU, intermittent health check failures, and 'Packet dropped' messages after a mass rollout strongly points to a performance issue. UAG 3.9 defaults to Cascade Mode for Tunnel, where one UAG acts as the primary for all connections. With 5,000 devices, this creates a significant performance bottleneck. The correct architecture for this scale is Relay-Endpoint mode, which load balances traffic across both UAGs. The high CPU and packet drops are classic symptoms of the Tunnel service being overwhelmed on the primary cascade node.
- Question 5IntermediateSelect 3
Troubleshooting and Repairing · Objective 6.21 - Describe how targeted logging can help endpoint troubleshooting
An administrator is attempting to troubleshoot why a specific Windows 10 device is not receiving an updated Wi-Fi profile. The administrator wants to use the Targeted Logging feature to capture detailed logs from the device. Which components can be selected for logging when initiating a Targeted Logging session for a Windows 10 device from the UEM console? (Select THREE)
Show answer & explanation
Correct answers: A, B, D
The Intelligent Hub is the primary agent on the device and its logs are crucial for troubleshooting most issues, including profile delivery.
System logs, which include Windows Event Logs, are essential for diagnosing issues related to the operating system's handling of MDM commands, such as installing a Wi-Fi profile.
MDM logs specifically capture the interactions between the device and the UEM server via the OMA-DM protocol. These are critical for troubleshooting profile installation failures.
- Question 6Advanced
Troubleshooting and Repairing · Objective 6.16 - Identify and troubleshoot common Certificate Authority errors
A Workspace ONE UEM environment is integrated with an internal Microsoft Certificate Authority. An administrator notices that SCEP certificate requests for macOS devices are failing. Reviewing the AirWatch Cloud Connector (ACC) server logs, the administrator finds the following error:
The request is missing a required certificate template extension or the certificate template extension is invalid.What is the most likely cause of this error?Show answer & explanation
Correct answer: B
This specific error message from a Microsoft CA indicates that the certificate template is not configured to allow the requester (in this case, the UEM SCEP request) to define the subject name within the certificate signing request (CSR). Workspace ONE UEM dynamically generates the subject name based on device and user information. To allow this, the 'Supply in the request' option must be enabled on the template's Subject Name tab.
- Question 7Intermediate
Troubleshooting and Repairing · Objective 6.29 - Identify and understand useful troubleshooting commands for UAG
An administrator is troubleshooting a Unified Access Gateway (UAG) that is failing to initialize the VMware Tunnel service. After connecting to the UAG via SSH and escalating to root, the administrator needs to check the status of the service and review its logs. Which command should the administrator run to view the real-time log output for the VMware Tunnel service?
Show answer & explanation
Correct answer: C
On the UAG appliance, services are managed by
systemd. Thejournalctlcommand is the standard tool for querying and displaying logs from the systemd journal. The-u vpnflag filters the logs for the VPN service unit (which corresponds to VMware Tunnel), and the-fflag follows the log output in real-time, similar totail -f. - Question 8Intermediate
Administrative and Operational Tasks · Objective 7.1 - Describe how an administrator's role affects the viewing of system settings
True or False: Enabling the 'Collect and Display' setting for 'Application Information' in the Privacy settings of the Workspace ONE UEM console will cause personally installed applications on employee-owned (BYOD) devices to be visible to administrators.
Show answer & explanation
Correct answer: A
The statement is true. The privacy settings are global or OG-specific. If 'Application Information' is set to 'Collect and Display' for the 'Employee Owned' ownership type, the UEM console will collect and show a list of all installed applications, including personal ones, for any BYOD device in that OG. This is a critical privacy consideration that administrators must manage carefully.
- Question 9Intermediate
Troubleshooting and Repairing · Objective 6.25 - Identify, understand, and troubleshoot common compliance policy issues
A compliance policy is configured to enterprise wipe any iOS device if the Workspace ONE Intelligent Hub is removed. A user reports that their device was wiped after they accidentally deleted the Hub app. The security team wants to prevent this from happening to non-malicious users in the future. Which action provides the most effective balance of security and user experience to mitigate this issue?
Show answer & explanation
Correct answer: C
Modifying the policy to include a grace period (e.g., 24 hours) with a notification action (e.g., push notification, email) is the best approach. This gives the user time to realize their mistake and reinstall the Hub from the App Store before the enterprise wipe is triggered. It maintains the security posture while preventing data loss from accidental deletions.
- Question 10Advanced
Troubleshooting and Repairing · Objective 6.12 - Understand common ACC problems
Case Study:
A large university has implemented Workspace ONE UEM to manage devices for students and faculty. They have integrated with their on-campus Active Directory for authentication and group synchronization. The integration is handled by an AirWatch Cloud Connector (ACC) server installed in their DMZ.
Recently, the university's IT team enabled SSL Certificate Pinning for the ACC to enhance security. The configuration was tested and working. A week later, the university renewed the public SSL certificate on their UEM Device Services server. Immediately after the certificate renewal, directory synchronization started failing. Users reported that newly created AD groups were not appearing in the UEM console, and new faculty members could not enroll their devices.
The administrator inspects the
CloudConnector.logon the ACC server and finds repeated entries stating 'SSL/TLS secure channel for authority could not be created' and 'The remote certificate is invalid according to the validation procedure'. The Device Services server is accessible from the ACC server over port 443.What is the root cause of this synchronization failure?
Show answer & explanation
Correct answer: C
The log message 'The remote certificate is invalid' combined with the fact that SSL Pinning was enabled and the server certificate was just renewed points directly to a thumbprint mismatch. SSL Pinning configures the ACC to trust only a specific certificate (identified by its thumbprint). When the Device Services certificate was renewed, the new certificate has a new thumbprint. The ACC is still configured with the old thumbprint, causing it to reject the new certificate and fail the TLS handshake. The administrator must update the pinned certificate thumbprint in the ACC configuration.
Ready for the real thing?
The full 5V0-62-22 simulator has every exam-style question, timed mode, and instant scoring.