nerdexam
Broadcom-VMware

2V0-62.23 · Question #50

A Workspace ONE UEM administrator is concerned about the security of their organization's mobile devices. The concern is with jail-broken or rooted devices accessing company resources or navigating…

The correct answer is C. Configure a compliance policy to check for Compromised Status = Compromised. Configure the. Option C is correct because it pairs a compliance policy that detects Compromised Status = Compromised with an automated enterprise wipe action, satisfying both detection and the CIO's "immediate removal" requirement - no human intervention needed once a device triggers the…

Section 4 – Workspace ONE Features and Functionality

Question

A Workspace ONE UEM administrator is concerned about the security of their organization's mobile devices. The concern is with jail-broken or rooted devices accessing company resources or navigating within the company network. The company's CIO wants a no-tolerance policy for devices in this state, requesting that they be removed immediately if detected. How can the administrator enforce the policy using Workspace ONE UEM?

Options

  • AConfigure a compliance policy to check for Compromised Status = Compromised. Configure the
  • BConfigure an application blacklist policy for one of the apps that is used to jail-break or root
  • CConfigure a compliance policy to check for Compromised Status = Compromised. Configure the
  • DConfigure a daily report checking for compromised devices. Manually send enterprise wipe

How the community answered

(35 responses)
  • A
    17% (6)
  • B
    9% (3)
  • C
    71% (25)
  • D
    3% (1)

Explanation

Option C is correct because it pairs a compliance policy that detects Compromised Status = Compromised with an automated enterprise wipe action, satisfying both detection and the CIO's "immediate removal" requirement - no human intervention needed once a device triggers the policy.

Why the distractors fail:

  • Option A also checks for compromised status but likely configures a softer action (such as notifying the user or restricting access) rather than an enterprise wipe, which doesn't meet the zero-tolerance removal mandate.
  • Option B blacklisting jailbreak-related apps is incomplete - it misses devices that were jailbroken via methods not tied to a known app and does not trigger device removal.
  • Option D relies on a manual daily report and a human-initiated enterprise wipe, violating the "immediately if detected" requirement; a daily cycle means compromised devices could linger for up to 24 hours.

Memory tip: Associate the CIO's demand with "Automated Zero Tolerance" - any answer that introduces a manual step (D) or targets symptoms instead of the root compromise state (B) cannot satisfy immediate enforcement. When you see "no-tolerance + instant removal," look for a compliance policy on Compromised Status paired with an automated enterprise wipe.

Topics

#Compliance Policies#Device Security#Jailbreak Detection#Mobile Device Management

Community Discussion

No community discussion yet for this question.

Full 2V0-62.23 Practice