SAP Certified Technology Professional - System Security Architect P_SECAUTH_21 Exam Questions

Page: 1 / 14
Total 80 questions
Question 1

When re-configuring the user management engine (UME) of an AS Java system, what do you need to consider to change the data source from system database to an ABAP system successfully?



Answer : B

This is one of the tasks that you need to consider to change the data source from system database to an ABAP system successfully when re-configuring the user management engine (UME) of an AS Java system. The UME is a component that handles user administration and authentication for AS Java systems. The UME can use different data sources for storing user and group data, such as system database, ABAP system, or LDAP directory. When changing the data source from system database to an ABAP system, you need to ensure that all users and groups in the system database have different IDs than existing users and groups in the ABAP system, otherwise there will be conflicts and errors during the migration process. Reference: https://help.sap.com/doc/saphelp_nw73ehp1/7.31.19/en-US/48/9e2e3f6f8e41e8a283aaf2ad2c64c4/content.htm?no_cache=true


Question 2

An end user has indicated that they are getting an authorization error when attempting to call a Transaction Code (TCD). However, the TCD exists in their User Menu. What could be

the issue and where would you check?



Answer : A

This could be the issue that causes the end user to get an authorization error when attempting to call a Transaction Code (TCD) that exists in their User Menu. SE93 is a transaction that allows you to create and maintain transaction codes and their properties. One of the properties is the authorization check, which determines whether additional authorization objects are checked when a transaction code is executed. If the authorization check for a transaction code is set to Yes, the user needs to have the corresponding authorization objects in their role or profile, otherwise they will get an error message. Reference: https://help.sap.com/doc/saphelp_nw73ehp1/7.31.19/en-US/48/9e2e3f6f8e41e8a283aaf2ad2c64c4/content.htm?no_cache=true


Question 3

Which SAP product supports General Data Privacy Regulation (GDPR) compliance through mitigating control testing and validation?



Answer : D

SAP Process Control is a SAP product that supports General Data Privacy Regulation (GDPR) compliance through mitigating control testing and validation. SAP Process Control enables you to define and monitor controls for various business processes and regulations, such as GDPR, SOX, or ISO standards. It also allows you to perform control testing and validation activities, such as self-assessments, surveys, issue management, or remediation plans. Reference: https://help.sap.com/viewer/product/SAP_PROCESS_CONTROL/en-US


Question 4

What is the SAP Best Practice to delete a security SAP role from the landscape running SAP systems?



Answer : D

The SAP Best Practice to delete a security SAP role from the landscape running SAP systems is to delete the SAP role using Profile Generator (transaction PFCG), and then put it in a transport request that can be moved across systems using Change and Transport System (CTS). This way, you can ensure that the role is deleted consistently and completely from all systems. Reference: https://help.sap.com/doc/saphelp_nw70ehp3/7.03/en-US/c8/e8d53d35fb11d182b90000e829fbfe/content.htm?no_cache=true https://help.sap.com/doc/saphelp_nw70ehp3/7.03/en-US


Question 5

Which users should exist in client 000? Note: There are 2 correct answers to this question.



Answer : C, D

These are some of the users that should exist in client 000 of an SAP system. Client 000 is a special client that contains configuration data and tools for system administration and maintenance. TMSADM is a user that is used for Transport Management System (TMS) communication and administration. SAP* is a user that can be used to log on to any client with a predefined password if no other users exist or if all users are locked. Reference: https://help.sap.com/doc/saphelp_nw73ehp1/7.31.19/en-US/c8/e8d53d35fb11d182b90000e829fbfe/content.htm?no_cache=true


Question 6

What are the key capabilities of Enterprise Threat Detection? Note: There are 2 correct

answers to this question.



Answer : A, C

Enterprise Threat Detection is a security solution that provides dashboard-based analysis for security risks and real time capture of abnormal user activities. It enables you to monitor and detect cyberattacks and internal fraud by analyzing log data from various sources, such as SAP systems, operating systems, databases, firewalls, and routers. Reference: https://help.sap.com/viewer/product/SAP_ENTERPRISE_THREAT_DETECTION/en-US https://help.sap.com/viewer/product/SAP_ENTERPRISE_THREAT_DETECTION/en-US


Question 7

You want to check the custom ABAP codes in your system for security vulnerabilities and you want to use the SAP Code Vulnerability Analyzer to carry out these extended security

checks. What needs to be done for this purpose? Note: There are 2 correct answers to thisquestion.



Answer : A, D

These are some of the tasks that you would perform to check the custom ABAP codes in your system for security vulnerabilities using the SAP Code Vulnerability Analyzer (CVA). CVA is a tool that enables you to perform static code analysis on ABAP programs and identify potential security issues, such as SQL injection, cross-site scripting, or buffer overflow. You can run CVA from the ABAP Test Cockpit (ATC), which is a framework for managing quality checks on ABAP programs and objects. You can also run CVA from the SLIN transaction, which performs an extended syntax check on ABAP programs and objects. Reference: https://help.sap.com/doc/saphelp_nw73ehp1/7.31.19/en-US/48/9e2e3f6f8e41e8a283aaf2ad2c64c4/content.htm?no_cache=true


Page:    1 / 14   
Total 80 questions