← All ERP Flashcard Decks

Security Flashcards

7 cards from real ERP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Security flashcards as text
  1. Which ERP security control helps detect when a privileged user exports an unusually large volume of records outside normal business patterns?

    Answer: User and entity behavior analytics (UEBA)

    UEBA establishes behavioral baselines and alerts when anomalous data access or export patterns are detected.

  2. When migrating an ERP system to a cloud provider, who is responsible for configuring ERP application-level user access controls?

    Answer: The organization, as the ERP application owner

    Under the cloud shared responsibility model, the customer always owns security configuration within the applications they deploy.

  3. A company wants to allow auditors read-only access to financial reports in the ERP without exposing transaction entry screens. Which approach is most appropriate?

    Answer: Assign a dedicated read-only auditor role with no posting privileges

    A purpose-built read-only role enforces least privilege, giving auditors exactly the access they need—nothing more.

  4. SAP's Security Audit Log (SM20) is used primarily for which purpose?

    Answer: Recording and reviewing security-relevant ERP events for forensic analysis

    SM20 captures login attempts, authorization failures, and sensitive transaction usage, enabling security incident investigation.

  5. Which type of ERP security test simulates a real-world attacker attempting to exploit vulnerabilities without prior knowledge of the system?

    Answer: Black-box penetration testing

    Black-box penetration testing mimics an external attacker with no insider knowledge, revealing externally exploitable weaknesses.

  6. An ERP administrator notices several failed login attempts from an unfamiliar IP address followed by a successful login. What should happen next?

    Answer: Immediately investigate for credential stuffing or brute force compromise

    A pattern of failures followed by success suggests credential stuffing or brute force, requiring urgent incident response.

  7. In ERP security, what does 'transport security' refer to in an SAP landscape?

    Answer: Controlling which code changes move from development to QA to production

    Transport security in SAP governs authorization to release, import, and approve change requests across system tiers.