SAP S/4HANA Administration

Access Protection, Data Security & Auditing

39 flashcards · answers and spaced-repetition review in the KnowCard app

Disk is filling with security audit log files. Why must you never delete them directly from the OS, and how does the system know if you did?
You need an audit filter change that will persist across restarts vs. one just for a short investigation. Which is static, which is dynamic, and what's the trap?
Web clients are getting access denied and you suspect ACL or filtered-object rejections. Which log captures that, and what kinds of events does it hold that the security audit log does not?
Someone proposes enabling table-change logging on master and transaction tables 'to catch every change.' Why is that the wrong target, and where do you read the logs you do keep?
To neutralize SAP*, an admin deletes the SAP* user. Why does that make things worse, and what's the correct procedure?
You open SM19/SM20 to configure and read the security audit log and they behave oddly. What replaced them, and which new transaction does each old job map to?
With gw/acl_mode set, what happens to the gateway if the gw/acl_file is missing or contains an error — and how should that shape your change process?
You want to ban any password containing 'SAP'. Where do you maintain the blacklist, what entry expresses that, and what scope gotcha bites people?
Before an upgrade you need to keep everyone out of a client. Why prefer the client lock (SCCR_LOCK_CLIENT) over locking all users with SU10?
You're choosing where to store the security audit log. What's the advantage of the database option over the file system, and when would you pick 'both'?
How does SAP actually scan an uploaded document for viruses, and what external piece must you supply yourself?
Which parameter must always be enabled to stop SSO logon tickets from ever crossing the wire unencrypted, and what's the trap if you leave it off 'because it's internal'?
Beyond just 'handling RFC,' what specific built-in feature makes the SAP gateway a serious security risk, and with whose authority can it act?
You lock a critical transaction with SM01_DEV but it's still runnable in other production clients. What did you miss about client 000, and what's the SM01_DEV vs SM01_CUS distinction?
An admin asks for SAP_ALL in production so they 'never get blocked.' What do you grant instead, and which of SAP_ALL / S_A.SYSTEM / S_A.DEVELOP must never reach production?
What value must auth/rfc_authority_check have in production, and what exactly is left unchecked if it sits at 0?
For GDPR you must show who *read* sensitive personal data. Why won't the security audit log alone satisfy this, and what do you use instead?
You need to find standard SAP users still using default passwords. Which of RSUSR003 / RSUSR006 / RSUSR007 is it, and what do the other two check?
A team wants to keep plain HTTP enabled 'just for redirects.' Why is that unacceptable, and what's the correct action?
An admin sets login/password_change_waittime to 0 to stop it 'annoying' users. What protection did they just disable, and what abuse does 0 re-enable?
Name the SAP system's four auditing tools and the one question each is best at answering.
Out of the box, are ICF services active or inactive — and what's the security consequence of that default for how you manage SICF?
What does login/disable_password_logon enforce when set, and which account must you be careful NOT to include?
An auditor wants a list of users holding critical authorizations. What's the fastest correct starting point in SUIM, rather than building it from scratch?
On what cadence does SAP release security fixes, what are they called, and why does the cadence matter for your patch planning?
An external RFC program needs to REGISTER with the gateway. Which file authorizes that — sec_info or reg_info — and where should both files live?
When a user is assigned a security policy (SECPOL), what replaces the profile parameters for them — and why can an unset value in the policy quietly weaken security?
An auditor asks for evidence of who logged on and changed user masters last quarter, but the security audit log was only turned on this week. What does the SAL actually capture, and what's the timing gotcha?
Beyond default passwords, what makes standard users (SAP*, DDIC, SAPCPIC, TMSADM, EARLYWATCH) a special risk in every system, and which report inventories them?
After adding ACLFILE to icm/server_port_<xx>, what happens to the ICM if that ACL file is missing or inconsistent, and what must the file always end with?
You set rec/client = ALL but a critical table still isn't logging changes. What second, per-table step did you miss, and where should table logging be limited?
You set rsau/enable = 1 but the audit log isn't where you expect and only a couple of filters take effect. Which related parameters did you forget to set?
Unlike older releases where you hardened a fresh SAP system by hand, what does S/4HANA do about security straight out of the box?
How can you automatically check that your S/4HANA systems still comply with the SAP Security Baseline — e.g. that SAP* is locked down?
In S/4HANA, do you still have to switch the Security Audit Log on yourself the way you did in older NetWeaver releases?
Regular SE16/SE16N table editing must be locked down — so how are admins meant to change table data in a genuine emergency?
Several customers' tenant databases share one HANA system — how do you isolate them all the way down to the operating-system level?
The message server is a single point of failure that rogue app servers could connect to. Which two parameters lock it down, and what does each specifically prevent?
On an older NetWeaver system you enabled the Security Audit Log through rsau profile parameters. Why does that approach no longer apply in S/4HANA?

Start learning today

Free to start — download the app or use it in your browser.

Get it on App StoreGet it on Google Play