C_SEC_2405 · Question #20
When creating PFCG roles for SAP Fiori access, what is included automatically when adding a catalog to the menu of a back-end PFCG role? Note: There are 2 correct answers to this question.
The correct answer is C. The start authorizations and the authorization default values for each IWSV TADIR service D. The IWSV TADIR service definitions from the catalog. When you add an SAP Fiori catalog to the menu of a back-end PFCG role, SAP automatically pulls in two things tied to the OData services within that catalog: the IWSV TADIR service definitions (the actual OData service objects - option D) and the start authorizations plus…
Question
When creating PFCG roles for SAP Fiori access, what is included automatically when adding a catalog to the menu of a back-end PFCG role? Note: There are 2 correct answers to this question.
Options
- AThe start authorizations and the authorization default values for each IWSG TADIR service
- BThe IWSG TADIR service definitions from the catalog.
- CThe start authorizations and the authorization default values for each IWSV TADIR service
- DThe IWSV TADIR service definitions from the catalog.
How the community answered
(25 responses)- A16% (4)
- B8% (2)
- C76% (19)
Explanation
When you add an SAP Fiori catalog to the menu of a back-end PFCG role, SAP automatically pulls in two things tied to the OData services within that catalog: the IWSV TADIR service definitions (the actual OData service objects - option D) and the start authorizations plus authorization default values for each of those IWSV services (option C). This automation saves administrators from manually assigning each OData service and its S_START authorization separately.
Options A and B are wrong because they reference IWSG (SAP Gateway Service Group), not IWSV. IWSG represents a grouping construct for services, not the individual OData services themselves. Back-end PFCG roles work with the individual services (IWSV), not the groups (IWSG) - the groups are more relevant to front-end/hub system configuration.
Memory tip: Think "IWSV = individual SerVices" (V for service) vs. "IWSG = service Groups." When a catalog lands in a back-end role, it brings the actual services (IWSV) and their authorization defaults - not the grouping layer (IWSG). If you see IWSG in an answer about back-end role automation, it's a trap.
Topics
Community Discussion
No community discussion yet for this question.