SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 211 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 211

Single answerConfigure replication groups to include critical security objects

A financial services company is setting up cross-region disaster recovery for its Snowflake account. The security team requires that, during failover, the secondary account already contain the account-level security configuration needed to enforce access controls without manual reconfiguration. Specifically, they need failover support for users, roles, grants, network policies, and masking/row access policies stored in a dedicated governance database. Which configuration best meets this requirement?

  1. A

    Create a failover group that includes the governance database and account objects, then replicate and refresh the failover group to the target account.

  2. B

    Create a database replication configuration for the governance database only, because users, roles, and network policies are automatically recreated in the target account during failover.

  3. C

    Create a replication group for account objects only, because masking policies and row access policies are account-level objects and do not need database replication.

  4. D

    Use object cloning to copy the governance database and security roles into the target account, then enable replication later only for network policies.

Show answer and explanation

Correct answer: A

Explanation

For disaster recovery of security configuration across accounts/regions, Snowflake best practice is to use a failover group when both account objects and databases must be protected together. Account objects relevant to security can include users, roles, and network policies, while masking policies and row access policies reside inside databases/schemas and therefore require the containing database to be included as well. Database replication by itself is insufficient for preserving account-level security objects. This question tests the distinction between account objects and database objects, and the practical requirement to group them correctly for failover. Refer to Snowflake documentation on replication and failover groups, especially supported account objects and the difference between database replication and failover group replication.

  • A. Correct.

    Correct. To protect critical security objects for cross-region/account failover, Snowflake uses a failover group, not just database replication. A failover group can include both databases and supported account objects such as users, roles, and network policies. Because masking policies and row access policies are schema-level objects stored in a database, the governance database containing those policies must also be included. Replicating and refreshing the failover group ensures the secondary account has the required security configuration ready for failover.

  • B. Incorrect.

    Incorrect. Replicating only the database would move database-contained objects such as masking policies and row access policies, but it would not provide account-level objects like users, roles, and network policies in the secondary account. Those objects are not automatically recreated there simply because a database is replicated. This is a common misunderstanding when teams assume database replication covers account security posture.

  • C. Incorrect.

    Incorrect. Users, roles, and network policies are account objects and can be included in a failover group, but masking policies and row access policies are not account-level objects. They are database objects defined within schemas. Therefore, account-object replication alone would omit the governance database and its policies, leaving an incomplete security configuration after failover.

  • D. Incorrect.

    Incorrect. Cloning is not the right mechanism for cross-account disaster recovery of security configuration in this scenario. Cloning does not replace replication/failover design for business continuity, and it does not provide the managed, refreshable DR behavior required for ongoing synchronization. This option also incorrectly suggests roles can simply be copied into another account using cloning.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam