[Nov-2023] Practice SAP P_SECAUTH_21 exam. Online Exam Practice Tests with detailed explanations! Pass P_SECAUTH_21 with confidence! [Q38-Q53]

Share

Practice SAP Certified Technology Professional P_SECAUTH_21 exam. Online Exam Practice Tests with detailed explanations! Pass P_SECAUTH_21 with confidence!

P_SECAUTH_21 - Certified Technology Professional - System Security Architect Practice Tests 2023 | Pass4Leader

NEW QUESTION # 38
How do you check when and by whom profiles were assigned or deleted?

  • A. Check security audit log using transact on SM20
  • B. Run report RSUSR008_009_NEW with appropriate filters
  • C. Check system trace using transaction ST01
  • D. Run report RSUSR100 with appropriate filters

Answer: D


NEW QUESTION # 39
What are the requirements of SPNego SSO configuration in an SAP Fiori front-end system? Note: There are 2 correct answers to this question.

  • A. The system's users in the ABAP system must have the same user names as the database users in SAP HANA
  • B. The system requires Microsoft Active Directory infrastructure in place.
  • C. The system should typically be located within the corporate network.
  • D. The system requires an identity provider as an issuing system to enable single sign-on with SPNego in an internet-facing deployment scenario.

Answer: B,C


NEW QUESTION # 40
Which authorization object controls access to the trusting system between the managed system and SAP Solution Manager?

  • A. S_RFCACL
  • B. S_RFC
  • C. S_ ICM
  • D. S_SERVICE

Answer: A


NEW QUESTION # 41
To which services packages does SAP Security Optimization Services (SOS) belong?

  • A. Application Integration Optimization
  • B. System Administration Optimization
  • C. EarlyWatch Reporting
  • D. Performance Optimization

Answer: B


NEW QUESTION # 42
Which tool do you use to customize the SAP HANA default password policy? Note: There are 2 correct answers to this question.

  • A. SAP HANA Lifecycle Manager
  • B. SAP HANA Cockpit
  • C. SAP HANA Studio
  • D. SAP Web IDE

Answer: C,D


NEW QUESTION # 43
How does the SAP SSO wizard (transaction SNCWIZARD) simplify the SNC configuration process?

  • A. It sets the profile parameters for SAP SNC in the instance profile.
  • B. It creates the SNC_LIB environment variable in OS user profile.
  • C. It restarts the SAP application server for all profile changes to take effect.
  • D. It sets the profile parameters for SAP SNC in the default profile

Answer: A

Explanation:
Explanation
This is one of the ways that the SAP SSO wizard (transaction SNCWIZARD) simplifies the SNC configuration process. SNC (Secure Network Communication) is a feature that enables secure and encrypted communication between SAP systems and components using certificates and keys. The SAP SSO wizard is a tool that guides you through the steps of configuring SNC for your SAP system, such as creating or importing certificates and keys, setting up trust relationships, and activating SNC protection level. It also sets the profile parameters for SAP SNC in the instance profile, which are required for enabling SNC on your system.
References:
https://help.sap.com/doc/saphelp_nw73ehp1/7.31.19/en-US/48/9e2e3f6f8e41e8a283aaf2ad2c64c4/content.htm?n


NEW QUESTION # 44
How would you control access to the ABAP RFC function modules? Note: There are 2 correct answers to this question.

  • A. O Implement UCON functionality
  • B. O Restrict RFC authorizations
  • C. O Deactivate switchable authorization checks
  • D. O Block RFC Callback Whitelists

Answer: B,C


NEW QUESTION # 45
Currently, transports into your SAP system are not scanned automatically. To avoid the import of non-secure programs, you have implemented the strategy to set up a virus scanner using a script to automatically scan for the malicious programs. What is the valid fi e format where data files are first converted into and then checked by a virus scanner?

  • A. Plain text
  • B. SAP compressed
  • C. 0csv
  • D. XML

Answer: D


NEW QUESTION # 46
You have delimited a single role that is part of a composite role, and a user comparison for the composite role has been performed. You notice that the comparison did NOT remove the profile assignments for that single role. What program would you run to resolve this situation?

  • A. PRGN_COMPARE_ROLE_MENU
  • B. PRGN_DELETE_ACTIVITY_GROUPS
  • C. PRGN_COMPRESS_TIMES
  • D. PRGN_MERGE_PREVIEW

Answer: B

Explanation:
Explanation
This is one of the programs that you would run to resolve this situation of not removing profile assignments for a single role after delimiting it and performing user comparison for its composite role. A single role is a role that contains authorizations for one application area or function. A composite role is a role that contains other roles as sub-roles without any authorizations by itself. A user comparison is a process that synchronizes user master records with role assignments and profile assignments in PFCG transaction.
PRGN_DELETE_ACTIVITY_GROUPS is a program that deletes single roles or composite roles from user master records along with their profile assignments. References:
https://help.sap.com/doc/saphelp_nw73ehp1/7.31.19/en-US/c8/e8d53d35fb11d182b90000e829fbfe/content.htm?


NEW QUESTION # 47
How can you describe the hierarchical relationships between technical entities in the Cloud Foundry?

  • A. A SaaS tenant acts as one provider account.
  • B. A SaaS tenant acts as one Cloud Foundry Organization.
  • C. A subscription is a PaaS tenant.
  • D. A global account can have one or many subaccounts

Answer: D


NEW QUESTION # 48
User1 grants role 1 to user2. Who can revoke role 1 role from user2?

  • A. Only User1
  • B. Any user with the 'ROLE ADMIN' database role
  • C. The owner of role 1
  • D. The system OBA user

Answer: B


NEW QUESTION # 49
What are characteristics of SAP HANA Deployment Infrastructure (HDI) roles? Note: There are 2 correct answers to this question.

  • A. They are owned by the user who creates them.
  • B. They are granted using database procedures.
  • C. They are transportable between systems.
  • D. They are managed by the native HDI version control.

Answer: B,D

Explanation:
Explanation
These are some of the characteristics of SAP HANA Deployment Infrastructure (HDI) roles. HDI roles are roles that are defined and deployed as part of HDI containers, which are isolated units of database objects and data in SAP HANA systems. HDI roles are managed by the native HDI version control, which tracks changes and dependencies among HDI objects and artifacts. HDI roles are granted using database procedures, such as GRANT_CONTAINER_GROUP_ROLE or GRANT_CONTAINER_SCHEMA_ROLE, which enable dynamic role assignments based on container groups or schemas. References:
https://help.sap.com/viewer/6b94445c94ae495c83a19646e7c3fd56/2.0.05/en-US/fafcbcf9d9101014b3d9a08ce33


NEW QUESTION # 50
What does the SAP Security Optimization Service provide? Note: There are 2 correct answers to this question.

  • A. Results containing the list of patches that have to be applied
  • B. Analysis of the security vulnerabilities within an SAP landscape
  • C. Analysis of the network configuration
  • D. Configuration checks of SAP systems

Answer: C,D

Explanation:
Explanation
These are some of the things that the SAP Security Optimization Service provides. SAP Security Optimization Service is a service that enables you to assess and improve the security level of your SAP systems and landscapes based on best practices and recommendations from SAP experts. The service provides configuration checks of SAP systems, which analyze various parameters and settings related to security aspects, such as passwords, authorizations, encryption, or logging. The service also provides analysis of the network configuration, which evaluates the network topology and communication channels between SAP systems and components. References: https://support.sap.com/en/security/security-optim


NEW QUESTION # 51
You are consolidating user measurement results and transferring them to SAP. What act on do you take?

  • A. Run report RFAUDI06_BCE
  • B. Run report RSUSR200
  • C. Run transact on USMM
  • D. Run report RSLAW_PLUGIN

Answer: C


NEW QUESTION # 52
What are characteristics of SAP HANA Deployment Infrastructure (HDI) roles? Note: there are 2 correct answers to this question.

  • A. They are owned by the user who creates them
  • B. They are transportable between systems
  • C. They are granted using database procedures
  • D. They are managed by the native HDI version control.

Answer: C,D


NEW QUESTION # 53
......

The best P_SECAUTH_21 exam study material and preparation tool is here: https://testoutce.pass4leader.com/SAP/P_SECAUTH_21-exam.html