Application Development and Automation Discussions
Join the discussions or start your own on all things application development, including tools and APIs, programming models, and keeping your skills sharp.
cancel
Showing results for 
Search instead for 
Did you mean: 
Read only

General interview questions in Security R3?

Former Member
0 Likes
581

Hi Everyone,

I just wanted to know what are the questions(in general)to be expected in R3 Security interview(4.6c)

as i am expecting an interview in couple of days..

Thank you in advance

shabana

2 REPLIES 2
Read only

Former Member
0 Likes
464

Questions that i encountered based on R/3 46C:

1. How frequent do you perform transport migration?

2. Understanding of Composite role, Derived Roles, Single Roles

3. Knowledge of SU01, PFCG

4. CUA

Read only

0 Likes
464

Hi,

these are a few quick thoughts:

IT-Infrastructure Security, SAP Landscape:

- Network layout and firewalling between systems

- Remote administration, backup, archiving procedures

- Hardening procedures for new systems, new clients, system or client copies

- examples are locking, unlocking, password changes of users, setting system wide password rules, SM59 configuration, SICF configuration

- Use of cryptographic mechanisms (SNC, SSL)

Authorizations:

- Does a documented authorization concept exist?

- Of course: Are there SAP_ALL, SAP_NEW users (or any equivalent sort of SAP_ALL)

- How are authorizations of communication / system users managed?

- What kind of functional roles are used (Task roles, job roles, etc.)?

- What kind of technical roles are used (single, composite, derived)?

- Are check indicators used (SU24)?

- Are there many "manual" authorization objects? (this would indicate that SU24 is not correctly used.)

- Are risky transactions (SU01, PFCG, SM59, SA38, ...) and risky transaction combinations (vendor creation / change and payment processing) known and documented?

- Are procedures in place that control / mitigate the execution of these risks?

- How is user and authorizations management regulated?

Regards,

Christian