2V0-62.23 · Question #50
A Workspace ONE UEM administrator is concerned about the security of their organization's mobile devices. The concern is with jail-broken or rooted devices accessing company resources or navigating…
The correct answer is C. Configure a compliance policy to check for Compromised Status = Compromised. Configure the. Option C is correct because it pairs a compliance policy that detects Compromised Status = Compromised with an automated enterprise wipe action, satisfying both detection and the CIO's "immediate removal" requirement - no human intervention needed once a device triggers the…
Question
A Workspace ONE UEM administrator is concerned about the security of their organization's mobile devices. The concern is with jail-broken or rooted devices accessing company resources or navigating within the company network. The company's CIO wants a no-tolerance policy for devices in this state, requesting that they be removed immediately if detected. How can the administrator enforce the policy using Workspace ONE UEM?
Options
- AConfigure a compliance policy to check for Compromised Status = Compromised. Configure the
- BConfigure an application blacklist policy for one of the apps that is used to jail-break or root
- CConfigure a compliance policy to check for Compromised Status = Compromised. Configure the
- DConfigure a daily report checking for compromised devices. Manually send enterprise wipe
How the community answered
(35 responses)- A17% (6)
- B9% (3)
- C71% (25)
- D3% (1)
Explanation
Option C is correct because it pairs a compliance policy that detects Compromised Status = Compromised with an automated enterprise wipe action, satisfying both detection and the CIO's "immediate removal" requirement - no human intervention needed once a device triggers the policy.
Why the distractors fail:
- Option A also checks for compromised status but likely configures a softer action (such as notifying the user or restricting access) rather than an enterprise wipe, which doesn't meet the zero-tolerance removal mandate.
- Option B blacklisting jailbreak-related apps is incomplete - it misses devices that were jailbroken via methods not tied to a known app and does not trigger device removal.
- Option D relies on a manual daily report and a human-initiated enterprise wipe, violating the "immediately if detected" requirement; a daily cycle means compromised devices could linger for up to 24 hours.
Memory tip: Associate the CIO's demand with "Automated Zero Tolerance" - any answer that introduces a manual step (D) or targets symptoms instead of the root compromise state (B) cannot satisfy immediate enforcement. When you see "no-tolerance + instant removal," look for a compliance policy on Compromised Status paired with an automated enterprise wipe.
Topics
Community Discussion
No community discussion yet for this question.