P-SECAUTH-21 Dumps 2024 New SAP P-SECAUTH-21 Exam Questions [Q20-Q41]

Share

P-SECAUTH-21 Dumps 2024 - New SAP P-SECAUTH-21 Exam Questions

Free P-SECAUTH-21 braindumps download (P-SECAUTH-21 exam dumps Free Updated)

NEW QUESTION # 20
How would you control access to the ABAP RFC function modules? Note: There are 2 correct answers to this question.

  • A. O Restrict RFC authorizations
  • B. O Deactivate switchable authorization checks
  • C. O Block RFC Callback Whitelists
  • D. O Implement UCON functionality

Answer: A,B


NEW QUESTION # 21
Which basis transaction provides an optimized user interface for evaluating authorization checks only?

  • A. RSECADMIN
  • B. ST01
  • C. STAUTHTRACE
  • D. ABAP_TRACE

Answer: C


NEW QUESTION # 22
Which features does SAProuter provide?
Note: There are 2 correct answers to this question

  • A. Load-balanced RFC connections
  • B. HTTP conversion into HTTPS connections
  • C. Password-protected connections
  • D. Filtered and logged network connections

Answer: C,D


NEW QUESTION # 23
You have created an RFC destination with a registered external RFC server program. When you try to connect to the external RFC destination you receive a
"SERVER_NOT_REGISTERED" error message. How can you resolve the issue? Note: There are 2 correct answers to this question.

  • A. Maintain the entries in the SECINFO file
  • B. Maintain the access list in the transaction SMMS
  • C. Maintain the profile parameter gw/acl_mode = 0
  • D. Maintain the entries in the REGINFO file

Answer: B,D

Explanation:
Explanation
These are some of the tasks that you would perform to resolve the issue of a
"SERVER_NOT_REGISTERED" error message when trying to connect to an external RFC destination with a registered external RFC server program. The REGINFO file is a file that contains rules for allowing or denying registration requests from external RFC server programs to the gateway of an SAP system. The access list in transaction SMMS is a list that contains rules for allowing or denying connection requests from external RFC clients to an SAP system. References:
https://help.sap.com/doc/saphelp_nw70ehp3/7.03/en-US/c8/e8d53d35fb11d182b90000e829fbfe/content.htm?no_


NEW QUESTION # 24
What are the requirements of SPNego SSO configuration in an SAP Fiori front-end system? Note: There are 2 correct answers to this question.

  • A. The system requires an identity provider as an issuing system to enable single sign-on with SPNego in an internet-facing deployment scenario.
  • B. The system's users in the ABAP system must have the same user names as the database users in SAP HANA
  • C. The system should typically be located within the corporate network.
  • D. The system requires Microsoft Active Directory infrastructure in place.

Answer: C,D


NEW QUESTION # 25
Which authorization object is required to support trusted system access by an RFC user following the configuration of a Managed System in SAP Solution Manager?

  • A. S_ACL_HIST
  • B. S_RFCACL
  • C. S_RFC_TT
  • D. S_RFC_TTAC

Answer: B

Explanation:
Explanation
Authorization object S_RFCACL is required to support trusted system access by an RFC user following the configuration of a Managed System in SAP Solution Manager. This authorization object allows you to restrict access to RFC calls from trusted systems based on the RFC user name and the name of the calling system.
References:
https://help.sap.com/viewer/bf82e6b26456494cbdd197057c09979f/7.2.10/en-US/4a0c1f51bb571014e10000000a
https://help.sap.com/viewer/bf82e6b26456494cbdd197057c09979f/7.2.10/en-US/4a0c1f51bb571014e10000000a


NEW QUESTION # 26
Currently, transports into your SAP system are not scanned automatically. To avoid the import of non-secure programs, you have implemented the strategy to set up a virus scanner using a script to automatically scan for the malicious programs. What is the valid fi e format where data files are first converted into and then checked by a virus scanner?

  • A. Plain text
  • B. 0csv
  • C. SAP compressed
  • D. XML

Answer: D


NEW QUESTION # 27
What is required when you configure the PFCG role for an end-user on the front-end server? Note: There are 2 correct answers to this question.

  • A. The catalog assignment for the start authorization
  • B. The group assignment to display it in the Fiori Launchpad
  • C. The S_RFC authorization object for the OData access
  • D. The Fiori Launchpad designer assignment

Answer: A,B


NEW QUESTION # 28
The security administrator is troubleshooting authorization errors using transaction SU53. While running transaction MM50, the user received the following error: "You are not authorized to use transaction MM01" The users position in the organization makes it inappropriate for them to have direct access to transaction MM01 because it creates a Segregation of Duties conflict.
What would cause the system to run an authority check using object S_TCODE for transaction MM01 while running transaction MM50?

  • A. The instance parameter auth/no_check_in_some_cases has been set to Y
  • B. The proposal value for the object S_TCODE in the SU24 data for transaction MM50 was incorrectly set to YES
  • C. MM01 was maintained as the CALLING transaction in table TCDCOUPLES with field OKFLAG value X
  • D. The developer who wrote the program for transaction MM50 issues the ABAL command CALL TRANSACTION for transaction MM01

Answer: D


NEW QUESTION # 29
What information constitutes an indirect connection to an individual, in the context of GDPR?
Note: There are 3 correct answers to this question.

  • A. National Identifier
  • B. Date of Birth
  • C. Postal Address
  • D. License plate number
  • E. IP Address

Answer: B,D,E

Explanation:
Explanation
These are some of the information that constitutes an indirect connection to an individual, in the context of GDPR (General Data Protection Regulation). GDPR is a regulation that aims to protect the privacy and personal data of individuals in the European Union (EU) and the European Economic Area (EEA). Personal data is any information that relates to an identified or identifiable individual, either directly or indirectly. An indirect connection means that the information can be used in combination with other information or identifiers to identify an individual. Examples of such information are IP address, license plate number, date of birth, location data, or online identifiers. References: https://gdpr-info.eu/art-4-gdpr/
https://gdpr-info.eu/art-4-gdpr/


NEW QUESTION # 30
What authorization object is checked when a user selects an ABAP Web Dynpro application to run?

  • A. S_TCODE
  • B. S_SERVICE
  • C. S_START
  • D. S_PROGRAM

Answer: B

Explanation:
Explanation
The authorization object S_SERVICE is checked when a user selects an ABAP Web Dynpro application to run. This authorization object controls the access to Web services and Web Dynpro applications based on the service name and type. References:
https://help.sap.com/doc/saphelp_nw70ehp3/7.03/en-US/c8/e8d53d35fb11d182b90000e829fbfe/content.htm?no_
https://help.sap.com/doc/saphelp_nw70ehp3/7.03/en-US/c8/e8d53d35fb11d182b90000e829fbfe/content.htm?no_


NEW QUESTION # 31
What are the characteristics of assertion tickets? Note: There are 2 correct answers to this question.

  • A. They are used for system-to-system communication
  • B. They are transmitted as cookies
  • C. They are used for user-to-system trusted login
  • D. They have an unconfigurable validity of 2 minutes

Answer: A,D


NEW QUESTION # 32
Where can you store Security Audit Log Events? Note: There are 2 correct answers to this question.

  • A. In the Linux system log
  • B. In the database table RSAU_BUF_DATA
  • C. Ip the file system of the application servers
  • D. In the kernel trace

Answer: B,C


NEW QUESTION # 33
Which authorizations should you restrict when you create a developer role in an AS ABAP production system? Note: There are 2 correct answers to this question.

  • A. The ability to run queries through authorization object S_QUERY
  • B. The ability to use the ABAP Debugger through authorization object S_DEVELOP
  • C. The ability to run class methods through authorization object S_PROGRAM
  • D. The ability to run function modules through authorization object S_DEVELOP

Answer: B,D

Explanation:
Explanation
Developers should not be able to use the ABAP Debugger or run function modules in a production system, as these actions could compromise the system integrity and security. Authorization object S_DEVELOP controls both these activities and should be restricted for developers in a production system. References:
https://help.sap.com/viewer/68bf513362174d54b58cddec28794093/7.5.20/en-US/4a0c1f51bb571014e10000000
https://help.sap.com/viewer/68bf513362174d54b58cddec28794093/7.5.20/en-US/4a0c1f51bb571014e10000000


NEW QUESTION # 34
A user reports an issue with data not showing up in the visualization of the SAP Fiori tiles. You want to verify the target mapping. At what level are you going to check the target mapping?

  • A. O At the catalog level in the SAP Fiori front-end server
  • B. O At the application level in the Web IDE
  • C. O At the group level in the SAP Fiori Launchpad
  • D. O At the group level in the SAP Fiori front-end server

Answer: A


NEW QUESTION # 35
You are setting up your SAP NetWeaver AS in a SSL client scenario. What are the reasons to choose an "anonymous SSL Client PSE" setup?
Note: There are 2 correct answers to this question.

  • A. To support mutual authentication
  • B. To use as a container for the list of CAs that the server trusts
  • C. To have an individual identity when accessing a specific application
  • D. To support server-side authentication and data encryption

Answer: B,D


NEW QUESTION # 36
The SAP HANA database is installed with multi database container (MDC) mode with multiple tenant databases configured. What are the required activities to enable access between tenants? Note: There are 2 correct answers to this question.

  • A. Create user mapping between local and remote tenant databases
  • B. Set whitelist of cross-tenant database communication channel
  • C. Decrease the level of isolation mode on all MDC tenants
  • D. Configure smart data access (SDA) between the relevant HANA tenants

Answer: A,B


NEW QUESTION # 37
How can you describe static and dynamic assignments? Note: There are 2 correct answers to this question

  • A. Dynamic assignments are based on attribute values
  • B. Static assignments occur at runtime
  • C. Dynamic assignments are based on scope values
  • D. Static assignments are set up via the Cloud Cockpit

Answer: A,D


NEW QUESTION # 38
You want to configure SNC in a newly-installed AS ABAP based SAP system. Besides running SNCWIZARD, what else do you need to perform for this scenario?
Note: There are 2 correct answers to this question

  • A. Enable encrypted HTTP service
  • B. Restart the SAP system
  • C. Set the parameters using sapgenpse
  • D. Manage the PSE

Answer: B,D


NEW QUESTION # 39
You verified the password of the TMSADM user in your SAP landscape to be SAP defaulted. You want to reset this password by using program TMS_UPDATE_PWD_OF_TMSADM. What steps would you take to reset this password?
Note: There are 2 correct answers to this question

  • A. Lock TMSADM in all the system/clients including 000
  • B. Deactivate the SNC option
  • C. Assign "SAP_ALL" to TMSADM in all systems/clients including 000
  • D. Run this program in the Domain Controller (client 000)

Answer: B,D


NEW QUESTION # 40
What are characteristics of SAP HANA Deployment Infrastructure (HDI) roles? Note: there are 2 correct answers to this question.

  • A. They are managed by the native HDI version control.
  • B. They are transportable between systems
  • C. They are granted using database procedures
  • D. They are owned by the user who creates them

Answer: A,C


NEW QUESTION # 41
......


SAP P-SECAUTH-21 exam is designed to test the knowledge and expertise of professionals in the field of system security architecture. As an SAP Certified Technology Professional, individuals who pass P-SECAUTH-21 exam are recognized as experts in the design and implementation of secure SAP systems. Certified Technology Professional - System Security Architect certification validates the knowledge and skills required to secure SAP systems and maintain the confidentiality, integrity, and availability of data.

 

Verified P-SECAUTH-21 dumps Q&As - Pass Guarantee Exam Dumps Test Engine: https://pass4sure.practicetorrent.com/P-SECAUTH-21-practice-exam-torrent.html