SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 142 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 142

Single answerConfigure and manage Snowflake Data Clean Rooms:

A media company wants to collaborate with an advertiser using Snowflake Data Clean Rooms. The media company must allow the advertiser to measure audience overlap and campaign reach, but its security team requires that the advertiser never see raw customer-level records and can only run pre-approved analysis. The company also wants to ensure the advertiser cannot change the approved logic after the clean room is published. Which action should the clean room provider take to best meet these requirements?

  1. A

    Create the clean room with provider-defined templates and policies, link only the approved datasets, and publish the clean room so the consumer can run only the allowed analyses through the template interface.

  2. B

    Share the underlying tables directly with the advertiser, then rely on masking policies to hide PII while allowing the advertiser to write any SQL needed for overlap analysis.

  3. C

    Replicate the customer tables into the advertiser's account and require the advertiser to use a warehouse with network policies so raw data cannot be exported.

  4. D

    Allow the advertiser to upload its own SQL templates into the provider's clean room after publication, because template execution in a clean room automatically prevents any logic changes from affecting data exposure.

Show answer and explanation

Correct answer: A

Explanation

The best answer is to use the Snowflake Data Clean Rooms governance model as intended: the provider links approved datasets, defines and controls the permitted analysis templates, and publishes the clean room for consumer use. This supports privacy-preserving collaboration by avoiding direct table sharing and limiting execution to sanctioned analytical workflows such as overlap and reach measurement. For security-sensitive use cases, best practice is to keep control with the provider over both data access and analytical logic, rather than relying on downstream controls like masking on directly shared tables or network restrictions in another account. This matches Snowflake guidance for configuring and managing Data Clean Rooms to enable collaboration without exposing raw underlying records.

  • A. Correct.

    Correct. In Snowflake Data Clean Rooms, the provider controls what data is linked and what analyses are allowed. Using provider-defined templates and policies aligns with the requirement to prevent raw record exposure and limit the consumer to pre-approved queries. Publishing the clean room with only approved datasets and templates ensures the advertiser can perform the intended overlap and reach analysis without direct table access or the ability to modify the approved logic.

  • B. Incorrect.

    Incorrect. Directly sharing underlying tables gives the advertiser much broader access than a clean room is intended to allow. Although masking policies can protect specific columns, this approach does not meet the requirement that the advertiser only run pre-approved analysis and never see customer-level records. It also increases risk because consumers can still write arbitrary SQL against shared objects within the access they are granted.

  • C. Incorrect.

    Incorrect. Replicating customer data into the advertiser's account materially weakens the provider's control model and is not how Snowflake Data Clean Rooms are designed to protect collaborative analysis. Network policies govern connectivity and access paths, not whether approved analytical logic is enforced. This does not satisfy the requirement to restrict the advertiser to provider-approved analysis only.

  • D. Incorrect.

    Incorrect. Allowing the advertiser to add or change SQL templates conflicts with the requirement that the provider control the approved logic after publication. A core benefit of the clean room model is that the provider governs what analysis templates are available. Assuming that any consumer-supplied template is automatically safe is a misconception; provider-controlled templates and policies are the appropriate mechanism for enforcing permitted analysis.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam