โ† All ERP Flashcard Decks

ERP Security, Access Control & Role-Based Permissions Flashcards

7 cards from real ERP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 ERP Security, Access Control & Role-Based Permissions flashcards as text
  1. What is the primary purpose of Role-Based Access Control (RBAC) in an ERP system?

    Answer: To assign system permissions based on a user's job function

    RBAC assigns permissions based on job roles, ensuring users access only the data and functions relevant to their responsibilities.

  2. In ERP security, what does 'Segregation of Duties' (SoD) primarily prevent?

    Answer: Fraud and errors by ensuring no single user controls an entire critical process

    SoD ensures that critical transactions require involvement from multiple users, preventing any one person from committing and concealing fraud.

  3. What does the 'principle of least privilege' mean in ERP security?

    Answer: Users should have the minimum access needed to perform their job duties

    Least privilege limits user access rights to only what is necessary for their specific job function, reducing the attack surface and risk of misuse.

  4. What is a 'super user' in an ERP security context?

    Answer: An account with unrestricted access to all system functions and data

    Super users have unrestricted system access and are typically reserved for emergency situations or system administrators with special oversight requirements.

  5. Which control best prevents a single user from both creating a vendor record and processing payment to that vendor?

    Answer: Segregation of Duties (SoD) controls

    SoD controls separate conflicting duties (creating vendors vs. processing payments) to prevent fraud where one person could create fictitious vendors and pay them.

  6. In an ERP system, what is an 'authorization object'?

    Answer: A data structure defining what actions users can perform on specific data

    Authorization objects in ERP systems define combinations of fields and values that control what actions a user can take on specific data objects.

  7. Which user account type should be used for day-to-day business operations in an ERP system?

    Answer: Standard user account with role-appropriate permissions

    Standard user accounts with limited, role-appropriate permissions should be used for daily operations to minimize security risk and comply with least privilege.