SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 212 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 212

Single answerReplicate network policies to maintain consistent access controls

A global enterprise uses Snowflake Business Critical Edition with account replication and failover groups between a primary production account in AWS us-east-1 and a secondary account in AWS us-west-2. The security team enforces inbound access restrictions by assigning a network policy to the account in the primary region. During a disaster recovery exercise, users are able to connect to the secondary account from IP addresses that should have been blocked in production. The company wants consistent access controls after failover with the least operational overhead. Which action should the Security Engineer take?

  1. A

    Add the network policy object to the failover group so it replicates with the rest of the account-level security configuration, then ensure the policy is assigned appropriately in the target account after failover.

  2. B

    Create the same network policy manually in the secondary account and rely on object replication to keep future IP allowlists and blocklists synchronized automatically.

  3. C

    Configure a session policy instead of a network policy because session policies are replicated automatically across accounts in a failover group.

  4. D

    Replicate users and roles only; the network policy assignment will be inherited automatically when users authenticate to the secondary account.

Show answer and explanation

Correct answer: A

Explanation

The scenario is about maintaining consistent IP-based access restrictions during account failover. In Snowflake, network policies are used to restrict access by client IP address using allowed and blocked lists. In a business continuity design that uses account replication and failover groups, security engineers should include relevant security objects such as network policies in the replication strategy rather than recreating them manually in each account. That reduces configuration drift and improves the likelihood that the secondary environment enforces the same controls after failover. The key misconception in the wrong answers is confusing replication of identity objects or session controls with replication of network-based ingress controls. Snowflake documentation on replication/failover groups and network policies supports using replication to maintain consistent security configuration across primary and secondary accounts, while also validating account-level assignments during DR testing.

  • A. Correct.

    Correct. Network policies are securable objects that can be included in replication/failover configurations so the policy definition can be available in the secondary account. For DR consistency, the practical approach is to replicate the network policy and verify how it is applied in the target account during failover. This minimizes manual drift and supports consistent IP-based access controls across regions.

  • B. Incorrect.

    Incorrect. Manually creating a matching network policy in the secondary account may work initially, but it increases operational overhead and creates drift risk. Object replication does not automatically synchronize two separately created objects just because they have the same name. The replicated object must be part of the configured replication/failover scope.

  • C. Incorrect.

    Incorrect. Session policies control session behavior such as idle timeout and are not a replacement for IP-based ingress controls. They do not solve the problem of restricting client source IP addresses. Choosing a session policy here reflects confusion between connection-origin controls and session-governance controls.

  • D. Incorrect.

    Incorrect. Replicating users and roles does not cause network policy definitions or assignments to appear automatically in the secondary account. Network policies are separate security objects, and access restrictions based on source IP must be explicitly handled through network policy replication and assignment.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam