Weekend Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

SAP C_SEC_2405 SAP Certified Associate - Security Administrator Exam Practice Test

Demo: 24 questions
Total 80 questions

SAP Certified Associate - Security Administrator Questions and Answers

Question 1

Which of the following functions within SAP GRC Access Control support access certification and review? Note: There are 2 correct answers to this question.

Options:

A.

Role Review

B.

SOD Review

C.

Role Reaffirm

D.

User Reaffirm

Question 2

Your developer has created a new custom transaction for your SAP S/4HANA on-premise system and has provided you a list of the authorizations needed to execute the new ABAP program. What must you do to ensure that each required authorization is automatically created every time this new custom transaction is added to a PFCG role?

Options:

A.

Maintain each authorization in transaction SU22 and set the Check Indicator value to "Check".

B.

Maintain each authorization object in transaction SU22 and set the Default Status to "Yes".

C.

Maintain each authorization in transaction SU24 and set the Default Status to "Yes".

D.

Maintain each authorization object in transaction SU24 and set the Default Status to "Yes".

Question 3

In the administration console of the Cloud Identity Services, for which system type can you define both read and write transformations?

Options:

A.

Target systems

B.

Source systems

C.

Proxy systems

Question 4

In SAP HANA Cloud, what can you configure in user groups? Note: There are 2 correct answers to this question.

Options:

A.

Authorization privileges

B.

Client connect restrictions

C.

Identity providers

D.

Password policy settings

Question 5

Which of the following are Security Goals? Note: There are 2 correct answers to this question.

Options:

A.

Encryption

B.

Information Integrity

C.

Identity Authentication

D.

Repudiation

Question 6

Which tool can you use to modify the entities schema content across multiple repositories?

Options:

A.

SAP BTP Account Explorer

B.

SAP Cloud Identity Services Transformation Editor

C.

SAP Cloud Identity Services Schemas app

D.

SAP Business Application Studio

Question 7

When creating PFCG roles for SAP Fiori access, what is included automatically when adding a catalog to the menu of a back-end PFCG role? Note: There are 2 correct answers to this question.

Options:

A.

The start authorizations and the authorization default values for each IWSG TADIR service definitions in the catalog.

B.

The IWSG TADIR service definitions from the catalog.

C.

The start authorizations and the authorization default values for each IWSV TADIR service definitions in the catalog.

D.

The IWSV TADIR service definitions from the catalog.

Question 8

When segregating the duties for user and role maintenance, which of the following should be part of a decentralized treble control strategy for a production system? Note: There are 3 correct answers to this question.

Options:

A.

One user administrator per application area in the production system

B.

One user administrator per production system

C.

One authorization profile administrator

D.

One authorization data administrator

E.

One decentralized role administrator

Question 9

Which of the following are SAP Fiori Launchpad functionalities? Note: There are 2 correct answers to this question.

Options:

A.

SAP GUI

B.

Spaces

C.

Web Dynpro

D.

User Actions Menu

Question 10

In which order do you define the security-relevant objects in SAP BTP?

Options:

Question 11

Under which of the following conditions can you merge authorizations for the same object during role maintenance? Note: There are 2 correct answers to this question.

Options:

A.

The activation status of a manual authorization must match the status of the changed authorizations.

B.

The activation status and the maintenance status of the authorizations must match.

C.

The maintenance status of the changed authorizations must match the status of a manual authorization.

D.

The activation status and the maintenance status of the authorizations must NOT match.

Question 12

In SAP S/4HANA Cloud Public Edition, which of the following can you change in a derived business role if the "Inherit Spaces in Derived Business Roles" checkbox is NOT selected in the leading business role?

Options:

A.

Business Role Template

B.

Restrictions

C.

Business Catalogs

D.

Pages

Question 13

What use cases are available for a Local Identity Directory? Note: There are 3 correct answers to this question.

Options:

A.

Merging attributes

B.

Classic use case

C.

Hybrid mode

D.

Proxy mode

E.

S/4HANA use case

Question 14

In S/4HANA on-premise, which of the following combinations is required to grant a business user access to data from a Core Data Services (CDS) view using the standard ABAP authorization concept and authorization object S_RS_AUTH?

Options:

A.

A CDS role with access conditions based on authorization object S_RS_AUTH, a PFCG role with authorization for object S_RS_AUTH and assignment of the PFCG role, the CDS role to the business user.

B.

A CDS role with access conditions based on authorization object S_RS_AUTH, a PFCG role containing the CDS role and access conditions based upon authorization object S_RS_AUTH, assignment of the PFCG role to the business user.

C.

A CDS role with access conditions based on authorization object S_RS_AUTH, a PFCG role containing the CDS role and access conditions based upon authorization object S_RS_AUTH, assignment of the PFCG role and the CDS role to the business user.

D.

A CDS role with access conditions based on authorization object S_RS_AUTH, a PFCG role with authorization for object S_RS_AUTH, assignment of the PFCG role to the business user.

Question 15

What can be assigned directly to a user when using the SAP Launchpad service in SAP BTP?

Options:

A.

Spaces

B.

Launchpad roles

C.

Catalogs

D.

Role collections

Question 16

Which SAP Fiori deployment option requires the Cloud connector?

Options:

A.

SAP S/4HANA Cloud Public Edition

B.

SAP Fiori for SAP S/4HANA standalone front-end server

C.

SAP S/4HANA embedded

D.

SAP Business Technology Platform

Question 17

Which optional components can be included when transporting a role definition from the development system to the quality assurance system? Note: There are 3 correct answers to this question.

Options:

A.

Direct user assignments

B.

Generated profiles of dependent roles

C.

Generated profiles of single roles

D.

Indirect user assignments

E.

Personalization data

Question 18

Which code does the authority-check return when a user does NOT have any authorizations for the authorization object checked?

Options:

A.

12

B.

0

C.

4

D.

16

Question 19

For users with system administration authorization, which additional functions are provided by the SAP Easy Access menu? Note: There are 2 correct answers to this question.

Options:

A.

Calling menus for roles and assigning them to users

B.

Calling programs

C.

Creating roles

D.

Creating users

Question 20

In SAP HANA Cloud, who has access to a database object?

Options:

A.

The creator and the schema owner

B.

The user DBADMIN and the group owner

C.

The owner and the SAP-owned users

D.

The user SYSTEM and the creator

Question 21

For which of the following can transformation variables be used?

Options:

A.

To save data to the output JSON file

B.

To save data temporarily

C.

To save data permanently

Question 22

Where can you find SAP Fiori tiles and target mappings according to segregation of duty?

Options:

A.

Assigned Pages

B.

Assigned Technical Catalogs

C.

Assigned Spaces

D.

Business Catalogs

Question 23

What is the correct configuration setting in table PRGN_CUST for user assignments when transporting roles within a Central User Administration scenario?

Options:

A.

SET_IMP_LOCK_USERS = YES

B.

SET_IMP_LOCK_USERS = NO

C.

USER_REL_IMPORT = YES

D.

USER_REL_IMPORT = NO

Question 24

Which functions in SAP Access Control can be used to approve or reject a user’s continued access to specific security roles? Note: There are 2 correct answers to this question.

Options:

A.

SOD Review

B.

Role Certification

C.

User Access Review

D.

Role Reaffirm

Demo: 24 questions
Total 80 questions