nerdexam
Broadcom-VMware

2V0-62.23 · Question #91

Drag and Drop Question In Workspace ONE Access, some authentication methods can best be used as Primary Authentication, while others can only be used as Secondary Authentication. Drag and drop the…

The correct answer is Password (Cloud Deployment); Mobile SSO (for Android / iOS); Authenticator App; Verify (Intelligent Hub); Device Compliance; Certificate (Cloud Deployment). Workspace ONE Access: Primary vs. Secondary Authentication The six methods split into two categories. Based on Workspace ONE Access architecture: --- Primary Authentication (standalone first factor) 1. Password (Cloud Deployment) The foundational authentication method. Users…

Section 4 – Workspace ONE Features and Functionality

Question

Drag and Drop Question In Workspace ONE Access, some authentication methods can best be used as Primary Authentication, while others can only be used as Secondary Authentication. Drag and drop the authentication methods on the left into the correct classification on the right. Answer:

Exhibit

2V0-62.23 question #91 exhibit

Answer Area

Drag items

Password (Cloud Deployment)Authenticator AppVerify (Intelligent Hub)Mobile SSO (for Android / iOS)Device ComplianceCertificate (Cloud Deployment)

Correct arrangement

  • Password (Cloud Deployment)
  • Mobile SSO (for Android / iOS)
  • Authenticator App
  • Verify (Intelligent Hub)
  • Device Compliance
  • Certificate (Cloud Deployment)

Explanation

Workspace ONE Access: Primary vs. Secondary Authentication

The six methods split into two categories. Based on Workspace ONE Access architecture:


Primary Authentication (standalone first factor)

1. Password (Cloud Deployment) The foundational authentication method. Users prove identity with a credential they know. Can initiate an authentication chain on its own - no prior factor required.

2. Mobile SSO (for Android / iOS) Uses device-level certificates provisioned via MDM enrollment. The device itself acts as the credential, making it self-sufficient as a first factor. No secondary prerequisite needed.

6. Certificate (Cloud Deployment) Certificate-based authentication (CBA) is cryptographically strong and fully capable of standing alone as the first factor. The client presents a certificate; the identity provider validates it without any prior step.


Secondary Authentication (additional factor only - cannot initiate auth alone)

3. Authenticator App A TOTP (time-based one-time password) generator. By design, TOTP codes are a something you have factor that supplements a first factor - they don't establish initial identity on their own in Workspace ONE Access policy chains.

4. Verify (Intelligent Hub) A push-notification approval method delivered through VMware's Intelligent Hub app. Requires that a user identity already be established (via a primary factor) before the push can be sent to the correct device.

5. Device Compliance Not truly an authentication method at all - it's a policy check. It validates that the enrolled device meets compliance requirements (patch level, encryption, etc.). It must run after identity is confirmed, so it's always secondary (or a conditional gate within a policy).


Common Mistakes / Misconceptions

MisconceptionReality
"Authenticator App is primary because it's strong security"Strength ≠ primary eligibility. It's a second-factor by design in WS1 Access.
"Device Compliance is a primary factor"It's a compliance gate, not an identity proof. Always secondary.
"Verify (Intelligent Hub) can start an auth flow"No - WS1 must know who to push the notification to first, requiring a prior primary factor.
"Certificate is only for enterprise/RADIUS setups"Certificate (Cloud Deployment) is explicitly designed for cloud-based primary auth in WS1 Access.
"Mobile SSO is secondary because it uses certificates"The device certificate is machine-bound and MDM-provisioned, making it a strong, self-sufficient primary factor.

Topics

#authentication methods#primary authentication#secondary authentication#Workspace ONE Access

Community Discussion

No community discussion yet for this question.

Full 2V0-62.23 Practice