
無料でゲット!2023年最新のに更新されたSAP P-SECAUTH-21試験問題と解答
P-SECAUTH-21問題集PDFとテストエンジン試験問題
SAP P-Secauth-21認定試験の準備をするために、候補者は、SAPシステムセキュリティアーキテクチャで少なくとも2年間の実際の経験を持つことをお勧めします。また、SAPセキュリティの概念とベストプラクティスを深く理解し、SAPセキュリティ機能の構成と管理における実践的な経験を理解する必要があります。
SAP P-Secauth-21認定試験は、情報セキュリティとSAPシステムの操作経験に強いバックグラウンドを持っている個人を対象としています。この試験に合格した候補者は、最高のセキュリティ基準を満たす安全なSAPシステムを設計、実装、および管理する能力を示しています。この認定は、SAPシステムに依存して重要なビジネスプロセスを管理する組織によって高く評価されています。これは、システムがセキュリティと整合性を確保できる資格のある専門家の手にあるという保証を提供するためです。
質問 # 13
Your company is running SAP S/4HANA on premise, with the requirement to run the SAP Fiori Launchpad in the SAP Cloud Platform. What would be the recommended scenario for user authentication for internet browser access to the SAP Fiori Launchpad?
- A. SAML2 and OData Provisioning
- B. SAP Logon Tickets
- C. X.509 Client Certificates
- D. Principal Propagation
正解:C
質問 # 14
How can you describe the hierarchical relationships between technical entities in the Cloud Foundry?
- A. A subscription is a PaaS tenant.
- B. A SaaS tenant acts as one Cloud Foundry Organization.
- C. A global account can have one or many subaccounts.
- D. A SaaS tenant acts as one provider account.
正解:C
解説:
Explanation
This is one of the ways that you can describe the hierarchical relationships between technical entities in the Cloud Foundry. Cloud Foundry is a platform-as-a-service (PaaS) that enables developers to deploy and run cloud-native applications using various services and frameworks. Cloud Foundry uses different technical entities to organize and manage resources and access rights, such as global accounts, subaccounts, organizations, spaces, applications, and services. A global account is an entity that represents a customer or partner who has subscribed to SAP Cloud Platform services and products. A global account can have one or many subaccounts, which are entities that represent logical subdivisions or business units within a global account. References:
https://help.sap.com/viewer/65de2977205c403bbc107264b8eccf4b/Cloud/en-US/9e1bf57130ef466e8017eab298
質問 # 15
What can you maintain in transaction SU24 to reduce the overall maintenance in PFCG? Note: There are 3 correct answers to this question.
- A. The default values so they are appropriate for the transactions used in the roles
- B. The authorization objects that are not linked to transact on codes correctly
- C. The default values in the tables USOBX and USOBT
- D. The authorization objects that have unacceptable default values
- E. The default authority check settings for the role maintenance tool
正解:A、B、D
質問 # 16
Which tool do you use to customize the SAP HANA default password policy? Note: There are 2 correct answers to this question.
- A. SAP HANA Lifecycle Manager
- B. SAP Web IDE
- C. SAP HANA Cockpit
- D. SAP HANA Studio
正解:B、D
質問 # 17
A system user created a User1 and a schema on the HANA database with some dat a. User2 is developing modelling views and requires access to objects in User1's schema. What needs to be done?
- A. User2 needs to be granted with the same roles like User1
- B. ROLE ADMIN needs to be granted to User2
- C. System user should grant User2 with SELECT privilege to User 1schema
- D. User1 should grant _SYS_REPO with SELECT WITH GRANT privilege
正解:C
質問 # 18
Which tools can you use to troubleshoot an authorization issue with a Fiori application? Note:
There are 2 correct answers to this question.
- A. /IWFND/ERROR_LOG
- B. /UI2/FLC
- C. /IWBEP/ERROR_LOG
- D. /UI2/GW_APPS_LOG
正解:A、C
解説:
Explanation
These are some of the tools that you can use to troubleshoot an authorization issue with a Fiori application.
/IWFND/ERROR_LOG is a transaction that displays the error log for the SAP Gateway framework, which handles the OData requests and responses between the Fiori front-end server and the back-end system.
/IWBEP/ERROR_LOG is a transaction that displays the error log for the SAP Gateway service implementation, which contains the business logic and data access for the OData services. References:
https://help.sap.com/viewer/a7b390faab1140c087b8926571e942b7/7.5.9/en-US/5c3d6d0f6c461014a1d99bc8a4f
質問 # 19
Which authorization object is required to support trusted system access by an RFC user following the configuration of a Managed System in SAP Solution Manager?
- A. S_RFC_TT
- B. S_RFC_TTAC
- C. S_RFCACL
- D. S_ACL_HIST
正解:C
質問 # 20
What are the characteristics of HTTP security session management? Note: There are 3 correct answers to this question.
- A. Refers to the session context through the session identifier
- B. Deletes security sessions at logoff
- C. Creates security sessions at logon
- D. Checks the logon credentials again for every request.
- E. Starts security sessions with a short user-based expiration time
正解:A、C、E
解説:
Explanation
These are some of the characteristics of HTTP security session management in SAP systems. HTTP security session management creates security sessions at logon that store information about the user's identity and authorizations in a session context on the server side. The security sessions start with a short user-based expiration time that can be extended by user activity or terminated by logoff or timeout. The security sessions refer to the session context through a session identifier that is passed between the client and the server using cookies or URL parameters. References:
https://help.sap.com/doc/saphelp_nw70ehp3/7.03/en-US/c8/e8d53d35fb11d182b90000e829fbfe/content.htm?no_
https://help.sap.com/doc/saphelp_nw70ehp3/7.03/en-US/c8/e8d53d35fb11d182b90000e829fbfe/content.htm?no_
質問 # 21
Which OData authorizations are required for a user to see business data in the SAP Fiori Launchpad? Note: There are 2 correct answers to this question.
- A. Access authorization in the SAP S/4HANA back-end system
- B. Access authorization in the SAP Fiori front-end system
- C. Start authorization in the SAP S/4HANA back-end system
- D. Start authorization in the SAP Fiori front-end system
正解:A、D
質問 # 22
Because of which security threat would you need to make additional configuration settings to run the SAP Fiori Launchpad from within your SAP NetWeaver Portal?
- A. Content Spoofing
- B. Clickjacking
- C. Cross-Site Scripting
- D. Cross-Site Request Forgery
正解:B
質問 # 23
You have configured a Gateway SSO authentication using X.509 client certificates. The configuration of the dual trust relationship between client (browser) and SAP Web Dispatcher as well as the configuration of the SAP Web Dispatcher to accept and forward client certificates were done. Users complain that they can't log in to the back-end system. How can you check the cause?
- A. Run back-end transaction SMICM and open the trace file
- B. Run gateway transaction /IWFND/ ERRORJ.OG
- C. Run gateway transaction /IWFND/TRACES
- D. Run back-end system trace using ST12
正解:B
質問 # 24
Which features does SAProuter provide?
Note: There are 2 correct answers to this question
- A. HTTP conversion into HTTPS connections
- B. Filtered and logged network connections
- C. Load-balanced RFC connections
- D. Password-protected connections
正解:B、D
質問 # 25
You want to create an SAP Fiori app for multiple users and multiple back-end systems. To support this, you create different roles for the different back-end systems in the SAP Fiori front-end system (central hub). What transactions do you have to use to map a back-end system to one of those roles?
- A. /UI2/GW_SYS_ALIAS
- B. SEGW
- C. /IWFND/MAINT_SERVICE
- D. PFCG
正解:C
質問 # 26
You want to use Configuration Validation functionality in SAP Solution Manager to check the consistency of settings across your SAP environment. What serves as the reference basis for Configuration Validation? Note: There are 2 correct answers to this question.
- A. A target system in your system landscape
- B. A virtual set of manually maintained configuration ems
- C. A list of recommended settings attached to a specific SAP Note
- D. A result list of configuration items from SAP Early Watch Alert (EWA)
正解:A、B
質問 # 27
Which of the following programs can be used to enable ALE Audit using the ALEAUD message type in the Customer Distribution Model and Partner Profiles?
Note: There are 2 correct answers to this question
- A. RBDSTATE
- B. RBDMIDOC
- C. RBDAPP01
- D. RBDAUD01
正解:A、D
質問 # 28
Which SAP product supports General Data Privacy Regulation (GDPR) compliance through mitigating control testing and validation?
- A. SAP Access Control
- B. SAP Solution Manager
- C. SAP Process Control
- D. SAP Identity Access Governance
正解:C
解説:
Explanation
SAP Process Control is a SAP product that supports General Data Privacy Regulation (GDPR) compliance through mitigating control testing and validation. SAP Process Control enables you to define and monitor controls for various business processes and regulations, such as GDPR, SOX, or ISO standards. It also allows you to perform control testing and validation activities, such as self-assessments, surveys, issue management, or remediation plans. References: https://help.sap.com/viewer/product/SAP_PROCESS_CONTROL/en-US
質問 # 29
While performing an audit of changes to the system and client change options for your production SAP S/4HANA environment, you receive the following message in transaction SCC4. "No logs found for selected period" How can you correct the problem.
- A. Maintain parameter rdisp/TRACE with value 3
- B. Maintain parameter rsau/enable with value 1
- C. Maintain parameter log-mode with value normal SAP HANA
- D. Maintain parameter rec/client with value ALL
正解:D
質問 # 30
You have created an RFC destination with a registered external RFC server program. When you try to connect to the external RFC destination you receive a
"SERVER_NOT_REGISTERED" error message. How can you resolve the issue? Note: There are 2 correct answers to this question.
- A. Maintain the access list in the transaction SMMS
- B. Maintain the profile parameter gw/acl_mode = 0
- C. Maintain the entries in the REGINFO file
- D. Maintain the entries in the SECINFO file
正解:A、C
解説:
Explanation
These are some of the tasks that you would perform to resolve the issue of a
"SERVER_NOT_REGISTERED" error message when trying to connect to an external RFC destination with a registered external RFC server program. The REGINFO file is a file that contains rules for allowing or denying registration requests from external RFC server programs to the gateway of an SAP system. The access list in transaction SMMS is a list that contains rules for allowing or denying connection requests from external RFC clients to an SAP system. References:
https://help.sap.com/doc/saphelp_nw70ehp3/7.03/en-US/c8/e8d53d35fb11d182b90000e829fbfe/content.htm?no_
質問 # 31
You have delimited a single role that is part of a composite role, and a user comparison for the composite role has been performed. You notice that the comparison did NOT remove the profile assignments for that single role. What program would you run to resolve this situation?
- A. PRGN_DELETE_ACTIVITY_GROUPS
- B. PRGN_MERGE_PREVIEW
- C. PRGN_COMPARE_ROLE_MENU
- D. PRGN_COMPRESS_TIMES
正解:A
解説:
Explanation
This is one of the programs that you would run to resolve this situation of not removing profile assignments for a single role after delimiting it and performing user comparison for its composite role. A single role is a role that contains authorizations for one application area or function. A composite role is a role that contains other roles as sub-roles without any authorizations by itself. A user comparison is a process that synchronizes user master records with role assignments and profile assignments in PFCG transaction.
PRGN_DELETE_ACTIVITY_GROUPS is a program that deletes single roles or composite roles from user master records along with their profile assignments. References:
https://help.sap.com/doc/saphelp_nw73ehp1/7.31.19/en-US/c8/e8d53d35fb11d182b90000e829fbfe/content.htm?
質問 # 32
You want to check the custom ABAP codes in your system for security vulnerabilities and you want to use the SAP Code Vulnerability Analyzer to carry out these extended security checks. What needs to be done for this purpose? Note: There are 2 correct answers to thisquestion.
- A. Run the transaction ST1 2 to start the analysis
- B. Run SAP Code Vulnerability Analyzer from the transaction ST01
- C. Run SAP Code Vulnerability Analyzer from the ABAP Test Cockpit
- D. Run the extended syntax check from the SLIN transaction
正解:A、C
解説:
Explanation
These are some of the tasks that you would perform to check the custom ABAP codes in your system for security vulnerabilities using the SAP Code Vulnerability Analyzer (CVA). CVA is a tool that enables you to perform static code analysis on ABAP programs and identify potential security issues, such as SQL injection, cross-site scripting, or buffer overflow. You can run CVA from the ABAP Test Cockpit (ATC), which is a framework for managing quality checks on ABAP programs and objects. You can also run CVA from the SLIN transaction, which performs an extended syntax check on ABAP programs and objects. References:
https://help.sap.com/doc/saphelp_nw73ehp1/7.31.19/en-US/48/9e2e3f6f8e41e8a283aaf2ad2c64c4/content.htm?n
質問 # 33
......
認定試験は、SAPシステムのランドスケープ、SAPシステムのセキュリティ、およびユーザー管理など、さまざまなトピックをカバーしています。候補者には、SAP NetWeaver Application ServerおよびABAPプログラミング言語に関する経験と知識が必要です。試験は多肢選択形式であり、80問から構成されており、3時間以内に完了する必要があります。認定を取得するには、65%以上の合格点が必要です。
検証済みのP-SECAUTH-21テスト問題集と解答で正確な80問題と解答あります:https://www.passtest.jp/SAP/P-SECAUTH-21-shiken.html
最新をゲットせよ!P-SECAUTH-21認定有効な試験問題集解答:https://drive.google.com/open?id=1WA6I8eWRFGnrwJHrAfP4oycufMcY1_En