nerdexam
SAP

C_SEC_2405 · Question #46

Which of the following can you use to check if there is an application start lock on an application contained in a PFCG role? Note: There are 2 correct answers to this question.

The correct answer is A. Transaction SUIM - Executable Transactions report C. Transaction SUIM - Transactions Executable with Profile report. Both SUIM reports (A and C) are correct because they let you view transactions assigned within a PFCG role and simultaneously indicate whether an application start lock exists on those transactions - giving you role-context visibility into locked executables. The Executable…

Identity and Access Management

Question

Which of the following can you use to check if there is an application start lock on an application contained in a PFCG role? Note: There are 2 correct answers to this question.

Options

  • ATransaction SUIM - Executable Transactions report
  • BTransaction SM01_CUS
  • CTransaction SUIM - Transactions Executable with Profile report
  • DTransaction SM01 DEV

How the community answered

(52 responses)
  • A
    71% (37)
  • B
    8% (4)
  • D
    21% (11)

Explanation

Both SUIM reports (A and C) are correct because they let you view transactions assigned within a PFCG role and simultaneously indicate whether an application start lock exists on those transactions - giving you role-context visibility into locked executables. The Executable Transactions report (A) shows transactions a user can run based on their roles, flagging any start locks, while the Transactions Executable with Profile report (C) does the same but scoped to authorization profiles, both surfacing lock status in one view.

Why B and D are wrong: SM01_CUS and SM01_DEV are maintenance transactions - they are used to set or remove application start locks (CUS for customer-namespace transactions, DEV for SAP standard/development transactions). They display a global list of all locked transactions, not filtered by what's in a specific PFCG role, so they don't answer the role-specific question being asked.

Memory tip: Think SUIM = "Show Us Information in My role" - whenever an exam question asks you to check or report on role content (authorizations, transactions, locks), SUIM is almost always the right tool. SM01 variants are for managing locks, not reporting on them in role context.

Topics

#PFCG roles#application start lock#SUIM#transaction lock

Community Discussion

No community discussion yet for this question.

Full C_SEC_2405 Practice