nerdexam
SAP

C_SEC_2405 · Question #14

You are building a PFCG role for access to an SAP Fiori app on your SAP S/4HANA on-premise system. After you enter the catalog in the role menu, an entry for an OData service is missing and you have…

The correct answer is B. Because the TADIR Service name for the back-end server component was automatically added. Option B is correct because when you add an OData service entry to the PFCG role menu, the system automatically determines and populates the TADIR Service name for the back-end server component in the S_SERVICE authorization object. Since this value is auto-generated through…

Identity and Access Management

Question

You are building a PFCG role for access to an SAP Fiori app on your SAP S/4HANA on-premise system. After you enter the catalog in the role menu, an entry for an OData service is missing and you have to add it manually to the role menu. When you maintain authorization data in the PFCG role, why does SAP recommend that you NOT maintain the SRV_NAME field value of the S_SERVICE authorization object manually?

Options

  • ABecause the SRV_NAME hash value for the front-end server component and back-end server
  • BBecause the TADIR Service name for the back-end server component was automatically added
  • CBecause the SRV_NAME hash value for the front-end server component and back-end server
  • DBecause the TADIR Service name is the same for the front-end server component and the back-

How the community answered

(43 responses)
  • A
    5% (2)
  • B
    79% (34)
  • C
    14% (6)
  • D
    2% (1)

Explanation

Option B is correct because when you add an OData service entry to the PFCG role menu, the system automatically determines and populates the TADIR Service name for the back-end server component in the S_SERVICE authorization object. Since this value is auto-generated through the role maintenance workflow, manually entering it introduces a high risk of errors - the TADIR name is a precise, system-internal identifier that must match exactly.

Options A and C are incorrect because they focus on hash values rather than TADIR Service names; while SRV_NAME does involve hashed values in some contexts, the core recommendation here is about the auto-generated TADIR name for the back-end component, not front-end vs. back-end hash mismatches. Option D is incorrect because the TADIR Service names are not the same across front-end and back-end components - they are distinct, which is precisely why the system handles the back-end value automatically to avoid confusion.

Memory tip: Think "AUTO = ACCURATE." In PFCG role maintenance, anything the system can generate automatically (like the back-end TADIR service name in S_SERVICE) should be left to the system - manual entry of auto-generated identifiers is where authorization errors hide during audits.

Topics

#PFCG roles#SAP Fiori#S_SERVICE#OData authorization

Community Discussion

No community discussion yet for this question.

Full C_SEC_2405 Practice