Security Flashcards
7 cards from real ERP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security flashcards as text
Which ERP security framework component maps business risks to specific system control points and monitors them continuously?
Answer: GRC (Governance, Risk, and Compliance) continuous controls monitoring
GRC continuous controls monitoring automates the detection of policy violations and SoD conflicts in real time.
A company's ERP vendor releases a critical security patch. The security team wants to test it before applying to production. What is the correct sequence?
Answer: Apply to sandbox/QA first, validate, then promote to production
Patching in a lower environment first allows validation that the patch does not break business processes before production deployment.
What is 'privilege creep' in an ERP environment?
Answer: The gradual accumulation of unnecessary access rights as a user changes roles over time
Privilege creep occurs when users retain old role permissions after moving to new positions, violating least privilege.
Which ERP security control prevents a payroll administrator from changing their own salary record in the HR module?
Answer: Self-service restriction through role design
Role design can restrict which employee records a user can modify, preventing self-modification of sensitive personal data.
In a multi-tenant cloud ERP environment, which control ensures one customer's data cannot be accessed by another customer?
Answer: Logical tenant isolation enforced at the application and database tier
Logical isolation uses tenant IDs, scoped API tokens, and separate schemas or databases to enforce strict data boundaries.
An internal audit finds that 47 ERP user accounts belong to employees who left the company over a year ago. Which process failed?
Answer: User access recertification and offboarding process
Periodic access recertification reviews and automated HR-to-ERP offboarding workflows should catch and disable departed users' accounts.
Which ERP security approach limits the potential damage of a compromised service account by granting it only the database tables it needs to read or write?
Answer: Principle of least privilege applied to service accounts
Restricting service accounts to exactly the tables and actions they require limits blast radius if the account credentials are stolen.