Installing, Configuring, and Setup
VCP-SEC · 150 questions
- After a perimeter firewall change, city permitting portal administrators can no longer open the Workspace ONE UEM console from the civic jump network. Which change re-enables the console without weakening the edge?
- A county library kiosk VLAN must enroll devices in Workspace ONE UEM through AirWatch Cloud Connector but must not browse the open internet. Which firewall design meets both goals?
- A transit authority places Workspace ONE Access behind the civic DMZ. How should the security administrator enable the Access connector without exposing it to untrusted networks?
- Public-health clinic Windows laptops fail Intelligent Hub install after the edge starts denying certificate-revocation lookups and CDN fetches. What should the administrator change?
- Parks and recreation staff administer Workspace ONE UEM from a VDI jump box. Which administrative-access design is appropriate?
- A water utility must enroll corporate laptops in Workspace ONE while keeping SCADA historian hosts isolated. What firewall stance should the security administrator take?
- Court records staff need Workspace ONE Tunnel so a case-management app can reach the records VLAN. Which component-firewall approach is correct?
- A school-district AirWatch Cloud Connector can no longer bind to Active Directory after a new host firewall is applied. Which rule restores directory integration securely?
- City 911 CAD workstations need Intelligent Hub, and the SOC still wants Workspace ONE traffic logged. What should the administrator do after the perimeter change?
- A housing-authority Secure Email Gateway for Workspace ONE must accept ActiveSync only from enrolled devices. How should the administrator enable that path?
- An elections office publishes a citizen-facing website on the same DMZ as Workspace ONE Access. How should the security administrator place Access and the UEM API?
- City Finance laptops need stricter Carbon Black Cloud prevention than Parks laptops. Which configuration applies the right control to each population?
- New library staff PCs check into Carbon Black Cloud but match no sensor-group criteria. What policy assignment should the administrator expect?
- A county assessor line-of-business tax application is terminated by Carbon Black Cloud. What is the correct policy change?
- Public-works rugged tablets run a GPS tool that Carbon Black Cloud still blocks after an event-reporting exclusion is added. Which change actually lets the tool run?
- A utilities SOC must block USB mass storage on plant-floor PCs and allow it on helpdesk PCs. How should that be enforced in Carbon Black Cloud?
- Courts want ransomware-like behavior set to Terminate, while clerks' machines stay at Alert for a week. What should the administrator configure?
- The city has a SHA-256 hash for a known-good permitting installer that Carbon Black Cloud currently treats as unknown. Where should the administrator record it so the installer can run?
- Transit bus-yard kiosks must not run unknown binaries. Which Carbon Black Cloud control meets that intent?
- After school-district lab PCs are added to a new Carbon Black Cloud sensor group, they keep the old policy. What should the administrator inspect first?
- Public-health non-persistent VDI desktops need Carbon Black Cloud protection and must still launch the published EHR client. What is the right setup?
- The city SOC enables the host-based firewall in Carbon Black Cloud policy for remote assessor laptops. How should that control be understood?
- Parks seasonal hires should receive a looser Carbon Black Cloud policy, and full-time staff should stay on a strict one, including when a seasonal account later becomes full-time. Which grouping method scales?
- Library tablets must be encrypted and on a supported OS or they must lose Hub applications. What Workspace ONE UEM object implements that outcome?
- County building inspectors' phones need the field SSID and must not allow USB file transfer. How should those settings be delivered?
- A school district issues supervised iPads to minors and must disable the App Store and the camera. Which control places those device restrictions?
- City attorneys must receive a VPN profile only while their phones remain compliant, and jailbroken devices must lose that tunnel. What should the administrator configure?
- Public-works rugged Android devices must keep a required safety application installed. How should the administrator enforce that requirement?
- Health-clinic Windows laptops must run BitLocker, and any laptop with encryption off must fail compliance. Which configuration meets that requirement?
- Elections poll tablets must authenticate to the civic WLAN with 802.1X certificates. Where should the administrator deploy that device identity?
- Transit dispatch phones that fail passcode complexity should receive an email and then an enterprise wipe after a grace period. Which compliance design matches that response?
- Parks BYOD phones and city-owned phones must receive different restriction profiles. How should the administrator target those payloads?
- Court-owned iPhones must not back case photos up to iCloud. Which control enforces that restriction?
- A city UEM compliance policy tests compromised status for jailbreak or root. What should the administrator do with devices that fail that test?
- County ERP in Workspace ONE Access must require both a compliant device and membership in the ERP Active Directory group. Which configuration meets that requirement?
- Library patrons must never single sign-on to the staff-only ILS administration app, even when the kiosk is enrolled in UEM. What should the administrator configure?
- City finance SaaS from home must step up authentication, while the on-campus corporate VLAN may use a lighter method. Which Access feature implements that split?
- 911 supervisors open the CAD web application from unmanaged home PCs. What should the Workspace ONE Access policy require?
- Public-health nurses on mobile use Intelligent Hub as the client. How should the administrator order Access policy rules so Hub still evaluates device posture?
- Parks seasonal kiosks should launch only a timekeeping application and must not inherit payroll and HR. Which Access design meets that requirement?
- City attorneys must use certificate or Mobile SSO for the matter-management application, and password fallback must be disabled. What should the administrator change?
- The school-district student application catalog must fail closed when UEM compliance cannot be read. How should the Access policy treat unknown device posture?
- Water-utility contractors may reach a vendor portal only during business hours. Which control sets that window for the SaaS identity flow?
- Elections staff who launch an application from a risky network should see a deny with a custom message. Which control provides that user-facing response?
- City employees see applications in Intelligent Hub that they cannot open. What should the administrator treat as two separate controls?
- The county issues rugged Android devices to animal-control officers. What is the first Workspace ONE endpoint-management step?
- City helpdesk must remotely lock a lost building-inspector tablet. Which action should they use?
- Library Windows PCs should auto-enroll through well-known MDM or drop-ship provisioning. What should the administrator enable?
- Transit wants one targeting object for Android, city-owned, Transportation organization group devices. What should the administrator create?
- Public-health wants Intelligent Hub as the only self-service catalog on clinic devices. Which configuration achieves that?
- Parks seasonal iPhones issued to summer rangers must leave Workspace ONE automatically when the season ends. Which control should the security administrator configure?
- Court-owned MacBooks must escrow FileVault recovery material and remain under supervised management. Which approach meets that requirement?
- The city SOC needs a dashboard of managed endpoints that failed Workspace ONE compliance. Which view should the administrator use?
- Water-utility contractors bring personal Android phones that need city email without IT owning the personal OS. Which enrollment path should the administrator enable?
- A school district wants classroom iPads that many students share during the day. How should the administrator enroll them in Workspace ONE UEM?
- 911 CAD laptops must remain in a locked organization group that help-desk child administrators cannot move. Which control enforces that?
- The city must put Carbon Black Cloud prevention on Windows staff laptops already managed by Workspace ONE UEM. What is the correct sensor path?
- County librarian Macs on macOS 12 and later install the Carbon Black Cloud sensor, but the sensor stays degraded until a system extension is approved. What should the administrator push with the sensor?
- Transit fare-box management VMs run Linux and need Carbon Black Cloud. Which package should the administrator deploy?
- Public-works kiosks never have an interactive user at install time. How should the administrator deploy the CB Defense sensor?
- School-lab non-persistent VDI desktops refresh from a golden image each night. How should the CB Defense sensor be deployed so it survives that cycle?
- City inspectors' Windows laptops should land in the Carbon Black Inspectors sensor group on first check-in, based on Active Directory OU. What must be in place before mass deployment?
- Courts firewalls deny all outbound traffic except an allowlist of SaaS destinations. Sensors will appear offline after install unless which step happens first?
- Water-utility guest VMs on ESXi already have VMware Tools with Guest Introspection. The security team still needs Carbon Black prevention on those workloads. What should the administrator deploy?
- Parks issues seasonal Chromebooks that must be managed, but Carbon Black Cloud does not provide a Defense sensor for Chrome OS. What should the administrator do?
- City staff have been uninstalling the CB Defense sensor from their laptops. Which control should the administrator enable?
- 911 CAD servers need a Carbon Black Cloud workload sensor. The cluster cannot take a simultaneous reboot at shift change. How should the administrator proceed?
- County staff must sign in to Workspace ONE Access with existing Active Directory credentials. What should the administrator configure first?
- The city must federate Workspace ONE Access to a statewide Microsoft Entra ID tenant using SAML. Which configuration is correct?
- Library staff authenticate with Active Directory while volunteers use a separate local or social identity provider. How should Access be set up?
- Schools want the first successful login from the statewide identity provider to create the Workspace ONE Access user automatically. Which feature should the administrator enable?
- Water-utility Workspace ONE Access must bind to on-premises Active Directory. How should the directory connection be built?
- Courts want Workspace ONE Access to use OpenID Connect against a statewide identity platform. Which settings belong on the Access identity-provider object?
- City staff suddenly fail Workspace ONE Access login after the statewide identity provider rotated certificates. What should the administrator update?
- Parks contractors must sign in through a separate identity provider and must not be able to reset city Active Directory passwords. How should the administrator design that identity provider?
- An elections office needs a handful of local break-glass accounts in Workspace ONE Access while regular staff already authenticate through the county enterprise identity provider. How should the security administrator configure identity providers?
- Public-health wants Workspace ONE UEM and Workspace ONE Access to target the same Active Directory groups for enrollment and Hub access. What should the administrator do so Access policies do not drift from UEM?
- City staff iPhones should open Hub apps with Mobile SSO and no extra password prompt. Which Workspace ONE Access configuration is required for that path?
- County field inspectors on Android must sign in to Hub with Mobile SSO using a device certificate. What should the administrator configure?
- Library Windows PCs receive client certificates from Workspace ONE UEM and must use those certificates to reach Hub. How should certificate-based authentication be set up in Access?
- A 911 CAD web app still requires RSA SecurID for a small vendor group. Where should the security administrator add that token path?
- School staff must use password plus a built-in one-time passcode when they open Hub apps from home. What should the administrator configure?
- Water-utility domain-joined PCs on campus should reach Hub with Windows SSO and no extra prompt. Which Access method belongs on that path?
- The city must stop password authentication on the finance Hub app but still allow password on the cafeteria menu app. What is the correct Access change?
- Parks visitor kiosks have no keyboard, so staff cannot enter OTP codes. How should the kiosk Access policy be built?
- Courts want Hub access only when the device is UEM-compliant, not after an Active Directory password alone. What should be added to the Access authentication chain?
- Transit helpdesk can reset AD passwords, so password alone is too weak for a VPN-like SaaS app in Hub. What should the administrator require?
- Elections break-glass accounts authenticate with password on the built-in Access identity provider and must work only from the jump network. How should that password path be scoped?
- The city is standing up NSX-T for civic datacenter security. How should NSX-T Manager be deployed for production?
- County compute clusters must enforce NSX distributed firewall. What prepares the ESXi hosts for that?
- Transit needs north-south gateway firewall at the civic perimeter, not only east-west host filtering. What must be deployed?
- A library workload VLAN must become an NSX object so security groups and tags can consume it. What should the administrator create?
- Water-utility compute hosts need overlay for distributed firewall and Guest Introspection, while Edge uplinks need VLAN connectivity to the civic core. How should transport zones be assigned?
- City DFW rules stay unrealized after objects are created. The inventory shows no security license applied. What should the administrator do first?
- Courts security groups must use vSphere VM names, tags, and clusters. NSX inventory is empty of those objects. What is missing?
- The school district wants distributed firewall only on the prepared student-info clusters, not citywide on day one. How should DFW be enabled?
- Public-health north-south firewall tests fail because the Edge uplink still has IPv6 enabled and the civic ISP is IPv4-only. What should be configured?
- Parks is adding a DR site that needs its own NSX-T security fabric. The requirement is local distributed firewall, not a multi-site routing design. How should NSX-T be deployed there?
- The 911 compute cluster will carry Geneve overlay, but the N-VDS still uses a 1500-byte MTU. What should be configured before relying on later DFW or Traceflow results?
- The city wants NSX-T distributed firewall in production. A contractor proposes writing DFW rules before Managers, licensing, or transport nodes exist. What install order should the administrator follow?
- A county deploys NSX-T Managers for the civic datacenter but skips DNS and NTP. Cluster formation later fails with name-resolution and time-skew errors. What missing preparation step should the security administrator complete?
- Transit applies a transport-node profile to the ESXi clusters that will host fare-system VMs, but no IP pools exist for tunnel endpoints. Overlay transport nodes fail to come up. What should the administrator add in the NSX-T preparation workflow?
- A library vCenter certificate is untrusted when NSX Manager tries to add it as a compute manager, so clusters and VMs never appear for security grouping. What should the administrator fix in the install workflow?
- Water-utility ESXi hosts are below the NSX-T 3.0 support matrix, and transport-node installation is about to start on the SCADA compute cluster. What should the administrator do first?
- After the courts NSX Manager cluster forms, the install checklist still has no NSX backup configured. What should the security administrator include as part of standing up NSX-T?
- A school district deploys NSX Edge nodes for gateway firewall before uplink pNICs and VLAN trunks exist on the top-of-rack switches. North-south traffic never leaves the Edges. What should have been sequenced first in the preparation workflow?
- A city wants Distributed Firewall in default-deny, but some transport nodes are not yet Up and inventory groups are not built. What should the administrator do during the install workflow?
- Parks cloned nested-lab tiny NSX Managers into production for a civic cluster count far larger than the lab. What should the administrator have done during the deploy workflow?
- After first boot of the 911 NSX Managers, the install checklist requires SSH and API access only from jump hosts. How should the administrator treat that requirement?
- A city needs east-west isolation between permitting web VMs and tax database VMs that share the same NSX segment. Which firewall should the administrator configure?
- County guest Wi-Fi VMs must not talk to court case-management VMs, and both can land on the same overlay transport. What control should the administrator use?
- Transit publishes a citizen trip-planner app north-south to the Internet. Where should the administrator place the primary Internet-facing firewall rules?
- A library after-hours batch job should be allowed only during a nightly window. What is the correct NSX-T firewall approach?
- A water-utility operator finds HTTP and SSH mixed on unexpected ports between historian VMs, so TCP/80 alone is not a reliable allow. What should the administrator use in Distributed Firewall?
- Courts require emergency deny rules that always evaluate first during an incident. Where should the administrator put those rules?
- School student VDI desktops may browse only allowlisted FQDNs. Which NSX-T firewall control matches that requirement?
- A city administrator creates a Distributed Firewall rule, but it never enforces on hosts. What should be checked first?
- Parks wants ICMP allowed for monitoring between environments but must not allow RDP. What should the administrator write?
- Public-health EHR VMs need logging whenever Distributed Firewall denies traffic. What should the administrator enable?
- On elections night a Distributed Firewall rule has inverted source and destination members, so poll-book VMs are blocked incorrectly. What is the correct administrative fix?
- 911 voice VMs were added to the Distributed Firewall exclusion list by mistake, so micro-segmentation never applies. Adding more gateway firewall rules does not fix east-west on the same segment. What should the administrator do?
- A city wants Active Directory group-based firewall for finance users on VDI. What must the administrator configure first for Identity Firewall?
- County Identity Firewall events never update for VDI logons. NSX Manager already has an LDAP connection, but Guest Introspection is missing on the VDI cluster. What should the administrator enable?
- A library will use LDAPS to the civic domain controller for NSX Identity Firewall. What should the administrator import into NSX Manager?
- Transit wants nested Active Directory groups as Identity Firewall sources for fare-system VDI. A technician suggests flattening the same groups in Carbon Black Cloud instead. What should the administrator verify?
- A water utility wants Identity Firewall user-based rules on Windows VDI but must not enable them on Linux historian hosts. How should IDFW be turned on?
- Court clerks who join Active Directory in the morning still cannot reach the case-management segment until the next day because NSX-T user mappings stay stale. What should the administrator do?
- A school district connects NSX-T Manager to Workspace ONE Access so civic admins can sign in. Teachers still need Active Directory group-based distributed firewall rules on student VDI. What should the administrator configure next?
- Parks seasonal contractors live in a separate Active Directory forest, and Identity Firewall rules must use those contractor groups. What should the administrator configure?
- Public health must immediately stop a terminated analyst’s Active Directory group from reaching the EHR segment between virtual machines. What should the administrator configure?
- City NSX Manager is bound to Active Directory, but Identity Firewall cannot enumerate finance users because the LDAP service account has no read permission on the user OU. What should the administrator fix first?
- A county tags new tax-system VMs with app=tax and env=prod and wants those VMs to inherit distributed firewall policy when they are cloned. What should the administrator build?
- Transit placed fare-collection on a known set of NSX-T segments and wants DFW policy to follow those segments as VMs are added. What should the administrator use?
- A library needs one NSX group of Active Directory patrons for Identity Firewall and a separate group of catalog VMs for ordinary distributed firewall rules. How should the groups be defined?
- A water utility wants a default-deny stance inside the historian application rather than one data-center-wide rule. What should the administrator configure?
- Courts must keep production case-management VMs from talking to the test cluster even if an Application-category rule later allows the same ports. Where should the prod-versus-test separation be placed?
- A school VDI security group unexpectedly includes the golden-image VM because that template shares the same NSX tag as the floating desktops. What should the administrator do first?
- A city badge printer sits on a physical VLAN and cannot receive an NSX VM tag, but firewall policy must still include it. How should the administrator add the printer?
- Parks clones a production DFW policy onto the disaster-recovery cluster but keeps the same production group names, and the cloned rules still match production members. What should the administrator change?
- Public health wants every VM whose name starts with ehr- in one NSX security group, but also wants membership that survives a later rename. What should the administrator recommend?
- An elections office wants one NSX group for the tabulation application and another for the election-night zone, then DFW rules that mean tabulation-app inside that zone. What construct should the administrator use?
- A 911 computer-aided dispatch policy is applied to a cluster-based security group that accidentally includes the NSX Edge VMs. What should the administrator do?
- A city needs Guest Introspection on VDI guests so Identity Firewall and file introspection can see in-guest events. Staff are about to push only a Carbon Black MSI. What should be installed for Guest Introspection?
- A county partner endpoint-protection service deployment shows Down even though the service VMs exist. The protected workloads are powered off and have no Guest Introspection policy. What does healthy GI require?
- Transit has NSX-T on the cluster, but fare-system guests still run an old VMware Tools build that never installed Guest Introspection drivers. What should the administrator do?
- A library wants antivirus scanning offloaded from catalog VMs to an NSX Guest Introspection partner service VM. What should the administrator deploy?
- A water utility wants Identity Firewall user mapping on Linux historian VMs as well as Windows engineering desktops. Some Linux builds are not on the NSX-T support matrix. What should the administrator do?
- Courts vMotion a protected VM to a cluster that has NSX-T but no Guest Introspection partner service VMs, and GI health goes down. What should the administrator do before expecting health Up?
- A school wants newly cloned student desktops to be Guest Introspection-ready at first boot instead of waiting for a post-clone Tools install. What should be baked into the golden image?
- Public health needs both partner antivirus offload through NSX Guest Introspection and Carbon Black Cloud prevention on the same EHR VMs. Staff believe the Thin Agent replaces the CB Defense sensor. What should be installed?