
2023 Realistic P-SECAUTH-21 100% Pass Guaranteed Download Exam Q&A
Accurate P-SECAUTH-21 Answers 365 Days Free Updates
SAP P-SECAUTH-21 Certification Exam Topics:
| Topic Areas | Topic Details, Courses, Books |
|---|---|
| SAP Cloud Platform Security 8% - 12% | Explain security and scenarios in SAP Cloud platform |
| Security Monitoring and Security Auditing > 12% | Monitor security and troubleshoot security issues using Solution Manager, security audits, traces and logs. |
| Access Governance and Compliance in SAP < 8% | Describe the security goals, data privacy goverance, access goverance solutions and tools in SAP. |
| SAP Netweaver Application Server and Infrastructure Security > 12% | Describe and implement security in a SAP NetWeaver Application Server and related infrastructure components |
| Authorization Concept for SAP Business Suite 8% - 12% | Describe and implement the authorization concept for SAP Business Suite |
| User Administration and Identity Lifecycle Management in SAP < 8% | Manage users in SAP systems |
| Secure an SAP System 8% - 12% | Explain how to secure an SAP system and conduct security checks |
| Authorization Concept for SAP S/4HANA > 12% | Describe and implement the authorization concept for SAP S/4HANA |
NEW QUESTION 55
What are characteristics of SAP HANA Deployment Infrastructure (HDI) roles? Note: there are 2 correct answers to this question.
- A. They are managed by the native HDI version control.
- B. They are granted using database procedures
- C. They are transportable between systems
- D. They are owned by the user who creates them
Answer: A,B
NEW QUESTION 56
Which features does the SAP Router support? Note: There are 2 correct answers to this question.
- A. Balancing the load to ensure an even distribution across the back-end servers
- B. Password-protecting connections from unauthorized access from outside the network
- C. Terminating, forwarding and (re)encrypting requests, depending on the SSL configuration
- D. Controlling and logging network connections to SAP systems
Answer: B,D
NEW QUESTION 57
To enable access between tenant databases, what do you need to do in an SAP HANA system for multitenant database containers? Note: there are 3 correct answers to this question.
- A. The bi-directional communication channel must be in the allow list.
- B. The user in the source system must be associated with a user in the target database.
- C. The user in the source system must have sufficient privileges in the target database.
- D. The INIFILE ADMIN system privilege must be assigned.
- E. The cross-tenant database communication must be explicitly activated.
Answer: B,C,E
NEW QUESTION 58
Which authorization object controls access to the trusting system between the managed system and SAP Solution Manager?
- A. S_ ICM
- B. S_RFCACL
- C. S_RFC
- D. S_SERVICE
Answer: B
NEW QUESTION 59
Which authorizations are required for an SAP Fiori Launchpad user? Note: There are 2 correct answers to this question
- A. /UI2/PAGE_BUILDER_CUST
- B. /UI2/PAGE_BUILDER_PERS
- C. /UI2/CHIP
- D. /UI2/INTEROP
Answer: B,D
NEW QUESTION 60
The SSO authentication using X.509 client certificates is configured. Users complain that they can't log in to the back-end system. The trace file shows the following error message: "HTTP request [2/5/9] Reject untrusted forwarded certificate". What is missing in the configuration? Note: There are 2 correct answers to this question.
- A. On the web-dispatcher, the SAPSSLS.pse must be signed by a trusted certification authority
- B. The web dispatcher's SAPSSLC.PSE certificate must be added to the trusted reverse proxies list in icm/trusted_reverse_proxy_<xx>
- C. On the back-end, the profile parameter icm/HTTPS/verify client must NOT be set to 0
- D. On the web-dispatcher, the profile parameter icm/HTTPS/verify_client must be set to 0
Answer: A,C
NEW QUESTION 61
For which purpose do you use instance Secure Storage File System (SSFS) in an SAP HANA system? Note: There are 2 correct answers to this question.
- A. To store the secure single sign-on configuration
- B. To protect the password of the root key backup
- C. To store root keys for data volume encryption
- D. To protect the X.509 public key infrastructure certificates
Answer: A,C
NEW QUESTION 62
Which of the following function can be used to troubleshoot authorization errors for ABAP CDS views with Authorization based on Access Control?
- A. E2E TRACE ANALYSIS
- B. STAUTHTRACE
- C. ABAP TRACE
- D. REPORT RSUSR008_009
Answer: B
NEW QUESTION 63
Which data source needs to be integrated into SAP Identity Management via the Virtual Directory Server (VOS)?
- A. SAP HCM
- B. LDAP
- C. AS ABAP
- D. AS Java
Answer: B
NEW QUESTION 64
What are the characteristics of assertion tickets? Note: There are 2 correct answers to this question.
- A. They are transmitted as cookies
- B. They are used for user-to-system trusted login
- C. They have an unconfigurable validity of 2 minutes
- D. They are used for system-to-system communication
Answer: C,D
NEW QUESTION 65
What is the User Management Engine (UME) property "connect on pooling" used for? Note: There are 2 correct answers to this question.
- A. To improve performance of requests to the LDAP directory server
- B. To share server resources among requesting LDAP clients
- C. To avoid unauthorized request to the LDAP directory server
- D. To create a new connect on to the LDAP directory server for each request
Answer: A,B
NEW QUESTION 66
How would you control access to the ABAP RFC function modules? Note: There are 2 correct answers to this question.
- A. Restrict RFC authorizations
- B. Deactivate switchable authorization checks
- C. Implement UCON functionality
- D. Block RFC Callback Whitelists
Answer: A,B
NEW QUESTION 67
Which type of systems can be found in the Identify Provisioning Service landscape? Note: There are 2 correct answers to this question
- A. Source
- B. Proxy
- C. Identify Provider
- D. Service Provider
Answer: A,C
NEW QUESTION 68
Which transaction or report can be used to audit profile assignments in an SU01 user master record? Note: There are 2 correct answers to this question
- A. RSUSR002
- B. SM20N
- C. RSUSR100
- D. ST01
Answer: A,C
NEW QUESTION 69
You want to use Configuration Validation functionality in SAP Solution Manager to check the consistency of settings across your SAP environment. What serves as the reference basis for Configuration Validation? Note: There are 2 correct answers to this question.
- A. A result list of configuration items from SAP Early Watch Alert (EWA)
- B. A target system in your system landscape
- C. A list of recommended settings attached to a specific SAP Note
- D. A virtual set of manually maintained configuration ems
Answer: B,D
NEW QUESTION 70
In your SAP HCM system, you are implementing structural authorizations for your users. What are the characteristics of this authorization type? Note: There are 2 correct answers to this question.
- A. The structural profile determines the access mode which the user can perform
- B. The structural profile determines the accessible object in the organizational structure
- C. The structural profile is maintained and assigned to users using the Implementation Guide
- D. The structural profile is maintained and assigned to users using the Profile Generator
Answer: B,C
NEW QUESTION 71
You are running a 3-tier SAP system landscape. Each time you are accessing STMS_IMPORT on any of these systems, you are prompted for a TMSADM password. How can you stop this prompt from appearing?
- A. Run the report TMS_ UPDATE_PWD_OF_TMSADM on the domain controller.
- B. Reset the TMSADM user's password on the system you are trying to access STMS_ IMPORT.
- C. Run the report RSUSR405 on the domain controller.
- D. Change the TMSA DM user's password directly in the TMS RFC destination in transact on SM59.
Answer: A
NEW QUESTION 72
Based on your company guidelines you have set the password expiration to 60 days. Unfortunately, there is an RFC user on your SAP system which must not have a password change for 180 days. Which option would you recommend to accomplish such a request?
- A. Create a security policy via SECPOL and assign it to tile RFC users
- B. Create additional authorizations for RFC users and assign it to them
- C. Create enhancement spot I user-exit
- D. Change profile parameter login/password_expiration_time to 180
Answer: A
NEW QUESTION 73
What authorization objects do we need to create job steps with external commands in a background job? Note: There are 2 correct answers to this question.
- A. S_ADMI_FCD
- B. S_RZL_ADM
- C. S_LOG_COM
- D. S_BTCH_EXT
Answer: B,C
NEW QUESTION 74
The security administrator is troubleshooting authorization errors using transaction SU53. While running transaction MM50, the user received the following error: "You are not authorized to use transaction MM01" The users position in the organization makes it inappropriate for them to have direct access to transaction MM01 because it creates a Segregation of Duties conflict.
What would cause the system to run an authority check using object S_TCODE for transaction MM01 while running transaction MM50?
- A. The instance parameter auth/no_check_in_some_cases has been set to Y
- B. The developer who wrote the program for transaction MM50 issues the ABAL command CALL TRANSACTION for transaction MM01
- C. MM01 was maintained as the CALLING transaction in table TCDCOUPLES with field OKFLAG value X
- D. The proposal value for the object S_TCODE in the SU24 data for transaction MM50 was incorrectly set to YES
Answer: B
NEW QUESTION 75
......
P-SECAUTH-21 Exam Certification Details:
| Cut Score: | 66% |
| Languages: | English |
| Level: | Professional |
| Duration: | 180 mins |
P-SECAUTH-21 dumps Exam Material with 139 Questions: https://www.vceengine.com/P-SECAUTH-21-vce-test-engine.html
P-SECAUTH-21 DUMPS Q&As with Explanations Verified & Correct Answers: https://drive.google.com/open?id=155g0iL_uX5ImywrW-_rwZhz0pThAXCBT
