C_SEC_2405 · Question #39
Which functions in SAP Access Control can be used to approve or reject a user's continued access to specific security roles? Note: There are 2 correct answers to this question.
The correct answer is C. User Access Review D. Role Reaffirm. User Access Review (C) and Role Reaffirm (D) are both functions within SAP Access Control's Access Risk Management module that enable managers or role owners to periodically review, approve, or revoke a user's continued access to specific roles - making them the two correct…
Question
Which functions in SAP Access Control can be used to approve or reject a user's continued access to specific security roles? Note: There are 2 correct answers to this question.
Options
- ASOD Review
- BRole Certification
- CUser Access Review
- DRole Reaffirm
How the community answered
(58 responses)- A14% (8)
- B9% (5)
- C78% (45)
Explanation
User Access Review (C) and Role Reaffirm (D) are both functions within SAP Access Control's Access Risk Management module that enable managers or role owners to periodically review, approve, or revoke a user's continued access to specific roles - making them the two correct answers. User Access Review triggers a formal certification workflow where reviewers confirm or reject active user-role assignments, while Role Reaffirm allows role owners to reaffirm which users should retain access to a particular role.
SOD Review (A) is a distractor because it focuses on identifying and managing Segregation of Duties conflicts, not on approving or rejecting continued role access. Role Certification (B) sounds plausible but is not a standard named function in SAP Access Control; it conflates terminology from other GRC tools (e.g., Oracle or generic IAM platforms) to mislead.
Memory tip: Think "Who keeps access?" - User Access Review = review from the User's perspective, Role Reaffirm = review from the Role's perspective. Both answer "should this user stay in this role?" - that's your pair.
Topics
Community Discussion
No community discussion yet for this question.