SAP Certified Associate - Security Administrator Free Sample Questions

20 free sample questions216 in the full practice test

Try simulator

c-sec-2405 Sample Questions

  1. Question 1

    A financial services company is implementing Kerberos-based Single Sign-On (SSO) for its SAP S/4HANA landscape. During testing, users in a trusted domain can log on seamlessly, but users from a newly acquired company in a separate forest fail to authenticate. The network firewalls are confirmed to be open. Which of the following is the most critical configuration to check for resolving cross-forest authentication issues?

    Answer and explanation

    Correct answer: B

    For Kerberos authentication to work across different Active Directory forests, a proper two-way forest trust must be established. Furthermore, if 'selective authentication' is enabled on the trust, the service account running the SAP application server must be explicitly granted the 'Allowed to Authenticate' permission on the domain controllers of the other forest. This is a common point of failure in complex multi-forest Kerberos setups.

  2. Question 2

    A user reports being able to see a Fiori tile on their launchpad for a new analytical app but receives an authorization error upon opening it. The security administrator has confirmed the OData service authorizations are correct in the PFCG role. Which of the following is the next most probable cause of the authorization failure?

    Answer and explanation

    Correct answer: B

    Modern Fiori analytical apps are built on ABAP CDS views. Access to the data presented by these views is controlled by an additional authorization layer called Data Control Language (DCL). Even if the user has the OData service authorization (which controls access to the service endpoint), they will still get an error if the DCL access controls prevent them from seeing the data itself. This is a common troubleshooting step after verifying OData authorizations.

  3. Question 3

    An organization is configuring Central User Administration (CUA). The administrator wants to ensure that certain fields, like the user's department, can only be maintained in the central system and are read-only in the child systems. Which transaction is used to configure this field-level distribution behavior?

    Answer and explanation

    Correct answer: C

    Transaction SCUM (Central User Administration - System Landscape) is the primary tool for managing the CUA landscape. Within SCUM, the 'Field distribution' tab allows an administrator to specify for each user master data field whether it should be maintained globally (in the central system only), locally (in child systems), or proposed from the central system. This is crucial for enforcing consistent user data across the landscape.

  4. Question 4

    Multiple answers

    A project requires securing RFC connections between an SAP S/4HANA system and a legacy SAP ECC system using SNC with the SAP Cryptographic Library. Which TWO of the following are mandatory steps for this configuration? (Select TWO)

    Answer and explanation

    Correct answers: A, B

    Each system needs its own SNC PSE, which contains its private key and public key certificate. For the systems to trust each other, the public key certificate of each system must be imported into the other system's PSE certificate list.

    Profile parameters like snc/gssapi_lib (pointing to the cryptographic library) and snc/identity/as (defining the system's SNC name) must be set on both systems to enable SNC and identify the systems to each other.

  5. Question 5

    During an internal audit, it was discovered that a sensitive custom table containing employee salary data did not have logging enabled. The security administrator has now activated table logging for this table in the technical settings. What is the direct consequence of this action?

    Answer and explanation

    Correct answer: A

    Activating table logging causes the system to record changes (inserts, updates, deletes) made to the table data. This logging is primarily triggered by standard maintenance transactions. The logs can then be analyzed using transaction SCU3. It does not log read access or changes made via native SQL.

  6. Question 6

    A company is migrating from SAP ECC to SAP S/4HANA. The security team needs to adapt existing roles for the new SAP Fiori Launchpad. What is the purpose of transaction SU25 steps 2a, 2b, and 2c in this context?

    Answer and explanation

    Correct answer: B

    Transaction SU25 is crucial for post-upgrade authorization adjustments. Steps 2a, 2b, and 2c are used to compare the authorization default values (from SU24) of the old release with the new S/4HANA release. This process helps administrators identify which of their existing PFCG roles contain transactions with changed authorization data, allowing them to manually review and merge the new defaults to ensure the roles function correctly in S/4HANA.

  7. Question 7

    True or False: In an SAP S/4HANA Cloud, Public Edition environment, it is a recommended best practice to create business roles from scratch to ensure a perfect fit for organizational requirements.

    Answer and explanation

    Correct answer: B

    False. The recommended best practice in SAP S/4HANA Cloud, Public Edition, is to copy the standard business role templates provided by SAP and then adjust the copy. This approach ensures that the role is based on a tested and supported foundation, simplifies future upgrades, and leverages the pre-configured business catalogs and applications associated with the template.

  8. Question 8

    A security consultant needs to implement an authentication flow where users logging into an on-premise SAP Fiori Launchpad are authenticated by a central corporate Identity Provider (IdP). The IdP supports SAML 2.0. Which components are essential to establish this trust relationship?

    sequenceDiagram participant User as User's Browser participant FLP as Fiori Launchpad participant IdP as Corporate IdP participant GW as SAP Gateway User->>FLP: Access Launchpad FLP-->>User: Redirect to IdP User->>IdP: Authenticate (e.g., password, MFA) IdP-->>User: Issue SAML 2.0 Assertion User->>GW: Present SAML Assertion GW->>GW: Validate Assertion GW-->>User: Grant Access / Session Cookie

    Answer and explanation

    Correct answer: B

    SAML 2.0 integration relies on a trust relationship established by exchanging metadata. The SAP Gateway system acts as the Service Provider (SP). Its SP metadata must be exported and given to the Identity Provider (IdP). Conversely, the IdP's metadata must be imported into the SAP system (using transaction SAML2). Additionally, the core SICF services for SAML processing (/sap/public/bc/sec/saml2 and /sap/bc/webdynpro/sap/saml2) must be active.

  9. Question 9

    An administrator is creating a new role using PFCG. After adding a transaction to the role menu, they navigate to the Authorizations tab and discover the status light is yellow. What does this indicate?

    Answer and explanation

    Correct answer: C

    In transaction PFCG, a yellow status light on the Authorizations tab indicates that the authorization data has been modified (e.g., by adding new transactions or manually changing objects) but the corresponding authorization profile has not yet been generated. The administrator must enter the authorization data in expert mode to maintain the values and then generate the profile, which will turn the light green.

  10. Question 10

    What is the primary function of the secinfo and reginfo files in an SAP Gateway environment?

    Answer and explanation

    Correct answer: B

    The reginfo (registration info) file controls which external RFC server programs are allowed to register themselves with the SAP Gateway using a specific Program ID. The secinfo (security info) file defines which clients (based on host and user) are permitted to start external programs via the Gateway. Together, they form a critical access control list (ACL) for protecting the Gateway from unauthorized external program execution and registration.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 216 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon