[2023年12月15日] 更新されたP_SECAUTH_21試験PDF問題集にはPassTest合格保証付き [Q48-Q65]

Share

[2023年12月15日] 更新されたP_SECAUTH_21試験PDF問題集にはPassTest合格保証付き

あなたを合格させるSAP試験にはP_SECAUTH_21試験問題集


SAP P_SECAUTH_21 認定試験の出題範囲:

トピック出題範囲
トピック 1
  • SAP ビジネス スイートの承認の概念
  • セキュリティの監視とセキュリティの監査
トピック 2
  • SAP NetWeaver Application Server および関連するインフラストラクチャ コンポーネントのセキュリティの説明と実装
  • SAP S
  • 4HANA の承認の概念
トピック 3
  • SAP でのユーザー管理と ID ライフサイクル管理
  • SAP HANA での承認、セキュリティ、およびシナリオについて説明する
トピック 4
  • SAP HANA のセキュリティ目標、データ プライバシー ガバナンス
  • 承認、セキュリティ、およびシナリオについて説明する
トピック 5
  • SAP Business Suite
  • SAP Netweaver Application Server および Infrastructure Security の承認コンセプトを説明および実装する
トピック 6
  • SAP のガバナンスとコンプライアンスへのアクセス
  • SAP Cloud Platform Security
  • SAP システムの保護


認定試験は、SAPシステムのセキュリティアーキテクチャの基礎的な概念をカバーした包括的なトピックの設定に基づいています。試験には、セキュアなシステム設計、データ保護、アクセス制御、認可管理、監査などのトピックに関する質問が含まれます。候補者は、これらの概念を実世界のシナリオに適用する能力が試されます。

 

質問 # 48
The security administrator is troubleshooting authorization errors using transaction SU53. While running transaction MM50, the user received the following error.
"You are not authorized to use transaction MM01"
The user's position in the organization makes it inappropriate for them to have direct access to transaction MM01 because it creates a Segregation of Duties conflict.
How can the security administrator resolve the issue and still provide the user with the needed access to MM50?

  • A. Set the value form instance parameter auth/no_check_in_some_cases to N.
  • B. Set the check indicator value for object S_TCODE in the SU24 data for transaction MM01 to Do Not Check.
  • C. Remove transaction MM01 as a CALLING transaction from table TCDCOUPLES.
  • D. Set the check indicator (for the transaction authorization called by the MM01 transaction) to NO, using transaction SE97 for transaction MM50.

正解:D


質問 # 49
How are user group administrators and user groups related in SAP HANA? Note: there are 2 correct answers to this question.

  • A. Only one user group administrator per user group
  • B. Multiple user group administrators per user group
  • C. Multiple user groups per user group administrator
  • D. Only one user group per user group administrator

正解:B、C


質問 # 50
How can you describe static and dynamic assignments? Note: There are 2 correct answers to this question.

  • A. Dynamic assignments are based on attribute values
  • B. Dynamic assignments are based on scope values.
  • C. Static assignments occur at runtime.
  • D. Static assignments are set up via the Cloud Cockpit.

正解:B、D

解説:
Explanation
Static assignments are the assignments of roles and role collections to users or groups that are done manually via the Cloud Cockpit. Dynamic assignments are the assignments of roles and role collections to users or groups that are done automatically based on scope values. Scope values are attributes that are derived from the user's identity provider or from the application context. References:
https://help.sap.com/viewer/65de2977205c403bbc107264b8eccf4b/Cloud/en-US/9e1bf57130ef466e8017eab298
https://help.sap.com/viewer/65de2977205c403bbc107264b8eccf4b/Cloud/en-US/9e1bf57130ef466e8017eab298


質問 # 51
The SSO authentication using X.509 client certificates is configured. Users complain that they can't log in to the back-end system. The trace file shows the following error message: "HTTP request [2/5/9] Reject untrusted forwarded certificate". What is missing in the configuration? Note: There are 2 correct answers to this question.

  • A. The web dispatcher's SAPSSLC.PSE certificate must be added to the trusted reverse proxies list in icm/trusted_reverse_proxy_<xx>
  • B. On the web-dispatcher, the profile parameter icm/HTTPS/verify_client must be set to 0
  • C. On the web-dispatcher, the SAPSSLS.pse must be signed by a trusted certification authority
  • D. On the back-end, the profile parameter icm/HTTPS/verify client must NOT be set to 0

正解:C、D


質問 # 52
When re-configuring the user management engine (UME) of an AS Java system, what do you need to consider to change the data source from system database to an ABAP system successfully?

  • A. All users and groups in the system database must have different IDs than existing users and groups in the ABAP system.
  • B. You need to import the users from the system database into the ABAP system.
  • C. You must manually replace the UME configuration file dataSourceConfiguration_database_only.xmlwith an appropriate dataSourceConfiguration_abap.xmlfile.
  • D. The logon security policy for the existing users is aligned with the logon security policy in the ABAP system.

正解:A


質問 # 53
Which authorizations are required for an SAP Fiori Launchpad user? Note: There are 2 correct answers to this question

  • A. /UI2/PAGE_BUILDER_CUST
  • B. /UI2/INTEROP
  • C. /UI2/PAGE_BUILDER_PERS
  • D. /UI2/CHIP

正解:B、C


質問 # 54
Which SAP tool provides functions to support Data Destruction, Business Rules Maintenance, and Processing of Audit Areas?

  • A. SAP Business Rule Framework Plus
  • B. SAP Data Controller Rule Framework
  • C. SAP Information Lifecycle Management
  • D. SAP Information Retrieval Framework

正解:C

解説:
Explanation
SAP Information Lifecycle Management (SAP ILM) provides functions to support Data Destruction, Business Rules Maintenance, and Processing of Audit Areas. SAP ILM enables you to manage the retention and destruction of data according to legal and business requirements, as well as to archive and delete data securely and compliantly. References:
https://help.sap.com/viewer/product/SAP_INFORMATION_LIFECYCLE_MANAGEMENT_ILM_/200/en-US
https://help.sap.com/viewer/product/SAP_INFORMATION_LIFECYCLE_MANAGEMENT_ILM_/200/en-US


質問 # 55
What connection type is used for restricted users?

  • A. HTTP/S
  • B. OLEDB
  • C. ODBC
  • D. JDBC

正解:A

解説:
Explanation
This is the connection type that is used for restricted users in SAP HANA systems. Restricted users are users that can only access SAP HANA via HTTP/S connections using predefined services or applications, such as XSODATA or XSJS services or SAP Fiori applications. Restricted users cannot use other connection types, such as JDBC, ODBC, or OLEDB, which allow direct SQL access to SAP HANA. References:
https://help.sap.com/viewer/6b94445c94ae495c83a19646e7c3fd56/2.0.05/en-US/fafcbcf9d9101014b3d9a08ce33


質問 # 56
You want to allow your trainee colleagues to use the SAP GUI to connect directly to your SAP S/4HANA (on-premise) demo system from a public internet connection. Which of the following SAP solutions is suited for this purpose?

  • A. SAP Cloud Connector
  • B. SAP NetWeaver Gateway
  • C. SAProuter
  • D. SAP Web Dispatcher

正解:C

解説:
Explanation
This is one of the SAP solutions that is suited for this purpose of allowing your trainee colleagues to use the SAP GUI to connect directly to your SAP S/4HANA (on-premise) demo system from a public internet connection. SAProuter is a program that acts as an application-level gateway between SAP systems and networks using TCP/IP protocol. SAProuter can be used to establish secure and encrypted connections between SAP systems and external networks using SNC (Secure Network Communication) certificates and keys. SAProuter can also be used to control access to SAP systems based on various criteria, such as source IP address, destination IP address, service name, or port number. References:
https://help.sap.com/doc/saphelp_nw73ehp1/7.31.19/en-US/c8/e8d53d35fb11d182b90000e829fbfe/content.htm?


質問 # 57
Which of the following function can be used to troubleshoot authorization errors for ABAP CDS views with Authorization based on Access Control?

  • A. ABAP TRACE
  • B. REPORT RSUSR008_009
  • C. STAUTHTRACE
  • D. E2E TRACE ANALYSIS

正解:C


質問 # 58
What is the purpose of the parameter rec/client in an AS ABAP based SAP system?

  • A. To log changes in Core Data Services views
  • B. To generate source code versions
  • C. To generate changes in documents
  • D. To log changes in tables

正解:D


質問 # 59
Which authorization object controls access to the trusting system between the managed system and SAP Solution Manager?

  • A. S_ ICM
  • B. S_SERVICE
  • C. S_RFC
  • D. S_RFCACL

正解:D


質問 # 60
What are some characteristics of an SAP HANA multitenant database system (MDC) running in high insolation mode? Note: there are 2 correct answers to this question.

  • A. All tenant-specific permissions to access files and directories are revoked from the <sid>adm user.
  • B. All tenant databases will share the operating system user and group.
  • C. The <sid>adm user can access the tenant-specific configuration and trace files.
  • D. All tenant-specific file and directory permissions are managed by the SAP HANA system.

正解:C、D


質問 # 61
What are the characteristics of assertion tickets? Note: There are 2 correct answers to this question.

  • A. They are used for user-to-system trusted login
  • B. They have an unconfigurable validity of 2 minutes
  • C. They are used for system-to-system communication
  • D. They are transmitted as cookies

正解:B、C


質問 # 62
Who can revoke a runtime role from a user in the SAP HANA tenant database? Note: There are 2 correct answers to this question. Note: there are 2 correct answers to this question.

  • A. Anyone with "ROLE ADMIN"
  • B. The owner of the HDI container
  • C. The DBACOCKPIT user
  • D. The grating user

正解:A、D


質問 # 63
How can you protect a table containing sensitive data using the authorization object S_TABU_DIS?

  • A. The field DICBERCLS of the authorization object must enumerate all table names of the tables containing sensitive data.
  • B. Authorization table groups containing tables with sensitive data must be defined in table TDDAT and these must be omitted for all employees who do not need access to these tables
  • C. The tables containing sensitive data must be associated with table groups in table TBRG.
  • D. The tables containing sensitive data must be named using the authorization object S_TA BU_NAM for all responsible administrator employees. The fields DICBERCLS of the object S_TABU_DIS can

正解:B

解説:
then be filled with *.


質問 # 64
What does the SAP Security Optimization Service provide? Note: There are 2 correct answers to this question.

  • A. Analysis of the security vulnerabilities within an SAP landscape
  • B. Results containing the list of patches that have to be applied
  • C. Analysis of the network configuration
  • D. Configuration checks of SAP systems

正解:C、D

解説:
Explanation
These are some of the things that the SAP Security Optimization Service provides. SAP Security Optimization Service is a service that enables you to assess and improve the security level of your SAP systems and landscapes based on best practices and recommendations from SAP experts. The service provides configuration checks of SAP systems, which analyze various parameters and settings related to security aspects, such as passwords, authorizations, encryption, or logging. The service also provides analysis of the network configuration, which evaluates the network topology and communication channels between SAP systems and components. References: https://support.sap.com/en/security/security-optim


質問 # 65
......


SAP P_SECAUTH_21認定試験は、システムセキュリティアーキテクトになりたい専門家の知識とスキルを検証するように設計されています。この認定は、Enterprise Software Solutionsの大手プロバイダーであるSAPによって提供されます。この試験では、SAPシステムにおけるセキュリティ制御の設計、実装、管理など、システムセキュリティアーキテクチャのさまざまな側面をカバーしています。これは、SAPシステムを強く理解し、システムセキュリティでのキャリアを追求することに関心がある個人を対象としています。

 

最新でリアルなP_SECAUTH_21試験問題集解答:https://www.passtest.jp/SAP/P_SECAUTH_21-shiken.html

P_SECAUTH_21試験問題集でSAP練習テスト問題:https://drive.google.com/open?id=1cg3QFJLPhDSE1BtES3NNXNmNdAV-McJU