
2022 The Most Effective P_SECAUTH_21 with 81 Questions Answers
Try Free and Start Using Realistic Verified P_SECAUTH_21 Dumps Instantly.
SAP P_SECAUTH_21 Certification Exam Topics:
| Topic Areas | Topic Details, Courses, Books |
|---|---|
| Authorization Concept for SAP S/4HANA > 12% | Describe and implement the authorization concept for SAP S/4HANA |
| SAP Cloud Platform Security 8% - 12% | Explain security and scenarios in SAP Cloud platform |
| SAP Netweaver Application Server and Infrastructure Security > 12% | Describe and implement security in a SAP NetWeaver Application Server and related infrastructure components |
| Authorization Concept for SAP Business Suite 8% - 12% | Describe and implement the authorization concept for SAP Business Suite |
P_SECAUTH_21 Exam Certification Details:
| Cut Score: | 66% |
| Level: | Professional |
| Exam: | 80 questions |
| Duration: | 180 mins |
| Languages: | English |
NEW QUESTION 35
What are the features of the Audit Information System (AIS)? Note: There are 2 correct answers to this question.
- A. The roles are built from nodes in the Implementation Guide (IMG)
- B. The report selection variables are configured during setup
- C. It can be launched directly using transact on SECR
- D. It offers two types of audit reports: system and business
Answer: B,D
NEW QUESTION 36
You want to launch classic SAP GUI transactions directly from the SAP Fiori Launchpad. Which of the following scenarios do you choose?
- A. Internet Explorer, SAP Business Client, SAP GUI for Windows
- B. Internet Explorer, ABAP front-end server, SAP GUI for Windows
- C. Chrome, SAP Enterprise Portal, SAP GUI for Java
- D. Chrome, SAP Cloud Platform, SAP GUI for Java
Answer: B
NEW QUESTION 37
To prevent session fixation and session hijacking attacks, SAP's HTTP security session management is highly recommended. What are the characteristics of HTTP security session management? Note: There are 2 correct answers to this question.
- A. The system is checking the logon credentials again for every request
- B. It uses URLs containing sap-context d to identify the security session
- C. The security sessions are created during logon and deleted during logoff.
- D. The session identifier is a reference to the session context transmitted through a cookie.
Answer: C,D
NEW QUESTION 38
What benefits does the SAP Cloud Connector have compared to a 3rd partyreverse proxy solution, when connecting your SAP Cloud Platform with your SAP backend systems? Note: There are 2 correct answers to this question.
- A. It establishes an SSL VPN tunnel to SAP Cloud Platform
- B. It can cache SAP proprietary OData packets to improve the response times
- C. It allows for remote invocation by the SAP Cloud Platform only
- D. It supports multiple application protocols, such as HTTP and RFC
Answer: A,D
NEW QUESTION 39
Your company is running SAP S/4HANA on premise, with the requirement to run the SAP Fiori Launchpad in the SAP Cloud Platform. What would be the recommended scenario for user authentication for internet browser access to the SAP Fiori Launchpad?
- A. Principal Propagation
- B. X.509 Client Certificates
- C. SAP Logon Tickets
- D. SAML2 and OData Provisioning
Answer: B
NEW QUESTION 40
You want to create an SAP Fiori app for multiple users and multiple back-end systems. To support this, you create different roles for the different back-end systems in the SAP Fiori front-end system (central hub). What transaction do you have to use to map a back-end system to one of those roles?
- A. PFCG
- B. SM59
- C. /UI2/GW_SYS_ALIAS
- D. /IWFND/MAINT_SERVICE
Answer: A
NEW QUESTION 41
You have delimited a single role which is part of a composite role, and a user comparison for the composite role has been performed. You notice that the comparison did NOT remove the profile assignments for that single role. What program would you run to resolve this situation?
- A. 0 PRGN_COMPRESS_TIMES
- B. 0 PRGN_MERGE_PREVIEW
- C. 0 PRGN_DELETE_ACT IVITY_GROUPS
- D. 0PRGN_COMPARE_ROLE_MENU
Answer: A
NEW QUESTION 42
You want to check the custom ABAP codes in your system for security vulnerabilities and you want to use the Code Vulnerability Analyzer (CVA) for carrying out these extended security checks. What needs to be done for this purpose? Note: There are 2 correct answers to this question.
- A. Execute program RSLIN_SEC_LICENSE_SETUP
- B. Run CVA from the ABAP Trace
- C. Execute transaction ST12 to start the analysis
- D. Run CVA from the ABAP Test Cockpit
Answer: B,D
NEW QUESTION 43
You want to carry out some preparatory work for executing the SAP Security Optimization Self-service on a customer system. Which of the following steps do you have to execute on the managed systems? Note: There are 2 correct answers to this question.
- A. Grant operating system access
- B. Install the ST-A/PI plug-in
- C. Configure specific authorizations
- D. Configure Secure Network Communications
Answer: B,C
NEW QUESTION 44
Which authorizations should you restrict when you create a developer role in an AS ABAP production system? Note: There are 2 correct answers to this question.
- A. The ability to execute queries through authorization object S_OUERY
- B. The ability to execute function modules through authorization object S_DEVELOP
- C. The ability to execute class methods through authorization object S_PROGRAM
- D. The ability to use the ABAP Debugger through authorization object S_DEVELOP
Answer: B,D
NEW QUESTION 45
You have Reason Codes already defined. Which is the correct sequence of steps to configure a Firefighter ID in Emergency Access Management?
- A. Maintain an Owner for a Firefighter ID
Maintain a Firefighter ID for Controllers and Firefighters
Maintain Access Control Owner - B. Maintain an Owner for a Firefighter ID
Maintain a Firefighter ID for Controllers and Firefighters
Maintain Access Control Owner - C. Maintain a Firefighter ID for Controllers and Firefighters
Maintain an Owner for a Firefighter ID
Maintain Access Control Owner - D. Maintain an Owner for a Firefighter ID
Maintain a Firefighter ID for Controllers and Firefighters
Maintain Access Control Owner
Answer: A
NEW QUESTION 46
You want to use Configuration Validation functionality in SAP Solution Manager to check the consistency of settings across your SAP environment. What serves as the reference basis for Configuration Validation? Note: There are 2 correct answers to this question.
- A. A virtual set of manually maintained configuration ems
- B. A result list of configuration items from SAP Early Watch Alert (EWA)
- C. A target system in your system landscape
- D. A list of recommended settings attached to a specific SAP Note
Answer: A,C
NEW QUESTION 47
The SSO authentication using X.509 client certificates is configured. Users complain that they can't log in to the back-end system. The trace file shows the following error message: "HTTP request [2/5/9] Reject untrusted forwarded certificate". What is missing in the configuration? Note: There are 2 correct answers to this question.
- A. The web dispatcher's SAPSSLC.PSE certificate must be added to the trusted reverse proxies list in icm/trusted_reverse_proxy_<xx>
- B. On the back-end, the profile parameter icm/HTTPS/verify client must NOT be set to 0
- C. On the web-dispatcher, the SAPSSLS.pse must be signed by a trusted certification authority
- D. On the web-dispatcher, the profile parameter icm/HTTPS/verify_client must be set to 0
Answer: B,C
NEW QUESTION 48
What are the characteristics of assertion tickets? Note: There are 2 correct answers to this question.
- A. They have an unconfigurable validity of 2 minutes
- B. They are used for user-to-system trusted login
- C. They are used for system-to-system communication
- D. They are transmitted as cookies
Answer: A,C
NEW QUESTION 49
How would you control access to the ABAP RFC function modules? Note: There are 2 correct answers to this question.
- A. O Deactivate switchable authorization checks
- B. O Implement UCON functionality
- C. O Block RFC Callback Whitelists
- D. O Restrict RFC authorizations
Answer: A,D
NEW QUESTION 50
You want to configure SNC with X.509 certificates using Common CryptoLib as the cryptographic library in a new installed AS ABAP system. Besides running SNCWIZARD, what do you need to set up for this scenario? Note: There are 2 correct answers to this question.
- A. Set the environment variable CCL_ PROFILE to SECUDIR
- B. Maintain the relevant CCL/SNC/' profile parameters
- C. Set the environment variable CCL_ PROFILE to the default profile file path
- D. Set the CCL SNC parameters using sapgenpse
Answer: B,C
NEW QUESTION 51
Which tool do you use to customize the SAP HANA default password policy? Note: There are 2 correct answers to this question.
- A. SAP Web IDE
- B. SAP HANA Studio
- C. SAP HANA Lifecycle Manager
- D. SAP HANA Cockpit
Answer: A,B
NEW QUESTION 52
You have implemented CUA in your organization and you want to set the field distribution attribute as follows: Maintain a default value in the central system that is automatically distributed to the child systems when you create a user. After distribution, the data is maintained only locally and is no longer distributed if you change it in the central or child system. Which field distribution parameter do you maintain?
- A. Global
- B. Proposal
- C. Local
- D. Redistribution
Answer: B
NEW QUESTION 53
What can you maintain in transaction SU24 to reduce the overall maintenance in PFCG? Note: There are 3 correct answers to this question.
- A. The default authority check settings for the role maintenance tool
- B. The default values so they are appropriate for the transactions used in the roles
- C. The default values in the tables USOBX and USOBT
- D. The authorization objects that are not linked to transact on codes correctly
- E. The authorization objects that have unacceptable default values
Answer: B,D,E
NEW QUESTION 54
User1 grants role 1 to user2. Who can revoke role 1 role from user2?
- A. Any user with the 'ROLE ADMIN' database role
- B. The owner of role 1
- C. The system OBA user
- D. Only User1
Answer: A
NEW QUESTION 55
The SAP HANA database is installed with multi database container (MDC) mode with multiple tenant databases configured. What are the required activities to enable access between tenants? Note: There are 2 correct answers to this question.
- A. Set whitelist of cross-tenant database communication channel
- B. Create user mapping between local and remote tenant databases
- C. Decrease the level of isolation mode on all MDC tenants
- D. Configure smart data access (SDA) between the relevant HANA tenants
Answer: A,B
NEW QUESTION 56
......
Download Free Latest Exam P_SECAUTH_21 Certified Sample Questions: https://pdftorrent.dumpexams.com/P_SECAUTH_21-vce-torrent.html