1Z0-518 · Question #2
Ten analysts are assigned the same Receivables responsibility and are given their own logins. The requirement is to restrict three of the analysts from creating chargebacks or adjustments. What…
The correct answer is C. Set the "AR: Cash - Allow Actions" system profile to no at the user level for the three analysts. Option C is correct because setting the "AR: Cash - Allow Actions" profile to No at the user level targets only the three specific analysts, leaving the remaining seven unaffected. In Oracle EBS, the profile option hierarchy is Site → Application → Responsibility → User, where…
Question
Ten analysts are assigned the same Receivables responsibility and are given their own logins. The requirement is to restrict three of the analysts from creating chargebacks or adjustments. What would be your advice to ensure compliance with this internal control?
Options
- AUse forms personalization to restrict function access.
- BSet the "AR: Cash - Allow Actions" system profile to no at the responsibility level.
- CSet the "AR: Cash - Allow Actions" system profile to no at the user level for the three analysts.
- DSet the "AR: Cash - Allow Actions" system profile to yes at the user level for the three analysts.
- ESet the "AR: Cash - Allow Actions" system profile to yes at the application level for the three analysts.
How the community answered
(37 responses)- A3% (1)
- B5% (2)
- C78% (29)
- D3% (1)
- E11% (4)
Explanation
Option C is correct because setting the "AR: Cash - Allow Actions" profile to No at the user level targets only the three specific analysts, leaving the remaining seven unaffected. In Oracle EBS, the profile option hierarchy is Site → Application → Responsibility → User, where the User level has the highest precedence and overrides all broader settings - making it the precise, surgical control needed here.
Why the distractors fail:
- A - Forms personalization can hide UI elements but is not a reliable or recommended method for enforcing this type of functional security control; profile options are the proper mechanism.
- B - Setting the profile to No at the responsibility level would restrict all ten analysts, since they all share the same responsibility - a sledgehammer when you need a scalpel.
- D - Setting to Yes at the user level does the opposite: it grants the action rather than restricting it.
- E - The application level is even broader than the responsibility level and would impact all AR users across the system, not just three analysts - and again, "Yes" grants access.
Memory tip: Picture a bullseye - Site is the outer ring, then Application, Responsibility, and User is the center. The closer to the center, the more specific and higher-priority the setting. When you need to restrict named individuals in a shared responsibility, always aim for the center (User level) and set to No.
Topics
Community Discussion
No community discussion yet for this question.