SAP AS ABAP Administration
Security Audit Log & Central User Administration
26 flashcards · answers and spaced-repetition review in the KnowCard app
In a Central User Administration (CUA) landscape you maintain a user centrally in SU01. Why is the user's data identical everywhere, yet their roles can differ per child system?
Where should you host the Central User Administration (CUA) central function, and why is putting it in an existing production client a poor choice?
Through Central User Administration (CUA) you distribute a user with role Z_FINANCE to a child system, but in that child the user's authorizations don't work. What is the underlying CUA limitation?
When wiring the RFC connections for a Central User Administration (CUA) landscape with one central and three child systems, how many connections and in which directions do you build?
You just activated a new SM19 audit profile because a critical incident is unfolding right now, but nothing new is being logged. What did you overlook and how do you make it take effect immediately?
You carefully defined the SM19 filter criteria for a critical user, saved the profile, and activated it — but SM20 still shows nothing for that user. What is the easy-to-miss filter step?
The Security Audit Log has been running for months and no one has touched the log files. Beyond disk space, what operational responsibility is being neglected?
You need to remove just one child system from Central User Administration (CUA) using report RSDELCUA. Where do you run it, and what happens if you run it on the wrong system?
In SCUM you must decide whether the telephone field is maintained centrally or locally. What is the practical difference between the Global and Local options?
You set a user field to the SCUM Proposal option expecting central and child values to stay in sync. Later a child edit never reaches the other systems. What does Proposal actually do?
In SCUM, both RetVal and Everywhere let a field be maintained centrally and locally. What is the difference in how changes flow between them?
Your landscape includes non-ABAP and non-SAP systems that also need centrally managed identities. Why is CUA (even with the LDAP connector) the wrong tool, and what fills the gap?
You have just activated Central User Administration (CUA), but the users that already existed in the child systems are not under central control. What step is still required, and what does it surface that you must resolve?
You activated the Security Audit Log with rsau/enable=1 but find you can only define 2 filters and the audit file keeps filling up. Which parameters do you tune, and what do their limits mean?
You enabled the Security Audit Log to investigate a suspected misuse by a critical user, but SM20 shows no entries for that user. Before concluding nothing happened, what must you check?
During an audit you are asked to remove some old user-master change records that are cluttering SUIM. What is the misconception here, and what is actually possible?
When setting up Central User Administration (CUA), which task belongs to SCUA versus SCUM, and what goes wrong if you confuse them?
On a current SAP system (NetWeaver 7.50+), you open SM19 out of habit to configure the Security Audit Log. What happens, and which transactions should you use instead?
In an SM19 filter you want to catch a family of test accounts named SAMPLE01, SAMPLE02, and so on. You type SAMPLE* in the user field. What happens?
A security lead asks you to simply turn on the Security Audit Log for every user and every action so nothing is missed. Why is that the wrong request?
After Central User Administration (CUA) is set up, a developer asks you to quickly add a temporary user directly in a child (receiver) system. Why is this the wrong move, and what is the correct path?
Someone proposes rolling out Central User Administration (CUA) across the whole landscape simply because there is more than one system. What factors actually decide whether CUA is worth the setup effort?
When you create the Application Link Enabling (ALE) model view for Central User Administration (CUA), which business objects and distribution method must it use, and why does it matter to get this right?
You are defining the Central User Administration (CUA) distribution model and list only the child systems as receivers. Why does CUA still not manage users in the central client itself?
After running RSDELCUA to remove all of Central User Administration (CUA), what cleanup remains — and which item is a lock, not a delete?
Your landscape has SAP systems plus a central directory service, and some child systems run older Basis releases. How does the Lightweight Directory Access Protocol (LDAP) connector help, and what is its reach compared with plain Central User Administration (CUA)?
Start learning today
Free to start — download the app or use it in your browser.
