SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 208 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 208

Single answerManage replication protocols and policies:

A global company uses Snowflake Business Critical Edition and has an account in AWS us-east-1 for production. The security team must maintain a warm standby account in AWS us-west-2 so that security-related objects can be activated quickly during a regional outage. Their requirements are: (1) replicate role-based access controls and grants, (2) replicate masking and row access policies used by protected tables, and (3) avoid manually recreating these objects in the secondary account. Which approach best meets these requirements?

  1. A

    Create a replication group in the primary account that includes the relevant databases and account objects, add the security integration objects to the group, and replicate it to the target account in us-west-2.

  2. B

    Create a failover group in the primary account that includes the protected databases and supported account objects such as users, roles, grants, and network policies, then replicate the failover group to the target account in us-west-2.

  3. C

    Enable database replication for each protected database because database replication automatically includes all account-level security objects referenced by those databases.

  4. D

    Use Secure Data Sharing to expose the protected databases to the standby account because shares preserve all security policies and role grants from the provider account.

Show answer and explanation

Correct answer: B

Explanation

The best answer is to use a failover group. For a realistic warm standby design, Snowflake failover groups support replication and failover of a set of databases together with certain supported account objects, which is what makes them suitable for preserving security posture across accounts. Database objects such as masking policies and row access policies are replicated with their databases because they are schema-level objects. However, RBAC continuity requires account-level objects such as roles, users, and grants, which are not fully covered by database replication alone. Secure Data Sharing is for cross-account data access, not replication of security configuration or failover readiness. In Snowflake documentation, best practices distinguish database replication from failover groups: database replication is scoped to database-contained objects, while failover groups are intended for broader business continuity by including both databases and supported account objects.

  • A. Incorrect.

    Incorrect. Replication groups are used for replicating specific account-level objects, but the scenario requires both databases and account objects together for a warm standby/failover-style design. In Snowflake, failover groups are the mechanism intended to replicate and fail over a collection of supported objects including databases and certain account objects such as users, roles, and grants. Also, not all security-related objects are supported simply by 'adding security integrations' in the way described here.

  • B. Correct.

    Correct. Failover groups are designed for business continuity scenarios and can replicate supported databases plus supported account objects across accounts in different regions/clouds when organization and edition requirements are met. This is the appropriate approach when the goal is to avoid manual recreation of role/grant structures and related supported security objects in a standby account. Because masking policies and row access policies are schema/database objects, they are replicated with the database objects that contain them, while supported account objects like users, roles, and grants are handled through the failover group configuration.

  • C. Incorrect.

    Incorrect. Database replication covers database-contained objects, which includes schema-level policy objects such as masking policies and row access policies, but it does not automatically include account-level objects like users, roles, and many grants required for full RBAC continuity. A common misconception is that database replication alone is enough for disaster recovery of security configuration; in practice, account objects must be handled through supported account object replication mechanisms such as failover groups.

  • D. Incorrect.

    Incorrect. Secure Data Sharing allows data access without copying data, but it is not a replication or disaster recovery mechanism for reproducing RBAC structures, users, roles, or account-level security configuration in a standby account. Consumers use their own roles to access shared data, and shares do not transfer ownership, account-level grants, or provide warm standby failover behavior.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam