SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 152 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 152

Select 22.3 Restrict data exfiltration.

A financial services company allows analysts to unload approved result sets from Snowflake to an internal Amazon S3 bucket for downstream processing. During a security review, the company discovers that several powerful roles can create new stages and use COPY INTO commands to export sensitive table data to arbitrary cloud storage locations. The security engineer must reduce the risk of data exfiltration while still allowing approved unload operations to the company-managed S3 bucket. Which TWO actions provide the most effective control?

  1. A

    Create a storage integration that is limited to the approved S3 bucket path, grant usage on that integration only to the required roles, and require unload operations to use that integration.

  2. B

    Revoke unnecessary CREATE STAGE privileges and restrict who can create or use external stages so users cannot define arbitrary external destinations for data unloads.

  3. C

    Enable Tri-Secret Secure so exported data cannot be written to unauthorized external locations.

  4. D

    Grant analysts the MONITOR privilege on warehouses so security teams can review query history for suspicious COPY INTO statements.

  5. E

    Rely on dynamic data masking policies alone to prevent all forms of data exfiltration during unload operations.

Show answer and explanation

Correct answers: A, B

Explanation

To restrict data exfiltration in Snowflake, the strongest approach is to combine least-privilege access with controlled outbound storage access. In this scenario, the company still needs approved unload capability, so the best solution is to use a storage integration constrained to specific S3 locations and to tightly control privileges to create and use external stages. These measures directly reduce the ability of users to export data to arbitrary external destinations. This aligns with Snowflake security best practices around external stages, storage integrations, and least privilege. By contrast, controls such as Tri-Secret Secure, monitoring privileges, or masking policies may improve encryption, observability, or data obfuscation, but they do not directly and comprehensively restrict outbound unload destinations. Relevant Snowflake documentation includes guidance for storage integrations, external stages, COPY INTO , and access control best practices.

  • A. Correct.

    Correct. A storage integration is a key Snowflake control for outbound access to cloud storage. By configuring the integration to allow only specific S3 locations and then limiting which roles can use it, the company can permit sanctioned unloads while preventing users from pointing exports to arbitrary buckets. This directly addresses the exfiltration risk by constraining the external destination used by COPY INTO and external stages.

  • B. Correct.

    Correct. Restricting CREATE STAGE and related access is an important preventive control. If users can create external stages freely, they can define new outbound destinations outside approved locations. Revoking unnecessary privileges and tightly controlling who can create or use external stages reduces the attack surface for exporting data to unauthorized cloud storage.

  • C. Incorrect.

    Incorrect. Tri-Secret Secure enhances key management and encryption control for data at rest in Snowflake, but it does not prevent a user with sufficient privileges from unloading data to an unauthorized external location. This option reflects a common misconception that stronger encryption or customer-controlled keys alone stop exfiltration; they do not replace outbound access controls.

  • D. Incorrect.

    Incorrect. MONITOR on warehouses may help with operational visibility, but it is not a preventive control for data exfiltration. Reviewing query history is detective rather than restrictive, and MONITOR privilege does not stop users from creating stages or running COPY INTO commands to external storage. It may support investigations, but it is not among the most effective controls for this scenario.

  • E. Incorrect.

    Incorrect. Dynamic data masking can reduce exposure of sensitive values for roles that should not see raw data, but it does not by itself prevent all exfiltration. Users with unmasked access could still unload data, and masking does not control the destination of exported files. This is a partial data protection mechanism, not a complete outbound restriction strategy.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam