SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 173 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 173

Single answerAlign retention policies with compliance requirements (for example, GDPR and HIPAA)

A healthcare analytics company stores patient treatment records and EU customer support data in Snowflake. The security engineer must align data retention with two requirements: HIPAA data must remain recoverable for an extended period to support audits and investigations, while GDPR-related personal data must be deleted as quickly as practical after an approved erasure request. Which approach BEST meets both requirements within Snowflake?

  1. A

    Place all tables in one schema and set a long Time Travel retention period on the schema so both HIPAA and GDPR data can be recovered if needed.

  2. B

    Separate HIPAA-regulated data and GDPR-erasure-prone data into different tables or schemas, use a longer Time Travel retention period for HIPAA data where edition/features allow, and use the minimum retention period for GDPR-sensitive data along with operational processes to purge data and manage Fail-safe expectations.

  3. C

    Disable Time Travel on all regulated data so deleted records are immediately unrecoverable and therefore compliant with both HIPAA and GDPR.

  4. D

    Rely on masking policies for GDPR data because masked rows are considered deleted for retention purposes, while keeping default retention settings for HIPAA tables.

Show answer and explanation

Correct answer: B

Explanation

The strongest design is to separate data with different retention obligations and apply retention settings at the most appropriate object scope. Snowflake supports Time Travel, which allows access to historical data for a defined retention period, and permanent objects are also subject to Fail-safe after Time Travel expires. For compliance alignment, security engineers should avoid co-mingling datasets that require very different retention behaviors. HIPAA-related records often need stronger recoverability and audit support, while GDPR erasure requests push organizations to minimize recoverability windows for personal data. In Snowflake, the practical pattern is to isolate these datasets, configure a longer retention period only where justified, and use the minimum possible retention for GDPR-sensitive objects. Candidates should also recognize that masking is not deletion, and that Fail-safe is not configurable as an immediate purge mechanism. This reflects Snowflake documentation and best practices around Time Travel, object-level data retention, and Fail-safe behavior.

  • A. Incorrect.

    Incorrect. Applying a single long retention period to mixed datasets conflicts with GDPR erasure objectives because deleted personal data may remain recoverable through Time Travel for longer than necessary. It may support HIPAA-oriented recoverability, but it does not appropriately minimize retention for GDPR-sensitive data. A common mistake is assuming one retention policy can satisfy all regulatory requirements across different data classes.

  • B. Correct.

    Correct. The best practice is to classify and separate data based on retention and deletion requirements, then apply object-level retention settings accordingly. HIPAA-related datasets may justify longer Time Travel retention to support recovery and audit needs, while GDPR-sensitive datasets should use the lowest practical retention period. Snowflake Time Travel retention can be configured at the account, database, schema, and table levels, subject to edition and object type constraints. However, even after Time Travel ends, Fail-safe may still keep data for a fixed period in Snowflake-managed recovery, so teams must account for that in GDPR processes and legal/compliance review rather than assuming immediate physical destruction.

  • C. Incorrect.

    Incorrect. Disabling or minimizing recoverability for all regulated data is not aligned with HIPAA-oriented operational and audit needs. In addition, Snowflake still has platform behaviors such as Fail-safe for permanent objects, so deleting data does not necessarily mean it is immediately and fully irrecoverable. This option reflects the misconception that turning off Time Travel alone satisfies all retention obligations.

  • D. Incorrect.

    Incorrect. Masking policies protect data visibility at query time but do not delete underlying data and do not change Time Travel or Fail-safe retention behavior. Masked data can still exist in storage and recovery windows. This is a common misconception when teams confuse access control with lifecycle management and deletion.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam