
[Full-Version] 2023 New DumpsReview P_SECAUTH_21 PDF Recently Updated Questions
P_SECAUTH_21 Exam with Guarantee Updated 80 Questions
NEW QUESTION # 46
Which tasks would you perform to allow increased security for the SAP Web Dispatcher Web Administration Interface? Note: There are 2 correct answers to this question
- A. Use a separate port for the administration interface
- B. Use access restrictions to the icm/HTTP/auth_<xx> profile parameter
- C. Use subparameter ALLOWPUB = TRUE of the profile parameter icm/server_port_<xx>
- D. Use Secure Socket Layer (SSL) for encrypted access
Answer: A,C
NEW QUESTION # 47
Which type of systems can be found in the Identify Provisioning Service landscape? Note: There are 2 correct answers to this question
- A. Proxy
- B. Identify Provider
- C. Source
- D. Service Provider
Answer: B,C
NEW QUESTION # 48
The SSO authentication using X.509 client certificates is configured. Users complain that they can't log in to the back-end system. The trace file shows the following error message: "HTTP request [2/5/9] Reject untrusted forwarded certificate". What is missing in the configuration? Note: There are 2 correct answers to this question.
- A. On the web-dispatcher, the profile parameter icm/HTTPS/verify_client must be set to 0
- B. On the back-end, the profile parameter icm/HTTPS/verify client must NOT be set to 0
- C. On the web-dispatcher, the SAPSSLS.pse must be signed by a trusted certification authority
- D. The web dispatcher's SAPSSLC.PSE certificate must be added to the trusted reverse proxies list in icm/trusted_reverse_proxy_<xx>
Answer: B,C
NEW QUESTION # 49
How can you protect a table containing sensitive data using the authorization object S_TABU_DIS?
- A. The field DICBERCLS of the authorization object must enumerate all table names of the tables containing sensitive data.
- B. Authorization table groups containing tables with sensitive data must be defined in table TDDAT and these must be omitted for all employees who do not need access to these tables
- C. The tables containing sensitive data must be associated with table groups in table TBRG.
- D. The tables containing sensitive data must be named using the authorization object S_TA BU_NAM for all responsible administrator employees. The fields DICBERCLS of the object S_TABU_DIS can
Answer: B
Explanation:
then be filled with *.
NEW QUESTION # 50
To which services packages does SAP Security Optimization Services (SOS) belong?
- A. System Administration Optimization
- B. Application Integration Optimization
- C. Performance Optimization
- D. EarlyWatch Reporting
Answer: A
NEW QUESTION # 51
You want to configure SNC in a newly-installed AS ABAP based SAP system. Besides running SNCWIZARD, what else do you need to perform for this scenario?
Note: There are 2 correct answers to this question
- A. Manage the PSE
- B. Restart the SAP system
- C. Enable encrypted HTTP service
- D. Set the parameters using sapgenpse
Answer: A,B
NEW QUESTION # 52
How is the role concept applied in the authorizations for Core Data Services (CDS) views?
- A. CDS roles are defined in the CDS view and implicitly applied to all users
- B. CDS roles are mapped to the CDS view in the access rules
- C. CDS roles are defined in the WHERE clause when calling a CDS view in Open SOL
- D. CDS roles are defined in the CDS view and assigned to users in the classic role editor
Answer: D
NEW QUESTION # 53
You have delimited a single role which is part of a composite role, and a user comparison for the composite role has been performed. You notice that the comparison did NOT remove the profile assignments for that single role. What program would you run to resolve this situation?
- A. 0 PRGN_MERGE_PREVIEW
- B. 0 PRGN_COMPRESS_TIMES
- C. 0 PRGN_DELETE_ACT IVITY_GROUPS
- D. 0PRGN_COMPARE_ROLE_MENU
Answer: B
NEW QUESTION # 54
Your company is running SAP S/4HANA on premise, with the requirement to run the SAP Fiori Launchpad in the SAP Cloud Platform. What would be the recommended scenario for user authentication for internet browser access to the SAP Fiori Launchpad?
- A. SAP Logon Tickets
- B. SAML2 and OData Provisioning
- C. Principal Propagation
- D. X.509 Client Certificates
Answer: D
NEW QUESTION # 55
Which of the following function can be used to troubleshoot authorization errors for ABAP CDS views with Authorization based on Access Control?
- A. REPORT RSUSR008_009
- B. E2E TRACE ANALYSIS
- C. STAUTHTRACE
- D. ABAP TRACE
Answer: C
NEW QUESTION # 56
For which reasons would you choose an "anonymous SSL Client PSE" setup? Note: There are
2 correct answers to this question.
- A. To perform mutual authentication
- B. To perform authentication
- C. To use data encryption
- D. To use as a container for the CAs
Answer: C,D
Explanation:
Explanation
These are some of the reasons why you would choose an "anonymous SSL Client PSE" setup in SAP systems.
An anonymous SSL Client PSE is a PSE that does not contain any client certificates or keys, but only contains certificates of trusted certificate authorities (CAs). It can be used to establish SSL connections with servers that do not require client authentication, but only use data encryption to protect the communication. It can also be used as a container for storing the CAs that are trusted by the client. References:
https://help.sap.com/doc/saphelp_nw70ehp3/7.03/en-US/c8/e8d53d35fb11d182b90000e829fbfe/content.htm?no_
https://help.sap.com/doc/saphelp_nw70ehp3/7.03/en-US/c8/e8d53d35fb11d182b90000e829fbfe/content.htm?no_
NEW QUESTION # 57
What are main characteristics of the Logon ticket throughout an SSO logon procedure? Note: There are 2 correct answers to this question
- A. The Logon ticket is sued for user-to-system communication
- B. The Logon ticket is always set to client 000
- C. The Logon ticket session is held in the working memory
- D. The Logon ticket is not domain restricted
Answer: A,D
NEW QUESTION # 58
Which tasks would you perform to allow increased security for the SAP Web Dispatcher Web Administration interface? Note: There are 2 correct answers to this question.
- A. Use Secure Socket Layer (SSL) for password encrypt on
- B. Use a separate port for the content
- C. Use subparameter ALLOWPUB = FALSE of the profile parameter icm/server_port_<xx>
- D. Use access restrictions with the icm/HTTP/auth_<xx> profile parameter
Answer: B,C
NEW QUESTION # 59
To which services package does SAP Security Optimization Services (SOS) belong?
- A. System Administration Optimization
- B. Application Integration Optimization
- C. Performance Optimization
- D. EarlyWatch Reporting
Answer: A
Explanation:
Explanation
This is one of the services packages that SAP Security Optimization Services (SOS) belongs to. SOS is a service that enables you to assess and improve the security level of your SAP systems and landscapes based on best practices and recommendations from SAP experts. SOS belongs to System Administration Optimization services package, which is a package that provides services for optimizing various aspects of system administration and operation, such as performance, availability, backup, or security. References:
https://support.sap.com/en/security/security-optimization-services.html
https://support.sap.com/en/security/security-optimization-services.html
NEW QUESTION # 60
You have a load balancer in a DMZ network zone (called natl.mydomain.com) in front of 2 SAP NetWeaver AS systems (hostl.mydomain.com, host2.mydomain.com). What is the recommended common name part of the distinguished name on the SSL Server's PSE?
- A. It should be natl.mydomain.com
- B. It should be host 1.mydomain.com, host2.mydornain.com individually for each PSE
- C. It should be a combined DNS alias for host 1.mydomain.com and host2.mydomain.com and nat1.mydomain.com
- D. It should be *.mydomain.com (wildcard) names
Answer: D
NEW QUESTION # 61
What does the SAP Security Optimization Service provide? Note: There are 2 correct answers to this question.
- A. Analysis of the network configuration
- B. Analysis of the security vulnerabilities within an SAP landscape
- C. Results containing the list of patches that have to be applied
- D. Configuration checks of SAP systems
Answer: A,D
Explanation:
Explanation
These are some of the things that the SAP Security Optimization Service provides. SAP Security Optimization Service is a service that enables you to assess and improve the security level of your SAP systems and landscapes based on best practices and recommendations from SAP experts. The service provides configuration checks of SAP systems, which analyze various parameters and settings related to security aspects, such as passwords, authorizations, encryption, or logging. The service also provides analysis of the network configuration, which evaluates the network topology and communication channels between SAP systems and components. References: https://support.sap.com/en/security/security-optim
NEW QUESTION # 62
Based on your company guidelines you have set the password expiration to 60 days. Unfortunately, there is an RFC user in your SAP system who must not have a password change for 180 days. Which option would you recommend to accomplish such a request?
- A. Create an enhancement spot or user exit
- B. Define the RFC user as a reference user
- C. Change the profile parameter login/password_expiration_time to 180
- D. Create a security policy via SECPOL and assign it to the RFC user
Answer: D
NEW QUESTION # 63
You are asked to set up controls to monitor sensitive objects (such as programs, user exits, and function modules) in a development system before they are transported to the quality assurance system. Which table would you maintain to monitor such sensitive objects before running an import?
- A. TMSCDES
- B. TMSTCRI
- C. TMSBUFFER
- D. TMSMCONF
Answer: B
Explanation:
Explanation
This is one of the tables that you would maintain to monitor sensitive objects (such as programs, user exits, or function modules) in a development system before they are transported to the quality assurance system.
TMSTCRI is a table that contains criteria for import checks of transport requests, which are packages of changes or objects that can be moved between SAP systems or clients. You can define criteria for specific objects or object types in this table, such as program name, object name, or object type. If a transport request contains an object that matches one of the criteria in this table, the import will be stopped and an error message will be displayed. References:
https://help.sap.com/doc/saphelp_nw73ehp1/7.31.19/en-US/c8/e8d53d35fb11d182b90000e829fbfe/content.htm?
NEW QUESTION # 64
Which SAP product supports General Data Privacy Regulation (GDPR) compliance through mitigating control testing and validation
- A. SAP Access Control
- B. SAP Process Control
- C. SAP Solution Manager
- D. SAP Identify Access Governance
Answer: B
NEW QUESTION # 65
Which tool do you use to customize the SAP HANA default password policy? Note: There are 2 correct answers to this question.
- A. SAP HANA Lifecycle Manager
- B. SAP HANA Cockpit
- C. SAP HANA Studio
- D. SAP Web IDE
Answer: C,D
NEW QUESTION # 66
Which communication methods does the SAP Fiori Launchpad use to retrieve business data? Note: There are 2 correct answers to this question
- A. InA
- B. HOP
- C. SNC
- D. OData
Answer: A,C
NEW QUESTION # 67
How are security relevant objects related in the Cloud Foundry? Note: There are 2 correct answers to this question
- A. Role Collections have 0 or many role templates
- B. Role Templates have 0 or many attributes
- C. Role Templates have 1 or many scopes
- D. Role Collections have 0 or many roles
Answer: A,B
NEW QUESTION # 68
How would you control access to the ABAP RFC function modules? Note: There are 2 correct answers to this question.
- A. Restrict RFC authorizations
- B. Deactivate switchable authorization checks
- C. Block RFC Callback Whitelists
- D. Implement UCON functionality
Answer: A,B
NEW QUESTION # 69
......
SAP P_SECAUTH_21 certification exam is a highly respected certification in the field of system security architecture. Certified Technology Professional - System Security Architect certification is recognized globally and is highly valued by employers. It is an ideal certification for professionals who want to advance their careers in the field of system security architecture.
To be eligible for the exam, candidates must have a minimum of two years of experience in SAP system security or a related field. They must also have completed the SAP TADM10 and TADM12 courses, which cover the basics of SAP system administration. P_SECAUTH_21 exam fee is $550, and it can be taken at any SAP authorized testing center.
Latest P_SECAUTH_21 Pass Guaranteed Exam Dumps Certification Sample Questions: https://www.dumpsreview.com/P_SECAUTH_21-exam-dumps-review.html
P_SECAUTH_21 Updated Exam Dumps [2023] Practice Valid Exam Dumps Question: https://drive.google.com/open?id=1THH9gvlyS4NQK6xxq3cdtk8niiQlhJxH

