nerdexam
SAP

C_SEC_2405 · Question #57

Which security measures are critical for maintaining SAP system compliance? There are 2 correct answers to this question.

The correct answer is A. Regular role and authorization reviews D. Enabling audit logging for key events. Regular role and authorization reviews (A) directly address SAP compliance by ensuring users only have appropriate access - a core requirement of frameworks like SOX, GDPR, and SAP's own GRC standards. Audit logging for key events (D) creates the traceable record of system…

Security Governance and Risk Management

Question

Which security measures are critical for maintaining SAP system compliance? There are 2 correct answers to this question.

Options

  • ARegular role and authorization reviews
  • BImplementing end-to-end encryption
  • CMonitoring transaction execution times
  • DEnabling audit logging for key events

How the community answered

(53 responses)
  • A
    83% (44)
  • B
    11% (6)
  • C
    6% (3)

Explanation

Regular role and authorization reviews (A) directly address SAP compliance by ensuring users only have appropriate access - a core requirement of frameworks like SOX, GDPR, and SAP's own GRC standards. Audit logging for key events (D) creates the traceable record of system activity required by regulators to prove controls are operating and to detect unauthorized actions.

Why the distractors are wrong:

  • B (End-to-end encryption) is a good general security practice but is not a defining compliance control specific to SAP system governance - SAP compliance centers on access control and auditability, not transport-layer encryption.
  • C (Monitoring transaction execution times) is a performance/operations concern, not a compliance or security measure.

Memory tip: Think "Who did what?" - SAP compliance is about controlling who has access (role reviews) and recording what they did (audit logs). If an answer doesn't help answer "who did what?", it's probably not the compliance answer.

Topics

#SAP compliance#role reviews#audit logging#security measures

Community Discussion

No community discussion yet for this question.

Full C_SEC_2405 Practice