SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 1 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 1

Single answerDomain 1.0: Access Control and Identity Management (22%)

A Snowflake security engineer is implementing federated authentication for employees using the company's corporate IdP. The company wants all interactive users to authenticate with SSO and MFA managed by the IdP, while service accounts used by ETL tools must continue to authenticate with key-pair authentication. During testing, some users can still sign in with a Snowflake username and password directly at the Snowflake login page, which violates the security requirement. What is the BEST action to meet the requirement without disrupting the ETL service accounts?

  1. A

    Set the account-level authentication policy to require SAML authentication for all users, and assign a separate user-level authentication policy to service accounts that allows key-pair authentication

  2. B

    Disable the PASSWORD parameter on all users, including service accounts, because key-pair authentication does not require a password

  3. C

    Configure network policies so employee logins are blocked unless they originate from the corporate office IP ranges

  4. D

    Grant the SECURITYADMIN role to the IdP integration user so the IdP can prevent direct Snowflake password logins

Show answer and explanation

Correct answer: A

Explanation

The best answer is to use Snowflake authentication policies to explicitly govern allowed authentication methods. For this requirement, the organization should enforce federated authentication for human users at the account level and create exceptions only for ETL/service accounts that must use key-pair authentication. This is the most precise and maintainable approach because it separates human and machine identities and enforces least privilege in authentication paths. Network policies are complementary but do not enforce SSO. Likewise, password changes alone are less effective than policy-based authentication controls. This approach is consistent with Snowflake best practices for identity management: use federated authentication for workforce users, use key-pair authentication for service users where appropriate, and apply centralized authentication policies to control permitted login methods.

  • A. Correct.

    Correct. Snowflake authentication policies can be applied at the account and user levels to control allowed authentication methods. In this scenario, the account should enforce federated/SAML-based authentication for interactive users, while specific service accounts can be exempted with a user-level policy that permits key-pair authentication. This aligns with the requirement to block direct username/password access for employees without breaking non-interactive service accounts.

  • B. Incorrect.

    Incorrect. Removing or disabling passwords broadly is not the best solution here. While key-pair authentication does not require a password, interactive users still need controlled access through federated authentication, and password-related settings alone do not comprehensively enforce the desired authentication method strategy. Also, applying this indiscriminately to all users is operationally risky and does not leverage Snowflake's intended authentication policy controls.

  • C. Incorrect.

    Incorrect. Network policies restrict where connections can originate, not how users authenticate. Even if network restrictions are useful as a defense-in-depth control, they do not prevent direct Snowflake password authentication from approved networks. This does not satisfy the core requirement that employees must authenticate through the IdP with SSO/MFA.

  • D. Incorrect.

    Incorrect. SAML/SCIM or other identity integrations do not work by granting administrative roles to an 'IdP integration user' to block login methods. Authentication behavior is controlled through Snowflake security configurations such as authentication policies and federated authentication setup, not by delegating SECURITYADMIN to an integration principal for login enforcement.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam