All Obstacles During P-SECAUTH-21 Exam Preparation with P-SECAUTH-21 Real Test Questions [Q33-Q48]

Share

All Obstacles During P-SECAUTH-21 Exam Preparation with P-SECAUTH-21 Real Test Questions

Fully Updated Free Actual SAP P-SECAUTH-21 Exam Questions

NEW QUESTION # 33
Based on your company guidelines you have set the password expiration to 60 days. Unfortunately, there is an RFC user in your SAP system who must not have a password change for 180 days. Which option would you recommend to accomplish such a request?

  • A. Change the profile parameter login/password_expiration_time to 180
  • B. Define the RFC user as a reference user
  • C. Create an enhancement spot or user exit
  • D. Create a security policy via SECPOL and assign it to the RFC user

Answer: D


NEW QUESTION # 34
How are security relevant objects related in the Cloud Foundry?Note: There are 2 correct answers to this question.

  • A. Role Collections have 0 or many role templates.
  • B. Role Templates have 1 or many scopes.
  • C. Role Collections have 0 or many roles.
  • D. Role Templates have 0 or many attributes.

Answer: A,C

Explanation:
Explanation
These are some of the ways that security relevant objects are related in the Cloud Foundry. Cloud Foundry is a platform-as-a-service (PaaS) that enables developers to deploy and run cloud-native applications using various services and frameworks. Cloud Foundry uses different security relevant objects to manage user access and authorization, such as role collections, roles, role templates, and scopes. Role collections are groups of roles that can be assigned to users or groups. Roles are sets of permissions that define what actions users can perform on resources or services. Role templates are predefined roles that can be reused for different role collections or services. Scopes are strings that represent specific permissions or attributes of a user or service.
References:
https://help.sap.com/viewer/65de2977205c403bbc107264b8eccf4b/Cloud/en-US/9e1bf57130ef466e8017eab298


NEW QUESTION # 35
You are setting up your SAP NetWeaver AS in a SSL client scenario. What are the reasons to choose an "anonymous SSL Client PSE" setup?
Note: There are 2 correct answers to this question.

  • A. To use as a container for the list of CAs that the server trusts
  • B. To support server-side authentication and data encryption
  • C. To support mutual authentication
  • D. To have an individual identity when accessing a specific application

Answer: A,B


NEW QUESTION # 36
You are evaluating the "Cross-client object change" option using transaction SCC4 for your Unit Test Client in the development environment. Which setting do you recommend?

  • A. No changes to cross-client customizing objects
  • B. No changes to repository and cross-client customizing objects
  • C. Changes to repository and cross-client customizing allowed
  • D. No changes to repository objects

Answer: C

Explanation:
Explanation
This is the recommended setting for the "Cross-client object change" option using transaction SCC4 for your Unit Test Client in the development environment. This setting allows you to make changes to repository objects (such as programs, function modules, classes, etc.) and cross-client customizing objects (such as number ranges, message classes, etc.) in your Unit Test Client without affecting other clients in the same system. References:
https://help.sap.com/doc/saphelp_nw70ehp3/7.03/en-US/c8/e8d53d35fb11d182b90000e829fbfe/content.htm?no_
https://help.sap.com/doc/saphelp_nw70ehp3/7.03/en-US/c8/e8d53d35fb11d182b90000e829fbfe/content.htm?no_


NEW QUESTION # 37
You have Reason Codes already defined. Which is the correct sequence of steps to configure a Firefighter ID in Emergency Access Management?

  • A. Maintain an Owner for a Firefighter ID
    Maintain a Firefighter ID for Controllers and Firefighters
    Maintain Access Control Owner
  • B. Maintain an Owner for a Firefighter ID
    Maintain a Firefighter ID for Controllers and Firefighters
    Maintain Access Control Owner
  • C. Maintain an Owner for a Firefighter ID
    Maintain a Firefighter ID for Controllers and Firefighters
    Maintain Access Control Owner
  • D. Maintain a Firefighter ID for Controllers and Firefighters
    Maintain an Owner for a Firefighter ID
    Maintain Access Control Owner

Answer: C


NEW QUESTION # 38
How can you register an SAP Gateway service? Note: There are 2 correct answers to this question.

  • A. Use transaction /IWFND/MA INT_SERVICE on the front-end server
  • B. Use transaction SEGW on the back-end server
  • C. Use SAP_GAT EWAY_BASIC_CONFIG in transact on STCO 1 on the frontend server
  • D. Use SAP_GAT EWAY_ACTIVATE_ODATA_SERV in transact on STC01 on the front-end server

Answer: A,B


NEW QUESTION # 39
How would you control access to ABAP RFC function modules? Note: There are 2 correct answers to this question.

  • A. Deactivate switchable authorization checks
  • B. Implement UCON functionality
  • C. Block RFC Callback Whitelists
  • D. Restrict RFC authorizations

Answer: B,D

Explanation:
Explanation
These are some of the functions that can be used to control access to ABAP RFC function modules in an SAP system. RFC (Remote Function Call) is a protocol that enables communication and data exchange between SAP systems and components using function modules. ABAP RFC function modules are function modules that are written in ABAP language and can be called remotely by other systems or components. UCON (Unified Connectivity) is a feature that allows you to monitor and restrict RFC calls based on various criteria, such as source system, target system, user, or function module. RFC authorizations are authorizations that control access to RFC function modules based on authorization objects, such as S_RFC or S_RFCACL.
References:
https://help.sap.com/doc/saphelp_nw73ehp1/7.31.19/en-US/48/9e2e3f6f8e41e8a283aaf2ad2c64c4/content.htm?n


NEW QUESTION # 40
You want to create an SAP Fiori app for multiple users and multiple back-end systems. To support this, you create different roles for the different back-end systems in the SAP Fiori front-end system (central hub). What transaction do you have to use to map a back-end system to one of those roles?

  • A. SEGW
  • B. PFCG
  • C. /UI2/GW_SYS_ALIAS
  • D. /IWFND/MAINT_SERVICE

Answer: C

Explanation:
Explanation
This is one of the transactions that you have to use to map a back-end system to one of those roles for creating an SAP Fiori app for multiple users and multiple back-end systems in an SAP Fiori front-end system (central hub). /UI2/GW_SYS_ALIAS is a transaction that allows you to create and maintain gateway system aliases for OData services in an SAP Fiori front-end system (central hub), which is a system that handles OData requests and responses between the user's browser and the back-end systems. A gateway system alias is a name that represents a connection to a specific back-end system or service. You can assign different gateway system aliases to different roles in the SAP Fiori front-end system to map them to different back-end systems or services. References:
https://help.sap.com/viewer/a7b390faab1140c087b8926571e942b7/7.5.9/en-US/5c3d6d0f6c461014a1d99bc8a4f


NEW QUESTION # 41
Which users should exist in client 000?
Note: There are 2 correct answers to this question

  • A. SAP*
  • B. TMSADM
  • C. SAPCPIC
  • D. EARLYWATCH

Answer: A,D


NEW QUESTION # 42
What are some characteristics of an SAP HANA multitenant database system (MDC) running in high isolation mode? Note: There are 2 correct answers to this question.

  • A. All tenant databases will share the operating system user and group.
  • B. All tenant-specific file and directory permissions are managed by the SAP HANA system
  • C. The <sid>adm user can access the tenant-specific configuration and trace files.
  • D. All tenant-specific permissions to access files and directories are revoked from the
    <sid>adm user.

Answer: B,D

Explanation:
Explanation
These are some of the characteristics of an SAP HANA multitenant database system (MDC) running in high isolation mode. MDC is a feature that allows you to run multiple databases on one SAP HANA system, each with its own users, catalog, repository, data, and services. High isolation mode is a mode that provides enhanced security and isolation for tenant databases by restricting access to files and directories at the operating system level. In high isolation mode, all tenant-specific permissions to access files and directories are revoked from the <sid>adm user, which is the operating system user for SAP HANA administration. All tenant-specific file and directory permissions are managed by the SAP HANA system using internal users and groups. References: https://help.sap.com/viewer/6b94445c94ae495c83a1


NEW QUESTION # 43
How are assertion tickets used?

  • A. They are used for encrypting Web service communication.
  • B. They are used for system-to-system encryption.
  • C. They are used for system-to-system communication.
  • D. They are used for user-to-system trusted login.

Answer: C

Explanation:
Explanation
Assertion tickets are used for system-to-system communication in SAP systems. They are based on the SAML (Security Assertion Markup Language) standard and contain information about the identity and attributes of a user or a system. Assertion tickets can be used to establish trust relationships between systems and enable single sign-on scenarios. References:
https://help.sap.com/doc/saphelp_nw70ehp3/7.03/en-US/c8/e8d53d35fb11d182b90000e829fbfe/content.htm?no_
https://help.sap.com/doc/saphelp_nw70ehp3/7.03/en-US/c8/e8d53d35fb11d182b90000e829fbfe/content.htm?no_


NEW QUESTION # 44
You have delimited a single role that is part of a composite role, and a user comparison for the composite role has been performed. You notice that the comparison did NOT remove the profile assignments for that single role. What program would you run to resolve this situation?

  • A. PRGN_COMPARE_ROLE_MENU
  • B. PRGN_COMPRESS_TIMES
  • C. PRGN_DELETE_ACTIVITY_GROUPS
  • D. PRGN_MERGE_PREVIEW

Answer: C

Explanation:
Explanation
This is one of the programs that you would run to resolve this situation of not removing profile assignments for a single role after delimiting it and performing user comparison for its composite role. A single role is a role that contains authorizations for one application area or function. A composite role is a role that contains other roles as sub-roles without any authorizations by itself. A user comparison is a process that synchronizes user master records with role assignments and profile assignments in PFCG transaction.
PRGN_DELETE_ACTIVITY_GROUPS is a program that deletes single roles or composite roles from user master records along with their profile assignments. References:
https://help.sap.com/doc/saphelp_nw73ehp1/7.31.19/en-US/c8/e8d53d35fb11d182b90000e829fbfe/content.htm?


NEW QUESTION # 45
Which type of systems can be found in the Identity Provisioning Service landscape? Note:
There are 2 correct answers to this question.

  • A. Identity Provider
  • B. Proxy
  • C. Source
  • D. Service Provider

Answer: C,D

Explanation:
Explanation
Source and Service Provider are two types of systems that can be found in the Identity Provisioning Service landscape. A source system is a system that provides user data to be provisioned to other systems, such as an identity provider or an LDAP server. A service provider system is a system that receives user data from a source system, such as an SAP Cloud Platform subaccount or an SAP SuccessFactors instance. References:
https://help.sap.com/viewer/product/SAP_CLOUD_PLATFORM_IDENTITY_PROVISIONING_SERVICE/en-
https://help.sap.com/viewer/product/SAP_CLOUD_PLATFORM_IDENTITY_PROVISIONING_SERVICE/en-


NEW QUESTION # 46
Which of the following functions can be used to troubleshoot authorization errors for ABAP CDS views with Authorization based on Access Control?

  • A. E2E TRACE ANALYSIS
  • B. STAUTHTRACE
  • C. REPORT RSUSR008_009
  • D. ABAP TRACE

Answer: B

Explanation:
Explanation
This is one of the functions that can be used to troubleshoot authorization errors for ABAP CDS views with Authorization based on Access Control (ABAC). ABAP CDS (Core Data Services) views are views that define data models and queries using SQL statements and annotations in ABAP Dictionary. ABAC is a feature that allows you to restrict access to data in ABAP CDS views based on certain conditions or filters using DCL (Data Control Language) statements and expressions. STAUTHTRACE is a transaction that allows you to activate and display authorization traces for users or sessions, which show detailed information about authorization checks and results for ABAP CDS views with ABAC. References:
https://help.sap.com/doc/saphelp_nw73ehp1/7.31.19/en-US/c8/e8d53d35fb11d182b90000e829fbfe/content.htm?


NEW QUESTION # 47
What are the requirements of SPNego SSO configuration in an SAP Fiori front-end system? Note: There are 2 correct answers to this question.

  • A. The system requires Microsoft Active Directory infrastructure in place.
  • B. The system requires an identity provider as an issuing system to enable single sign-on with SPNego in an internet-facing deployment scenario.
  • C. The system's users in the ABAP system must have the same user names as the database users in SAP HANA
  • D. The system should typically be located within the corporate network.

Answer: A,D


NEW QUESTION # 48
......


SAP P_SECAUTH_21 certification exam is designed for professionals who are interested in becoming certified technology professionals specializing in system security architecture. Certified Technology Professional - System Security Architect certification exam is aimed at individuals who have a good understanding of SAP technology and want to extend their knowledge to the field of system security architecture.

 

Validate your P-SECAUTH-21 Exam Preparation with P-SECAUTH-21 Practice Test: https://realexamcollection.examslabs.com/SAP/SAP-Certified-Technology-Professional/best-P-SECAUTH-21-exam-dumps.html