← All ERP Flashcard Decks

Security Flashcards

7 cards from real ERP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Security flashcards as text
  1. Which ERP security concept ensures that no single user can complete a sensitive transaction from start to finish without another user's involvement?

    Answer: Segregation of duties

    Segregation of duties (SoD) divides critical tasks among multiple users to prevent fraud and error.

  2. In SAP ERP, which authorization object controls access to specific financial posting transactions?

    Answer: F_BKPF_BUK

    F_BKPF_BUK governs document posting authorizations by company code in SAP FI.

  3. An ERP system stores sensitive HR salary data. Which encryption approach best protects this data at rest?

    Answer: AES-256 column-level encryption

    AES-256 column-level encryption protects specific sensitive fields in the database even if the storage media is compromised.

  4. A company discovers that an ERP consultant's account was used to export the entire customer list after their contract ended. What control failure does this represent?

    Answer: Failure to revoke access upon offboarding

    Timely deprovisioning of user accounts when employment or contracts end is a critical access management control.

  5. Which ERP security layer protects against SQL injection attacks targeting the ERP database?

    Answer: Parameterized queries and input validation

    Parameterized queries prevent malicious SQL code from being injected through user input fields.

  6. In Oracle EBS, what is the purpose of function security profiles?

    Answer: To restrict which menus and functions a responsibility can access

    Function security in Oracle EBS controls which application functions are available within a given responsibility.

  7. A SOX compliance audit requires evidence that ERP financial reports cannot be altered by the users who generate them. Which control satisfies this requirement?

    Answer: Report output immutability and access logging

    Immutable report storage combined with access logging demonstrates that financial outputs have not been tampered with.