SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 206 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 206

Single answerDefine and secure ownership of replication and failover group objects

A global enterprise uses Snowflake Business Critical Edition with organization-level account replication. The security team wants a tightly controlled model for administering replication and failover. They need one custom role to own and manage replication groups and failover groups, while preventing general account administrators from making unapproved changes. During implementation, an engineer notices that members of ACCOUNTADMIN can still take ownership of these objects if needed. Which action best aligns with Snowflake's security model for defining and securing ownership of replication and failover group objects?

  1. A

    Create a dedicated custom role, grant it the privileges required to create and manage replication and failover groups, and transfer OWNERSHIP of the group objects to that role while recognizing that ACCOUNTADMIN retains the ability to manage ownership-sensitive operations.

  2. B

    Grant MANAGE GRANTS on the account to the custom role and remove ACCOUNTADMIN from all users, which prevents ACCOUNTADMIN from changing replication or failover group ownership.

  3. C

    Assign ownership of replication and failover groups to SECURITYADMIN because only system-defined roles can own account-level replication objects securely.

  4. D

    Grant USAGE on the replicated databases to the custom role; this automatically allows the role to control replication group and failover group ownership without additional privileges.

Show answer and explanation

Correct answer: A

Explanation

The best answer is to use a dedicated custom role to own replication and failover group objects and to grant only the necessary administrative privileges to that role. This is consistent with Snowflake best practices around least privilege and separation of duties. Replication groups and failover groups are account-level securable objects with an owner, and ownership determines who can perform many administrative actions on them. In practice, organizations often create a narrowly scoped operational role for business continuity administration instead of relying on broad system roles.

However, Snowflake's security model still gives ACCOUNTADMIN extensive authority at the account level. The exam-relevant point is not that ACCOUNTADMIN can be fully blocked from such objects, but that ownership should be deliberately assigned to a dedicated role to minimize routine exposure and support governance controls, auditing, and operational discipline.

Relevant Snowflake documentation areas include access control and object ownership, as well as replication and failover group management. Those materials emphasize that OWNERSHIP is the strongest privilege on an object, that custom roles are preferred for least-privilege designs, and that high-level administrative roles such as ACCOUNTADMIN retain broad platform control.

  • A. Correct.

    Correct. Replication groups and failover groups are securable objects with an owner, and using a dedicated custom role is the recommended least-privilege approach for operational separation. OWNERSHIP can be transferred to that custom role so day-to-day administration is isolated from broader administrative roles. However, in Snowflake, ACCOUNTADMIN is the highest-level account role and still has broad control, so you cannot fully make these objects invisible or inaccessible to ACCOUNTADMIN. This reflects real-world governance: reduce operational access through role design, but recognize platform-level administrative authority.

  • B. Incorrect.

    Incorrect. MANAGE GRANTS does not replace object OWNERSHIP for replication and failover group administration, and it does not negate the broad authority of ACCOUNTADMIN. Also, removing ACCOUNTADMIN from all users is an organizational staffing decision, not a technical control that changes the built-in capabilities of the ACCOUNTADMIN role itself. This option confuses grant administration with object ownership and overstates the ability to restrict ACCOUNTADMIN.

  • C. Incorrect.

    Incorrect. SECURITYADMIN is powerful for role and grant management, but there is no requirement that only system-defined roles can securely own replication groups or failover groups. In Snowflake, using custom roles for ownership is a best practice because it supports least privilege and separation of duties. Choosing SECURITYADMIN by default would often grant broader powers than necessary.

  • D. Incorrect.

    Incorrect. USAGE on databases does not confer ownership or administrative control over replication groups or failover groups. These group objects require their own creation/management privileges and are governed separately from database object access. This distractor reflects a common misconception that access to replicated content automatically implies control over the replication container or failover configuration.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam