nerdexam
SAP

C_SEC_2405 · Question #65

An IT audit reveals several violations of segregation of duties (SoD) within an SAP system. The compliance team needs to resolve these violations to mitigate risks. What actions should the…

The correct answer is A. Use SAP GRC Access Control for SoD risk analysis B. Redesign roles to eliminate conflicting access E. Generate periodic SoD violation reports for review. A (SAP GRC Access Control for SoD risk analysis) is correct because GRC Access Control is specifically designed to identify, analyze, and manage SoD conflicts within SAP - it's the purpose-built tool for this exact problem. B (Redesign roles) is correct because the root fix for…

Security Governance and Risk Management

Question

An IT audit reveals several violations of segregation of duties (SoD) within an SAP system. The compliance team needs to resolve these violations to mitigate risks. What actions should the compliance team take to resolve SoD violations? There are 3 correct answers to this question.

Options

  • AUse SAP GRC Access Control for SoD risk analysis
  • BRedesign roles to eliminate conflicting access
  • CEnable automated SoD monitoring tools
  • DRemove all conflicting roles immediately
  • EGenerate periodic SoD violation reports for review

How the community answered

(53 responses)
  • A
    83% (44)
  • C
    11% (6)
  • D
    6% (3)

Explanation

A (SAP GRC Access Control for SoD risk analysis) is correct because GRC Access Control is specifically designed to identify, analyze, and manage SoD conflicts within SAP - it's the purpose-built tool for this exact problem. B (Redesign roles) is correct because the root fix for SoD violations is restructuring conflicting roles so no single user holds incompatible permissions (e.g., creating and approving the same transaction). E (Periodic SoD violation reports) is correct because ongoing reporting ensures violations are detected and reviewed over time, not just resolved once and forgotten - continuous monitoring is a core compliance practice.

C is wrong because "enabling automated monitoring" alone is a detective control, not a resolution - it finds violations but doesn't fix them. The question asks what actions resolve violations, not just detect them. D is wrong because removing all conflicting roles immediately is operationally dangerous and unrealistic; business processes may require temporary mitigating controls (like manual approvals) while roles are properly redesigned.

Memory tip: Think A-B-E = Analyze, Build-better-roles, Evaluate-ongoing - you analyze the problem with GRC (A), fix it by redesigning roles (B), and ensure it stays fixed by reviewing reports (E). Removing everything at once (D) is the "panic button" wrong answer, and monitoring alone (C) watches the problem without solving it.

Topics

#segregation of duties#SAP GRC#SoD violations#role design

Community Discussion

No community discussion yet for this question.

Full C_SEC_2405 Practice