SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 2 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 2

Single answerDomain 1.0: Access Control and Identity Management (22%)

A financial services company uses Snowflake with federated authentication for all employees. The security team wants to ensure that analysts can access Snowflake only through the corporate identity provider (IdP) with MFA enforced by the IdP, while a small group of break-glass administrators must still be able to sign in with Snowflake-managed credentials if the IdP is unavailable. The company also wants to reduce the risk of password-based attacks against standard employee accounts. Which configuration best meets these requirements?

  1. A

    Set the account-level authentication policy to require SAML authentication for all users, and create a network policy that allows only corporate IP ranges.

  2. B

    Configure federated authentication for the account, set SAML_IDENTITY_PROVIDER on all employee users, disable passwords for those employee users, and retain Snowflake passwords only for the designated break-glass administrator accounts.

  3. C

    Enable key-pair authentication for all users, because key-pair authentication replaces the need for federated SSO and supports IdP-enforced MFA.

  4. D

    Create a custom role for analysts that denies the USE_ANY_ROLE privilege unless they authenticate through the IdP, and leave passwords enabled for all users as a fallback.

Show answer and explanation

Correct answer: B

Explanation

The best answer is Option 2 because it uses Snowflake federation design appropriately: employees should authenticate through the external IdP, where MFA is centrally enforced, and standard employee passwords in Snowflake should be disabled to prevent local password fallback and reduce credential attack risk. At the same time, a limited set of emergency or break-glass administrator accounts can retain Snowflake-managed credentials for continuity if the IdP is unavailable. This reflects the principle of least privilege and minimizes standing risk while preserving operational resilience. In Snowflake documentation, federated authentication and user-level configuration support directing users to SSO, while Snowflake-managed passwords can be disabled for users who should not authenticate locally. Network policies are useful complementary controls, but they do not replace the need to separate federated-only users from emergency local accounts. Likewise, roles govern authorization after authentication and do not enforce the required authentication method.

  • A. Incorrect.

    Incorrect. Requiring SAML for all users would also block the break-glass administrators from using Snowflake-managed credentials during an IdP outage, which directly conflicts with the requirement. A network policy can restrict source IPs, but it does not by itself enforce the desired separation between federated-only standard users and password-capable emergency administrators.

  • B. Correct.

    Correct. This approach aligns with Snowflake best practices for federated authentication and access hardening. By configuring federated authentication and associating employee users with the SAML identity provider, employees authenticate through the corporate IdP where MFA can be enforced. Disabling passwords for those users reduces password attack surface because they cannot fall back to Snowflake-native passwords. Keeping Snowflake-managed passwords only for a tightly controlled set of break-glass administrator accounts preserves emergency access if the IdP is unavailable.

  • C. Incorrect.

    Incorrect. Key-pair authentication is primarily used for programmatic access and does not replace federated SSO for interactive workforce authentication. It also does not inherently provide IdP-enforced MFA for users. Using it for all users would not satisfy the requirement that analysts authenticate through the corporate IdP with MFA.

  • D. Incorrect.

    Incorrect. Snowflake roles control authorization, not the authentication path in the manner described here. There is no role configuration that conditionally denies privileges based on whether the user authenticated through the IdP versus a Snowflake password in this way. Leaving passwords enabled for all users also fails the goal of minimizing password-based attacks against standard employee accounts.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam