What is the goal of Mobile SSO?
Answer : D
Reference:
https://docs.vmware.com/en/VMware-Workspace-ONE-UEM/1908/iOS_Platform/GUID-AWT-PROFILESSO.html
Refer to the ACME Financials design use case.
ACME Financials Design Use Case -
1. Introduction
1.1 Business Overview
ACME Financials is an investment firm that has established itself as a leader in USA's fast-moving financial asset management market and has around 1000 employees.
ACME plans to transform its end-user computing resources to the digital workspace. ACME wants a secure platform that is available from any device and from anywhere, as well as a solution that reduces operating costs.
ACME's major business driver for the digital workplace is to enable employees to work remotely, and to enable the secure access to all of its resources from anywhere and any device while enhancing security with multi-factor authentication. The solution should support its BYOD strategy and let remote employees use their own laptop, desktop, or mobile device to access the resources from any location.
ACME also wants to remove the need to supply and manage desktop hardware to external contractors. Because financial data is highly sensitive, the firm needs a technology that would protect customer and other critical information - even when accessed on a mobile device. ACME is looking to improve the security of the desktop and application platforms across the enterprise. In addition to using endpoint security tools and multi-factor authentication, ACME insists on using additional security and controls to provide the highest level of security and protection to services and applications.
ACME currently uses a VPN-based remote access solution. ACME would like to remove additional components that add support or management complexity, and device dependence for remote access users. ACME is looking to achieve the same access to virtual desktops and Windows 10 or mobile applications, both inside and outside of the ACME enterprise network.
ACME is very keen on enforcing standardization to keep the IT infrastructure as consistent as possible. IT wants to use standardized versions of Windows
(Windows 10), consistent configurations, and application delivery from a central source. All while maintaining the compliance of every device that requires encryption, password and PIN protection, as well as update -and anti-virus control.
To simplify and standardize desktop and application delivery, ACME wants to offer a service catalog based approach based on ACME IT standards. This will allow
ACME to effectively deliver and manage resources, allowing IT to deliver device and application services that meet business and technical needs, while maximizing the use of shared IT computing resources.
Additional Facts -
-> Speaking to the developers revealed that most apps are standardized apps from public app-stores, but ACME uses some their in-house developed, critical mobile apps, where some of the developers have already left the company, so that they cannot be rewritten in a short amount of time.
-> To reduce operating costs, ACME has already moved to Office 365 and is currently running a few migrations from on-premises to the cloud for other applications.
-> ACME's IT says that it is a Microsoft Windows only shop, but the assessment shows that currently most of the managers are using Apple devices.
-> ACME currently uses directory services and two-factor authentication mechanisms (Radius) for internal and external access. ACME requires to support Single
Sign-On (SSO) integration with their current authentication solutions. They also require to use SSO whenever possible, as they do not believe in having multiple user accounts and passwords for their end users.
-> ACME wants the solution to provide mechanisms to provide a secure e-mail solution to any device that complies to global security standards even for BYO devices.
1.2 High Level User Classification
680 Office workers (call center, corporate and office administrators) use standardized PCs or Thin-Clients to access ACME's core apps and tools.
Answer : BE
Refer to the ACME Financials design use case.
ACME Financials Design Use Case -
1. Introduction
1.1 Business Overview
ACME Financials is an investment firm that has established itself as a leader in USA's fast-moving financial asset management market and has around 1000 employees.
ACME plans to transform its end-user computing resources to the digital workspace. ACME wants a secure platform that is available from any device and from anywhere, as well as a solution that reduces operating costs.
ACME's major business driver for the digital workplace is to enable employees to work remotely, and to enable the secure access to all of its resources from anywhere and any device while enhancing security with multi-factor authentication. The solution should support its BYOD strategy and let remote employees use their own laptop, desktop, or mobile device to access the resources from any location.
ACME also wants to remove the need to supply and manage desktop hardware to external contractors. Because financial data is highly sensitive, the firm needs a technology that would protect customer and other critical information - even when accessed on a mobile device. ACME is looking to improve the security of the desktop and application platforms across the enterprise. In addition to using endpoint security tools and multi-factor authentication, ACME insists on using additional security and controls to provide the highest level of security and protection to services and applications.
ACME currently uses a VPN-based remote access solution. ACME would like to remove additional components that add support or management complexity, and device dependence for remote access users. ACME is looking to achieve the same access to virtual desktops and Windows 10 or mobile applications, both inside and outside of the ACME enterprise network.
ACME is very keen on enforcing standardization to keep the IT infrastructure as consistent as possible. IT wants to use standardized versions of Windows
(Windows 10), consistent configurations, and application delivery from a central source. All while maintaining the compliance of every device that requires encryption, password and PIN protection, as well as update -and anti-virus control.
To simplify and standardize desktop and application delivery, ACME wants to offer a service catalog based approach based on ACME IT standards. This will allow
ACME to effectively deliver and manage resources, allowing IT to deliver device and application services that meet business and technical needs, while maximizing the use of shared IT computing resources.
Additional Facts -
Speaking to the developers revealed that most apps are standardized apps from public app-stores, but ACME uses some their in-house developed, critical
Answer : AB
Which two authentication methods are for built-in identity providers? (Choose two.)
Answer : AC
Reference:
https://docs.vmware.com/en/VMware-Workspace-ONE/services/WS1-IDM-deploymentguide/GUID-AD9A5715-C21B-4D54-A413-28980A70A4B4.html
What are two prerequisites for VMware Identity Manager as the Default Claims Provider for an application that is joined using AD FS? (Choose two.)
Answer : BE
Reference:
https://docs.vmware.com/en/VMware-Identity-Manager/services/workspaceone_adfs_integration/GUID-6E9EC5E1-3AD3-429B-86F6-
DCB776A87655.html -
What are three prerequisites for Workspace ONE Airlift? (Choose three.)
Answer : ACD
Reference:
https://docs.vmware.com/en/VMware-Workspace-ONE-UEM/1907/AirLift_Configuration/GUID-AWT-REQUIREMENTS-AIRLIFT.html
What are two prerequisites for using Workspace ONE and Azure AD? (Choose two.)
Answer : BC
Reference:
https://docs.vmware.com/en/VMware-Workspace-ONE-UEM/9.4/vmware-airwatch-guides-94/GUID-AW94-Enroll_ConfigAADServices.html
What is required in a multi-Office 365 domain environment?
Answer : B
What are three requirements before beginning work on a VMware Workspace ONE and Okta Integration? (Choose three.)
Answer : CEF
Reference:
https://docs.vmware.com/en/VMware-Workspace-ONE/services/workspaceone_okta_integration.pdf
What statement is true about OAuth2?
Answer : C
An administrator has created a new VMware Horizon desktop pool and added the entitlement within the Horizon Administrator. The Horizon environment is properly connected to VMware Identity Manager.
What are the next steps in the VMware Identity Manager admin console to make the desktop pool available to users?
Answer : C
Reference:
https://docs.vmware.com/en/VMware-Horizon-7/7.9/horizon-console-administration.pdf
An architect is planning for a cloud-hosted implementation of VMware Identity Manager to integrate with an existing implementation of Workspace ONE UEM. The solution will include the following authentication methods:
Username/Password (Cloud Deployment)
VMware Verify -
RADIUS (Cloud Deployment)
Device Compliance -
Workspace ONE UEM is also cloud hosted, however, the Active Directory and RADIUS servers are deployed on-premises.
Which two design elements are required to ensure all authentication methods are highly available? (Choose two.)
Answer : CD
Reference:
https://docs.vmware.com/en/VMware-Identity-Manager/services/vidm_cloud_deployment.pdf
What are the requirements to configure Kerberos for VMware Identity Manager?
Answer : D
Reference:
https://docs.vmware.com/en/VMware-Identity-Manager/3.3/com.vmware.vidm-dmz-deployment/GUID-28F5A610-FD08-404D-AC4B-
F2F8B0DD60E4.html -
An administrator configured Okta as an identity provider for Workspace ONE. Users complain that they still cannot authenticate via Okta.
What is most likely the issue?
Answer : C
Reference:
https://help.okta.com/en/prod/Content/Topics/device-trust/SAML/Mobile/configure-okta-idp-vidm.htm
What are two prerequisites to integrate Ping into VMware Workspace ONE? (Choose two.)
Answer : AE
Have any questions or issues ? Please dont hesitate to contact us