nerdexam
SAP

C_SEC_2405 · Question #84

When performing a comparison from the imparting role, what happens to organizational level field values in the derived role? Note: There are 2 correct answers to this question.

The correct answer is A. Data for organizational levels that have already been maintained in the derived role is NOT C. Data for organizational levels is transferred only when authorization data for the derived role is. In SAP role management, derived roles inherit menu and authorization objects from a parent (imparting) role, but maintain their own organizational level values - this is the whole point of derived roles, enabling one template to serve multiple org units. Why A and C are…

Identity and Access Management

Question

When performing a comparison from the imparting role, what happens to organizational level field values in the derived role? Note: There are 2 correct answers to this question.

Options

  • AData for organizational levels that have already been maintained in the derived role is NOT
  • BData for organizational levels that have already been maintained in the derived role is overwritten.
  • CData for organizational levels is transferred only when authorization data for the derived role is
  • DData for organizational levels is always transferred when authorization data for the derived role is

How the community answered

(40 responses)
  • A
    85% (34)
  • B
    5% (2)
  • D
    10% (4)

Explanation

In SAP role management, derived roles inherit menu and authorization objects from a parent (imparting) role, but maintain their own organizational level values - this is the whole point of derived roles, enabling one template to serve multiple org units.

Why A and C are correct: When you run a comparison from the imparting role, SAP deliberately protects any organizational level values already set in the derived role - they are not overwritten (A). Additionally, organizational level data is only transferred under a specific condition: when the derived role's authorization data is being regenerated or reset (C), not unconditionally on every comparison.

Why B is wrong: It states org level data is overwritten, which contradicts SAP's design - overwriting would destroy the org-specific customization that makes derived roles useful.

Why D is wrong: "Always transferred" removes the conditional logic that C correctly captures; org level transfer is gated on the state of the derived role's authorization data, not guaranteed on every sync.

Memory tip: Think of derived roles as "children with their own address" - the parent (imparting role) can update the family rules (authorizations), but it won't change each child's personal address (org levels) unless the child's record is being rebuilt from scratch.

Topics

#derived roles#organizational levels#role comparison#imparting role

Community Discussion

No community discussion yet for this question.

Full C_SEC_2405 Practice