C-S4CPB-2602 無料問題集「SAP Certified - Implementation Consultant - SAP S/4HANA Cloud Public Edition (C_S4CPB_2602)」
SIMULATION
Create a Custom Business Role with Restrictions
Business Scenario:
You are building a custom business role with restrictions to ensure the end users assigned the role have only the minimum level of access necessary to complete their core job tasks. The end users are project managers based in the United States. They should only be able to create projects, edit projects, and access projects that are occurring in the United States. They should not be able to staff any resources outside of the United States. Write, Read, and Value Help access should be restricted to only the United States for all relevant fields.
Prerequisites:
Note: In the task below, always replace ###### with the last 6 digits of your group number.
Note: Make sure to use the EXACT names/values/spaces as they are listed in the task. Even forgetting a space or a number will cause the validation of the task to fail and be marked as incorrect.
Task:
Restrict the fields listed below for the US / 1710. All other fields should be marked as Not Maintained. Save the role when finished.

Create a Custom Business Role with Restrictions
Business Scenario:
You are building a custom business role with restrictions to ensure the end users assigned the role have only the minimum level of access necessary to complete their core job tasks. The end users are project managers based in the United States. They should only be able to create projects, edit projects, and access projects that are occurring in the United States. They should not be able to staff any resources outside of the United States. Write, Read, and Value Help access should be restricted to only the United States for all relevant fields.
Prerequisites:
Note: In the task below, always replace ###### with the last 6 digits of your group number.
Note: Make sure to use the EXACT names/values/spaces as they are listed in the task. Even forgetting a space or a number will cause the validation of the task to fail and be marked as incorrect.
Task:
Restrict the fields listed below for the US / 1710. All other fields should be marked as Not Maintained. Save the role when finished.

正解:
See Explanation below for all solution
Explanation:
Task 7: Restrict the Custom Business Role for US / 1710 and Mark All Other Fields as Not Maintained Objective The purpose of this task is to maintain the restriction values of the custom business role created in the previous task so that project managers only have the minimum access required for their work in the United States.
This task is performed on the custom business role created from the template:
Template Role: SAP_BR_PROJECT_MANAGER_PROF
Custom Role Example Pattern: BR_PROJECT_MANAGER_PROF_US_######
The task requires you to:
maintain only the listed restriction fields,
enter the exact required values for US and 1710,
set all other restriction fields to Not Maintained,
and save the role.
Business Scenario Explanation
This restriction setup is what makes the new custom role safe and fit for purpose.
The business requirement says that end users:
are project managers based in the United States,
should only access relevant US project data,
should not be able to staff or work outside the intended scope,
should only see and maintain data for the allowed organizational scope.
This is achieved by limiting the role to:
US for country-related fields
1710 for company / organizational fields
Everything else must be Not Maintained so that unnecessary access is not left open.
Important Notes
Replace ###### with the last 6 digits of your group number.
Use the values exactly as shown.
Maintain only the fields listed in the table.
Set all other restriction fields to Not Maintained.
Do not leave unrelated fields blank while still restricted.
Restricted + blank is usually wrong.
Not Maintained is the correct setting for all unrelated fields.
Required Restriction Values
Use the following values exactly as shown in your task screenshot.

That means:
Country restriction = US
Org/company restrictions = 1710
Detailed Step-by-Step Procedure
Step 1: Open the app "Maintain Business Roles"
From the SAP S/4HANA Cloud launchpad:
Log in to the system.
Search for:
Maintain Business Roles
Open the app.
Explanation:
This app is where the custom role was created in the previous task and where its restrictions are maintained.
Step 2: Open your custom Project Manager US role
In Maintain Business Roles:
Search for your custom role.
Open the role with ID pattern:
BR_PROJECT_MANAGER_PROF_US_######
Example
If the suffix is 000457, then the role is:
BR_PROJECT_MANAGER_PROF_US_000457
Explanation:
You must open the custom role, not the standard SAP template role.
The restrictions belong to the derived custom role only.
Step 3: Confirm the correct custom role is open
Check the role details and confirm:
the business role ID matches your custom role,
the description matches the US-specific project manager role,
the role is based on template SAP_BR_PROJECT_MANAGER_PROF.
Explanation:
This avoids accidentally changing the wrong role.
Step 4: Click "Maintain Restrictions"
On the custom role page:
Click:
Maintain Restrictions
Explanation:
This opens the detailed restriction maintenance area where access categories and field-level values are controlled.
Step 5: Set the access categories for restriction maintenance
On the restriction page, ensure the access categories are maintained as required for the role.
During your run, these categories were maintained as restricted so values could be entered for the listed fields.
Explanation:
Restriction values can only be maintained correctly when the role is in the right restriction mode.
This step prepares the role so the listed fields can be populated with US / 1710 values.
Step 6: Understand the rule before entering values
This task uses a strict rule:
Keep maintained
Only the fields explicitly listed in the table should be maintained with values.
Set to Not Maintained
Every other restriction field not listed in the table must be marked:
Not Maintained
Explanation:
This is the most important logic in the whole task.
If a field is unrelated and still left as restricted or blank, it can cause validation problems or give more access than intended.
Part A: Maintain the required restriction fields
Step 7: Maintain Bank Country/Region Key
Search for:
Bank Country/Region Key
Then maintain:
Read, Value Help = US
Value Help = US
Explanation:
This ensures the user can only read and search bank-related values for the United States.


Step 8: Maintain Company Code
Search for:
Company Code
Then maintain:
Write, Read, Value Help = 1710
Read, Value Help = 1710
Do not maintain an extra standalone Value Help entry for Company Code unless the task explicitly requires it.
Explanation:
The task table does not include a standalone Company Code Value Help line.
So only the listed two Company Code restriction types should contain 1710.


Step 9: Maintain Purchasing Organization
Search for:
Purchasing Organization
Then maintain:
Write, Read, Value Help = 1710
Read, Value Help = 1710
Value Help = 1710
Explanation:
This ensures all purchasing-organization-related access for the role is limited to organizational value 1710.
Step 10: Maintain Valuation Area
Search for:
Valuation Area
Then maintain:
Read, Value Help = 1710
Value Help = 1710
Explanation:
This limits valuation-related access to the intended organizational scope.
Part B: Set all other fields to Not Maintained
Step 11: Search through the other restriction fields
After entering the required fields, review the remaining restriction objects.
Examples from your run included fields such as:
Accounting Principle
Authorization Group for Business Partners
Billing Type
and many other unrelated restriction fields
Explanation:
These fields were not listed in the task table, so they must not stay restricted.
Step 12: Mark unrelated fields as Not Maintained
For each field not listed in the required table:
Open the field setting / restriction dialog.
Choose:
Not Maintained
Important examples
From your run:
Accounting Principle → Not Maintained
Authorization Group for Business Partners → Not Maintained
Billing Type → Not Maintained
Explanation:
These fields are outside the required US / 1710 restriction list.
If you leave them restricted without a required value, the setup is incorrect.
Step 13: Do not mark the listed fields as Not Maintained
The following must stay maintained with values because they are in the required table:
Bank Country/Region Key
Company Code
Purchasing Organization
Valuation Area
Explanation:
Only the unrelated fields become Not Maintained.
The listed fields must remain restricted with the required values.
Step 14: Save the role
After all required fields are maintained and all other fields are marked Not Maintained:
Click Save
Explanation:
This finalizes the role restrictions.
Without saving, the restriction changes remain incomplete.
Step 15: Verify the restriction result
After saving, verify that:
required fields contain US and 1710 exactly as defined,
unrelated fields are no longer restricted,
the role saves without error.
Explanation:
This is your final proof that the restricted custom role has been completed correctly.
Expected Result
After the task is completed successfully:
the custom role remains based on SAP_BR_PROJECT_MANAGER_PROF,
required US / 1710 restriction fields are maintained,
all unrelated restriction fields are marked Not Maintained,
the role is saved successfully,
the role now reflects minimum necessary access for US-based project managers.
Explanation:
Task 7: Restrict the Custom Business Role for US / 1710 and Mark All Other Fields as Not Maintained Objective The purpose of this task is to maintain the restriction values of the custom business role created in the previous task so that project managers only have the minimum access required for their work in the United States.
This task is performed on the custom business role created from the template:
Template Role: SAP_BR_PROJECT_MANAGER_PROF
Custom Role Example Pattern: BR_PROJECT_MANAGER_PROF_US_######
The task requires you to:
maintain only the listed restriction fields,
enter the exact required values for US and 1710,
set all other restriction fields to Not Maintained,
and save the role.
Business Scenario Explanation
This restriction setup is what makes the new custom role safe and fit for purpose.
The business requirement says that end users:
are project managers based in the United States,
should only access relevant US project data,
should not be able to staff or work outside the intended scope,
should only see and maintain data for the allowed organizational scope.
This is achieved by limiting the role to:
US for country-related fields
1710 for company / organizational fields
Everything else must be Not Maintained so that unnecessary access is not left open.
Important Notes
Replace ###### with the last 6 digits of your group number.
Use the values exactly as shown.
Maintain only the fields listed in the table.
Set all other restriction fields to Not Maintained.
Do not leave unrelated fields blank while still restricted.
Restricted + blank is usually wrong.
Not Maintained is the correct setting for all unrelated fields.
Required Restriction Values
Use the following values exactly as shown in your task screenshot.

That means:
Country restriction = US
Org/company restrictions = 1710
Detailed Step-by-Step Procedure
Step 1: Open the app "Maintain Business Roles"
From the SAP S/4HANA Cloud launchpad:
Log in to the system.
Search for:
Maintain Business Roles
Open the app.
Explanation:
This app is where the custom role was created in the previous task and where its restrictions are maintained.
Step 2: Open your custom Project Manager US role
In Maintain Business Roles:
Search for your custom role.
Open the role with ID pattern:
BR_PROJECT_MANAGER_PROF_US_######
Example
If the suffix is 000457, then the role is:
BR_PROJECT_MANAGER_PROF_US_000457
Explanation:
You must open the custom role, not the standard SAP template role.
The restrictions belong to the derived custom role only.
Step 3: Confirm the correct custom role is open
Check the role details and confirm:
the business role ID matches your custom role,
the description matches the US-specific project manager role,
the role is based on template SAP_BR_PROJECT_MANAGER_PROF.
Explanation:
This avoids accidentally changing the wrong role.
Step 4: Click "Maintain Restrictions"
On the custom role page:
Click:
Maintain Restrictions
Explanation:
This opens the detailed restriction maintenance area where access categories and field-level values are controlled.
Step 5: Set the access categories for restriction maintenance
On the restriction page, ensure the access categories are maintained as required for the role.
During your run, these categories were maintained as restricted so values could be entered for the listed fields.
Explanation:
Restriction values can only be maintained correctly when the role is in the right restriction mode.
This step prepares the role so the listed fields can be populated with US / 1710 values.
Step 6: Understand the rule before entering values
This task uses a strict rule:
Keep maintained
Only the fields explicitly listed in the table should be maintained with values.
Set to Not Maintained
Every other restriction field not listed in the table must be marked:
Not Maintained
Explanation:
This is the most important logic in the whole task.
If a field is unrelated and still left as restricted or blank, it can cause validation problems or give more access than intended.
Part A: Maintain the required restriction fields
Step 7: Maintain Bank Country/Region Key
Search for:
Bank Country/Region Key
Then maintain:
Read, Value Help = US
Value Help = US
Explanation:
This ensures the user can only read and search bank-related values for the United States.


Step 8: Maintain Company Code
Search for:
Company Code
Then maintain:
Write, Read, Value Help = 1710
Read, Value Help = 1710
Do not maintain an extra standalone Value Help entry for Company Code unless the task explicitly requires it.
Explanation:
The task table does not include a standalone Company Code Value Help line.
So only the listed two Company Code restriction types should contain 1710.


Step 9: Maintain Purchasing Organization
Search for:
Purchasing Organization
Then maintain:
Write, Read, Value Help = 1710
Read, Value Help = 1710
Value Help = 1710
Explanation:
This ensures all purchasing-organization-related access for the role is limited to organizational value 1710.
Step 10: Maintain Valuation Area
Search for:
Valuation Area
Then maintain:
Read, Value Help = 1710
Value Help = 1710
Explanation:
This limits valuation-related access to the intended organizational scope.
Part B: Set all other fields to Not Maintained
Step 11: Search through the other restriction fields
After entering the required fields, review the remaining restriction objects.
Examples from your run included fields such as:
Accounting Principle
Authorization Group for Business Partners
Billing Type
and many other unrelated restriction fields
Explanation:
These fields were not listed in the task table, so they must not stay restricted.
Step 12: Mark unrelated fields as Not Maintained
For each field not listed in the required table:
Open the field setting / restriction dialog.
Choose:
Not Maintained
Important examples
From your run:
Accounting Principle → Not Maintained
Authorization Group for Business Partners → Not Maintained
Billing Type → Not Maintained
Explanation:
These fields are outside the required US / 1710 restriction list.
If you leave them restricted without a required value, the setup is incorrect.
Step 13: Do not mark the listed fields as Not Maintained
The following must stay maintained with values because they are in the required table:
Bank Country/Region Key
Company Code
Purchasing Organization
Valuation Area
Explanation:
Only the unrelated fields become Not Maintained.
The listed fields must remain restricted with the required values.
Step 14: Save the role
After all required fields are maintained and all other fields are marked Not Maintained:
Click Save
Explanation:
This finalizes the role restrictions.
Without saving, the restriction changes remain incomplete.
Step 15: Verify the restriction result
After saving, verify that:
required fields contain US and 1710 exactly as defined,
unrelated fields are no longer restricted,
the role saves without error.
Explanation:
This is your final proof that the restricted custom role has been completed correctly.
Expected Result
After the task is completed successfully:
the custom role remains based on SAP_BR_PROJECT_MANAGER_PROF,
required US / 1710 restriction fields are maintained,
all unrelated restriction fields are marked Not Maintained,
the role is saved successfully,
the role now reflects minimum necessary access for US-based project managers.
SIMULATION
Create a Custom Launchpad Space and Page
Business Scenario
You are building a custom business role that will be assigned to all employees in the organization. The business role and its corresponding Launchpad Space and Page need to include the apps that have been granted through the business catalogs assigned to the business role to ensure employees have an easy time finding the relevant applications.
Note: In the task below, always replace ###### with the last 6 digits of your group number.
Note:
Make sure to use the EXACT names/values/spaces as they are listed in the task.
Even forgetting a space or a number will cause the validation of the task to fail and be marked as incorrect.
Task:
Assign the business role to your user and save. Then refresh the browser and navigate home to verify the new Launchpad Space and tiles are visible.
Create a Custom Launchpad Space and Page
Business Scenario
You are building a custom business role that will be assigned to all employees in the organization. The business role and its corresponding Launchpad Space and Page need to include the apps that have been granted through the business catalogs assigned to the business role to ensure employees have an easy time finding the relevant applications.
Note: In the task below, always replace ###### with the last 6 digits of your group number.
Note:
Make sure to use the EXACT names/values/spaces as they are listed in the task.
Even forgetting a space or a number will cause the validation of the task to fail and be marked as incorrect.
Task:
Assign the business role to your user and save. Then refresh the browser and navigate home to verify the new Launchpad Space and tiles are visible.
正解:
See Explanation below for all solution
Explanation:
Objective
The purpose of this task is to assign the newly created custom all-employee business role to your own business user, save the assignment, refresh the browser, and then verify that the new Launchpad Space and its tiles are visible on the homepage.
This is the final verification step for the all-employee role and launchpad setup.
Business Scenario Explanation
In the previous tasks, you created and configured:
a new custom business role for all employees,
the required business catalogs,
a custom launchpad space,
a custom launchpad page,
and the employee self-service tiles:
Manage My Timesheet
Concur Travel Expense
However, even if all of that is configured correctly, you still will not see the new page and tiles on your homepage until the custom role is assigned to your own business user.
This task connects the configuration to your user and verifies the final end-user result.
Important Notes
Always replace ###### with the last 6 digits of your group number.
Use the exact business role ID.
Save the user after adding the role.
Refresh the browser after saving.
Then navigate back to Home and confirm the space/page/tiles are visible.
Required Business Role
Assign the custom all-employee role created earlier:
Business Role ID: Z_EMPLOYEES_ALL_######
Business Role Description: All Employee Role ######
Example
If your suffix is 000013, the role is:
Z_EMPLOYEES_ALL_000013
Detailed Step-by-Step Procedure
Step 1: Open the app "Maintain Business Users"
From the SAP S/4HANA Cloud launchpad:
Log in to SAP S/4HANA Cloud.
Search for:
Maintain Business Users
Open the app.
Explanation:
This app is used to assign business roles to users.
The launchpad space and tiles will only become visible after the custom role is assigned to your own user.
Step 2: Search for your own business user
In Maintain Business Users:
Enter your own user name or business user ID in the search field.
Click Go.
Explanation:
You must assign the role to your own user because you are the one who will verify the launchpad result on the homepage.
Step 3: Open your user record
From the search results:
Click your user entry.
Open the user details page.
Explanation:
This opens the maintenance page where assigned business roles can be reviewed and changed.
Step 4: Switch to Edit mode
On the business user page:
Click Edit
Explanation:
Without edit mode, the role assignment list is display-only.
Step 5: Open the "Assigned Business Roles" tab
Inside the user record:
Click:
Assigned Business Roles
Explanation:
This tab contains the list of all business roles currently assigned to your user and is the correct place to add the all-employee role.
Step 6: Click Add
In the Assigned Business Roles section:
Click Add
This opens the popup:
Add Business Roles
Explanation:
This popup allows you to search for and assign the custom all-employee role.
Step 7: Search for the custom all-employee role
In the Add Business Roles popup:
In the business role search field, enter:
Z_EMPLOYEES_ALL_######
Click Go
Select the role:
Z_EMPLOYEES_ALL_######
All Employee Role ######
Example
If your suffix is 000013, search for:
Z_EMPLOYEES_ALL_000013
Explanation:
This is the custom role created in the earlier launchpad/employee-role tasks.
It contains the launchpad space, catalogs, and page content that must now become visible to your user.
Step 8: Add the role
After selecting the role:
Click OK or Apply
Explanation:
This adds the role to your user in draft mode.
Step 9: Save the business user
Back on the business user page:
Click Save
Explanation:
This is a mandatory step.
Without saving, the role assignment is not finalized, and the new launchpad content will not appear for your user.
Step 10: Confirm the role assignment
After saving, verify that your assigned roles list includes:
Z_EMPLOYEES_ALL_######
All Employee Role ######
Explanation:
This confirms that the role is now officially assigned to your user.
Step 11: Refresh the browser
After saving:
Refresh the browser completely
Explanation:
SAP launchpad content is often cached in the current session.
A browser refresh ensures the newly assigned role content is loaded.
Step 12: Navigate back to Home
After refreshing:
Return to Home
Explanation:
The role's launchpad space and page must be verified from the end-user homepage, not only from configuration apps.
Step 13: Open the page / launchpad tab
On the homepage, look for the custom page/tab that contains the employee content.
In your run, the visible page was:
General
Explanation:
The launchpad page created earlier was titled General, so that is the page you should open to verify the result.
Step 14: Verify the section title
On the page, confirm that you can see the section:
Self-Services
Explanation:
This was the section title created in the earlier page-content maintenance task.
Step 15: Verify the tiles
Under the Self-Services section, confirm that both tiles are visible:
Concur Travel Expense
Manage My Timesheet
Explanation:
These are the two required employee self-service tiles added to the page in the previous task.
Seeing both of them confirms that:
the catalogs were assigned correctly,
the launchpad page was maintained correctly,
the business role was assigned correctly,
and the browser refresh loaded the new content successfully.
Expected Result
After completing this task successfully:
your own user has the custom business role assigned,
the role is saved successfully,
after browser refresh the launchpad updates,
the homepage shows the new launchpad page,
the Self-Services section is visible,
and the tiles Concur Travel Expense and Manage My Timesheet are visible.

Explanation:
Objective
The purpose of this task is to assign the newly created custom all-employee business role to your own business user, save the assignment, refresh the browser, and then verify that the new Launchpad Space and its tiles are visible on the homepage.
This is the final verification step for the all-employee role and launchpad setup.
Business Scenario Explanation
In the previous tasks, you created and configured:
a new custom business role for all employees,
the required business catalogs,
a custom launchpad space,
a custom launchpad page,
and the employee self-service tiles:
Manage My Timesheet
Concur Travel Expense
However, even if all of that is configured correctly, you still will not see the new page and tiles on your homepage until the custom role is assigned to your own business user.
This task connects the configuration to your user and verifies the final end-user result.
Important Notes
Always replace ###### with the last 6 digits of your group number.
Use the exact business role ID.
Save the user after adding the role.
Refresh the browser after saving.
Then navigate back to Home and confirm the space/page/tiles are visible.
Required Business Role
Assign the custom all-employee role created earlier:
Business Role ID: Z_EMPLOYEES_ALL_######
Business Role Description: All Employee Role ######
Example
If your suffix is 000013, the role is:
Z_EMPLOYEES_ALL_000013
Detailed Step-by-Step Procedure
Step 1: Open the app "Maintain Business Users"
From the SAP S/4HANA Cloud launchpad:
Log in to SAP S/4HANA Cloud.
Search for:
Maintain Business Users
Open the app.
Explanation:
This app is used to assign business roles to users.
The launchpad space and tiles will only become visible after the custom role is assigned to your own user.
Step 2: Search for your own business user
In Maintain Business Users:
Enter your own user name or business user ID in the search field.
Click Go.
Explanation:
You must assign the role to your own user because you are the one who will verify the launchpad result on the homepage.
Step 3: Open your user record
From the search results:
Click your user entry.
Open the user details page.
Explanation:
This opens the maintenance page where assigned business roles can be reviewed and changed.
Step 4: Switch to Edit mode
On the business user page:
Click Edit
Explanation:
Without edit mode, the role assignment list is display-only.
Step 5: Open the "Assigned Business Roles" tab
Inside the user record:
Click:
Assigned Business Roles
Explanation:
This tab contains the list of all business roles currently assigned to your user and is the correct place to add the all-employee role.
Step 6: Click Add
In the Assigned Business Roles section:
Click Add
This opens the popup:
Add Business Roles
Explanation:
This popup allows you to search for and assign the custom all-employee role.
Step 7: Search for the custom all-employee role
In the Add Business Roles popup:
In the business role search field, enter:
Z_EMPLOYEES_ALL_######
Click Go
Select the role:
Z_EMPLOYEES_ALL_######
All Employee Role ######
Example
If your suffix is 000013, search for:
Z_EMPLOYEES_ALL_000013
Explanation:
This is the custom role created in the earlier launchpad/employee-role tasks.
It contains the launchpad space, catalogs, and page content that must now become visible to your user.
Step 8: Add the role
After selecting the role:
Click OK or Apply
Explanation:
This adds the role to your user in draft mode.
Step 9: Save the business user
Back on the business user page:
Click Save
Explanation:
This is a mandatory step.
Without saving, the role assignment is not finalized, and the new launchpad content will not appear for your user.
Step 10: Confirm the role assignment
After saving, verify that your assigned roles list includes:
Z_EMPLOYEES_ALL_######
All Employee Role ######
Explanation:
This confirms that the role is now officially assigned to your user.
Step 11: Refresh the browser
After saving:
Refresh the browser completely
Explanation:
SAP launchpad content is often cached in the current session.
A browser refresh ensures the newly assigned role content is loaded.
Step 12: Navigate back to Home
After refreshing:
Return to Home
Explanation:
The role's launchpad space and page must be verified from the end-user homepage, not only from configuration apps.
Step 13: Open the page / launchpad tab
On the homepage, look for the custom page/tab that contains the employee content.
In your run, the visible page was:
General
Explanation:
The launchpad page created earlier was titled General, so that is the page you should open to verify the result.
Step 14: Verify the section title
On the page, confirm that you can see the section:
Self-Services
Explanation:
This was the section title created in the earlier page-content maintenance task.
Step 15: Verify the tiles
Under the Self-Services section, confirm that both tiles are visible:
Concur Travel Expense
Manage My Timesheet
Explanation:
These are the two required employee self-service tiles added to the page in the previous task.
Seeing both of them confirms that:
the catalogs were assigned correctly,
the launchpad page was maintained correctly,
the business role was assigned correctly,
and the browser refresh loaded the new content successfully.
Expected Result
After completing this task successfully:
your own user has the custom business role assigned,
the role is saved successfully,
after browser refresh the launchpad updates,
the homepage shows the new launchpad page,
the Self-Services section is visible,
and the tiles Concur Travel Expense and Manage My Timesheet are visible.
