Skip to content

c-sec-2405 SAP Certified Associate - Security Administrator Practice Questions

Prepare for c-sec-2405 with more than an answer.

216 questions in the full set20 sample questionsUpdated Oct 18, 2025
Exam fee
$1308 USD
Level
Associate
Valid for
12 months
Domains covered on the exam 6
  1. Authorization and Role Maintenance25.5%
  2. Governance, Compliance, and Cybersecurity25.5%
  3. Infrastructure Security and Authentication25.5%
  4. Public Cloud User and Role Management25.5%
  5. SAP Fiori Authorizations and SAP S/4HANA15.5%
  6. User Administration5%
  1. 1

    Which of the following are valid user types in an SAP ABAP system? (Select THREE)

    Show answer details

    Correct answer: A, B, D

    Dialog users are for interactive system access by a single person (e.g., via SAP GUI).

    System users are for dialog-free communication within a system, such as background processing or RFC calls.

    Service users are typically used for anonymous system access for a larger, anonymous group of users (e.g., through an ITS service).

  2. 2

    A security consultant is asked to implement Segregation of Duties (SoD) controls. The goal is to prevent a single user from being able to both create a vendor master record and post a payment to that vendor. In the context of SAP GRC Access Control, what is this combination of conflicting actions called?

    Show answer details

    Correct answer: B

    In SAP GRC Access Control, an 'Access Risk' (or SoD Risk) is defined as a combination of two or more conflicting functions (e.g., create vendor and pay vendor) that could potentially be exploited for fraudulent activity. The GRC ruleset is built upon these risk definitions to analyze user and role assignments for violations.

  3. 3

    A company has a requirement that all changes to the vendor bank details in the production system must be logged for audit purposes. Which combination of actions is required to meet this requirement?

    Show answer details

    Correct answer: B

    This is a two-part requirement. First, the specific tables that store vendor bank details (like LFBK) must have the 'Log data changes' flag set in their technical settings (transaction SE11). Second, table logging must be activated system-wide for the client by setting the rec/client profile parameter. Once both are active, changes made via standard transactions will be recorded in the DBTABLOG table and can be viewed with transaction SCU3.

  4. 4

    Case Study: A pharmaceutical company, 'PharmaCorp', is centralizing its user administration for its global SAP landscape, which includes SAP S/4HANA, SAP BW/4HANA, and an SAP NetWeaver Portal. The landscape consists of a central development system, a QA system, and separate production systems for the Americas, EMEA, and APAC regions. The primary goal is to manage all user master data from a single point of control to ensure consistency and improve auditability.

    PharmaCorp's security team has decided to implement Central User Administration (CUA). They have designated their primary S/4HANA production system in the EMEA region as the CUA central system. All other systems, including development and QA, will be child systems. A key requirement is that roles should be assigned globally from the central system, but certain parameters, like the output device, should be maintained locally by regional support teams.

    During the initial rollout, a user in the APAC region reports that their roles are not appearing correctly after being assigned in the central EMEA system. The CUA administrator checks transaction SCUL (CUA Log Display) and sees that the IDoc distribution for this user has failed. The error message indicates a problem with the role assignment data.

    What is the most likely reason for the IDoc failure in this CUA scenario?

    Show answer details

    Correct answer: C

    A fundamental prerequisite for CUA to function correctly is that all roles assigned in the central system must also exist in the child systems where they are being assigned. CUA only distributes the assignment of the role to the user, not the role definition itself. The roles must be transported to all relevant child systems independently. If the role definition is missing in the target system, the IDoc containing the user's assignment data will fail to process.

  5. 5

    What is the primary purpose of using derived roles in PFCG?

    Show answer details

    Correct answer: B

    Derived roles are used to efficiently manage authorizations for users who perform the same function but in different organizational units (e.g., company code, plant). A master role is created with all the necessary transactions and non-organizational authorizations. Derived roles inherit this data, and the administrator only needs to maintain the specific organizational level values in each derived role. This significantly reduces maintenance effort.

  6. 6

    A financial services company is implementing Kerberos-based Single Sign-On (SSO) for its SAP S/4HANA landscape. During testing, users in a trusted domain can log on seamlessly, but users from a newly acquired company in a separate forest fail to authenticate. The network firewalls are confirmed to be open. Which of the following is the most critical configuration to check for resolving cross-forest authentication issues?

    Show answer details

    Correct answer: B

    For Kerberos authentication to work across different Active Directory forests, a proper two-way forest trust must be established. Furthermore, if 'selective authentication' is enabled on the trust, the service account running the SAP application server must be explicitly granted the 'Allowed to Authenticate' permission on the domain controllers of the other forest. This is a common point of failure in complex multi-forest Kerberos setups.

  7. 7

    A user reports being able to see a Fiori tile on their launchpad for a new analytical app but receives an authorization error upon opening it. The security administrator has confirmed the OData service authorizations are correct in the PFCG role. Which of the following is the next most probable cause of the authorization failure?

    Show answer details

    Correct answer: B

    Modern Fiori analytical apps are built on ABAP CDS views. Access to the data presented by these views is controlled by an additional authorization layer called Data Control Language (DCL). Even if the user has the OData service authorization (which controls access to the service endpoint), they will still get an error if the DCL access controls prevent them from seeing the data itself. This is a common troubleshooting step after verifying OData authorizations.

  8. 8

    An organization is configuring Central User Administration (CUA). The administrator wants to ensure that certain fields, like the user's department, can only be maintained in the central system and are read-only in the child systems. Which transaction is used to configure this field-level distribution behavior?

    Show answer details

    Correct answer: C

    Transaction SCUM (Central User Administration - System Landscape) is the primary tool for managing the CUA landscape. Within SCUM, the 'Field distribution' tab allows an administrator to specify for each user master data field whether it should be maintained globally (in the central system only), locally (in child systems), or proposed from the central system. This is crucial for enforcing consistent user data across the landscape.

  9. 9

    A project requires securing RFC connections between an SAP S/4HANA system and a legacy SAP ECC system using SNC with the SAP Cryptographic Library. Which TWO of the following are mandatory steps for this configuration? (Select TWO)

    Show answer details

    Correct answer: A, B

    Each system needs its own SNC PSE, which contains its private key and public key certificate. For the systems to trust each other, the public key certificate of each system must be imported into the other system's PSE certificate list.

    Profile parameters like snc/gssapi_lib (pointing to the cryptographic library) and snc/identity/as (defining the system's SNC name) must be set on both systems to enable SNC and identify the systems to each other.

  10. 10

    During an internal audit, it was discovered that a sensitive custom table containing employee salary data did not have logging enabled. The security administrator has now activated table logging for this table in the technical settings. What is the direct consequence of this action?

    Show answer details

    Correct answer: A

    Activating table logging causes the system to record changes (inserts, updates, deletes) made to the table data. This logging is primarily triggered by standard maintenance transactions. The logs can then be analyzed using transaction SCU3. It does not log read access or changes made via native SQL.

Create an account to continue.