C_SEC_2405 · Question #23
Which solution is NOT used to identify security recommendations for the SAP Security Baseline?
The correct answer is C. SAP Code Vulnerability Analyzer. SAP Code Vulnerability Analyzer (CVA) is the odd one out because it is designed to scan custom ABAP code for programming-level vulnerabilities - it does not assess or identify recommendations tied to the SAP Security Baseline. It serves a different purpose: catching insecure…
Question
Which solution is NOT used to identify security recommendations for the SAP Security Baseline?
Options
- ASAP Security Notes
- BSAP EarlyWatch Alert
- CSAP Code Vulnerability Analyzer
- DSAP Security Optimization Service
How the community answered
(20 responses)- A10% (2)
- B15% (3)
- C70% (14)
- D5% (1)
Explanation
SAP Code Vulnerability Analyzer (CVA) is the odd one out because it is designed to scan custom ABAP code for programming-level vulnerabilities - it does not assess or identify recommendations tied to the SAP Security Baseline. It serves a different purpose: catching insecure code patterns in customer-developed programs.
The three distractors are all legitimate Security Baseline identification tools:
- SAP Security Notes (A) publish mandatory and recommended security fixes that directly feed into Baseline requirements.
- SAP EarlyWatch Alert (B) is a diagnostic report that checks system health and flags Security Baseline gaps automatically.
- SAP Security Optimization Service (D) performs an in-depth analysis of your system specifically against the Security Baseline and delivers a prioritized recommendation report.
Memory tip: Think of CVA as a developer tool - it looks inward at your code. The other three are auditor tools - they look at your system configuration against SAP's standards. On the exam, if a choice is about scanning custom code rather than evaluating system settings, it likely doesn't belong in the Baseline-identification category.
Topics
Community Discussion
No community discussion yet for this question.