SAP AS ABAP Administration

Security Audit Log & Central User Administration

26 flashcards · answers and spaced-repetition review in the KnowCard app

You are defining the CUA distribution model and list only the child systems as receivers. Why does CUA still not manage users in the central client itself?
In a CUA landscape you maintain a user centrally in SU01. Why is the user's data identical everywhere, yet their roles can differ per child system?
Where should you host the CUA central function, and why is putting it in an existing production client a poor choice?
Your landscape has SAP systems plus a central directory service, and some child systems run older Basis releases. How does the LDAP connector help, and what is its reach compared with plain CUA?
You just activated a new SM19 audit profile because a critical incident is unfolding right now, but nothing new is being logged. What did you overlook and how do you make it take effect immediately?
You carefully defined the SM19 filter criteria for a critical user, saved the profile, and activated it — but SM20 still shows nothing for that user. What is the easy-to-miss filter step?
The Security Audit Log has been running for months and no one has touched the log files. Beyond disk space, what operational responsibility is being neglected?
Someone proposes rolling out CUA across the whole landscape simply because there is more than one system. What factors actually decide whether CUA is worth the setup effort?
Through CUA you distribute a user with role Z_FINANCE to a child system, but in that child the user's authorizations don't work. What is the underlying CUA limitation?
When wiring the RFC connections for a CUA landscape with one central and three child systems, how many connections and in which directions do you build?
When you create the ALE model view for CUA, which business objects and distribution method must it use, and why does it matter to get this right?
In SCUM you must decide whether the telephone field is maintained centrally or locally. What is the practical difference between the Global and Local options?
You set a user field to the SCUM Proposal option expecting central and child values to stay in sync. Later a child edit never reaches the other systems. What does Proposal actually do?
In SCUM, both RetVal and Everywhere let a field be maintained centrally and locally. What is the difference in how changes flow between them?
You need to remove just one child system from CUA using report RSDELCUA. Where do you run it, and what happens if you run it on the wrong system?
Your landscape includes non-ABAP and non-SAP systems that also need centrally managed identities. Why is CUA (even with the LDAP connector) the wrong tool, and what fills the gap?
After CUA is set up, a developer asks you to quickly add a temporary user directly in a child (receiver) system. Why is this the wrong move, and what is the correct path?
You have just activated CUA, but the users that already existed in the child systems are not under central control. What step is still required, and what does it surface that you must resolve?
You activated the Security Audit Log with rsau/enable=1 but find you can only define 2 filters and the audit file keeps filling up. Which parameters do you tune, and what do their limits mean?
You enabled the Security Audit Log to investigate a suspected misuse by a critical user, but SM20 shows no entries for that user. Before concluding nothing happened, what must you check?
During an audit you are asked to remove some old user-master change records that are cluttering SUIM. What is the misconception here, and what is actually possible?
When setting up CUA, which task belongs to SCUA versus SCUM, and what goes wrong if you confuse them?
On a current SAP system (NetWeaver 7.50+), you open SM19 out of habit to configure the Security Audit Log. What happens, and which transactions should you use instead?
In an SM19 filter you want to catch a family of test accounts named SAMPLE01, SAMPLE02, and so on. You type SAMPLE* in the user field. What happens?
After running RSDELCUA to remove all of CUA, what cleanup remains — and which item is a lock, not a delete?
A security lead asks you to simply turn on the Security Audit Log for every user and every action so nothing is missed. Why is that the wrong request?

Start learning today

Free to start — download the app or use it in your browser.

Get it on App StoreGet it on Google Play