Which Unified Access Gateway (UAG) component can use an AirWatch generated certificate for Inbound SSL traffic?
A. VMware Tunnel
B. Content Gateway
C. AirWatch Cloud Connector
D. VMware Secure Email Gateway
Which domain attribute must be included to meet the SAML assertion requirement for Just-In-Time provisioning in Workspace ONE?
A. email
B. lastName
C. firstName
D. userName
Which are three reasons an administrator would need to create an Organizational Group instead of using a Smart Group? (Choose three.)
A. Override Directory Services settings
B. Integrate with a second LDAP forest
C. Assign compliance policies
D. Set a different set of privacy settings
E. Assign device profiles
F. Create regional administrator accounts
Which three on-premises components require a public IP address. (Choose three.)
A. Secure Email Gateway (SEG)
B. Integration Broker
C. Database Server
D. Unified Access Gateway -Content Gateway service
E. AirWatch Cloud Connector (ACC)
F. Unified Access Gateway -Vmware Tunnel service
Which two ways can managed content be assigned to users? (Choose two.)
A. Smart Group
B. Domains Group
C. Organization Group
D. User Group
E. Functional Group
What type of authentication token is used by the IDM API?
A. SAML
B. oAuth2
C. MS-CHAP
D. WS-FED
What step is required to configure the Workspace ONE Access Connector for outbound mode?
A. Deploy VMware Unified Access Gateway and configure Reverse Proxy.
B. Ensure the connector has a valid certificate signed by a public Certificate Authority.
C. Add a built-in IdP and associate it with the connector.
D. Configure firewall rule to allow inbound TCP 443 from the Identity Manager Service.
An administrator is implementing Kerberos to support integrated windows authentication and needs to ensure the solution is highly available. What are the required actions to ensure Kerberos is highly available across multiple connectors? (Choose two.)
A. Configure the connectors for outbound mode and enable Kerberos in the built-in Idp.
B. Change the IdP hostname to the Service Principle name of the KDC.
C. Enable redirect on each connector and specify the connector's host name.
D. Change the IdP hostname to the fully qualified domain name of the load balancer.
E. Enable redirect on each connector and specify the fully qualified domain name of the load balancer.
Which is required to push a Passport for Work Profile to a Windows endpoint?
A. Azure AD Domain Services
B. Passcode SDK Profile
C. Windows Auto Discovery Service
D. Workspace ONE Access Connector
When Android devices are on the Internal network, Mobile SSO is failing and users have to instead authenticate with AD credentials to Workspace ONE. Mobile SSO is successful when the device is on LTE.
What troubleshooting step should be performed to resolve this?
A. Validate if the internal network has outbound access to the Workspace ONE UEM servers.
B. Validate if the internal network has outbound access to the Certificate Proxy Adapter.
C. Validate if the internal network has outbound access to the VMware Tunnel server.
D. Validate if the internal network has outbound access to the Kerberos Adapter.