In XSUAA security model:
Roles group multiple scopes.
Role collections group multiple roles, not scopes.
Scopes are the finest-grain authorization units.
Therefore, the entity that holds several scopes is the Role (B).
Incorrect options:
A: Role collections bundle roles, not scopes directly.
C: A scope is a single authorization unit.
D: User groups are not part of XSUAA authorization structures.
[References:, , XSUAA Security Model – Roles, Scopes, and Role Collections, , CAP Authorization Overview, ]
Submit