Updated SAP P_SECAUTH_21 Dumps – Check Free P_SECAUTH_21 Exam Dumps (2023) [Q27-Q50]

Share

Updated SAP P_SECAUTH_21 Dumps – Check Free P_SECAUTH_21 Exam Dumps (2023)

Updated P_SECAUTH_21 exam with SAP Real Exam Questions

NEW QUESTION # 27
Which transaction or report can be used to audit profile assignments in an SU01 user master record? Note: There are 2 correct answers to this question

  • A. RSUSR002
  • B. ST01
  • C. RSUSR100
  • D. SM20N

Answer: A,C


NEW QUESTION # 28
Which Object ID is used to integrate Business Rule Framework (BRF+) to Multi Step Multi Process (MSMP) initiator workflow?

  • A. Application ID
  • B. Function ID
  • C. Expression ID
  • D. Process ID

Answer: B


NEW QUESTION # 29
You have implemented CUA in your organization and you want to set the field distribution attribute as follows: Maintain a default value in the central system that is automatically distributed to the child systems when you create a user. After distribution, the data is maintained only locally and is no longer distributed if you change it in the central or child system. Which field distribution parameter do you maintain?

  • A. Global
  • B. Redistribution
  • C. Local
  • D. Proposal

Answer: D


NEW QUESTION # 30
Which users should exist in client 000? Note: There are 2 correct answers to this question.

  • A. TMSADM
  • B. SAP*
  • C. EARLYWATCH
  • D. SAPCPIC

Answer: A,B

Explanation:
Explanation
These are some of the users that should exist in client 000 of an SAP system. Client 000 is a special client that contains configuration data and tools for system administration and maintenance. TMSADM is a user that is used for Transport Management System (TMS) communication and administration. SAP* is a user that can be used to log on to any client with a predefined password if no other users exist or if all users are locked.
References:
https://help.sap.com/doc/saphelp_nw73ehp1/7.31.19/en-US/c8/e8d53d35fb11d182b90000e829fbfe/content.htm?


NEW QUESTION # 31
User1 grants role 1 to user2. Who can revoke role 1 role from user2?

  • A. The owner of role 1
  • B. Any user with the 'ROLE ADMIN' database role
  • C. Only User1
  • D. The system OBA user

Answer: B


NEW QUESTION # 32
You are using the SAP Web Dispatcher for load-balancing purposes. Which actions are performed by the SAP Web Dispatcher in this scenario? Note: There are 2 correct answers to this question.

  • A. Authenticates the user's credentials
  • B. Uses SAP logon groups to determine which requests are directed to which server
  • C. Checks current state of the message server
  • D. Decrypts the HTTPS request and then selects the server

Answer: B,C


NEW QUESTION # 33
An end user has indicated that they are getting an authorization error when attempting to call a Transaction Code (TCD). However, the TCD exists in their User Menu. What could be the issue and where would you check?

  • A. The TCD is assigned to the user via multiple roles; check in PFCG.
  • B. This user is blocked from calling the TCD; check in SM01 .
  • C. Additional authorization checks are required for the TC; check in SE93.
  • D. An entry in table USRBF prevents them from calling the TCD; check in SE1 6

Answer: C

Explanation:
Explanation
This could be the issue that causes the end user to get an authorization error when attempting to call a Transaction Code (TCD) that exists in their User Menu. SE93 is a transaction that allows you to create and maintain transaction codes and their properties. One of the properties is the authorization check, which determines whether additional authorization objects are checked when a transaction code is executed. If the authorization check for a transaction code is set to Yes, the user needs to have the corresponding authorization objects in their role or profile, otherwise they will get an error message. References:
https://help.sap.com/doc/saphelp_nw73ehp1/7.31.19/en-US/48/9e2e3f6f8e41e8a283aaf2ad2c64c4/content.htm?n


NEW QUESTION # 34
Which tasks would you perform to allow increased security for the SAP Web Dispatcher Web Administration Interface? Note: There are 2 correct answers to this question

  • A. Use subparameter ALLOWPUB = TRUE of the profile parameter icm/server_port_<xx>
  • B. Use Secure Socket Layer (SSL) for encrypted access
  • C. Use a separate port for the administration interface
  • D. Use access restrictions to the icm/HTTP/auth_<xx> profile parameter

Answer: A,C


NEW QUESTION # 35
You have implemented CUA in your organization and you only want to compare the company address data between the central system and child systems to perform the synchronization activities. Which transact on do you use for comparing the company address between these systems?

  • A. SCUG
  • B. SCUC
  • C. SUCOMP
  • D. SCUM

Answer: C


NEW QUESTION # 36
Which characteristics apply to the SAP ID Service? Note: There are 2 correct answers to this question.

  • A. Configurable password policy
  • B. User base owned and managed by SAP
  • C. Non-configurable MFA for SAP BTP Cockpit
  • D. Customizable user interface

Answer: A,B

Explanation:
Explanation
The SAP ID Service is a cloud-based identity provider that offers a configurable password policy and a user base owned and managed by SAP. The SAP ID Service is used to authenticate users for various SAP cloud applications and services, such as SAP Cloud Platform, SAP Analytics Cloud, and SAP Fiori Launchpad.
References: https://help.sap.com/viewer/product/SAP_ID_SERVICE/en-US
https://help.sap.com/viewer/product/SAP_ID_SERVICE/en-US


NEW QUESTION # 37
Why should you create multiple dispatchers in SAP Identity Management? Note: There are 2 correct answers to this question.

  • A. To handle password provisioning
  • B. To support fail-over scenarios
  • C. To accommodate scalability
  • D. To handle special network access requirements

Answer: C,D


NEW QUESTION # 38
Which communication protocols are supported by the SAP Cloud Connector? Note: There are 2 correct answers to this question

  • A. LDAP
  • B. NNTP
  • C. SNA
  • D. RFC

Answer: A,D


NEW QUESTION # 39
What is the SAP Best Practice to delete a security SAP role from the landscape running SAP systems?

  • A. Delete the SAP role using Profile Generator, and then put it in the transport
  • B. Delete the SAP role in all clients in all systems using Profile Generator
  • C. Delete the SAP role in all clients using Profile Generator
  • D. Transport the SAP role and delete the role using Profile Generator

Answer: A

Explanation:
Explanation
The SAP Best Practice to delete a security SAP role from the landscape running SAP systems is to delete the SAP role using Profile Generator (transaction PFCG), and then put it in a transport request that can be moved across systems using Change and Transport System (CTS). This way, you can ensure that the role is deleted consistently and completely from all systems. References:
https://help.sap.com/doc/saphelp_nw70ehp3/7.03/en-US/c8/e8d53d35fb11d182b90000e829fbfe/content.htm?no_
https://help.sap.com/doc/saphelp_nw70ehp3/7.03/en-US


NEW QUESTION # 40
You want to check the custom ABAP codes in your system for security vulnerabilities and you want to use the Code Vulnerability Analyzer (CVA) for carrying out these extended security checks. What needs to be done for this purpose? Note: There are 2 correct answers to this question.

  • A. Run CVA from the ABAP Trace
  • B. Run CVA from the ABAP Test Cockpit
  • C. Execute program RSLIN_SEC_LICENSE_SETUP
  • D. Execute transaction ST12 to start the analysis

Answer: A,B


NEW QUESTION # 41
Which of the following programs can be used to enable ALE Audit using the ALEAUD message type in the Customer Distribution Model and Partner Profiles? Note: There are 2 correct answers to this question.

  • A. RBDAPP01
  • B. RBDAUD01
  • C. RBDSTATE
  • D. RBDMIDOC

Answer: A,D

Explanation:
Explanation
These are some of the programs that can be used to enable ALE Audit using the ALEAUD message type in the Customer Distribution Model and Partner Profiles. ALE (Application Link Enabling) is a technology that enables distributed communication and data exchange between SAP systems and components. ALE Audit is a feature that allows you to monitor and verify the status and results of ALE processes, such as data distribution or message processing. ALEAUD is a message type that is used to send audit information from one system to another. RBDAPP01 is a program that processes inbound IDocs (Intermediate Documents), which are data containers for ALE messages. RBDMIDOC is a program that creates outbound IDocs based on change pointers, which are records of changes in application data. References:
https://help.sap.com/doc/saphelp_nw73ehp1/7.31.19/en-US/48/9e2e3f6f8e41e8a283aaf2ad2c64c4/content.htm?n


NEW QUESTION # 42
A system user created a User1 and a schema on the HANA database with some dat a. User2 is developing modelling views and requires access to objects in User1's schema. What needs to be done?

  • A. User1 should grant _SYS_REPO with SELECT WITH GRANT privilege
  • B. ROLE ADMIN needs to be granted to User2
  • C. User2 needs to be granted with the same roles like User1
  • D. System user should grant User2 with SELECT privilege to User 1schema

Answer: D


NEW QUESTION # 43
For which reasons would you choose an "anonymous SSL Client PSE" setup? Note: There are
2 correct answers to this question.

  • A. To perform authentication
  • B. To use data encryption
  • C. To perform mutual authentication
  • D. To use as a container for the CAs

Answer: B,D

Explanation:
Explanation
These are some of the reasons why you would choose an "anonymous SSL Client PSE" setup in SAP systems.
An anonymous SSL Client PSE is a PSE that does not contain any client certificates or keys, but only contains certificates of trusted certificate authorities (CAs). It can be used to establish SSL connections with servers that do not require client authentication, but only use data encryption to protect the communication. It can also be used as a container for storing the CAs that are trusted by the client. References:
https://help.sap.com/doc/saphelp_nw70ehp3/7.03/en-US/c8/e8d53d35fb11d182b90000e829fbfe/content.htm?no_
https://help.sap.com/doc/saphelp_nw70ehp3/7.03/en-US/c8/e8d53d35fb11d182b90000e829fbfe/content.htm?no_


NEW QUESTION # 44
What are characteristic of the SAP_INTERNAL_HANA_SUPPORT catalog role? Note: there are 2 correct answers to this question.

  • A. Object privileges can be granted to the role
  • B. It has full access to all metadata
  • C. No role can be granted to it
  • D. System privileges can be granted to the role

Answer: C,D


NEW QUESTION # 45
How can you describe the hierarchical relationships between technical entities in the Cloud Foundry?

  • A. A SaaS tenant acts as one provider account.
  • B. A subscription is a PaaS tenant.
  • C. A SaaS tenant acts as one Cloud Foundry Organization.
  • D. A global account can have one or many subaccounts.

Answer: D

Explanation:
Explanation
This is one of the ways that you can describe the hierarchical relationships between technical entities in the Cloud Foundry. Cloud Foundry is a platform-as-a-service (PaaS) that enables developers to deploy and run cloud-native applications using various services and frameworks. Cloud Foundry uses different technical entities to organize and manage resources and access rights, such as global accounts, subaccounts, organizations, spaces, applications, and services. A global account is an entity that represents a customer or partner who has subscribed to SAP Cloud Platform services and products. A global account can have one or many subaccounts, which are entities that represent logical subdivisions or business units within a global account. References:
https://help.sap.com/viewer/65de2977205c403bbc107264b8eccf4b/Cloud/en-US/9e1bf57130ef466e8017eab298


NEW QUESTION # 46
What are some characteristics of an SAP HANA multitenant database system (MDC) running in high isolation mode? Note: There are 2 correct answers to this question.

  • A. All tenant-specific file and directory permissions are managed by the SAP HANA system
  • B. The <sid>adm user can access the tenant-specific configuration and trace files.
  • C. All tenant databases will share the operating system user and group.
  • D. All tenant-specific permissions to access files and directories are revoked from the
    <sid>adm user.

Answer: A,D

Explanation:
Explanation
These are some of the characteristics of an SAP HANA multitenant database system (MDC) running in high isolation mode. MDC is a feature that allows you to run multiple databases on one SAP HANA system, each with its own users, catalog, repository, data, and services. High isolation mode is a mode that provides enhanced security and isolation for tenant databases by restricting access to files and directories at the operating system level. In high isolation mode, all tenant-specific permissions to access files and directories are revoked from the <sid>adm user, which is the operating system user for SAP HANA administration. All tenant-specific file and directory permissions are managed by the SAP HANA system using internal users and groups. References: https://help.sap.com/viewer/6b94445c94ae495c83a1


NEW QUESTION # 47
Which data source needs to be integrated into SAP Identity Management via the Virtual Directory Server (VOS)?

  • A. AS ABAP
  • B. SAP HCM
  • C. LDAP
  • D. AS Java

Answer: C


NEW QUESTION # 48
For which purpose do you use instance Secure Storage File System (SSFS) in an SAP HANA system? Note: There are 2 correct answers to this question.

  • A. To protect the password of the root key backup
  • B. To store root keys for data volume encryption
  • C. To store the secure single sign-on configuration
  • D. To protect the X.509 public key infrastructure certificates

Answer: B,C


NEW QUESTION # 49
In your SAP HCM system, you are implementing structural authorizations for your users. What are the characteristics of this authorization type? Note: There are 2 correct answers to this question.

  • A. The structural profile determines the accessible object in the organizational structure
  • B. The structural profile is maintained and assigned to users using the Profile Generator
  • C. The structural profile is maintained and assigned to users using the Implementation Guide
  • D. The structural profile determines the access mode which the user can perform

Answer: A,C


NEW QUESTION # 50
......

Actual P_SECAUTH_21 Exam Recently Updated Questions with Free Demo: https://www.actualtestsit.com/SAP/P_SECAUTH_21-exam-prep-dumps.html

Free SAP P_SECAUTH_21 Exam Questions: https://drive.google.com/open?id=1BwA9ExRK6B8cLCVlP_rW20YrRfun1J7f