C_SEC_2405 · Question #52
When segregating the duties for user and role maintenance, which of the following should be part of a decentralized treble control strategy for a production system? Note: There are 3 correct answers…
The correct answer is B. One user administrator per production system D. One authorization data administrator E. One decentralized role administrator. In a decentralized treble control strategy, administrative duties are split across exactly three distinct roles to enforce segregation of duties in SAP or similar enterprise systems. B, D, and E are correct because they map precisely to the three pillars of treble control: a…
Question
When segregating the duties for user and role maintenance, which of the following should be part of a decentralized treble control strategy for a production system? Note: There are 3 correct answers to this question.
Options
- AOne user administrator per application area in the production system
- BOne user administrator per production system
- COne authorization profile administrator
- DOne authorization data administrator
- EOne decentralized role administrator
How the community answered
(19 responses)- A16% (3)
- B74% (14)
- C11% (2)
Explanation
In a decentralized treble control strategy, administrative duties are split across exactly three distinct roles to enforce segregation of duties in SAP or similar enterprise systems.
B, D, and E are correct because they map precisely to the three pillars of treble control: a single user administrator per production system (B) maintains centralized oversight of who has system access; an authorization data administrator (D) separately controls what authorization data/objects exist; and a decentralized role administrator (E) manages roles at the application-area level, keeping role management close to the business while still separated from user and auth-data management.
A is wrong because having one user administrator per application area over-decentralizes user management - user administration stays at the system level (B) precisely to avoid inconsistency and maintain central accountability across the production environment.
C is wrong because "authorization profile administrator" conflates two distinct concepts - in modern role-based systems, profiles are auto-generated from roles, so the correct third pillar is the authorization data administrator (D), not a profile administrator, which is a legacy or overlapping concept.
Memory tip: Think of "treble" as three musical notes that must stay separate to avoid dissonance - User (system-wide) + Auth Data + Role (decentralized) = UAR, like a security "chord." If one person holds two of these, the control breaks.
Topics
Community Discussion
No community discussion yet for this question.