nerdexam
SAP

C_SEC_2405 · Question #23

Which solution is NOT used to identify security recommendations for the SAP Security Baseline?

The correct answer is C. SAP Code Vulnerability Analyzer. SAP Code Vulnerability Analyzer (CVA) is the odd one out because it is designed to scan custom ABAP code for programming-level vulnerabilities - it does not assess or identify recommendations tied to the SAP Security Baseline. It serves a different purpose: catching insecure…

Security Governance and Risk Management

Question

Which solution is NOT used to identify security recommendations for the SAP Security Baseline?

Options

  • ASAP Security Notes
  • BSAP EarlyWatch Alert
  • CSAP Code Vulnerability Analyzer
  • DSAP Security Optimization Service

How the community answered

(20 responses)
  • A
    10% (2)
  • B
    15% (3)
  • C
    70% (14)
  • D
    5% (1)

Explanation

SAP Code Vulnerability Analyzer (CVA) is the odd one out because it is designed to scan custom ABAP code for programming-level vulnerabilities - it does not assess or identify recommendations tied to the SAP Security Baseline. It serves a different purpose: catching insecure code patterns in customer-developed programs.

The three distractors are all legitimate Security Baseline identification tools:

  • SAP Security Notes (A) publish mandatory and recommended security fixes that directly feed into Baseline requirements.
  • SAP EarlyWatch Alert (B) is a diagnostic report that checks system health and flags Security Baseline gaps automatically.
  • SAP Security Optimization Service (D) performs an in-depth analysis of your system specifically against the Security Baseline and delivers a prioritized recommendation report.

Memory tip: Think of CVA as a developer tool - it looks inward at your code. The other three are auditor tools - they look at your system configuration against SAP's standards. On the exam, if a choice is about scanning custom code rather than evaluating system settings, it likely doesn't belong in the Baseline-identification category.

Topics

#SAP Security Baseline#security recommendations#Code Vulnerability Analyzer#security tools

Community Discussion

No community discussion yet for this question.

Full C_SEC_2405 Practice