SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 210 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 210

Select 2Configure replication groups to include critical security objects

A company is preparing a disaster recovery (DR) account in a different region for a business-critical Snowflake environment. The security team must ensure that, during failover, the DR account already contains the key account-level security configuration and access-control objects needed to resume operations quickly. They want to use a replication group rather than recreate security settings manually. Which objects should be included in the replication group to meet this requirement?

  1. A

    Users, roles, and grants to roles

  2. B

    Network policies and password policies

  3. C

    Virtual warehouses and their sizes

  4. D

    Resource monitors

  5. E

    Databases and all tables

Show answer and explanation

Correct answers: A, B

Explanation

To protect critical security configuration across regions or accounts for disaster recovery, Snowflake replication groups are used to replicate account objects, especially security-related objects such as users, roles, grants, network policies, and password policies. This helps preserve identity and access controls in the target account so failover can occur with less manual intervention. Compute objects like warehouses are not replicated as security objects, and data objects such as databases/tables are handled through database replication or failover groups depending on the design. Best practice is to separate account security replication from data replication planning and ensure the replication group includes the specific security objects required for business continuity.

  • A. Correct.

    Correct. Replication groups are designed to replicate account objects, including important security principals and access-control structures such as users, roles, and grants to roles. Including these objects helps ensure that authentication and authorization mappings are available in the DR account after failover.

  • B. Correct.

    Correct. Replication groups can include critical account-level security objects such as network policies and password policies. These settings are important in a DR scenario because they preserve access restrictions and authentication-related controls without requiring manual reconfiguration.

  • C. Incorrect.

    Incorrect. Virtual warehouses are not the focus of replication groups for security-object replication. Warehouses are compute objects and are not included as critical security objects in a replication group for DR security configuration. A candidate might choose this because warehouses are required to run workloads after failover, but they are not replicated as security objects through replication groups.

  • D. Incorrect.

    Incorrect. Resource monitors are account objects, but they are not among the critical security objects typically targeted when configuring replication groups to preserve security posture for DR. This distractor is plausible because resource monitors are account-level governance objects, but they do not address the requirement to replicate core security configuration and access-control objects.

  • E. Incorrect.

    Incorrect. Databases and tables are replicated using database or failover-group capabilities for data/business continuity, not as security objects within a replication group focused on account security configuration. This option reflects a common misconception that all DR needs should be handled by one object type; in practice, account-object replication and data replication are handled separately.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam