Which VMware Tunnel utility can help troubleshooting by gathering all the necessary component log files that may be required during the process?
- A . tunnel_snap
- B . tunnel_vi
- C . tunnela_udrt
- D . tunnel_nano
A
Explanation:
The tunnel_snap utility can help troubleshooting by gathering all the necessary component log files that may be required during the process. This utility is available on both Linux and Windows versions of VMware Tunnel1.
The tunnel_snap utility collects logs from the following components:
VMware Tunnel service
Per-App Tunnel service
Proxy service
Content Gateway service
VMware Tunnel configuration files
System information
Network information The other options are not valid utilities for VMware Tunnel.
An organization has successfully used VMware Workspace ONE UEM to deploy a managed, public application to Android, iOS, and Windows devices in the same OG for the last year.
The Windows and Android users can still install this application The iOS device users, however, report that they can see and install other applications in the VMware Workspace ONE Catalog, but suddenly they are unable to see this application in the VMware Workspace ONE Catalog.
What is the most likely cause of this issue?
- A . The application assignment via a smart group was misconfigured.
- B . The application assignment via the enrollment type was misconfigured.
- C . The organization’s Apple Push Notification certificate expired.
- D . The organization’s Apple sToken expired.
An administrator has started to integrate Workspace ONE UEM with test connection and is unable to move forward.
Which situation could cause this test connection failure?
- A . The provided Workspace ONE Access Username is incorrect
- B . The provided Workspace ONE UEM API key is incorrect
- C . The provided Workspace ONE UEM Username is incorrect.
- D . The provided Workspace ONE Access API key is incorrect.
B
Explanation:
When integrating Workspace ONE UEM, it’s crucial that the correct API keys and credentials are used. A test connection failure could stem from a number of issues, but looking at the options provided:
The following error is seen on the AirWatch Cloud Connector (ACC) logging:
Which connectivity should be investigated to restore ACC functionality?
- A . From ACC to AWCM
- B . From the Active Directory Server to the ACC
- C . From AWCM to the Active Directory Server
- D . From the ACC to the Active Directory server
D
Explanation:
The connectivity that should be investigated to restore ACC functionality is from the ACC to the Active Directory server. The error message in the ACC logging indicates that the ACC cannot connect to the Active Directory server due to a network error. This could be caused by firewall settings, proxy settings, network configuration, or other factors that prevent the ACC from communicating with the Active Directory server. The administrator should check and resolve these issues to restore the ACC functionality2.
An administrator is unable to enroll Android devices with directory accounts but successfully enrolled the device with a basic working previously.
Which logs should the administrator review to begin troubleshooting the Android directory account enrollment issue?
- A . VMware Tunnel
- B . VMware Workspace ONE Intelligent Android Hub
- C . AirWatch Cloud Connector
- D . Unified Access Gateway
C
Explanation:
According to the Device enrollment issues with Workspace ONE article3, one of the possible causes of enrollment failure is that the ACC service is not working properly or cannot communicate with the directory service. The administrator can review the ACC logs and test the connection to verify if there are any errors or issues with the ACC service or configuration.
The logs that the administrator should review to begin troubleshooting the Android directory account enrollment issue are AirWatch Cloud Connector (ACC) logs. The ACC is responsible for integrating Workspace ONE UEM with directory services such as Active Directory or LDAP. If the administrator is unable to enroll Android devices with directory accounts, it could indicate that there is a problem with the ACC configuration, connectivity, or synchronization. The administrator should review the ACC logs to identify and troubleshoot the root cause of the issue3.
A company uses Secure Email Gateway to provide email access to its mobile devices and uses Exchange 20VT6 as its email infrastructure.
Today the VMware Workspace ONE UEM administrator received a report that all newly enrolled devices (iOS and Android) were unable to receive email After speaking with some end users, the administrator found previously enrolled devices were still able to receive email on their mobile devices. The users who reported this issue are able to access their email through Outlook Web Access (OWA) on their computers.
Which statement describes the possible root cause of this issue?
- A . The Secure Email Gateway server is unable to connect to the Exchange server.
- B . The Exchange 2016 client access server cluster sporadically refuses to connect (HTTP 500)
- C . There is an email compliance policy restricting email access to only Android devices.
- D . The Secure Email Gateway is unable to update policy with VMware Workspace ONE UEM API
D
Explanation:
The key details provided are:
Only newly enrolled devices are unable to receive email.
Previously enrolled devices still receive emails without issues.
Affected users can access their emails via Outlook Web Access (OWA) on their computers.
Let’s analyze each option:
An organization has introduced a complex password requirement on enrolled mobile devices. This has also caused a significant increase in the help desk’s ticket load around password resets for mobile devices. The organization needs to curb these requests and allow users, once authenticated, to resolve their own device passcode issues
Which service can help meet this goal?
- A . Device Management Console
- B . Self-Service Portal
- C . SQLCMD
- D . AWCM
B
Explanation:
The service that can help meet this goal is the Self-Service Portal. The Self-Service Portal is a web-based application that allows users to perform various actions on their enrolled devices, such as lock, unlock, wipe, or unenroll1. Users can also reset their device passcode through the Self-Service Portal, which can reduce the number of help desk tickets and improve user satisfaction2.
A VMware Workspace ONE administrator is managing a fleet of console.
Which step would assist in troubleshooting this problem?
- A . Network traffic tools to capture Android traffic
- B . xCode to extract the device debug log
- C . Android SDK and do a tcpdump
- D . Workspace ONE UEM Console Request Debug Log
D
Explanation:
When troubleshooting issues in a fleet of devices managed by VMware Workspace ONE UEM, having the right tools and logs is crucial to identify and resolve the problem. Let’s evaluate each option:
Which option is available for Unified Access Gateway to export a collection of all logs?
- A . Use the UAG-log-archive.zip download button within the VMware Workspace ONE Access Admin Ul.
- B . Export the UAG-log-archive.zip from the VMware Workspace ONE UEM console troubleshooting page.
- C . Use the UAG-log-archive zip download button from the Support Settings section in the UAG Admin Ul.
- D . Export the UAG-log-archive.zip from the logging option in the OVF template
C
Explanation:
The option that is available for Unified Access Gateway to export a collection of all logs is using the UAG-log-archive.zip download button from the Support Settings section in the UAG Admin UI. This ZIP file contains all logs from the Unified Access Gateway appliance, such as system information, network configuration, edge service logs, and so on4. This option can help troubleshoot any issues or errors related to Unified Access Gateway deployment and operation.
Which VMware Workspace ONE UEM console configuration page would be
- A . Groups & Settings > All Settings > Admin > Diagnostics > Logging
- B . Groups & Settings > All Settings > Storage > Logging
- C . Groups & Settings > All Settings > Troubleshooting > Logging
- D . Groups & Settings > All Settings > System > Logging
A
Explanation:
The VMware Workspace ONE UEM console configuration page that would be used to enable debug logging for a specific device is Groups & Settings > All Settings > Admin > Diagnostics > Logging5. This page allows administrators to enable debug logging for a specific device or a group of devices based on various criteria, such as platform, model, ownership, and so on5. Debug logging can help collect more detailed information about device events, actions, and errors for troubleshooting purposes.
Which feature is included in VMware Workspace ONE Assist in Attended Mode?
- A . View and export detailed device information, access activity logs, run commands, and manage files
- B . Restrict employees’ ability to pause or end a remote session for enhanced privacy.
- C . Remotely connect to any unenrolled or enrolled device in seconds, directly from the VMware Workspace ONE console
- D . Restrict additional users to a remote session to assist with issues.
A
Explanation:
The feature that is included in VMware Workspace ONE Assist in Attended Mode is view and export detailed device information, access activity logs, run commands, and manage files. This feature allows the administrator to remotely access the device screen and perform various actions to troubleshoot issues or assist the user. The administrator can also view the device details, such as battery level, network status, memory usage, and so on. The administrator can also access the device logs, run commands such as ping or traceroute, and manage the device files1.
The SSL certificates for on-premises VMware Workspace ONE UEM recently expired and were rotated Soon after. Android devices entirely stopped receiving push notifications and many reported AWCM as being disconnected. It was confirmed that the SSL certificates held been rotated on IIS as well as the load balancer.
Which strategy accurately describes the solution for this problem?
- A . The SSL certificates were not updated on all device services servers, so updating the remaining servers would resolve the issue.
- B . The Device Services service was not restarted after the SSL certificate rotation on IIS. so restarting the service would resolve the issue.
- C . The Device Management binding was not updated for SSL handshake compatibility, so selecting the correct binding would resolve the issue.
- D . The AWCM keystore was missed for rotation of SSL certificates, so running the keytool import targeting the new certificate would resolve the issue
D
Explanation:
The strategy that accurately describes the solution for this problem is running the keytool import targeting the new certificate. The AWCM keystore is a Java keystore file that contains the SSL certificates used by AWCM to establish secure connections with devices and other components. If the SSL certificates are rotated on IIS and the load balancer, but not on the AWCM keystore, then AWCM will not be able to communicate with devices using push notifications. To resolve this issue, the administrator must import the new SSL certificates into the AWCM keystore using the keytool command2.
A number of enrolled devices have not checked in with VMware Workspace ONE UEM for several days. When the administrator attempted to push a profile to the devices the devices did not check in to receive the profile.
Which component should be focused on when troubleshooting this device connectivity issue to VMware Workspace ONE UEM?
- A . UEM Console
- B . UAG
- C . API
- D . Device Services
D
Explanation:
The component that should be focused on when troubleshooting this device connectivity issue to VMware Workspace ONE UEM is Device Services. Device Services is a component of Workspace ONE UEM that handles device enrollment, management, and communication. Device Services also hosts the AWCM service, which is responsible for delivering push notifications to devices. If Device Services is not working properly, devices may not be able to check in with Workspace ONE UEM or receive profiles, commands, or policies3.
When an organization administrator attempts to configure a shared SaaS Workspace ONE UEM environment to use their internal Active Directory Certificate Authority, "Test Connection" fails.
For which service should the organization administrator enable verbose logging to resolve this issued?
- A . ACC (AirWatch Cloud Connector) service
- B . AWCM (AirWatch Cloud Messaging) service
- C . UAG (Unified Access Gateway) Tunnel service
- D . Console service
A
Explanation:
The service that the organization administrator should enable verbose logging to resolve this issue is ACC (AirWatch Cloud Connector) service. ACC is a service that integrates Workspace ONE UEM with internal enterprise systems, such as Active Directory or Certificate Authority. ACC enables Workspace ONE UEM to use internal resources without exposing them to the Internet. If “Test Connection” fails when configuring a shared SaaS Workspace ONE UEM environment to use an internal Active Directory Certificate Authority, it could indicate that there is a problem with ACC configuration, connectivity, or synchronization. Enabling verbose logging for ACC can help identify and troubleshoot the root cause of the issue4.
A dozen users just reported various issues with VMware Workspace ONE UFM managed applications on their Android and iOS devices The administrator would like to use VMware Workspace ONE to simultaneously gather detailed troubleshooting information about all these devices with one action
Which form of logging should be used to accomplish this goal?
- A . Settings-based targeted logging
- B . ACC (AirWatch Cloud Connector) verbose logging
- C . Device-based targeted logging
- D . AWCM (AirWatch Cloud Messaging) verbose logging
C
Explanation:
The form of logging that should be used to accomplish this goal is device-based targeted logging. Device-based targeted logging allows the administrator to enable debug logging for multiple devices at once, based on various criteria, such as platform, model, ownership, and so on1. Device-based targeted logging can help collect more detailed information about device events, actions, and errors for troubleshooting purposes.
A VMware Workspace ONE 3dministrator is troubleshooting an information in the CloudConnector.log.
Which logging level should the administrator use?
- A . Verbose
- B . Debug
- C . Error
- D . Information
A
Explanation:
The logging level that the administrator should use is verbose. Verbose logging provides the most detailed information about the ACC (AirWatch Cloud Connector) service, such as configuration, connectivity, synchronization, and errors2. Verbose logging can help identify and troubleshoot the root cause of the issue with the CloudConnector.log.
Refer to the exhibit.
An IT administrator tried to start a remote session using Workspace ONE Assist but received this request timeout error:
What might be the root cause of this issue"?
- A . Workspace ONE Assist agent failed to connect to the Workspace ONE Assist server
- B . Workspace ONE Intelligent Hub failed to connect to the Workspace ONE Assist server
- C . The devices were connected remotely using the unattended mode in Workspace ONE Assist agent.
- D . The Administrator didn’t have proper level of access to Workspace ONE Assist’s features.
A
Explanation:
The root cause of this issue is that Workspace ONE Assist agent failed to connect to the Workspace ONE Assist server. The request timeout error indicates that the Workspace ONE Assist agent did not receive a response from the Workspace ONE Assist server within the specified time limit3. This could be due to network issues, firewall settings, or authentication problems. The administrator should check and resolve these issues to enable remote sessions using Workspace ONE Assist.
An organization wants to use VMware Workspace ONE UEM to deploy a new internal application to Android devices. An organization administrator uploads the application installation file into UEM and assigns the application via a smart group Users report the application installation begins on their devices but fails after about ten minutes
What is the most likely cause of this issue?
- A . The application installation file is corrupted.
- B . The application installation file extension is not supported.
- C . The organization’s Google integration is misconfigured.
- D . The application assignment is misconfigured.
A
Explanation:
The most likely cause of this issue is that the application installation file is corrupted. A corrupted file may cause the application installation to fail or abort on the devices4. The administrator should verify the integrity of the application installation file and upload a new file if needed.
Upon deploying a fresh Unified Access Gateway via the OVF template, the administrator sees the following:
Refer to the exhibit.
The administrator would like to avoid running the VAMI command and reconfiguring the network
Which other option to remediate this error message is possible?
- A . Reboot the UAG, press F10, and in the setparams, enter rw init=/bin/bash.
- B . Login to the UAG with the root account, and manually modify the Ifconfig.
- C . Redeploy the UAG to ensure that all of the guest property configurations have been configured correctly
- D . Power off the UAG, and reconfigure the quest properties to ensure that the information is correct.
C
Explanation:
The other option to remediate this error message is to redeploy the UAG to ensure that all of the guest property configurations have been configured correctly. The error message indicates that there is a problem with the guest property settings of the UAG appliance, such as network configuration, edge service settings, or certificate settings5. Redeploying the UAG can help fix any errors or inconsistencies in the guest property settings.
Refer to the exhibit.
The VMBeans company has created the following organization group (OG) structure:
The administrator at the Logistics OG has the Console Administrator role.
Which two smart groups could this administrator manage? (Choose two.)
- A . VMBeans (VMBeans)
- B . Logistics Team Central Office
- C . Midwest Rugged
- D . Sales Android Device
- E . Sales Laptop
B, C
Explanation:
The administrator at the Logistics OG has the Console Administrator role, which means they can manage all the smart groups that are created in their own OG or below1. Therefore, they can manage the Logistics Team Central Office and Midwest Rugged smart groups, which are both created in the Logistics OG. They cannot manage the VMBeans (VMBeans), Sales Android Device, and Sales Laptop smart groups, which are created in higher OGs.