SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 199 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 199

Single answer2.6 Configure and maintain data replication policies and procedures.

A financial services company uses Snowflake Business Critical Edition and has configured account-level object replication from its primary account in AWS us-east-1 to a secondary account in AWS us-west-2 for disaster recovery. The security team must ensure that failover can occur without exposing masked customer data to unauthorized users in the secondary account. During testing, they discover that replicated databases are present in the secondary account, but some users there can query sensitive columns without the expected masking behavior. Which action should the security engineer take to address this issue while preserving the intended disaster recovery design?

  1. A

    Replicate the database again using a more frequent replication schedule so that masking policies are fully synchronized before failover.

  2. B

    Ensure that the roles used in the secondary account have the same names and grant hierarchy as the roles referenced by the masking policies in the primary account.

  3. C

    Convert the masking policies to row access policies because row access policies are enforced automatically after database replication.

  4. D

    Create network policies in the secondary account to restrict user access to the replicated database until failover occurs.

Show answer and explanation

Correct answer: B

Explanation

The key issue is that replicated databases can include policy objects such as masking policies, but account-level objects and context required for equivalent enforcement may need to be configured separately in the target account. In practice, if a masking policy references roles, the secondary account must contain corresponding roles and grants so policy conditions evaluate as intended after replication or failover. This is an important security consideration for replication runbooks and DR validation. Snowflake documentation on replication/failover and policy-based protection emphasizes understanding which objects replicate and ensuring dependent security configuration exists in the target account. Best practice is to test failover regularly and validate both object availability and security behavior, including masking and role resolution.

  • A. Incorrect.

    Incorrect. Increasing replication frequency does not solve role-resolution issues in policy enforcement. Database replication synchronizes supported database objects, including masking policies, but if a policy body references roles, those roles must exist and be appropriately granted in the target account for behavior to match expectations. The issue is not stale replication data; it is inconsistent security context in the secondary account.

  • B. Correct.

    Correct. In Snowflake, masking policies can use context functions and role-based logic. When databases containing masking policies are replicated or failed over, account-level objects such as roles are not automatically replicated with the database. To preserve consistent masking behavior after replication or failover, the secondary account must have the necessary roles and grant hierarchy expected by the policy logic. This is a key operational requirement when maintaining secure replication and failover procedures.

  • C. Incorrect.

    Incorrect. Row access policies and masking policies solve different problems. Row access policies filter rows, while masking policies protect column values. Replacing masking policies with row access policies would not be a valid or equivalent fix for unauthorized visibility of sensitive column data. Also, replication does not eliminate the need to align account-level security constructs referenced by policies.

  • D. Incorrect.

    Incorrect. Network policies can restrict where users connect from, but they do not correct masking policy evaluation or role-based policy logic. This may reduce exposure temporarily, but it does not preserve the intended disaster recovery design in which the secondary account must be ready for controlled failover with correct data protection behavior.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam