[2024] Pass your P-SECAUTH-21 exam with this 100% Free P-SECAUTH-21 Braindump [Q41-Q66]

Share

[2024] Pass your P-SECAUTH-21 exam with this 100% Free P-SECAUTH-21 Braindump

View All P-SECAUTH-21 Actual Exam Questions, Answers and Explanations for Free

NEW QUESTION # 41
In your SAP HCM system, you are implementing structural authorizations for your users. What are the characteristics of this authorization type? Note: There are 2 correct answers to this question.

  • A. The structural profile is maintained and assigned to users using the Implementation Guide
  • B. The structural profile determines the access mode which the user can perform
  • C. The structural profile determines the accessible object in the organizational structure
  • D. The structural profile is maintained and assigned to users using the Profile Generator

Answer: A,C


NEW QUESTION # 42
You are evaluating the "Cross-client object change" option using transact on SCC4 for your Unit Test Client in the development environment. Which setting do you recommend?

  • A. No changes to repository and cross-client customizing objects
  • B. No changes to repository objects
  • C. No changes to cross-client customizing objects
  • D. Changes to repository and cross-client customizing allowed

Answer: A


NEW QUESTION # 43
To prevent session fixation and session hijacking attacks, SAP's HTTP security session management is highly recommended. What are the characteristics of HTTP security session management? Note: There are 2 correct answers to this question.

  • A. The security sessions are created during logon and deleted during logoff.
  • B. The system is checking the logon credentials again for every request
  • C. It uses URLs containing sap-context d to identify the security session
  • D. The session identifier is a reference to the session context transmitted through a cookie.

Answer: A,D


NEW QUESTION # 44
What must be included in a PFCG role for an end user on the Fiori front-end server to run an app?

  • A. The group assignment to display it in the Fiori Launchpad
  • B. The catalog assignment for the start authorization
  • C. The S_START authorization object for starting the OData service
  • D. The S_RFC authorization object for the OData access

Answer: B

Explanation:
Explanation
This must be included in a PFCG role for an end user on the Fiori front-end server to run an app. The catalog assignment for the start authorization defines which apps can be started by the user from the Fiori Launchpad.
The catalog assignment is done using the authorization object S_CTS_ADMI with field CTS_ADMI_RUN = SAP_CATALOG_ALL. References:
https://help.sap.com/viewer/a7b390faab1140c087b8926571e942b7/7.5.9/en-US/5c3d6d0f6c461014a1d99bc8a4f
https://help.sap.com/viewer/a7b390faab1140c087b8926571e942b7/7.5.9/en-US/5c3d6d0f6c461014a1d99bc8a4f


NEW QUESTION # 45
Which OData authorizations are required for a user to see business data in the SAP Fiori Launchpad? Note: There are 2 correct answers to this question.

  • A. Access authorization in the SAP Fiori front-end system
  • B. Access authorization in the SAP S/4HANA back-end system
  • C. Start authorization in the SAP S/4HANA back-end system
  • D. Start authorization in the SAP Fiori front-end system

Answer: A,B

Explanation:
Explanation
These are some of the OData authorizations that are required for a user to see business data in the SAP Fiori Launchpad. OData (Open Data Protocol) is a protocol that enables CRUD (Create, Read, Update, Delete) operations on data using RESTful web services. SAP Fiori Launchpad is a web-based tool that provides access to various SAP Fiori applications and functions. SAP S/4HANA is an ERP (Enterprise Resource Planning) system that provides various business processes and functions. To see business data in the SAP Fiori Launchpad, the user needs to have access authorization in both the SAP Fiori front-end system, which handles the OData requests and responses between the user's browser and the back-end system, and the SAP S/4HANA back-end system, which contains the business logic and data access for the OData services.
References:
https://help.sap.com/viewer/a7b390faab1140c087b8926571e942b7/7.5.9/en-US/5c3d6d0f6c461014a1d99bc8a4f


NEW QUESTION # 46
Which authorizations are required for an SAP Fiori Launchpad user? Note: There are 2 correct answers to this question

  • A. /UI2/CHIP
  • B. /UI2/PAGE_BUILDER_CUST
  • C. /UI2/INTEROP
  • D. /UI2/PAGE_BUILDER_PERS

Answer: C,D


NEW QUESTION # 47
In addition to the authorization /UI2/LAUNCHPAD, which other authorizations are required to assign to an SAP Fiori Launchpad user? Note: There are 2 correct answers to this question.

  • A. /UI2JPAGE_BUILDER_CUST
  • B. /U12/INTEROP
  • C. /U12JPAGE_BUILDER_PERS
  • D. /UI2/FLC

Answer: B,C


NEW QUESTION # 48
You are running an SAP HANA database in a multi database container (MDC) mode with a single tenant configured. The global_auditing_state parameter has been set to "true" on the global.ini.After restarting the system and tenant databases, the tenant did not come up. When checking the cause, it was discovered that a tenant configuration parameter has been changed. The audit logging did NOT show any events.What could be the reason for this? Note: There are 2 correct answers to this question.

  • A. The system was offline when the changes were done
  • B. The configuration parameter was changed from the OS level
  • C. The audit level was set to INFO
  • D. The global_auditing_state parameter on the nameserver.ini file needs to be activated

Answer: B,D


NEW QUESTION # 49
How would you control access to the ABAP RFC function modules? Note: There are 2 correct answers to this question.

  • A. O Implement UCON functionality
  • B. O Block RFC Callback Whitelists
  • C. O Deactivate switchable authorization checks
  • D. O Restrict RFC authorizations

Answer: C,D


NEW QUESTION # 50
Who can revoke a runtime role from a user in the SAP HANA tenant database? Note: There are 2 correct answers to this question. Note: there are 2 correct answers to this question.

  • A. The owner of the HDI container
  • B. The DBACOCKPIT user
  • C. The grating user
  • D. Anyone with "ROLE ADMIN"

Answer: C,D


NEW QUESTION # 51
What can you maintain in transaction SU24 to reduce the overall maintenance in PFCG? Note:
There are 3 correct answers to this question.

  • A. The default values so they are appropriate for the transactions used in the roles
  • B. The authorization objects that have unacceptable default values
  • C. The authorization objects that are not linked to transaction codes correctly
  • D. The default authority check settings for the role maintenance tool
  • E. The default values in the tables USOBX and USOBT

Answer: A,B,D

Explanation:
Explanation
You can maintain these aspects in transaction SU24 to reduce the overall maintenance in PFCG. By doing so, you can define which authorization objects are checked by default for each transaction code, what values are proposed for each authorization field, and which authorization objects are excluded from the proposal. This way, you can avoid manual adjustments in PFCG and ensure consistency across roles. References:
https://help.sap.com/viewer/df185fd53bb645b1bd99284ee4e4a750/7.5.21/en-US/4a0c1f51bb571014e10000000a
https://help.sap.com/viewer/df185fd53bb645b1bd99284ee4e4a750/7.5.21/en-US/4a0c1f51bb571014e10000000a


NEW QUESTION # 52
You have delimited a single role that is part of a composite role, and a user comparison for the composite role has been performed. You notice that the comparation did NOT.... profile assignments for that single role. What program would you run to resolve this situation?

  • A. PRGN_COMPARE_ROLE_MENU
  • B. PRGN_MERGE_PREVIEW
  • C. PRGN_DELETE_ACTIVITY_GROUPS
  • D. PRGN_COMPRESS_TIMES

Answer: D


NEW QUESTION # 53
You want to configure SNC with X.509 certificates using Common CryptoLib as the cryptographic library in a new installed AS ABAP system. Besides running SNCWIZARD, what do you need to set up for this scenario? Note: There are 2 correct answers to this question.

  • A. Maintain the relevant CCL/SNC/' profile parameters
  • B. Set the environment variable CCL_ PROFILE to the default profile file path
  • C. Set the environment variable CCL_ PROFILE to SECUDIR
  • D. Set the CCL SNC parameters using sapgenpse

Answer: A,B


NEW QUESTION # 54
What are characteristics of SAP HANA Deployment Infrastructure (HDI) roles? Note: there are 2 correct answers to this question.

  • A. They are transportable between systems
  • B. They are granted using database procedures
  • C. They are owned by the user who creates them
  • D. They are managed by the native HDI version control.

Answer: B,D


NEW QUESTION # 55
Which transaction or report can be used to audit profile assignments in an SU01 user master record? Note: There are 2 correct answers to this question

  • A. ST01
  • B. SM20N
  • C. RSUSR002
  • D. RSUSR100

Answer: C,D


NEW QUESTION # 56
You want to create an SAP Fiori app for multiple users and multiple back-end systems. To support this, you create different roles for the different back-end systems in the SAP Fiori front-end system (central hub). What transaction do you have to use to map a back-end system to one of those roles?

  • A. /IWFND/MAINT_SERVICE
  • B. SM59
  • C. PFCG
  • D. /UI2/GW_SYS_ALIAS

Answer: C


NEW QUESTION # 57
You are using the SAP Web Dispatcher for load-balancing purposes. Which actions are performed by the SAP Web Dispatcher in this scenario? Note: There are 2 correct answers to this question.

  • A. Decrypts the HTTPS request and then selects the server
  • B. Authenticates the user's credentials
  • C. Uses SAP logon groups to determine which requests are directed to which server
  • D. Checks current state of the message server

Answer: C,D


NEW QUESTION # 58
What are the key capabilities of Enterprise Threat Detection? Note: There are 2 correct answers to this question.

  • A. Predictive threat notification
  • B. Dashboard-based analysis for security risks
  • C. Blocking user access
  • D. Real time capture of abnormal user activities

Answer: B,D

Explanation:
Explanation
Enterprise Threat Detection is a security solution that provides dashboard-based analysis for security risks and real time capture of abnormal user activities. It enables you to monitor and detect cyberattacks and internal fraud by analyzing log data from various sources, such as SAP systems, operating systems, databases, firewalls, and routers. References:
https://help.sap.com/viewer/product/SAP_ENTERPRISE_THREAT_DETECTION/en-US
https://help.sap.com/viewer/product/SAP_ENTERPRISE_THREAT_DETECTION/en-US


NEW QUESTION # 59
What are main characteristics of the Logon ticket throughout an SSO logon procedure? Note: There are 2 correct answers to this question

  • A. The Logon ticket is not domain restricted
  • B. The Logon ticket is sued for user-to-system communication
  • C. The Logon ticket is always set to client 000
  • D. The Logon ticket session is held in the working memory

Answer: A,B


NEW QUESTION # 60
For which reasons would you choose an "anonymous SSL Client PSE" setup? Note: There are
2 correct answers to this question.

  • A. To perform mutual authentication
  • B. To use as a container for the CAs
  • C. To perform authentication
  • D. To use data encryption

Answer: B,D

Explanation:
Explanation
These are some of the reasons why you would choose an "anonymous SSL Client PSE" setup in SAP systems.
An anonymous SSL Client PSE is a PSE that does not contain any client certificates or keys, but only contains certificates of trusted certificate authorities (CAs). It can be used to establish SSL connections with servers that do not require client authentication, but only use data encryption to protect the communication. It can also be used as a container for storing the CAs that are trusted by the client. References:
https://help.sap.com/doc/saphelp_nw70ehp3/7.03/en-US/c8/e8d53d35fb11d182b90000e829fbfe/content.htm?no_
https://help.sap.com/doc/saphelp_nw70ehp3/7.03/en-US/c8/e8d53d35fb11d182b90000e829fbfe/content.htm?no_


NEW QUESTION # 61
A security consultant has activated a trace via ST01 and is analyzing the authorization error with Return Code 12. What does the Return Code 12 signify?

  • A. "Objects not contained in User Buffer"
  • B. "No authorizations and does NOT have authorization object in their buffer"
  • C. "Too many parameters for authorization checks"
  • D. "No authorizations but does have authorization object in their buffer"

Answer: D


NEW QUESTION # 62
Which measures should we implement to protect the PSEs? Note: There are 2 correct answers to this question.

  • A. Restrict access to the operating system users
  • B. Review the usage of the S_DATASET object
  • C. Encrypt the files with the transaction SNC0
  • D. Review the usage of the S_ADMI_FCD object

Answer: A,D

Explanation:
Explanation
These are some of the measures that should be implemented to protect the PSEs (Personal Security Environments). PSEs are files that store cryptographic information, such as keys and certificates, for various security purposes, such as SSL, SNC, or SSO. The usage of the S_ADMI_FCD object should be reviewed because it controls the access to PSE administration functions, such as creating, deleting, or displaying PSEs.
The access to the operating system users should be restricted because they can access the PSE files directly from the file system and manipulate them. References:
https://help.sap.com/doc/saphelp_nw70ehp3/7.03/en-US/c8/e8d53d35fb11d182b90000e829fbfe/content.htm?no_
https://help.sap.com/doc/saphelp_nw70ehp3/7.03/en-US/c8/e8d53d35fb11d182b90000e829fbfe/content.htm?no_


NEW QUESTION # 63
How does the SAP SSO wizard (transaction SNCWIZARD) simplify the SNC configuration process?

  • A. It exports an SNC SAPCRYPTOLIB certificate and imports it into the partner system
  • B. It creates the SNC_LIB environment variable
  • C. It installs the CA certificate response
  • D. It sets the profile parameters for SAP SNC and SPNego in the default profile

Answer: D


NEW QUESTION # 64
What is required when you configure the PFCG role for an end-user on the front-end server? Note: There are 2 correct answers to this question.

  • A. The group assignment to display it in the Fiori Launchpad
  • B. The Fiori Launchpad designer assignment
  • C. The catalog assignment for the start authorization
  • D. The S_RFC authorization object for the OData access

Answer: C


NEW QUESTION # 65
What are characteristics only valid for the MDC high isolation mode?

  • A. Every tenant has its own set of database users belonging to the same sapsys group
  • B. All internal database communication is secured using SNC
  • C. Every tenant has its own set of database users
  • D. Every tenant has its own set of OS users

Answer: D


NEW QUESTION # 66
......


SAP P_SECAUTH_21 certification is an excellent opportunity for individuals who want to specialize in SAP system security architecture. It validates the candidate's knowledge and skills in securing SAP systems, and it is recognized globally by employers. Certified Technology Professional - System Security Architect certification opens up various career opportunities in SAP system security, making it a valuable investment for professionals seeking to advance their careers.

 

P-SECAUTH-21 dumps Free Test Engine Verified By It Certified Experts: https://realexamcollection.examslabs.com/SAP/SAP-Certified-Technology-Professional/best-P-SECAUTH-21-exam-dumps.html