nerdexam
Broadcom-VMware

2V0-62.23 · Question #75

Which configuration should be set to limit the ability of users to perform device wipes while still maintaining SSP access and the ability to unenroll?

The correct answer is D. user-based role to disallow Device Wipe. Option D is correct because restricting the Device Wipe action at the user-based role level prevents end users from performing a full factory reset through the Self-Service Portal (SSP), while leaving their SSP access and unenrollment capability intact - unenrollment triggers…

Section 4 – Workspace ONE Features and Functionality

Question

Which configuration should be set to limit the ability of users to perform device wipes while still maintaining SSP access and the ability to unenroll?

Options

  • Aadmin-based role to disallow Device Wipe
  • Buser-based role to disallow Enterprise Wipe
  • Cadmin-based role to disallow Enterprise Wipe
  • Duser-based role to disallow Device Wipe

How the community answered

(26 responses)
  • A
    15% (4)
  • B
    8% (2)
  • C
    4% (1)
  • D
    73% (19)

Explanation

Option D is correct because restricting the Device Wipe action at the user-based role level prevents end users from performing a full factory reset through the Self-Service Portal (SSP), while leaving their SSP access and unenrollment capability intact - unenrollment triggers an Enterprise Wipe (corporate data only), which is a separate, less destructive action.

Why the distractors fail:

  • A targets the wrong audience - admin-based roles govern what administrators can do, not end users in the SSP.
  • B disallows Enterprise Wipe at the user level, which breaks unenrollment since unenrolling a device typically executes an Enterprise Wipe; this directly violates the stated requirement.
  • C doubles down on both mistakes: wrong role type (admin) and wrong wipe type (Enterprise), which would disrupt admin workflows without protecting against user-initiated full wipes.

Memory tip: Think of it as two axes - who (user vs. admin) and what (Device Wipe = nuclear option vs. Enterprise Wipe = corporate data only). The question is about protecting users from nuking their own device, so you need a user role blocking the Device (full) wipe - not the Enterprise wipe they need for unenrollment.

Topics

#Role-based access control (RBAC)#Device wipe management#User role configuration#Workspace ONE security policies

Community Discussion

No community discussion yet for this question.

Full 2V0-62.23 Practice