
P-SECAUTH-21 Certification - The Ultimate Guide [Updated 2022]
P-SECAUTH-21 Practice Exam and Study Guides - Verified By GuideTorrent
NEW QUESTION 39
Which OData authorizations are required for a user to see business data in the SAP Fiori Launchpad? Note: There are 2 correct answers to this question.
- A. Start authorization in the SAP Fiori front-end system
- B. Start authorization in the SAP S/4HANA back-end system
- C. Access authorization in the SAP S/4HANA back-end system
- D. Access authorization in the SAP Fiori front-end system
Answer: A,C
NEW QUESTION 40
Which tasks would you perform to allow increased security for the SAP Web Dispatcher Web Administration interface? Note: There are 2 correct answers to this question.
- A. Use a separate port for the content
- B. Use access restrictions with the icm/HTTP/auth_<xx> profile parameter
- C. Use subparameter ALLOWPUB = FALSE of the profile parameter icm/server_port_<xx>
- D. Use Secure Socket Layer (SSL) for password encrypt on
Answer: A,C
NEW QUESTION 41
The SSO authentication using X.509 client certificates is configured. Users complain that they can't log in to the back-end system. The trace file shows the following error message: "HTTP request [2/5/9] Reject untrusted forwarded certificate". What is missing in the configuration? Note: There are 2 correct answers to this question.
- A. On the back-end, the profile parameter icm/HTTPS/verify client must NOT be set to 0
- B. On the web-dispatcher, the profile parameter icm/HTTPS/verify_client must be set to 0
- C. The web dispatcher's SAPSSLC.PSE certificate must be added to the trusted reverse proxies list in icm/trusted_reverse_proxy_<xx>
- D. On the web-dispatcher, the SAPSSLS.pse must be signed by a trusted certification authority
Answer: A,D
NEW QUESTION 42
Where can we store the Security Audit Log events? Note: There are 2 correct answers to this question.
- A. In the database table RSAU_BUF_DATA
- B. In a central fi e system
- C. In the SAP Solution Manager system
- D. In the file system of the application servers
Answer: C,D
NEW QUESTION 43
What is the User Management Engine (UME) property "connect on pooling" used for? Note: There are 2 correct answers to this question.
- A. To create a new connect on to the LDAP directory server for each request
- B. To improve performance of requests to the LDAP directory server
- C. To share server resources among requesting LDAP clients
- D. To avoid unauthorized request to the LDAP directory server
Answer: B,C
NEW QUESTION 44
In your system, you have a program which calls transaction A. Users with access to this program can still execute transaction A without explicit authorizations given to this transaction.
How do you prevent the access of users to the transaction A from within the program?
- A. Ensure that transact on A is NOT assigned into the same program authorization group
- B. Make sure you do NOT assign transact on A to the authorization object S_TCODE in the role that you assign to the unauthorized users.
- C. Maintain SE93 with authorization objects for transact on A.
- D. Maintain the check indicator in table TCDCOUPLES
Answer: C
NEW QUESTION 45
What is the SAP Best Practice to delete a security SAP role in SAP landscape?
- A. Delete the SAP role in all clients in all systems using Profile Generator
- B. Delete the SAP role in all clients using Profile Generator
- C. Transport the SAP role and delete the role using Profile Generator
- D. Delete the SAP role using Profile Generator, and then put it in the transport
Answer: C
NEW QUESTION 46
What are characteristics only valid for the MDC high isolation mode?
- A. Every tenant has its own set of database users
- B. All internal database communication is secured using SNC
- C. Every tenant has its own set of OS users
- D. Every tenant has its own set of database users belonging to the same sapsys group
Answer: C
NEW QUESTION 47
You have an HR table for which you want to create a role to provide users the ability to display and change its table content based on the country groupings. Which of the steps would you take to accomplish these requirements? Note: There are 2 correct answers to this question.
- A. Define an organization criterion through transaction SPRO
- B. Create an authorization group with appropriate authorization fields for the table
- C. Maintain the authorization object S_TABU_NAM
- D. Maintain the authorization object S_TABU_LIN
Answer: A,D
NEW QUESTION 48
You verified the password of the TMSADM user in your SAP landscape to be SAP defaulted. You want to reset this password by using program TMS_UPDATE_PWD_OF_TMSADM. What steps would you take to reset this password?
Note: There are 2 correct answers to this question
- A. Assign "SAP_ALL" to TMSADM in all systems/clients including 000
- B. Run this program in the Domain Controller (client 000)
- C. Lock TMSADM in all the system/clients including 000
- D. Deactivate the SNC opt on
Answer: B,C
NEW QUESTION 49
How would you control access to the ABAP RFC function modules? Note: There are 2 correct answers to this question.
- A. O Implement UCON functionality
- B. O Restrict RFC authorizations
- C. O Deactivate switchable authorization checks
- D. O Block RFC Callback Whitelists
Answer: B,C
NEW QUESTION 50
How can you protect a table containing sensitive data using the authorization object S_TABU_DIS?
- A. The tables containing sensitive data must be associated with table groups in table TBRG.
- B. The tables containing sensitive data must be named using the authorization object S_TA BU_NAM for all responsible administrator employees. The fields DICBERCLS of the object S_TABU_DIS can
- C. Authorization table groups containing tables with sensitive data must be defined in table TDDAT and these must be omitted for all employees who do not need access to these tables
- D. The field DICBERCLS of the authorization object must enumerate all table names of the tables containing sensitive data.
Answer: C
Explanation:
then be filled with *.
NEW QUESTION 51
You are evaluating the "Cross-client object change" option using transact on SCC4 for your Unit Test Client in the development environment. Which setting do you recommend?
- A. No changes to cross-client customizing objects
- B. Changes to repository and cross-client customizing allowed
- C. No changes to repository objects
- D. No changes to repository and cross-client customizing objects
Answer: D
NEW QUESTION 52
The SAP HANA database is installed with multi database container (MDC) mode with multiple tenant databases configured. What are the required activities to enable access between tenants? Note: There are 2 correct answers to this question.
- A. Create user mapping between local and remote tenant databases
- B. Configure smart data access (SDA) between the relevant HANA tenants
- C. Set whitelist of cross-tenant database communication channel
- D. Decrease the level of isolation mode on all MDC tenants
Answer: A,C
NEW QUESTION 53
Your customer runs a 3-tier environment You are asked to set up controls around monitoring the sensitive objects (such as programs, user-exits, function modules) in a development system before they are transported to the quality assurance system.
Which table would you maintain to monitor such sensitive objects before executing an import?
- A. TMSMCONF
- B. TMSTCRI
- C. TMSCDES
- D. TMSBUFFER
Answer: B
NEW QUESTION 54
You want to configure SNC with X.509 certificates using Common CryptoLib as the cryptographic library in a new installed AS ABAP system. Besides running SNCWIZARD, what do you need to set up for this scenario? Note: There are 2 correct answers to this question.
- A. Set the environment variable CCL_ PROFILE to the default profile file path
- B. Set the environment variable CCL_ PROFILE to SECUDIR
- C. Maintain the relevant CCL/SNC/' profile parameters
- D. Set the CCL SNC parameters using sapgenpse
Answer: A,C
NEW QUESTION 55
How do you check when and by whom profiles were assigned or deleted?
- A. Run report RSUSR008_009_NEW with appropriate filters
- B. Run report RSUSR100 with appropriate filters
- C. Check security audit log using transact on SM20
- D. Check system trace using transaction ST01
Answer: B
NEW QUESTION 56
In your SAP HCM system, you are implementing structural authorizations for your users. What are the characteristics of this authorization type? Note: There are 2 correct answers to this question.
- A. The structural profile determines the accessible object in the organizational structure
- B. The structural profile determines the access mode which the user can perform
- C. The structural profile is maintained and assigned to users using the Profile Generator
- D. The structural profile is maintained and assigned to users using the Implementation Guide
Answer: A,D
NEW QUESTION 57
Because of which security threat would you need to make additional configuration settings to run the SAP Fiori Launchpad from within your SAP NetWeaver Portal?
- A. Clickjacking
- B. Cross-Site Scripting
- C. Cross-Site Request Forgery
- D. Content Spoofing
Answer: A
NEW QUESTION 58
How does the SAP SSO wizard (transaction SNCWIZARD) simplify the SNC configuration process?
- A. It installs the CA certificate response
- B. It sets the profile parameters for SAP SNC and SPNego in the default profile
- C. It exports an SNC SAPCRYPTOLIB certificate and imports it into the partner system
- D. It creates the SNC_LIB environment variable
Answer: B
NEW QUESTION 59
Which communication methods does the SAP Fiori Launchpad use to retrieve business data? Note: There are 3 correct answers to this question.
- A. Info Access (InA)
- B. Trusted RFC
- C. Secure Network Communication (SNC)
- D. Data
- E. HTIP(S)
Answer: A,B,C
NEW QUESTION 60
For which purpose do you use instance Secure Storage File System (SSFS) in an SAP HANA system? Note: There are 2 correct answers to this question.
- A. To store root keys for data volume encryption
- B. To protect the X.509 public key infrastructure certificates
- C. To protect the password of the root key backup
- D. To store the secure single sign-on configuration
Answer: A,C
NEW QUESTION 61
What can you maintain in transaction SU24 to reduce the overall maintenance in PFCG? Note: There are 3 correct answers to this question.
- A. The default values in the tables USOBX and USOBT
- B. The authorization objects that are not linked to transact on codes correctly
- C. The default values so they are appropriate for the transactions used in the roles
- D. The default authority check settings for the role maintenance tool
- E. The authorization objects that have unacceptable default values
Answer: B,C,E
NEW QUESTION 62
......
Ultimate Guide to the P-SECAUTH-21 - Latest Edition Available Now: https://testking.guidetorrent.com/P-SECAUTH-21-dumps-questions.html