
Latest P-SECAUTH-21 exam dumps with real SAP questions and answers
P-SECAUTH-21 Exam in First Attempt Guaranteed
SAP P-SECAUTH-21 exam is a comprehensive test that requires a thorough understanding of SAP security concepts and their practical application. P-SECAUTH-21 exam is designed to assess the candidate's ability to design, implement, and manage secure SAP systems. Certified Technology Professional - System Security Architect certification is recognized globally and is highly valued by organizations that use SAP technology. The SAP P-SECAUTH-21 certification demonstrates the candidate's knowledge and skills in providing secure and reliable SAP systems that meet the organization's security requirements. It is an excellent opportunity for professionals to enhance their career prospects and increase their earning potential in the SAP technology field.
SAP P-SECAUTH-21 certification exam is designed for the technology professionals who want to specialize in the field of system security architecture. P-SECAUTH-21 exam is a globally recognized certification, which provides the candidates with the skills and knowledge required to design, implement and maintain the security of SAP systems. Certified Technology Professional - System Security Architect certification exam is a validation of the candidates' expertise in the field of system security architecture, and is highly sought after by both employers and professionals alike.
NEW QUESTION # 23
What authorization objects do we need to create job steps with external commands in a background job? Note:
There are 2 correct answers to this question.
- A. S_LOG_COM
- B. S_BTCH_EXT
- C. S_BTCH_ADM
- D. S_RZL_ADM
Answer: B,C
Explanation:
Explanation
These are some of the authorization objects that we need to create job steps with external commands in a background job. A background job is a process that runs in the background without user interaction and performs tasks such as data processing or report generation. A job step is a unit of work within a background job that executes a program or an external command. S_BTCH_EXT is an authorization object that controls the execution of external commands or programs in a job step. S_BTCH_ADM is an authorization object that controls the administration of background jobs, such as creating, changing, or deleting jobs. References:
https://help.sap.com/doc/saphelp_nw73ehp1/7.31.19/en-US/c8/e8d53d35fb11d182b90000e829fbfe/content.htm?
NEW QUESTION # 24
How would you control access to ABAP RFC function modules? Note: There are 2 correct answers to this question.
- A. Implement UCON functionality
- B. Restrict RFC authorizations
- C. Deactivate switchable authorization checks
- D. Block RFC Callback Whitelists
Answer: A,B
Explanation:
Explanation
These are some of the functions that can be used to control access to ABAP RFC function modules in an SAP system. RFC (Remote Function Call) is a protocol that enables communication and data exchange between SAP systems and components using function modules. ABAP RFC function modules are function modules that are written in ABAP language and can be called remotely by other systems or components. UCON (Unified Connectivity) is a feature that allows you to monitor and restrict RFC calls based on various criteria, such as source system, target system, user, or function module. RFC authorizations are authorizations that control access to RFC function modules based on authorization objects, such as S_RFC or S_RFCACL.
References:
https://help.sap.com/doc/saphelp_nw73ehp1/7.31.19/en-US/48/9e2e3f6f8e41e8a283aaf2ad2c64c4/content.htm?n
NEW QUESTION # 25
Which authorizations should you restrict when you create a developer role in an AS ABAP production system? Note: There are 2 correct answers to this question.
- A. The ability to use the ABAP Debugger through authorization object S_DEVELOP
- B. The ability to run function modules through authorization object S_DEVELOP
- C. The ability to run queries through authorization object S_QUERY
- D. The ability to run class methods through authorization object S_PROGRAM
Answer: A,B
Explanation:
Explanation
Developers should not be able to use the ABAP Debugger or run function modules in a production system, as these actions could compromise the system integrity and security. Authorization object S_DEVELOP controls both these activities and should be restricted for developers in a production system. References:
https://help.sap.com/viewer/68bf513362174d54b58cddec28794093/7.5.20/en-US/4a0c1f51bb571014e10000000
https://help.sap.com/viewer/68bf513362174d54b58cddec28794093/7.5.20/en-US/4a0c1f51bb571014e10000000
NEW QUESTION # 26
Where does SAP HANA store the values for the default Password Policy parameter? Note: there are 2 correct answers to this question.
- A. global.ini
- B. indexserver.ini
- C. nameservice.ini
- D. attributes.ini
Answer: B,C
NEW QUESTION # 27
Which type of systems can be found in the Identify Provisioning Service landscape? Note: There are 2 correct answers to this question
- A. Source
- B. Service Provider
- C. Proxy
- D. Identify Provider
Answer: A,D
NEW QUESTION # 28
You have delimited a single role that is part of a composite role, and a user comparison for the composite role has been performed. You notice that the comparation did NOT.... profile assignments for that single role. What program would you run to resolve this situation?
- A. PRGN_DELETE_ACTIVITY_GROUPS
- B. PRGN_MERGE_PREVIEW
- C. PRGN_COMPARE_ROLE_MENU
- D. PRGN_COMPRESS_TIMES
Answer: D
NEW QUESTION # 29
You have Reason Codes already defined. Which is the correct sequence of steps to configure a Firefighter ID in Emergency Access Management?
- A. Maintain an Owner for a Firefighter ID
Maintain a Firefighter ID for Controllers and Firefighters
Maintain Access Control Owner - B. Maintain an Owner for a Firefighter ID
Maintain a Firefighter ID for Controllers and Firefighters
Maintain Access Control Owner - C. Maintain an Owner for a Firefighter ID
Maintain a Firefighter ID for Controllers and Firefighters
Maintain Access Control Owner - D. Maintain a Firefighter ID for Controllers and Firefighters
Maintain an Owner for a Firefighter ID
Maintain Access Control Owner
Answer: C
NEW QUESTION # 30
What reference is used to connect multiple Cloud Connectors to one SAP Cloud Platform subaccount?
- A. Location ID
- B. Virtual Host
- C. System Alias
- D. Instance ID
Answer: A
NEW QUESTION # 31
For which reasons would you choose an "anonymous SSL Client PSE" setup? Note: There are 2 correct answers to this question
- A. To perform mutual authentication
- B. To use as a container for the CAs
- C. To use data encryption
- D. To perform authentication
Answer: B,D
NEW QUESTION # 32
You want to carry out some preparatory work for running the SAP Security Optimization Selfservice on a customer system. Which of the following steps do you have to run on the managed systems? Note: There are 2 correct answers to this question.
- A. Grant operating system access
- B. Configure Secure Network Communications
- C. Install the ST-A/PI plug-in
- D. Configure specific authorizations
Answer: C,D
Explanation:
Explanation
These are some of the steps that you have to run on the managed systems to prepare for running the SAP Security Optimization Self-service on a customer system. The SAP Security Optimization Self-service is a service that allows you to perform security checks on your SAP systems using predefined questionnaires and automated analysis tools. The service requires specific authorizations on the managed systems, such as RFC authorizations or Security Audit Log authorizations, which you have to configure using PFCG transaction or RZ10 transaction respectively. The service also requires the ST-A/PI plug-in on the managed systems, which is a plug-in that provides various functions and tools for service delivery, such as data collection or remote analysis. References: https://support.sap.com/en/security/security-optimization-services.html
https://support.sap.com/en/security/security-optimization-services.html
NEW QUESTION # 33
You want to use Configuration Validation functionality in SAP Solution Manager to check the consistency of settings across your SAP environment. What serves as the reference basis for Configuration Validation? Note: There are 2 correct answers to this question.
- A. A list of recommended settings attached to a specific SAP Note
- B. A target system in your system landscape
- C. A result list of configuration items from SAP Early Watch Alert (EWA)
- D. A virtual set of manually maintained configuration ems
Answer: B,D
NEW QUESTION # 34
You have configured a Gateway SSO authentication using X.509 client certificates. The configuration of the dual trust relationship between client (browser) and SAP Web Dispatcher as well as the configuration of the SAP Web Dispatcher to accept and forward client certificates were done. Users complain that they can't log in to the back-end system. How can you check the cause?
- A. Run back-end transaction SMICM and open the trace file
- B. Run gateway transaction /IWFND/TRACES
- C. Run back-end system trace using ST12
- D. Run gateway transaction /IWFND/ ERRORJ.OG
Answer: D
NEW QUESTION # 35
You want to allow some of your colleagues to use the SAP GUI for Java to connect directly to your SAP back-end system from a public internet connection without having to set up a VPN connection first. Which of the following SAP solutions is suited for this purpose?
- A. SAP router
- B. SAP Cloud Connector
- C. SAP Web Dispatcher
- D. SAP NetWeaver Gateway
Answer: B
NEW QUESTION # 36
You want to allow your trainee colleagues to use the SAP GUI to connect directly to your SAP S/4HANA (on-premise) demo system form a public internet connection Which of the following SAP solutions is suited for this purpose?
- A. SAP Cloud Connector
- B. SAP Prouter
- C. SAP Web Dispatcher
- D. SAP NetWeaver Gateway
Answer: A
NEW QUESTION # 37
Your company is running SAP S/4HANA on premise, with the requirement to run the SAP Fiori Launchpad in the SAP Cloud Platform. What would be the recommended scenario for user authentication for internet browser access to the SAP Fiori Launchpad?
- A. X.509 Client Certificates
- B. SAP Logon Tickets
- C. SAML2 and OData Provisioning
- D. Principal Propagation
Answer: A
NEW QUESTION # 38
How can you protect a table containing sensitive data using the authorization object S_TABU_DIS?
- A. Authorization table groups containing tables with sensitive data must be defined in table TDDAT and these must be omitted for all employees who do not need access to these tables
- B. The field DICBERCLS of the authorization object must enumerate all table names of the tables containing sensitive data.
- C. The tables containing sensitive data must be associated with table groups in table TBRG.
- D. The tables containing sensitive data must be named using the authorization object S_TA BU_NAM for all responsible administrator employees. The fields DICBERCLS of the object S_TABU_DIS can then be filled with *.
Answer: A
NEW QUESTION # 39
How can you protect a table containing sensitive data using the authorization object S_TABU_DIS?
- A. Authorization table groups containing tables with sensitive data must be defined in table TDDAT and these must be omitted for all employees who do not need access to these tables
- B. The field DICBERCLS of the authorization object must enumerate all table names of the tables containing sensitive data.
- C. The tables containing sensitive data must be associated with table groups in table TBRG.
- D. The tables containing sensitive data must be named using the authorization object S_TA BU_NAM for all responsible administrator employees. The fields DICBERCLS of the object S_TABU_DIS can
Answer: A
Explanation:
then be filled with *.
NEW QUESTION # 40
What are characteristics of SAP HANA Deployment Infrastructure (HDI) roles? Note: There are 2 correct answers to this question.
- A. They are granted using database procedures.
- B. They are owned by the user who creates them.
- C. They are transportable between systems.
- D. They are managed by the native HDI version control.
Answer: A,D
Explanation:
Explanation
These are some of the characteristics of SAP HANA Deployment Infrastructure (HDI) roles. HDI roles are roles that are defined and deployed as part of HDI containers, which are isolated units of database objects and data in SAP HANA systems. HDI roles are managed by the native HDI version control, which tracks changes and dependencies among HDI objects and artifacts. HDI roles are granted using database procedures, such as GRANT_CONTAINER_GROUP_ROLE or GRANT_CONTAINER_SCHEMA_ROLE, which enable dynamic role assignments based on container groups or schemas. References:
https://help.sap.com/viewer/6b94445c94ae495c83a19646e7c3fd56/2.0.05/en-US/fafcbcf9d9101014b3d9a08ce33
NEW QUESTION # 41
......
Exam Sure Pass SAP Certification with P-SECAUTH-21 exam questions: https://protechtraining.actualtestsit.com/SAP/P-SECAUTH-21-exam-prep-dumps.html