Understand the fundamentals
Explain the account model, runtimes, entitlements, service instances versus subscriptions and the clean core idea without notes.
SAP BTP interviews test whether you understand the platform as a whole (account model, runtimes, security and connectivity) and whether you can design and build extensions and integrations around SAP S/4HANA without modifying the core. The questions below cover SAP Business Technology Platform basics for freshers, architecture and services, developer-level technical topics and real design scenarios for experienced consultants and architects.
SAP regularly renames and regroups BTP services. This guide uses current terminology, notes earlier names where candidates still hear them (such as *Extension Suite*), and focuses on concepts that stay stable: subaccounts, entitlements, destinations, identity, CAP, Integration Suite and event-driven design.
Answers reflect SAP S/4HANA terminology. Transaction codes, menu paths and cloud features can vary by release and edition, so confirm details in your project system.
Foundational SAP BTP interview questions on what the platform is, how accounts are structured and which services you will meet first.
SAP Business Technology Platform (BTP) is SAP's platform-as-a-service offering. It brings together application development and automation, integration, data and analytics, and AI services in one platform. Companies use it to extend SAP applications such as S/4HANA without modifying them, integrate SAP and non-SAP systems, build new cloud applications and work with business data and AI.
LinkAn entitlement is the right to use a service plan; a quota is how much of it a subaccount may consume (for example memory or number of instances). Entitlements are distributed from the global account to subaccounts. Commercially, BTP can be bought through consumption-based models (credits or pay-as-you-go) or subscription models, which affects how usage is billed.
LinkPlatform services such as the destination service, Authorization and Trust Management (XSUAA) or SAP HANA Cloud are consumed by creating service instances and binding them to applications, which provides credentials. Multi-tenant SaaS applications such as SAP Build Work Zone or SAP Integration Suite are consumed by subscribing at subaccount level and assigning role collections to users.
LinkSAP Integration Suite is SAP's integration platform as a service. Key capabilities:
SAP HANA Cloud is the managed, cloud version of SAP HANA. It provides an in-memory database with multi-model support (relational, spatial, graph, JSON documents and vectors) and a data lake for large volumes of less frequently used data. BTP applications usually access it through HDI containers, which isolate each application's database artifacts.
Link*Extension Suite* was an earlier name for BTP's application development and extension capabilities. SAP has since grouped these under SAP Build (for low-code and pro-code development, process automation and business sites) together with runtimes and services such as CAP, Cloud Foundry and Kyma. Candidates may still see the old name in documents and job descriptions; explaining the change shows you follow the platform.
LinkCAP is SAP's framework for building enterprise services and applications in Node.js or Java. You describe the domain model and services in CDS (Core Data Services); CAP then provides generic handlers for create, read, update and delete operations, exposes OData services, supports authentication and authorisation annotations, multitenancy and messaging, and deploys to SAP HANA Cloud. Developers add custom logic in event handlers.
LinkThe SAP BTP ABAP environment (often called *Steampunk*) is a platform-as-a-service for ABAP development in the cloud. It uses the ABAP Cloud development model: the ABAP RESTful Application Programming Model (RAP), CDS and released APIs only. The same model is available inside S/4HANA Cloud as *embedded Steampunk*, which lets ABAP teams build cloud-ready extensions with existing skills.
LinkSide-by-side suits new applications, different lifecycles or integration with several systems; in-app suits small changes that need tight access to business data.
LinkThe Cloud Connector is an agent installed in the customer's on-premise network that creates a secure tunnel to a BTP subaccount. It is an outbound connection, so no inbound firewall ports need to be opened. Administrators expose only specific backend hosts and resource paths through virtual host mappings and access control, and it supports principal propagation of the logged-in user.
LinkThe destination service stores connection information centrally: URL, proxy type, authentication method (for example OAuth2 client credentials, OAuth2 SAML bearer, principal propagation or basic) and additional properties. Applications refer to destinations by name instead of hardcoding credentials. The connectivity service provides the proxy that applications use to reach on-premise systems through the Cloud Connector when a destination has proxy type *OnPremise*.
Linkcf) and the BTP CLI (btp).mbt) for multitarget applications.kubectl and Helm for Kyma.SAP BTP architecture interview questions for candidates with practical exposure: runtimes, security, connectivity, events and APIs.
VCAP_SERVICES).Applications should be stateless so instances can be added or replaced at any time.
LinkKyma is a managed Kubernetes runtime with modules for API exposure (API rules with authentication), eventing, serverless functions, a service mesh and the SAP BTP service operator for creating BTP service instances from Kubernetes. Choose it when you need containers, fine-grained control over deployments, polyglot microservices or an existing Kubernetes skill set. Cloud Foundry remains simpler for standard CAP and Node.js or Java applications.
LinkAn MTA is a package of modules (for example a CAP service, a database deployer, an application router and UI content) and the resources (service instances) they need, described in mta.yaml. It is built into an .mtar archive with the MTA Build Tool and deployed in one step to Cloud Foundry, which creates services, deploys modules in order and binds them. MTAs are also the unit transported between subaccounts.
The application router is the single entry point for a business application's UI. It authenticates users by redirecting them to the identity provider, forwards requests with the user's token to backend services or destinations according to routes in xs-app.json, and serves static UI content. In many setups, a managed application router provided by SAP Build Work Zone is used instead of deploying your own.
xs-security.json.SAP Cloud Identity Services is a set of identity services:
Many SAP cloud products, including Joule and SAP Build, expect a customer IAS tenant to be in place.
LinkPrincipal propagation forwards the identity of the logged-in cloud user to a backend system, so the backend applies that user's own authorisations instead of a shared technical user. For on-premise systems it typically works through the Cloud Connector, which issues a short-lived X.509 certificate for the user; the backend maps the certificate to a user. The destination uses the *PrincipalPropagation* authentication type.
LinkS/4HANA can publish business events, for example when a business partner or sales order changes, through its event enablement framework. Events are sent to an event broker such as SAP Event Mesh or SAP Advanced Event Mesh, where consumers subscribe through queues and topics. Consumers then react asynchronously, often calling an API for full details. This decouples systems, avoids polling and lets new consumers be added without changing the source.
LinkEvent Mesh is a capability for SAP-centric, asynchronous messaging between applications. Advanced Event Mesh is a fully managed, distributed event broker service designed for large volumes and complex landscapes, with event brokers deployable across clouds and regions, dynamic routing between brokers and an event portal for designing and governing events. The choice depends on volume, latency, topology and governance needs.
LinkThe SAP Business Accelerator Hub (formerly SAP API Business Hub) catalogues SAP APIs, events and integration content, with documentation and a sandbox. API Management in Integration Suite places API proxies in front of backends and applies policies such as authentication, quotas, spike arrest, threat protection and transformation. A developer portal lets internal or partner developers discover APIs and request access, while analytics shows usage and errors.
LinkA provider subaccount runs the application, and each customer (tenant) subscribes from its own consumer subaccount. The SaaS provisioning service calls the application on subscription, so it can set up tenant-specific resources such as database containers. CAP provides built-in multitenancy support, and tenant isolation is based on the tenant ID in the user's token.
LinkAn HDI (SAP HANA Deployment Infrastructure) container is an isolated schema with its own technical users, into which an application's design-time database artifacts (tables, views, procedures) are deployed. Each application or tenant gets its own container, which avoids naming conflicts and enables consistent, repeatable deployments. CAP generates HDI artifacts from CDS models.
LinkSAP Datasphere provides data warehousing and data integration with business semantics. SAP Analytics Cloud provides BI, planning and predictive analytics. SAP Business Data Cloud brings these together with SAP-managed data products from SAP applications and partner data platforms, so business data can be used for analytics and AI with its context preserved. Explain them from the angle of a use case you know.
LinkSAP Build Process Automation is a low-code tool for workflows, approvals, forms, business rules and robotic process automation. Processes can be triggered by events, APIs or forms, call S/4HANA through actions and destinations, and run bots on desktops for tasks without APIs. It suits approval extensions and repetitive tasks that should not be built inside the ERP.
LinkSAP Build Work Zone provides business sites and launchpads on BTP. The standard edition offers a central launchpad that can federate content from S/4HANA and other SAP systems, plus custom UI5 and Fiori apps from the HTML5 application repository. The advanced edition adds workspaces, collaboration and richer content for digital workplaces.
LinkSAP BTP developer and technical interview questions for experienced candidates: CAP development, security configuration, connectivity, DevOps and AI services.
cds init) and define entities in db/schema.cds.srv/ with projections.cds watch, which uses an in-memory SQLite database and mock authentication.cds add hana, cds add xsuaa, cds add mta).before, on, after) and deploy.// db/schema.cds
namespace aplus.training;
entity Courses {
key ID : UUID;
title : String(100);
level : String enum { Fresher; Intermediate; Experienced };
seats : Integer;
}
// srv/catalog-service.cds
using { aplus.training as db } from '../db/schema';
service CatalogService @(requires: 'authenticated-user') {
@readonly entity Courses as projection on db.Courses;
}Use @requires for role checks on services or entities and @restrict for finer rules, including instance-based conditions. CAP can generate the matching scopes and role templates for xs-security.json, and administrators assign role collections.
annotate CatalogService.Courses with @(restrict: [
{ grant: 'READ', to: 'Viewer' },
{ grant: '*', to: 'Admin' }
]);Import the API definition (for example an EDMX file from the SAP Business Accelerator Hub) with cds import, which creates a CDS model for the external service. Configure it under cds.requires with a destination name, then connect in code with cds.connect.to() and run queries against it. Locally, CAP can mock the remote service; in the cloud, the destination and connectivity services handle URLs, authentication and on-premise access.
The SAP Cloud SDK is a set of libraries for JavaScript/TypeScript and Java that simplifies calling SAP APIs. It provides typed clients for SAP services, handles destination lookup, connectivity, authentication and multitenancy, and supports resilience patterns such as timeouts and retries. CAP uses it internally for remote services.
Link/sap/opu/odata.sap-client.It is the security descriptor for an XSUAA instance: the application name (xsappname), tenant mode (dedicated or shared), scopes, attributes, role templates, optional role collections and OAuth 2.0 settings such as allowed redirect URIs.
{
"xsappname": "aplus-catalog",
"tenant-mode": "dedicated",
"scopes": [
{ "name": "$XSAPPNAME.Viewer", "description": "Read courses" },
{ "name": "$XSAPPNAME.Admin", "description": "Maintain courses" }
],
"role-templates": [
{ "name": "Viewer", "scope-references": ["$XSAPPNAME.Viewer"] },
{ "name": "Admin", "scope-references": ["$XSAPPNAME.Admin"] }
]
}Use cf logs <app> --recent and cf events for quick checks, and a central logging service (such as SAP Cloud Logging) for search, dashboards and retention. Health checks and alerting (for example through the Alert Notification service) detect failures, and the application autoscaler handles load. Add correlation IDs so requests can be traced through the application router, services and backends.
SAP Continuous Integration and Delivery provides predefined pipelines that build, test and deploy CAP, UI5 and MTA projects from a Git repository. SAP Cloud Transport Management moves the built MTA archives between subaccounts (development → test → production) with approvals, and can integrate with on-premise change management. Teams using Jenkins or other tools can use SAP's open-source pipeline library (project *Piper*).
LinkBuild a container image (Dockerfile or Cloud Native Buildpacks) and push it to a registry. Deploy with Kubernetes manifests or a Helm chart, expose the service through an API rule with authentication, and create BTP service instances and bindings with the SAP BTP service operator. Secrets from bindings are mounted into the pods.
LinkRun several instances, keep applications stateless (state in SAP HANA Cloud, Redis or other backing services), configure health checks and the autoscaler, and use blue-green deployment for MTAs (cf deploy with the blue-green strategy) so a new version is validated before traffic is switched.
Decouple sender and receiver with JMS queues so messages can be retried, use exception subprocesses to handle and log errors, design idempotent processing (for example with an idempotent process call based on a message ID) so retries do not create duplicates, set adapter timeouts deliberately, and configure alerting on failed messages. Avoid permanent trace logging in production because of performance and data protection.
LinkA typical policy set: verify the API key or OAuth 2.0 token, apply spike arrest and quotas per application, add JSON or XML threat protection, remove internal headers and mask errors, and log for analytics. Backend credentials stay in API Management, so partners never see them.
LinkConfigure a messaging service (for example SAP Event Mesh) in cds.requires.messaging, declare or import the event definitions, and register handlers with srv.on('<event name>', ...). CAP subscribes to the queue and calls the handler for each event; the handler usually reads full data through the S/4HANA API and updates the application's own data.
Fiori elements applications are generated from OData services and annotations (list report, object page and other floorplans), while freestyle applications are written in SAPUI5. They are deployed to the HTML5 application repository, served through a managed or standalone application router, and added to a SAP Build Work Zone site so users can launch them.
LinkPush logic down to the database (CDS views, calculation views, SQL) instead of loading large data sets into the application, select only needed columns, use appropriate partitioning, and size memory realistically. Use native storage extension or the data lake for warm or cold data, and analyse expensive statements with the database explain plan and monitoring tools.
LinkSAP AI Core includes the generative AI hub, which gives access to multiple foundation models through one service, with an orchestration layer for prompt templating, grounding, content filtering and data masking. For retrieval-augmented generation, documents can be stored as embeddings in the SAP HANA Cloud vector engine and retrieved by similarity before calling a model. Governance (which models, which data, logging) should be designed up front.
LinkSAP BTP scenario based interview questions for architects and senior developers. Explain trade-offs, not just service names.
A side-by-side extension: an S/4HANA event or API triggers a workflow in SAP Build Process Automation (or a CAP application with a Fiori elements UI if more custom logic is needed). Approvers use the SAP Build Work Zone launchpad or the task inbox, and the decision is written back through a released API. Single sign-on uses SAP Cloud Identity Services. This keeps the S/4HANA core clean and lets the approval logic change independently.
LinkCheck, in order: whether the user has the right role collection (directly or via an identity provider group mapping), whether the role collection contains the role from the correct application (the xsappname may have changed between deployments), whether the user logged in again after assignment, and whether the token contains the expected scopes. For CAP, confirm that the role names in @requires or @restrict match the role templates. The application logs usually show which check failed.
The destination's connection check and the Cloud Connector's audit and trace logs narrow it down quickly.
LinkStart with an inventory and use SAP's migration assessment to categorise interfaces by complexity. Group similar patterns, use the available migration tooling for supported scenarios, and redesign interfaces that rely on features without a direct equivalent. Plan connectivity (Cloud Connector, adapters), security material and monitoring, run old and new interfaces in parallel where possible, and migrate in waves. SAP has announced end-of-maintenance dates for Process Orchestration 7.5, so many companies are planning this now.
LinkPrefer events where available: S/4HANA publishes relevant changes to an event broker, and a consumer (an iFlow or microservice) fetches the current availability through an API and pushes it to the e-commerce platform. If suitable events are not available, use scheduled delta extraction at a short interval. Consider volume peaks, ordering of updates, idempotent processing and a periodic full reconciliation so the two systems never drift for long.
LinkAlso weigh cost model, operational effort, available skills and how the extension will be supported long term.
LinkUnderstand which services are already highly available within a region and what their recovery commitments are. For critical applications, keep deployments reproducible through CI/CD and transports, keep configuration in code, back up or replicate data (for example SAP HANA Cloud replicas), and decide whether a second region with failover through a custom domain is justified by the business impact.
LinkPlace an API proxy in API Management in front of the backend, require OAuth 2.0 client credentials or API keys per partner, apply quotas and spike arrest, add threat protection and IP restrictions if needed, and publish the API on the developer portal with an approval process. Backend access goes through the Cloud Connector with a narrowly scoped technical user, and analytics tracks usage per partner.
LinkAnalyse usage by subaccount and service in the global account cockpit, then act on the main drivers: right-size SAP HANA Cloud instances and stop non-production instances outside working hours, remove unused service instances, reduce memory over-allocation on Cloud Foundry, and set quotas per subaccount so teams cannot exceed budgets. Introduce regular cost reviews and tagging by project.
LinkLook at the message processing logs for patterns (time of day, payload size, specific receivers). Check backend response times, adapter timeout settings, Cloud Connector load and connection limits. Short-term, add retry through JMS; long-term, move long-running calls to an asynchronous pattern, split large payloads, and agree performance targets with backend owners.
LinkUse separate subaccounts for development, test and production, with source code in Git and CI/CD pipelines that build and test every change. Transport MTAs through Cloud Transport Management with approval steps, keep stage-specific configuration in destinations and environment variables rather than code, and store secrets in the Credential Store or equivalent. Restrict production access to support roles with audit logging.
LinkHands-on SAP BTP questions about commands, descriptors and configuration you are expected to recognise.
cf login -a https://api.cf.<region>.hana.ondemand.com
cf target -o <org> -s <space>
cf apps # list applications
cf logs <app> --recent # recent logs
cf create-service <service> <plan> <instance-name>
cf bind-service <app> <instance-name>
cf env <app> # environment, including bound credentials
cf deploy mta_archives/<file>.mtar # needs the MultiApps CLI plugin
cf scale <app> -i 2 -m 512MThe BTP command line interface (btp) automates account administration: logging in to a global account, listing and creating subaccounts and directories, managing entitlements, subscribing to applications and assigning role collections. For example, btp list accounts/subaccount lists subaccounts and btp assign security/role-collection <name> --to-user <email> assigns a role collection. It is useful for repeatable landscape setup.
_schema-version: "3.1"
ID: aplus-catalog
version: 1.0.0
modules:
- name: aplus-catalog-srv
type: nodejs
path: gen/srv
requires:
- name: aplus-catalog-db
- name: aplus-catalog-auth
- name: aplus-catalog-db-deployer
type: hdb
path: gen/db
requires:
- name: aplus-catalog-db
resources:
- name: aplus-catalog-db
type: com.sap.xs.hdi-container
- name: aplus-catalog-auth
type: org.cloudfoundry.managed-service
parameters:
service: xsuaa
service-plan: application
path: ./xs-security.jsonName, type (usually HTTP), URL, proxy type (*Internet* or *OnPremise*), authentication method and its credentials or token service settings, and optional location ID for a specific Cloud Connector. Additional properties such as sap-client or HTML5.DynamicDestination control how SAP tools and runtimes use the destination.
In the subaccount's trust configuration, establish trust with the customer's Identity Authentication tenant. Configure Identity Authentication to authenticate users locally or forward to a corporate identity provider, and map identity provider groups to role collections so authorisations follow group membership. Disable the default SAP identity provider for business users if the security policy requires it.
LinkUse the monitoring section for integrations to view message processing logs, filter by status, time and iFlow, and inspect individual steps. Increase the log level temporarily for troubleshooting, then reset it. Monitor JMS queues for stuck messages, check security material expiry dates, and configure alerts for failed messages.
LinkRun cds watch in the project folder. CAP starts with an in-memory SQLite database, loads sample data from CSV files, uses mocked users for authentication and serves the OData endpoints and a test page. You can test with the browser, REST client files or automated tests before connecting to SAP HANA Cloud or remote services.
Use the Fiori application generator in SAP Business Application Studio or VS Code, choose a floorplan such as list report and object page, and select the local CAP service. Add UI annotations (for example line items and field groups) in CDS to control columns and sections. Add the application to the MTA for deployment to the HTML5 application repository.
LinkBTP interviews mix concepts, hands-on development and architecture. Prepare all three.
Explain the account model, runtimes, entitlements, service instances versus subscriptions and the clean core idea without notes.
Be comfortable with destinations, Cloud Connector, XSUAA and SAP Cloud Identity Services, SAP HANA Cloud, Integration Suite and SAP Build.
Create a small CAP service with a Fiori elements UI, secure it, connect it to a remote API and deploy it as an MTA. Being able to describe what you built is powerful.
Know when to use synchronous APIs, events and batch, and how Cloud Integration, API Management and event brokers fit together.
Rehearse 401/403 errors, connectivity failures, deployment errors and failed iFlow messages. Interviewers often ask how you diagnosed a real issue.
Prepare a project summary covering architecture, your contribution, security design and how the solution was deployed and monitored.
List only services you have used, and be ready to draw your solution's architecture on a whiteboard.
Revise CDS syntax, mta.yaml, xs-security.json, cf commands and current service names. For guided, hands-on practice, see Aplus Edtech's SAP BTP training.
Yes. Clean core strategies and S/4HANA cloud programmes move extensions and integrations to SAP BTP, which increases demand for developers, integration consultants and architects with BTP skills.
JavaScript/Node.js or Java, CDS and CAP, OData and REST, SAPUI5 or Fiori elements, Git and CI/CD basics, plus BTP security and connectivity. ABAP developers can enter through the ABAP environment and RAP.
Yes. Functional consultants often work with low-code tools such as SAP Build Process Automation and SAP Build Apps, and with integration design. Understanding business processes is a real advantage in extension projects.
Expect architecture and integration design, security (XSUAA, Identity Authentication, principal propagation), CAP development, deployment and transport, troubleshooting and cost or governance questions, usually through scenarios.
It can help, particularly for developers and integration consultants new to SAP. Interviewers still focus on hands-on experience and design reasoning.
SAP BTP is the successor to what was earlier called SAP Cloud Platform. The platform has since been reorganised and many services renamed, so use current names in interviews.
If several answers on this page felt unfamiliar, the gap is usually hands-on practice rather than theory. Aplus Edtech's SAP BTP programme is instructor-led, with practice on SAP S/4HANA and real business scenarios, so you can walk an interviewer through what you configured, built or fixed.
Share your background and target role. An advisor will explain batch timings, curriculum and the right module for you.
Explore SAP Training +91 910-8249-111Last updated: · Prepared by the Aplus Edtech SAP training team.