
[2024年更新]合格できるP_SECAUTH_21試験にはリアルな問題解答
P_SECAUTH_21試験問題ゲット最新[2024]と正解回答
質問 # 32
You are running an SAP HANA database in a multi database container (MDC) mode with a single tenant configured. The global_auditing_state parameter has been set to "true" on the global.ini.After restarting the system and tenant databases, the tenant did not come up. When checking the cause, it was discovered that a tenant configuration parameter has been changed. The audit logging did NOT show any events.What could be the reason for this? Note: There are 2 correct answers to this question.
- A. The system was offline when the changes were done
- B. The configuration parameter was changed from the OS level
- C. The global_auditing_state parameter on the nameserver.ini file needs to be activated
- D. The audit level was set to INFO
正解:B、C
質問 # 33
Which type of systems can be found in the Identify Provisioning Service landscape? Note: There are 2 correct answers to this question
- A. Proxy
- B. Source
- C. Service Provider
- D. Identify Provider
正解:B、D
質問 # 34
You want to allow your trainee colleagues to use the SAP GUI to connect directly to your SAP S/4HANA (on-premise) demo system from a public internet connection. Which of the following SAP solutions is suited for this purpose?
- A. SAProuter
- B. SAP Cloud Connector
- C. SAP NetWeaver Gateway
- D. SAP Web Dispatcher
正解:A
解説:
Explanation
This is one of the SAP solutions that is suited for this purpose of allowing your trainee colleagues to use the SAP GUI to connect directly to your SAP S/4HANA (on-premise) demo system from a public internet connection. SAProuter is a program that acts as an application-level gateway between SAP systems and networks using TCP/IP protocol. SAProuter can be used to establish secure and encrypted connections between SAP systems and external networks using SNC (Secure Network Communication) certificates and keys. SAProuter can also be used to control access to SAP systems based on various criteria, such as source IP address, destination IP address, service name, or port number. References:
https://help.sap.com/doc/saphelp_nw73ehp1/7.31.19/en-US/c8/e8d53d35fb11d182b90000e829fbfe/content.htm?
質問 # 35
Insufficient authorization checks might allow A BAP programs to access the PSE files. Which authorization objects should we check to protect the PSEs? Note: There are 2 correct answers to this question.
- A. S_ADMI_FCD
- B. S_DATASET
- C. S_RZL_ADM
- D. S_DEVELOP
正解:B、C
質問 # 36
You want to configure SNC with X.509 certificates using Common CryptoLib as the cryptographic library in a new installed AS ABAP system. Besides running SNCWIZARD, what do you need to set up for this scenario? Note: There are 2 correct answers to this question.
- A. Set the CCL SNC parameters using sapgenpse
- B. Set the environment variable CCL_ PROFILE to the default profile file path
- C. Maintain the relevant CCL/SNC/' profile parameters
- D. Set the environment variable CCL_ PROFILE to SECUDIR
正解:B、C
質問 # 37
A security consultant has activated a trace via ST01 and is analyzing the authorization error with Return Code 12. What does the Return Code 12 signify?
- A. "Objects not contained in User Buffer"
- B. "No authorizations and does NOT have authorization object in their buffer"
- C. "No authorizations but does have authorization object in their buffer"
- D. "Too many parameters for authorization checks"
正解:B
質問 # 38
When re-configuring the user management engine (UME) of an AS Java system, what do you need to consider to change the data source from system database to an ABAP system successfully?
- A. The UME configuration file dataSourceConfiguration_database_only.xml is automatically updated with an appropriate dataSourceConfiguration_abap.xml file.
- B. You need to import the users from the system database into the ABAP system.
- C. The logon security policy for the existing users is aligned with the logon security policy in the ABAP system.
- D. All users and groups in the system database must have different IDs than existing users and groups in the ABAP system.
正解:D
解説:
Explanation
This is one of the tasks that you need to consider to change the data source from system database to an ABAP system successfully when re-configuring the user management engine (UME) of an AS Java system. The UME is a component that handles user administration and authentication for AS Java systems. The UME can use different data sources for storing user and group data, such as system database, ABAP system, or LDAP directory. When changing the data source from system database to an ABAP system, you need to ensure that all users and groups in the system database have different IDs than existing users and groups in the ABAP system, otherwise there will be conflicts and errors during the migration process. References:
https://help.sap.com/doc/saphelp_nw73ehp1/7.31.19/en-US/48/9e2e3f6f8e41e8a283aaf2ad2c64c4/content.htm?n
質問 # 39
You are reviewing the authorizations for Core Data Services (CDS) views. How are classic authorizations integrated with CDS authorizations?
- A. By defining access conditions in an access rule for the CDS view
- B. By assigning the CDS view to the authorization profile in PFCG
- C. By using the statement AUTHORITY-CHECK in the access control of the CDS view
- D. By defining the CDS view in the authorization object in SU21
正解:A
質問 # 40
Which transaction or report can be used to audit profile assignments in an SU01 user master record? Note: There are 2 correct answers to this question.
- A. RSUSR1 00
- B. RSUSR002
- C. SM20N
- D. ST01
正解:A、B
解説:
Explanation
These are some of the transactions or reports that can be used to audit profile assignments in an SU01 user master record. A user master record is a record that contains information about a user in an SAP system, such as personal data, logon data, defaults, parameters, or authorizations. A profile assignment is an assignment of a profile to a user master record, which grants the user certain authorizations or permissions in the system.
RSUSR002 is a transaction or report that displays users by complex selection criteria, such as profiles, authorizations, or transactions. RSUSR100 is a transaction or report that displays users according to logon date and password change date, along with their profiles and roles. References:
https://help.sap.com/doc/saphelp_nw73ehp1/7.31.19/en-US/c8/e8d53d35fb11d182b90000e829fbfe/content.htm?
質問 # 41
Which characteristics apply to the SAP ID Service? Note: There are 2 correct answers to this question.
- A. Configurable password policy
- B. Customizable user interface
- C. Non-configurable MFA for SAP BTP Cockpit
- D. User base owned and managed by SAP
正解:A、D
解説:
Explanation
The SAP ID Service is a cloud-based identity provider that offers a configurable password policy and a user base owned and managed by SAP. The SAP ID Service is used to authenticate users for various SAP cloud applications and services, such as SAP Cloud Platform, SAP Analytics Cloud, and SAP Fiori Launchpad.
References: https://help.sap.com/viewer/product/SAP_ID_SERVICE/en-US
https://help.sap.com/viewer/product/SAP_ID_SERVICE/en-US
質問 # 42
What authorization object is checked when a user selects an ABAP Web Dynpro application to run?
- A. S_PROGRAM
- B. S_TCODE
- C. S_START
- D. S_SERVICE
正解:D
解説:
Explanation
The authorization object S_SERVICE is checked when a user selects an ABAP Web Dynpro application to run. This authorization object controls the access to Web services and Web Dynpro applications based on the service name and type. References:
https://help.sap.com/doc/saphelp_nw70ehp3/7.03/en-US/c8/e8d53d35fb11d182b90000e829fbfe/content.htm?no_
https://help.sap.com/doc/saphelp_nw70ehp3/7.03/en-US/c8/e8d53d35fb11d182b90000e829fbfe/content.htm?no_
質問 # 43
How is the role concept applied for modeled authorizations based on Core Data Services (CDS) views?
- A. CDS roles are defined for the CDS views and implicitly applied to each user.
- B. CDS roles are mapped to the CDS view in the access rules.
- C. CDS roles are defined for CDS views in Object Navigator.
- D. CDS roles are defined in the WHERE clause when calling a CDS view in Open SQL.
正解:B
解説:
Explanation
The role concept for modeled authorizations based on Core Data Services (CDS) views works in this way:
CDS roles are mapped to the CDS view in the access rules that define which users can access which data from the CDS view. The access rules are defined using annotations in the CDS view definition or using a separate access control DDL source file. References:
https://help.sap.com/viewer/cc0c305d2fab47bd808adcad3ca7ee9d/7.5.9/en-US/fafcbcf9d9101014b3d9a08ce33d
https://help.sap.com/viewer/cc0c305d2fab47bd808adcad3ca7ee9d/7.5.9/en-US/fafcbcf9d9101014b3d9a08ce33d
質問 # 44
Which of the following function can be used to troubleshoot authorization errors for ABAP CDS views with Authorization based on Access Control?
- A. ABAP TRACE
- B. STAUTHTRACE
- C. E2E TRACE ANALYSIS
- D. REPORT RSUSR008_009
正解:B
質問 # 45
Which authorizations are required for an SAP Fiori Launchpad user? Note: There are 2 correct answers to this question
- A. /UI2/PAGE_BUILDER_PERS
- B. /UI2/CHIP
- C. /UI2/PAGE_BUILDER_CUST
- D. /UI2/INTEROP
正解:A、D
質問 # 46
Which communication methods does the SAP Fiori Launchpad use to retrieve business data? Note: There are 2 correct answers to this question
- A. InA
- B. OData
- C. SNC
- D. HOP
正解:A、C
質問 # 47
To prevent session fixation and session hijacking attacks, SAP's HTTP security session management is highly recommended. What are the characteristics of HTTP security session management? Note: There are 2 correct answers to this question.
- A. The system is checking the logon credentials again for every request
- B. The session identifier is a reference to the session context transmitted through a cookie.
- C. It uses URLs containing sap-context d to identify the security session
- D. The security sessions are created during logon and deleted during logoff.
正解:B、D
質問 # 48
Which communication methods does the SAP Fiori Launchpad use to retrieve business data? Note: There are 3 correct answers to this question.
- A. Data
- B. HTIP(S)
- C. Trusted RFC
- D. Info Access (InA)
- E. Secure Network Communication (SNC)
正解:C、D、E
質問 # 49
Which tasks would you perform to allow increased security for the SAP Web Dispatcher WebAdministration interface? Note: There are 2 correct answers to this question.
- A. Use subparameter ALLOWPUB = TRUE of the profile parameter icm/server_port_<xx>
- B. Use a separate port for the administration interface
- C. Use Secure Socket Layer (SSL) for encrypted access
- D. Use access restrictions with the icm/HTTP/auth_<xx> profile parameter
正解:C、D
解説:
Explanation
These are some of the tasks that you would perform to allow increased security for the SAP Web Dispatcher WebAdministration interface, which is a web-based tool for configuring and monitoring the SAP Web Dispatcher instance. You can use access restrictions with the icm/HTTP/auth_<xx> profile parameter, which allows you to define rules for allowing or denying access based on IP addresses, host names, or URLs. You can also use Secure Socket Layer (SSL) for encrypted access, which protects the communication between your browser and the WebAdministration interface using certificates and keys. References:
https://help.sap.com/doc/saphelp_nw70ehp3/7.03/en-US/c8/e8d53d35fb11d182b90000e829fbfe/content.htm?no_
質問 # 50
Which authorization object is required to support trusted system access by an RFC user following the configuration of a Managed System in SAP Solution Manager?
- A. S_RFC_TT
- B. S_RFCACL
- C. S_RFC_TTAC
- D. S_ACL_HIST
正解:B
質問 # 51
Which of the following programs can be used to enable ALE Audit using the ALEAUD message type in the Customer Distribution Model and Partner Profiles?
Note: There are 2 correct answers to this question
- A. RBDAPP01
- B. RBDAUD01
- C. RBDSTATE
- D. RBDMIDOC
正解:B、C
質問 # 52
......
練習できるP_SECAUTH_21問題で認証試験問題集ガイド解答は練習専門PassTest:https://www.passtest.jp/SAP/P_SECAUTH_21-shiken.html
無料SAP P_SECAUTH_21テスト練習テスト問題試験問題集:https://drive.google.com/open?id=1cg3QFJLPhDSE1BtES3NNXNmNdAV-McJU