5
SAP Security interview Questions: 1. What is the user type for a background jobs user? Ans: 1system user, 2.communication user 2. How to trouble shoot problems for background user Ans: 3. There are two options in the PFCG while modifying a role. One change authorizations and another expert mode-what is the difference between them Ans:I 1. In change authorization we can give the new authorization to the role and generation of profile 2. In expert mode we can I) delete the old autho, profile and recreate, ii) edit old status 4. If we give Organizational values as * in the master role and want to restrict the derived roles for a specific country, how do we do? Ans: 5. What is the table name to see illegal passwords? Ans: USR40 6. What is the table name to see the authorization objects for a user Ans: 7. What are two main tables to maintain authorization objects Ans: USOBT, USOBX 8. BW security: Concept of analysis authorization and steps involved. Ans: 9. How to secure tables in SAP? Ans: Using Authorization group (S_TABU_DIS, S_TABU_CLI) in T.Code SE54

SAP_secinterview_questions209561292312898

Embed Size (px)

Citation preview

Page 1: SAP_secinterview_questions209561292312898

SAP Security interview Questions:

1. What is the user type for a background jobs user?

Ans: 1system user, 2.communication user

2. How to trouble shoot problems for background userAns:

3. There are two options in the PFCG while modifying a role. One change authorizations and another expert mode-what is the difference between them

Ans:I 1. In change authorization we can give the new authorization to the role and generation of profile

2. In expert mode we can I) delete the old autho, profile and recreate, ii) edit old status

4. If we give Organizational values as * in the master role and want to restrict the derived roles for a specific country, how do we do?Ans:

5. What is the table name to see illegal passwords?Ans: USR40

6. What is the table name to see the authorization objects for a userAns:

7. What are two main tables to maintain authorization objects Ans: USOBT, USOBX

8. BW security: Concept of analysis authorization and steps involved.Ans:

9. How to secure tables in SAP?Ans: Using Authorization group (S_TABU_DIS, S_TABU_CLI) in T.Code SE54

10. How to secure line/row in a tableAns:

11. Different steps to install security from scratchAns:

Page 2: SAP_secinterview_questions209561292312898

12. What are the critical authorization objects in SecurityAns:

13. Can we stop/hold the clock in Solution manager when we put to Waiting for user answer so that the delay by user will be not be counted in our SLAsAns:

14. Difference between USOBT and USOBX tablesAns: 1.USOBT-Transaction VS Authorization objects 2. USOBX- Transaction VS Authorization objects check indicators

15. Use of Firefighter application

Whenever the request coming from the user for new authorization .the request goes to firefighter owner. FF owner proved the FF ID to normal user then the user (secu admin) will assign the authori to those users (end user)

16. Where do we add the FF ids to the SAP user idsAns:

17. How to create FF idsAns:

18. Process of Access enforcer to provide access to a userAns:

19. Different types of usersAns: 1.Diolag user 2.service user 3.system user 4.communication user 5.refrences user

20. Different types of rolesAns: 1.Single role 2.Composite role 3.Derived role

21. Inheritance conceptAns:

22. Can a single role be used as master role?Ans: yes

23. How to create derived roleAns: go to PFCG type the Role name stating with Z .click on create role icon .Then right side u will find derive from here type the parent Role name

24. HR Security: How to create structural authorizations in HRAns:

25. HR Security: What are the objects for HR and what is the importance of each HR objectAns:

26. How to copy 100 roles from a client 800 to client 900?

Page 3: SAP_secinterview_questions209561292312898

Ans: Add all 100 roles as one single composite Role and Transfer the Composite role automatically the 100 Role will transfer to the target client (Using SCC1)

27. How to delete roles in CUA?Ans:

28. When we add a role to the users in CUA, and it is not appearing, how do you trouble shoot?Ans:

29. User reports that they lost the access. We check in SUIM and no change docs found...How do you trouble shoot?Ans:

30. How to trouble shoot HR issues?Ans:

31. What is the correct procedure for Mass Generation of Roles? Ans: Using T.Code –SUPC

32. What is the T.Code SQVI? What is the main usage of this SQVI?

Ans: SQVI -Quick View

33. How can we maintain Organizational values? How can we create Organizational?

34. How can we update the unique E-mail IDs for 1000 users at a time? 35. I want to see list of roles assigned to 10 different users. How do you do it?

Ans: Using T.Code SUIM 36.What do you mean by User Buffer? How it works with the user's Authorizations?

Ans: User buffer means user context it contain user related information i.e.) authorizations, parameters, reports, earlier acceded screens .We can see the user context using T.Code –SU56

37. What is the advantage of CUA from a layman/manager point of view?

Ans: CUA used for maintain and manage the users centrally.

38. Values? What is the purpose of these Org. values?

Ans: Values: it’s used for restrict the user by values e.g. Sale order value (1-100) it means user can create only 100 sales orders not more than that

39. How to create secatt script in sap step by step

40.What is the main purpose of Parameters Groups & Personalization tabs in SU01 and Miniapps in

PFCG?

Ans: 1.Parameter tab: its used to auto fills the some of the values during the creation of orders

Page 4: SAP_secinterview_questions209561292312898

2. Personalization tab is user to restrict the user in selection criteria E.g.: while selecting pay slip it will shows only last month pay slip by default. If u select the attendances it will shows current month by default

3. Miniapps

41. Reports.what is the possible ways of getting it done?

42. How many maximum profiles we can assign to one user?

43. In which way we can assign single role to many users (more than 5000 users).

44. Can we assign generated profiles to users directly?