
Brilliant P_SECAUTH_21 Exam Dumps Get P_SECAUTH_21 Dumps PDF
P_SECAUTH_21 Dumps PDF - P_SECAUTH_21 Real Exam Questions Answers
To prepare for the SAP P-SECAUTH-21 certification exam, candidates are recommended to have at least two years of practical experience in SAP system security architecture. They should also have a deep understanding of SAP security concepts and best practices, as well as practical experience in configuring and managing SAP security features.
NEW QUESTION # 39
What benefits does the SAP Cloud Connector have compared to a 3rd partyreverse proxy solution, when connecting your SAP Cloud Platform with your SAP backend systems? Note: There are 2 correct answers to this question.
- A. It establishes an SSL VPN tunnel to SAP Cloud Platform
- B. It supports multiple application protocols, such as HTTP and RFC
- C. It allows for remote invocation by the SAP Cloud Platform only
- D. It can cache SAP proprietary OData packets to improve the response times
Answer: A,B
NEW QUESTION # 40
What does the SAP Security Optimization Service provide? Note: There are 2 correct answers to this question.
- A. Analysis of your operating system, database, and entire SAP system to ensure optimal performance and reliability
- B. Configuration check of the SAP systems and the SAP middleware components against defined configurations
- C. Results with recommendations on how to resolve identified vulnerabilities without prioritization
- D. Analysis of security vulnerabilities within an enterprise's SAP landscape to ensure optimal protection against intrusions
Answer: B,D
NEW QUESTION # 41
You want to allow your trainee colleagues to use the SAP GUI to connect directly to your SAP S/4HANA (on-premise) demo system form a public internet connection Which of the following SAP solutions is suited for this purpose?
- A. SAP Cloud Connector
- B. SAP NetWeaver Gateway
- C. SAP Prouter
- D. SAP Web Dispatcher
Answer: A
NEW QUESTION # 42
What are characteristics of SAP HANA Deployment Infrastructure (HDI) roles? Note: there are 2 correct answers to this question.
- A. They are granted using database procedures
- B. They are managed by the native HDI version control.
- C. They are owned by the user who creates them
- D. They are transportable between systems
Answer: A,B
NEW QUESTION # 43
Why should you create multiple dispatchers in SAP Identity Management? Note: There are 2 correct answers to this question.
- A. To handle special network access requirements
- B. To support fail-over scenarios
- C. To accommodate scalability
- D. To handle password provisioning
Answer: A,C
NEW QUESTION # 44
What is required when you configure the PFCG role for an end-user on the front-end server? Note: There are 2 correct answers to this question.
- A. The S_RFC authorization object for the OData access
- B. The group assignment to display it in the Fiori Launchpad
- C. The catalog assignment for the start authorization
- D. The Fiori Launchpad designer assignment
Answer: B,C
NEW QUESTION # 45
A security consultant has activated a trace via ST01 and is analyzing the authorization error with Return Code 12. What does the Return Code 12 signify?
- A. "Objects not contained in User Buffer"
- B. "No authorizations and does NOT have authorization object in their buffer"
- C. "No authorizations but does have authorization object in their buffer"
- D. "Too many parameters for authorization checks"
Answer: B
NEW QUESTION # 46
A user is authorized to run SP01. What can this user access with authorization object S_ SPO_ ACT when the 'Value for Authorization Check' field is set to "__USER__"?
- A. All spool requests for users in the same user group
- B. All spool requests for a specific user in the client
- C. All unprotected spool requests for all users in the client
- D. All spool requests for all users in the client
Answer: B
Explanation:
Explanation
This is one of the things that a user can access with authorization object S_SPO_ACT when the 'Value for Authorization Check' field is set to "USER" and they are authorized to run SP01 transaction. S_SPO_ACT is an authorization object that controls access to spool requests based on various criteria, such as spool request number, output device, or user name. SP01 is a transaction that allows you to display and manage spool requests, which are requests for printing or outputting data from SAP systems. If the 'Value for Authorization Check' field is set to "USER" in S_SPO_ACT authorization object, the user can access all spool requests for their own user name in the client where they are logged on. References:
https://help.sap.com/doc/saphelp_nw73ehp1/7.31.19/en-US/c8/e8d53d35fb11d182b90000e829fbfe/content.htm?
NEW QUESTION # 47
You want to use Configuration Validation functionality in SAP Solution Manager to check the consistency of settings across your SAP environment. What serves as the reference basis for Configuration Validation? Note: There are 2 correct answers to this question.
- A. A list of recommended settings attached to a specific SAP Note
- B. A result list of configuration items from SAP Early Watch Alert (EWA)
- C. A target system in your system landscape
- D. A virtual set of manually maintained configuration ems
Answer: C,D
NEW QUESTION # 48
What are main characteristics of the Logon ticket throughout an SSO logon procedure? Note: There are 2 correct answers to this question
- A. The Logon ticket is sued for user-to-system communication
- B. The Logon ticket session is held in the working memory
- C. The Logon ticket is not domain restricted
- D. The Logon ticket is always set to client 000
Answer: A,C
NEW QUESTION # 49
To which services packages does SAP Security Optimization Services (SOS) belong?
- A. Performance Optimization
- B. Application Integration Optimization
- C. EarlyWatch Reporting
- D. System Administration Optimization
Answer: D
NEW QUESTION # 50
What are main characteristics of the Logon ticket throughout an SSO logon procedure? Note:
There are 2 correct answers to this question.
- A. The Logon ticket is always set to client 000.
- B. The Logon ticket session is held in the working memory.
- C. The Logon ticket is used for user-to-system communication.
- D. The Logon ticket is not domain restricted.
Answer: B,C
Explanation:
Explanation
These are some of the main characteristics of the Logon ticket throughout an SSO logon procedure. SSO (Single Sign-On) is a feature that enables users to log on to multiple systems or applications with one authentication process and without entering their credentials multiple times. Logon ticket is one of the methods for implementing SSO in SAP systems, which uses digital certificates and cookies to authenticate users and systems. The Logon ticket is used for user-to-system communication, which means that it contains information about the user's identity and authorizations that can be verified by the target system or application.
The Logon ticket session is held in the working memory, which means that it is stored temporarily in the memory of the user's browser or system and deleted when the session ends or expires. References:
https://help.sap.com/doc/saphelp_nw73ehp1/7.31.19/en-US/c8/e8d53d35fb11d182b90000e829fbfe/content.htm?
NEW QUESTION # 51
How is the role concept applied for modeled authorizations based on Core Data Services (CDS) views?
- A. CDS roles are defined in the WHERE clause when calling a CDS view in Open SQL.
- B. CDS roles are defined for CDS views in Object Navigator.
- C. CDS roles are defined for the CDS views and implicitly applied to each user.
- D. CDS roles are mapped to the CDS view in the access rules.
Answer: D
Explanation:
Explanation
The role concept for modeled authorizations based on Core Data Services (CDS) views works in this way:
CDS roles are mapped to the CDS view in the access rules that define which users can access which data from the CDS view. The access rules are defined using annotations in the CDS view definition or using a separate access control DDL source file. References:
https://help.sap.com/viewer/cc0c305d2fab47bd808adcad3ca7ee9d/7.5.9/en-US/fafcbcf9d9101014b3d9a08ce33d
https://help.sap.com/viewer/cc0c305d2fab47bd808adcad3ca7ee9d/7.5.9/en-US/fafcbcf9d9101014b3d9a08ce33d
NEW QUESTION # 52
You have an HR table for which you want to create a role to provide users the ability to display and change its table content based on the country groupings. Which of the steps would you take to accomplish these requirements? Note: There are 2 correct answers to this question.
- A. Define an organization criterion through transaction SPRO
- B. Create an authorization group with appropriate authorization fields for the table
- C. Maintain the authorization object S_TABU_NAM
- D. Maintain the authorization object S_TABU_LIN
Answer: A,D
NEW QUESTION # 53
You are evaluating the "Cross-client object change" option using transact on SCC4 for your Unit Test Client in the development environment. Which setting do you recommend?
- A. No changes to cross-client customizing objects
- B. Changes to repository and cross-client customizing allowed
- C. No changes to repository and cross-client customizing objects
- D. No changes to repository objects
Answer: C
NEW QUESTION # 54
Which measures should we implement to protect the PSEs? Note: There are 2 correct answers to this question.
- A. Restrict access to the operating system users
- B. Encrypt the files with the transaction SNC0
- C. Review the usage of the S_DATASET object
- D. Review the usage of the S_ADMI_FCD object
Answer: A,D
Explanation:
Explanation
These are some of the measures that should be implemented to protect the PSEs (Personal Security Environments). PSEs are files that store cryptographic information, such as keys and certificates, for various security purposes, such as SSL, SNC, or SSO. The usage of the S_ADMI_FCD object should be reviewed because it controls the access to PSE administration functions, such as creating, deleting, or displaying PSEs.
The access to the operating system users should be restricted because they can access the PSE files directly from the file system and manipulate them. References:
https://help.sap.com/doc/saphelp_nw70ehp3/7.03/en-US/c8/e8d53d35fb11d182b90000e829fbfe/content.htm?no_
https://help.sap.com/doc/saphelp_nw70ehp3/7.03/en-US/c8/e8d53d35fb11d182b90000e829fbfe/content.htm?no_
NEW QUESTION # 55
Which of the following events will create security alerts in the CCMS Alert Monitor of SAP Solution Manager? Note: There are 2 correct answers to this question.
- A. Changes to the instance profile
- B. Manual table changes
- C. Call of RFC functions
- D. Start of reports
Answer: C,D
NEW QUESTION # 56
To prevent session fixation and session hijacking attacks, SAP's HTTP security session management is highly recommended. What are the characteristics of HTTP security session management? Note: There are 2 correct answers to this question.
- A. It uses URLs containing sap-context d to identify the security session
- B. The security sessions are created during logon and deleted during logoff.
- C. The session identifier is a reference to the session context transmitted through a cookie.
- D. The system is checking the logon credentials again for every request
Answer: B,C
NEW QUESTION # 57
Based on your company guidelines you have set the password expiration to 60 days.
Unfortunately, there is an RFC user on your SAP system who must not have a password change for 1 80 days. Which option would you recommend to accomplish such a request?
- A. Create an enhancement spot or user exit
- B. Change the profile parameter login/password_expiration_time to 1 80
- C. Define the RFC user as a reference user
- D. Create a security policy via SECPOL and assign it to the RFC users
Answer: D
Explanation:
Explanation
This is one of the options that you would recommend to accomplish such a request of having an RFC user with a password expiration of 180 days instead of 60 days based on your company guidelines. SECPOL is a transaction that allows you to create and maintain security policies for password settings, such as minimum length, expiration time, or lockout threshold. You can assign different security policies to different users or user groups based on their roles or requirements. References:
https://help.sap.com/doc/saphelp_nw73ehp1/7.31.19/en-US/c8/e8d53d35fb11d182b90000e829fbfe/content.htm?
NEW QUESTION # 58
What are characteristic of the SAP_INTERNAL_HANA_SUPPORT catalog role? Note: there are 2 correct answers to this question.
- A. Object privileges can be granted to the role
- B. No role can be granted to it
- C. System privileges can be granted to the role
- D. It has full access to all metadata
Answer: B,C
NEW QUESTION # 59
SAP GRC Access Control provides risk analysis for which of the following? Note: There are 2 correct answers to this question.
- A. Password Self-Service
- B. Access Request Managment
- C. Business Role Management
- D. Business Rule Framework
Answer: B,C
Explanation:
Explanation
SAP GRC Access Control provides risk analysis for these components. SAP GRC Access Control is a suite of applications that enables you to manage access risks and compliance across your SAP systems and landscapes.
Business Role Management is a component that allows you to design and maintain business roles based on user tasks and functions, and analyze them for potential risks or conflicts. Access Request Management is a component that allows you to request, approve, provision, and monitor access changes for users and roles, and analyze them for potential risks or violations. References:
https://help.sap.com/viewer/product/SAP_ACCESS_CONTROL/en-US
NEW QUESTION # 60
What are characteristics of SAP HANA Deployment Infrastructure (HDI) roles? Note: There are 2 correct answers to this question.
- A. They are transportable between systems.
- B. They are owned by the user who creates them.
- C. They are granted using database procedures.
- D. They are managed by the native HDI version control.
Answer: C,D
Explanation:
Explanation
These are some of the characteristics of SAP HANA Deployment Infrastructure (HDI) roles. HDI roles are roles that are defined and deployed as part of HDI containers, which are isolated units of database objects and data in SAP HANA systems. HDI roles are managed by the native HDI version control, which tracks changes and dependencies among HDI objects and artifacts. HDI roles are granted using database procedures, such as GRANT_CONTAINER_GROUP_ROLE or GRANT_CONTAINER_SCHEMA_ROLE, which enable dynamic role assignments based on container groups or schemas. References:
https://help.sap.com/viewer/6b94445c94ae495c83a19646e7c3fd56/2.0.05/en-US/fafcbcf9d9101014b3d9a08ce33
NEW QUESTION # 61
......
Valid P_SECAUTH_21 Test Answers & SAP P_SECAUTH_21 Exam PDF: https://itexambus.passleadervce.com/SAP-Certified-Technology-Professional/reliable-P_SECAUTH_21-exam-learning-guide.html