SAP Security Questions and Answers
Q - 1 What are the components of grc?

Ans- SAP GRC covers following components:
1) Access Control
2) Process Control
3) Risk Management
4) Environment, Health and Safety
5) Global Trade Service

Further, Global Trade Service (which is an area more specific to my interest) has following sub-modules:
1) Compliance Management
2) Customs Management
3) Risk Management
Q - 2 What is the use of RSECADMIN?

Reporting Users - Analysis Authorization using transaction
RSECADMIN, to maintain authorizations for reporting users.

RSECADMIN - To maintain analysis authorization and role
assignment to user.
Q - 3 Explain about SPM?

Ans- SPM can be used to maintain and monitor the super user
access in an SAP system. This enables the super-users to
perform emergency activities and critical transactions
within a completely auditable environment. The logs of the
SPM user IDs helps auditors in easily tracing the critical
transactions that have been performed by the Business users
Q - 4 What is the T-code to get into RAR from R/3?

Ans- /virsar/ZVRAT
Q - 5 Does s_tabu_dis org level values in a master role gets reflected in the child role?

Ans- If we do the adjusted derived role in the master role
while updating the values in the master role thn values will
be reflected in the child roles.
Q - 6 What is the main difference between single role and a derived role?

Ans- Main difference--we can add/delete the tcodes for the
single roles but we cann't do it for the derived roles.
Q - 7 Tell me about derived role?

Ans- Derived roles..To restrict the user access based on
organizational level values.
Derived role will be inherited by master role and inherit
all the properties except org level values.
Q - 8 What is the main purpose of Parameters, Groups &
Personalization tabs?

Ans- parameters : when ever user want some defaults values
when ever he/she excute the t-code we can mainatian some
pid's by taking help of abapers.
Q - 9 What does the Profile Generator do?

Ans- we can create roles , transport , copy ,
download,modifications , all these thing done from pfcg t-
Q - 10 What is the difference between PFCG,PFCG_TIME_DEPENDENCY&PFUD?

Ans- PFCG is used to create maintain and modify the roles.
PFCG_TIME_DEPENDENCY is a background job of PFUD.
PFUD is used for mass user comparison but the difference is
if you set the background job daily basis it will do mass
user comparison automatically
