SAP Security Challenge - February 2018

What should be changed in a derived role only?
Which user type should be used in RFC connections?
You want to avoid double TCODES. How do you do it?
In a CUA environment, in which transaction can you define that reference users are defined locally (directly in the child system)?
Jerry wants to see Tim's spools. What authorization does Jerry need for this?
How many authorization fields can an authorization object have at most?
In which transaction can you define authorization groups for document types?
What transaction can you use to create user-specific security policies?
User Tom reports a failed authorization check. In SU53, however, you cannot find Tom’s failed authorization check, even though he just got the message in the same client. What can be the issue?
What is the default number of stored authorization checks of SU53?

Alessandro Banzer

Alessandro has worked in the field of IT since 2004, specializing in SAP in 2009 and working on global SAP projects in various roles since that date. Alessandro is an active contributor and moderator in the Governance, Risk and Compliance space on SAP SCN. Alessandro is in charge of Xiting's operations in the United States and a subject matter expert in SAP Access Control and SAP Security.