
SAP Certified P_SECAUTH_21 Dumps Questions Valid P_SECAUTH_21 Materials
Current P_SECAUTH_21 Exam Dumps [2024] Complete SAP Exam Smoothly
The Certified Technology Professional - System Security Architect certification exam consists of multiple choice questions and is conducted in a proctored environment. P_SECAUTH_21 exam is designed to test the candidate's knowledge of security architecture and design principles, as well as their ability to implement security solutions in a SAP environment. P_SECAUTH_21 exam covers topics such as protecting data and applications, designing secure system architectures, and implementing security policies and procedures.
SAP P-SECAUTH-21 exam covers a range of topics related to system security architecture, including access control, authentication, authorization, and auditing. P_SECAUTH_21 exam also covers topics such as secure communication, data protection, and secure coding practices. Certified Technology Professional - System Security Architect certification is intended for professionals who are responsible for designing and implementing security measures in SAP systems, including system administrators, security architects, and consultants.
NEW QUESTION # 42
How would you control access to the ABAP RFC function modules? Note: There are 2 correct answers to this question.
- A. Deactivate switchable authorization checks
- B. Restrict RFC authorizations
- C. Block RFC Callback Whitelists
- D. Implement UCON functionality
Answer: A,B
NEW QUESTION # 43
Based on your company guidelines you have set the password expiration to 60 days.
Unfortunately, there is an RFC user on your SAP system who must not have a password change for 1 80 days. Which option would you recommend to accomplish such a request?
- A. Create an enhancement spot or user exit
- B. Define the RFC user as a reference user
- C. Create a security policy via SECPOL and assign it to the RFC users
- D. Change the profile parameter login/password_expiration_time to 1 80
Answer: C
Explanation:
Explanation
This is one of the options that you would recommend to accomplish such a request of having an RFC user with a password expiration of 180 days instead of 60 days based on your company guidelines. SECPOL is a transaction that allows you to create and maintain security policies for password settings, such as minimum length, expiration time, or lockout threshold. You can assign different security policies to different users or user groups based on their roles or requirements. References:
https://help.sap.com/doc/saphelp_nw73ehp1/7.31.19/en-US/c8/e8d53d35fb11d182b90000e829fbfe/content.htm?
NEW QUESTION # 44
Which authorizations are required for an SAP Fiori Launchpad user? Note: There are 2 correct answers to this question
- A. /UI2/INTEROP
- B. /UI2/PAGE_BUILDER_PERS
- C. /UI2/CHIP
- D. /UI2/PAGE_BUILDER_CUST
Answer: A,B
NEW QUESTION # 45
Which communication methods does the SAP Fiori Launchpad use to retrieve business data?
Note: There are 2 correct answers to this question.
- A. SNC
- B. IIOP
- C. InA
- D. OData
Answer: C,D
Explanation:
Explanation
These are the communication methods that the SAP Fiori Launchpad uses to retrieve business data from various data sources and services. InA (Information Access) is a protocol that enables analytical queries and data visualization using SAP Analytics Cloud or SAP Lumira. OData (Open Data Protocol) is a protocol that enables CRUD (Create, Read, Update, Delete) operations on data using RESTful web services. References:
https://help.sap.com/viewer/product/SAP_FIORI_LAUNCHPAD/en-US
NEW QUESTION # 46
Which tools can you use to troubleshoot an authorization issue with a Fiori application? Note: There are 2 correct answers to this question
- A. /IWFND/ERROR_LOG
- B. /IWBEP/ERROR_LOG
- C. /UI2/GW_APPS_LOG
- D. /UI2/FLC
Answer: A,C
NEW QUESTION # 47
How can you protect a table containing sensitive data using the authorization object S_TABU_DIS?
- A. The tables containing sensitive data must be associated with table groups in table TBRG.
- B. The tables containing sensitive data must be named using the authorization object S_TA BU_NAM for all responsible administrator employees. The fields DICBERCLS of the object S_TABU_DIS can
- C. The field DICBERCLS of the authorization object must enumerate all table names of the tables containing sensitive data.
- D. Authorization table groups containing tables with sensitive data must be defined in table TDDAT and these must be omitted for all employees who do not need access to these tables
Answer: D
Explanation:
then be filled with *.
NEW QUESTION # 48
What is the SAP Best Practice to delete a security SAP role in SAP landscape?
- A. Delete the SAP role in all clients using Profile Generator
- B. Transport the SAP role and delete the role using Profile Generator
- C. Delete the SAP role using Profile Generator, and then put it in the transport
- D. Delete the SAP role in all clients in all systems using Profile Generator
Answer: B
NEW QUESTION # 49
You want to create an SAP Fiori app for multiple users and multiple back-end systems. To support this, you create different roles for the different back-end systems in the SAP Fiori front-end system (central hub). What transactions do you have to use to map a back-end system to one of those roles?
- A. /UI2/GW_SYS_ALIAS
- B. PFCG
- C. SEGW
- D. /IWFND/MAINT_SERVICE
Answer: D
NEW QUESTION # 50
Which authorization object controls access to the trusting system between the managed system and SAP Solution Manager?
- A. S_ ICM
- B. S_RFCACL
- C. S_SERVICE
- D. S_RFC
Answer: B
NEW QUESTION # 51
What authorization objects do we need to create job steps with external commands in a background job? Note: There are 2 correct answers to this question.
- A. S_ADMI_FCD
- B. S_LOG_COM
- C. S_RZL_ADM
- D. S_BTCH_EXT
Answer: B,C
NEW QUESTION # 52
What are the key capabilities of Event Analyzer in Enterprise Threat Detection 1.0? Note: There are 2 correct answers to this question.
- A. Baseline detection
- B. Pseudonymize user identities for data protection
- C. Synchronization of user contexts from ABAP Systems
- D. Predictive threat notification
Answer: A,B
NEW QUESTION # 53
Which tasks would you perform to allow increased security for the SAP Web Dispatcher Web Administration interface? Note: There are 2 correct answers to this question.
- A. Use Secure Socket Layer (SSL) for password encrypt on
- B. Use subparameter ALLOWPUB = FALSE of the profile parameter icm/server_port_<xx>
- C. Use a separate port for the content
- D. Use access restrictions with the icm/HTTP/auth_<xx> profile parameter
Answer: B,C
NEW QUESTION # 54
Which of the objects do you assign to an SAP Fiori tile to make it visible in the SAP Fiori Launchpad? Note: There are 2 correct answers to this question.
- A. Role
- B. Group
- C. Catalog
- D. User
Answer: B,C
NEW QUESTION # 55
The SSO authentication using X.509 client certificates is configured. Users complain that they can't log in to the back-end system. The trace file shows the following error message: "HTTP request [2/5/9] Reject untrusted forwarded certificate". What is missing in the configuration? Note: There are 2 correct answers to this question.
- A. On the web-dispatcher, the profile parameter icm/HTTPS/verify_client must be set to 0
- B. The web dispatcher's SAPSSLC.PSE certificate must be added to the trusted reverse proxies list in icm/trusted_reverse_proxy_<xx>
- C. On the web-dispatcher, the SAPSSLS.pse must be signed by a trusted certification authority
- D. On the back-end, the profile parameter icm/HTTPS/verify client must NOT be set to 0
Answer: C,D
NEW QUESTION # 56
How can you describe the hierarchical relationships between technical entities in the Cloud Foundry?
- A. A global account can have one or many subaccounts.
- B. A SaaS tenant acts as one Cloud Foundry Organization.
- C. A subscription is a PaaS tenant.
- D. A SaaS tenant acts as one provider account.
Answer: A
Explanation:
Explanation
This is one of the ways that you can describe the hierarchical relationships between technical entities in the Cloud Foundry. Cloud Foundry is a platform-as-a-service (PaaS) that enables developers to deploy and run cloud-native applications using various services and frameworks. Cloud Foundry uses different technical entities to organize and manage resources and access rights, such as global accounts, subaccounts, organizations, spaces, applications, and services. A global account is an entity that represents a customer or partner who has subscribed to SAP Cloud Platform services and products. A global account can have one or many subaccounts, which are entities that represent logical subdivisions or business units within a global account. References:
https://help.sap.com/viewer/65de2977205c403bbc107264b8eccf4b/Cloud/en-US/9e1bf57130ef466e8017eab298
NEW QUESTION # 57
SNC is configured in the production system. For emergency purposes, you want to allow certain accounts to be able to access the system with password logon. What do you need to set up for this purpose? Note: There are 2 correct answers to this question.
- A. Use profile parameter SNC/ACCEPT_ INSECURE_GUI with value 'U'
- B. Use profile parameter SNC/ONLY_ENCRYPTED_GUI with value 'O'
- C. Maintain the user access control list in table USRACLEXT
- D. Use the 'Unsecure communication permitted option' In SU01 for specific users
Answer: A,D
NEW QUESTION # 58
A system user created a User1 and a schema on the HANA database with some dat a. User2 is developing modelling views and requires access to objects in User1's schema. What needs to be done?
- A. User1 should grant _SYS_REPO with SELECT WITH GRANT privilege
- B. System user should grant User2 with SELECT privilege to User 1schema
- C. User2 needs to be granted with the same roles like User1
- D. ROLE ADMIN needs to be granted to User2
Answer: B
NEW QUESTION # 59
You want to use Configuration Validation functionality in SAP Solution Manager to check the consistency of settings across your SAP environment. What serves as the reference basis for Configuration Validation? Note: There are 2 correct answers to this question.
- A. A list of recommended settings attached to a specific SAP Note
- B. A target system in your system landscape
- C. A result list of configuration items from SAP Early Watch Alert (EWA)
- D. A virtual set of manually maintained configuration ems
Answer: B,D
NEW QUESTION # 60
While performing an audit of changes to the system and client change options for your production SAP S/4HANA environment, you receive the following message in transaction SCC4. "No logs found for selected period" How can you correct the problem.
- A. Maintain parameter rsau/enable with value 1
- B. Maintain parameter rec/client with value ALL
- C. Maintain parameter log-mode with value normal SAP HANA
- D. Maintain parameter rdisp/TRACE with value 3
Answer: B
NEW QUESTION # 61
What is the SAP Best Practice to delete a security SAP role from the landscape running SAP systems?
- A. Delete the SAP role in all clients using Profile Generator
- B. Delete the SAP role using Profile Generator, and then put it in the transport
- C. Transport the SAP role and delete the role using Profile Generator
- D. Delete the SAP role in all clients in all systems using Profile Generator
Answer: B
Explanation:
Explanation
The SAP Best Practice to delete a security SAP role from the landscape running SAP systems is to delete the SAP role using Profile Generator (transaction PFCG), and then put it in a transport request that can be moved across systems using Change and Transport System (CTS). This way, you can ensure that the role is deleted consistently and completely from all systems. References:
https://help.sap.com/doc/saphelp_nw70ehp3/7.03/en-US/c8/e8d53d35fb11d182b90000e829fbfe/content.htm?no_
https://help.sap.com/doc/saphelp_nw70ehp3/7.03/en-US
NEW QUESTION # 62
Which features does the SAP Router support? Note: There are 2 correct answers to this question.
- A. Terminating, forwarding and (re)encrypting requests, depending on the SSL configuration
- B. Balancing the load to ensure an even distribution across the back-end servers
- C. Controlling and logging network connections to SAP systems
- D. Password-protecting connections from unauthorized access from outside the network
Answer: C,D
NEW QUESTION # 63
......
SAP P_SECAUTH_21 certification is an excellent choice for IT professionals who want to validate their skills and knowledge in the field of system security architecture. Certified Technology Professional - System Security Architect certification is recognized globally and can help professionals enhance their career prospects. The SAP P_SECAUTH_21 exam tests the candidate's knowledge of SAP system security architecture, risk management, and compliance. Obtaining this certification can help professionals gain a competitive edge in the job market and increase their earning potential.
P_SECAUTH_21 Premium PDF & Test Engine Files with 80 Questions & Answers: https://www.passcollection.com/P_SECAUTH_21_real-exams.html
Get 100% Real P_SECAUTH_21 Accurate & Verified Answers As Seen in the Real Exam!: https://drive.google.com/open?id=1VJtUxviIiQoTJhNeM65FN-BA4bQkMIIv

