nerdexam
SAP

C_SEC_2405 · Question #52

When segregating the duties for user and role maintenance, which of the following should be part of a decentralized treble control strategy for a production system? Note: There are 3 correct answers…

The correct answer is B. One user administrator per production system D. One authorization data administrator E. One decentralized role administrator. In a decentralized treble control strategy, administrative duties are split across exactly three distinct roles to enforce segregation of duties in SAP or similar enterprise systems. B, D, and E are correct because they map precisely to the three pillars of treble control: a…

Security Governance and Risk Management

Question

When segregating the duties for user and role maintenance, which of the following should be part of a decentralized treble control strategy for a production system? Note: There are 3 correct answers to this question.

Options

  • AOne user administrator per application area in the production system
  • BOne user administrator per production system
  • COne authorization profile administrator
  • DOne authorization data administrator
  • EOne decentralized role administrator

How the community answered

(19 responses)
  • A
    16% (3)
  • B
    74% (14)
  • C
    11% (2)

Explanation

In a decentralized treble control strategy, administrative duties are split across exactly three distinct roles to enforce segregation of duties in SAP or similar enterprise systems.

B, D, and E are correct because they map precisely to the three pillars of treble control: a single user administrator per production system (B) maintains centralized oversight of who has system access; an authorization data administrator (D) separately controls what authorization data/objects exist; and a decentralized role administrator (E) manages roles at the application-area level, keeping role management close to the business while still separated from user and auth-data management.

A is wrong because having one user administrator per application area over-decentralizes user management - user administration stays at the system level (B) precisely to avoid inconsistency and maintain central accountability across the production environment.

C is wrong because "authorization profile administrator" conflates two distinct concepts - in modern role-based systems, profiles are auto-generated from roles, so the correct third pillar is the authorization data administrator (D), not a profile administrator, which is a legacy or overlapping concept.

Memory tip: Think of "treble" as three musical notes that must stay separate to avoid dissonance - User (system-wide) + Auth Data + Role (decentralized) = UAR, like a security "chord." If one person holds two of these, the control breaks.

Topics

#segregation of duties#user administration#role maintenance#decentralized control

Community Discussion

No community discussion yet for this question.

Full C_SEC_2405 Practice