โ† All ERP Flashcard Decks

Security Flashcards

7 cards from real ERP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security flashcards as text
  1. Which attack vector specifically targets ERP systems by exploiting trust relationships between connected third-party integrations?

    Answer: Supply chain / API integration attacks

    ERP systems connected to third-party APIs can be compromised through insecure integration points, making API security critical.

  2. What is the primary purpose of an ERP security baseline configuration?

    Answer: To define the minimum secure settings required before go-live

    A security baseline establishes the hardened default configuration that every ERP instance must meet before deployment.

  3. A user in the procurement module can create purchase orders and also approve them. This violates which principle?

    Answer: Segregation of duties

    SoD requires that creating and approving the same transaction be handled by different users to prevent unauthorized purchasing.

  4. Which ERP security log event should trigger an immediate security alert?

    Answer: Access to SAP basis transaction SE16 by a non-basis user

    SE16 (table browser) allows direct database table access and should never be used by non-basis users in production.

  5. In Microsoft Dynamics 365, what mechanism controls which entities and fields a user security role can read, write, or delete?

    Answer: Privileges and access levels on security roles

    Dynamics 365 security roles combine entity-level privileges with access level scopes (user, business unit, organization) to govern data access.

  6. An ERP penetration test reveals that the default SAP system administrator password 'Appl1ance' was never changed. This is an example of which vulnerability?

    Answer: Default credential exposure

    Unchanged vendor default credentials are a critical vulnerability because they are publicly known and easily exploited.

  7. Which concept describes restricting ERP users to access only the data records belonging to their business unit or geography?

    Answer: Data-level security / organizational restriction

    Data-level (or organizational) security restricts row-level record access so users see only their own entity's data.