c-sec-2405 Sample Questions

c-sec-2405 Sample Questions & Answers

Four areas share the heaviest weight: setting up roles and authorization strategy, SAP GRC and cybersecurity basics, network and authentication security, and public cloud authorization, next to Fiori-specific permissions and ABAP, Java and HANA user admin.

Launch the full c-sec-2405 simulator →

Showing 10 of 20 free samples.

  1. Question 1Intermediate

    SAP Fiori Authorizations and SAP S/4HANA · S/4HANA Authorization Migration

    A company is migrating from SAP ECC to SAP S/4HANA. The security team needs to adapt existing roles for the new SAP Fiori Launchpad. What is the purpose of transaction SU25 steps 2a, 2b, and 2c in this context?

    Show answer & explanation

    Correct answer: B

    Transaction SU25 is crucial for post-upgrade authorization adjustments. Steps 2a, 2b, and 2c are used to compare the authorization default values (from SU24) of the old release with the new S/4HANA release. This process helps administrators identify which of their existing PFCG roles contain transactions with changed authorization data, allowing them to manually review and merge the new defaults to ensure the roles function correctly in S/4HANA.

  2. Question 2Beginner

    Public Cloud User and Role Management · Cloud Role Management

    True or False: In an SAP S/4HANA Cloud, Public Edition environment, it is a recommended best practice to create business roles from scratch to ensure a perfect fit for organizational requirements.

    Show answer & explanation

    Correct answer: B

    False. The recommended best practice in SAP S/4HANA Cloud, Public Edition, is to copy the standard business role templates provided by SAP and then adjust the copy. This approach ensures that the role is based on a tested and supported foundation, simplifies future upgrades, and leverages the pre-configured business catalogs and applications associated with the template.

  3. Question 3Advanced

    Infrastructure Security and Authentication · SAML 2.0 Configuration

    A security consultant needs to implement an authentication flow where users logging into an on-premise SAP Fiori Launchpad are authenticated by a central corporate Identity Provider (IdP). The IdP supports SAML 2.0. Which components are essential to establish this trust relationship?

    sequenceDiagram participant User as User's Browser participant FLP as Fiori Launchpad participant IdP as Corporate IdP participant GW as SAP Gateway User->>FLP: Access Launchpad FLP-->>User: Redirect to IdP User->>IdP: Authenticate (e.g., password, MFA) IdP-->>User: Issue SAML 2.0 Assertion User->>GW: Present SAML Assertion GW->>GW: Validate Assertion GW-->>User: Grant Access / Session Cookie

    Show answer & explanation

    Correct answer: B

    SAML 2.0 integration relies on a trust relationship established by exchanging metadata. The SAP Gateway system acts as the Service Provider (SP). Its SP metadata must be exported and given to the Identity Provider (IdP). Conversely, the IdP's metadata must be imported into the SAP system (using transaction SAML2). Additionally, the core SICF services for SAML processing (/sap/public/bc/sec/saml2 and /sap/bc/webdynpro/sap/saml2) must be active.

  4. Question 4Beginner

    Authorization and Role Maintenance · Role Maintenance Fundamentals

    An administrator is creating a new role using PFCG. After adding a transaction to the role menu, they navigate to the Authorizations tab and discover the status light is yellow. What does this indicate?

    Show answer & explanation

    Correct answer: C

    In transaction PFCG, a yellow status light on the Authorizations tab indicates that the authorization data has been modified (e.g., by adding new transactions or manually changing objects) but the corresponding authorization profile has not yet been generated. The administrator must enter the authorization data in expert mode to maintain the values and then generate the profile, which will turn the light green.

  5. Question 5Intermediate

    Infrastructure Security and Authentication · Gateway Security

    What is the primary function of the secinfo and reginfo files in an SAP Gateway environment?

    Show answer & explanation

    Correct answer: B

    The reginfo (registration info) file controls which external RFC server programs are allowed to register themselves with the SAP Gateway using a specific Program ID. The secinfo (security info) file defines which clients (based on host and user) are permitted to start external programs via the Gateway. Together, they form a critical access control list (ACL) for protecting the Gateway from unauthorized external program execution and registration.

  6. Question 6Beginner

    Authorization and Role Maintenance · Authorization Analysis and Monitoring

    Which tool would a security administrator use to get a comprehensive overview of a user's authorizations by searching for roles containing specific authorization objects, or users assigned to profiles with critical values?

    Show answer & explanation

    Correct answer: C

    The User Information System (SUIM) is a powerful reporting toolset designed for comprehensive authorization analysis. It allows administrators to run a wide variety of reports, such as finding users by role or profile assignment, finding roles that contain a specific authorization object, or even searching for users who have an authorization object with a particular value. It is the primary tool for this kind of analysis.

  7. Question 7Intermediate

    Public Cloud User and Role Management · Cloud Identity Services Integration

    A company is using SAP Cloud Identity Services. What are the distinct primary functions of the Identity Authentication service (IAS) and the Identity Provisioning service (IPS)?

    Show answer & explanation

    Correct answer: B

    This correctly separates the functions. The Identity Authentication service (IAS) is a cloud-based Identity Provider (IdP) that handles user login, SSO, MFA, and trust relationships. The Identity Provisioning service (IPS) is responsible for identity lifecycle management; it reads users and groups from a source system (like a corporate directory) and provisions (creates, updates, deletes) them into various target systems (both cloud and on-premise).

  8. Question 8Beginner

    User Administration · Basic User Maintenance

    To enhance security, an administrator wants to enforce a policy that locks a user account after 5 failed logon attempts. Where is this policy configured in an ABAP system?

    Show answer & explanation

    Correct answer: B

    System-wide password and logon policies, such as the number of failed attempts before an account is locked, password length, and complexity rules, are controlled by profile parameters. These parameters are maintained using transaction RZ10 (for static profiles) or RZ11 (for dynamic changes) and apply to all users in the system. The specific parameter for this requirement is login/fails_to_user_lock.

  9. Question 9Advanced

    SAP Fiori Authorizations and SAP S/4HANA · Fiori Launchpad Roles and Catalogs

    An organization wants to analyze the usage of its custom Fiori apps to identify which apps are used most frequently and by which departments, in order to prioritize future development. Which Fiori component is essential for collecting this type of usage data?

    Show answer & explanation

    Correct answer: C

    The SAP Fiori Launchpad has built-in capabilities to collect detailed usage statistics, such as which apps are launched, how long they are used, and by which users. This functionality needs to be activated and configured. The collected data is stored in the backend system and can be extracted to a data warehouse (like SAP BW) for detailed analysis, providing valuable insights into user behavior and app popularity.

  10. Question 10Intermediate

    Public Cloud User and Role Management · Cloud Role Management

    A manufacturing firm is implementing SAP S/4HANA Cloud, Public Edition. They need to restrict access to a specific Fiori app so that users in the 'US01' company code can only see data related to plant '1000', while users in the 'DE01' company code can only see data for plant '2000'. What is the most efficient and standard way to achieve this?

    graph TD subgraph Business Role [Business Role: Production Planner] direction LR Catalog[Business Catalog: Production Planning] App[Fiori App: Manage Production Orders] end subgraph User Assignments UserUS[User A - USA] UserDE[User B - Germany] end UserUS -->|Assigned With Restrictions| Business Role UserDE -->|Assigned With Restrictions| Business Role subgraph Restrictions ResUS[" User A: Company Code: US01 Plant: 1000"] ResDE[" User B: Company Code: DE01 Plant: 2000"] end Business Role -- defines access to --> App Restrictions -- applied to --> UserUS Restrictions -- applied to --> UserDE

    Show answer & explanation

    Correct answer: B

    The standard and most scalable method in S/4HANA Cloud, Public Edition is to use a single business role that grants access to the app (via a business catalog) and then apply granular restrictions. Using the 'Maintain Business Role' or 'Maintain Business User' apps, an administrator can define access restrictions for specific fields (like Company Code and Plant) and assign different values to different users, all under the same role. This avoids role proliferation and simplifies maintenance.

Ready for the real thing?

The full c-sec-2405 simulator has every exam-style question, timed mode, and instant scoring.