SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 167 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 167

Single answerDifferentiate between Time Travel and Fail-safe in context of security and compliance

A financial services company stores regulated customer records in Snowflake. The security team accidentally drops a table containing transaction history, and the compliance team asks two questions: (1) whether the table can be restored immediately by the company's own administrators, and (2) whether Snowflake retains any copy of the data after the customer-configured recovery window ends. Which statement best answers both concerns?

  1. A

    The table can be restored by administrators during the Time Travel retention period, and after that period Snowflake keeps the data in Fail-safe for a limited time for disaster recovery, not for self-service querying or routine restores.

  2. B

    The table can be restored only during Fail-safe, because Time Travel is intended for cloning and does not support recovery of dropped objects.

  3. C

    Once the Time Travel retention period ends, the data is permanently removed and Snowflake does not retain any additional copy.

  4. D

    Administrators can query and restore the dropped table at any time during both Time Travel and Fail-safe, but Fail-safe requires the SECURITYADMIN role.

Show answer and explanation

Correct answer: A

Explanation

This scenario tests whether the candidate can distinguish customer-controlled recovery from Snowflake-managed disaster recovery. In Snowflake, Time Travel allows access to historical data and recovery of dropped or changed objects within the configured retention period. This is the feature administrators use for immediate operational recovery. Fail-safe begins after Time Travel ends for permanent objects and exists primarily so Snowflake can recover data in catastrophic situations. It is not designed as a user-accessible archive, not queryable by customers, and not a substitute for backup strategy or compliance retention tooling. For security and compliance, the key nuance is that data may remain in Snowflake beyond the Time Travel window due to Fail-safe, even though customers lose direct self-service restore capability. This aligns with Snowflake documentation on Time Travel and Fail-safe, which emphasizes Time Travel for historical access and Fail-safe for Snowflake disaster recovery support.

  • A. Correct.

    Correct. Time Travel is the customer-facing recovery feature that allows restoring dropped objects and accessing historical data within the configured retention period. After Time Travel expires, Snowflake places permanent objects into Fail-safe for an additional period for disaster recovery purposes. Fail-safe is not intended for self-service access, historical querying, or routine operational restores by customer administrators. This distinction is important for compliance discussions because data may still exist in Snowflake after the Time Travel window, but customer control over recovery is much more limited.

  • B. Incorrect.

    Incorrect. This reverses the roles of Time Travel and Fail-safe. Time Travel does support recovery of dropped tables, schemas, and databases, as well as querying historical data within retention limits. Fail-safe is not the normal customer mechanism for object recovery and is designed for Snowflake's disaster recovery processes.

  • C. Incorrect.

    Incorrect. A common misconception is that data disappears completely when the Time Travel period ends. For permanent objects, Snowflake retains data in Fail-safe for a limited additional period. From a compliance perspective, this means the data may still physically exist in Snowflake even though customers can no longer perform self-service recovery through Time Travel.

  • D. Incorrect.

    Incorrect. Fail-safe is not a customer-queryable extension of Time Travel, and it is not accessed simply by using a higher-privileged role such as SECURITYADMIN. Roles do not grant direct self-service access to Fail-safe data. Customers generally cannot query historical data or perform routine restores from Fail-safe themselves.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam