SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 150 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 150

Single answerConfigure Data Listings

A security engineer at a data provider is preparing a private Snowflake data listing that exposes a secure view containing masked customer attributes. The provider wants to share the listing only with two specific consumer accounts and must ensure consumers cannot see data outside the secure view definition. Which action should the engineer take to meet these requirements when configuring the listing?

  1. A

    Create a private listing from a share that contains only the secure view, then target the two consumer accounts when publishing the listing

  2. B

    Create a public listing so the secure view can be discovered broadly, and rely on masking policies to limit visibility to the intended two accounts

  3. C

    Add the base tables and the secure view to the share, then mark the listing as private so consumers can choose the appropriate object

  4. D

    Publish the listing to the two accounts first, then apply the secure view to the share after consumers install the listing

Show answer and explanation

Correct answer: A

Explanation

When configuring Snowflake data listings, the listing is backed by a share, so access control begins with what objects are placed in that share. To ensure consumers cannot access data outside the intended interface, best practice is to share only secure views or other curated secure objects rather than underlying base tables. For restricted distribution, a private listing should be used and targeted to specific consumer accounts or organizations, depending on the sharing model. This aligns with Snowflake guidance for secure data sharing and listings: use secure views to protect query logic and object exposure, and use private listings for controlled distribution rather than public discoverability.

  • A. Correct.

    Correct. A listing is created from a share, so the provider must ensure the share contains only the objects intended for consumers. Including only the secure view prevents direct access to underlying base tables. Making the listing private and targeting specific consumer accounts satisfies the requirement to restrict discovery and access to those two accounts.

  • B. Incorrect.

    Incorrect. A public listing is intended for broad discovery in the marketplace or exchange context, not for restricting access to two named consumer accounts. Although masking policies can protect sensitive columns, they do not replace the need to properly scope listing visibility and share contents.

  • C. Incorrect.

    Incorrect. If base tables are added to the share, consumers may be able to query them directly, bypassing the provider's intent to expose only the secure view. Marking the listing as private restricts who can access the listing, but it does not hide other shared objects from authorized consumers.

  • D. Incorrect.

    Incorrect. Consumers access what is present in the underlying share at the time the listing is configured and consumed. The provider should define the secure view and share contents before publishing. Publishing first and changing object exposure afterward is operationally risky and does not align with least-privilege sharing practices.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam