SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 10 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 10

Single answerIntegrate RBAC management with IdPs using SCIM (user group membership)

A company uses Microsoft Entra ID as its identity provider and wants to reduce manual administration of Snowflake access. The security team has enabled SCIM provisioning so that Entra ID groups are synchronized into Snowflake and used to drive role assignments. They want users added to the Entra ID group DATA_ANALYSTS to automatically receive the appropriate Snowflake privileges through a Snowflake role, and they want group membership changes in the IdP to be reflected in Snowflake without manually updating users. Which approach should the security engineer implement?

  1. A

    Create a Snowflake role for analyst access, grant the required privileges to that role, map the SCIM-provisioned Snowflake group representing DATA_ANALYSTS to the role, and allow SCIM to manage user membership in that group.

  2. B

    Create individual Snowflake users manually, grant privileges directly to each user, and use SCIM only for password synchronization from Entra ID.

  3. C

    Use SCIM to provision Snowflake roles directly from Entra ID, so users are added to roles without any Snowflake group objects or grants.

  4. D

    Configure Entra ID for SAML SSO only, and rely on JUST-IN-TIME user creation so that Entra ID group membership automatically grants Snowflake object privileges at login.

Show answer and explanation

Correct answer: A

Explanation

The correct design is to use the IdP as the source of truth for user and group membership through SCIM, while continuing to use Snowflake RBAC for authorization. In practice, the security engineer should create Snowflake roles that contain the required privileges, then connect IdP-managed group membership to those roles through Snowflake’s access model. This ensures that when users are added to or removed from the DATA_ANALYSTS group in Entra ID, their effective access can be updated centrally without direct user-by-user privilege administration. Snowflake documentation distinguishes authentication federation such as SAML from provisioning via SCIM, and Snowflake best practices consistently recommend assigning privileges to roles rather than directly to users. SCIM helps automate identity and group lifecycle management; Snowflake roles remain the core mechanism for object privilege assignment.

  • A. Correct.

    Correct. In Snowflake, SCIM integration is used to provision and manage users and groups from the IdP. A common best-practice pattern is to let the IdP manage group membership, have those groups represented in Snowflake, and then associate access through Snowflake RBAC by granting roles appropriately. This supports centralized lifecycle management in the IdP while keeping authorization aligned with Snowflake roles and privilege grants.

  • B. Incorrect.

    Incorrect. Directly granting privileges to users is contrary to Snowflake RBAC best practices, which recommend granting privileges to roles and assigning roles to users. Also, SCIM is not used for password synchronization into Snowflake. With federated authentication, password management remains with the IdP, and SCIM is used for identity and group provisioning rather than password sync.

  • C. Incorrect.

    Incorrect. SCIM in Snowflake is used for provisioning users and groups, not for provisioning Snowflake roles directly from the IdP as RBAC objects with privileges. Roles remain Snowflake authorization objects that must be created and managed in Snowflake. The misconception is assuming IdP groups and Snowflake roles are the same object type; in practice, groups from SCIM are mapped into Snowflake access design rather than replacing Snowflake roles.

  • D. Incorrect.

    Incorrect. SAML SSO handles authentication, not authorization provisioning of object privileges. Just-in-time user creation can reduce manual user creation in some identity patterns, but it does not make IdP group membership automatically grant Snowflake object privileges unless RBAC grants are configured in Snowflake. The misconception is confusing login federation with full lifecycle and entitlement management.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam