SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 219 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 219

Single answer2.7 Manage secure replication and failover operations.

A global company uses Snowflake Business Critical Edition in AWS us-east-1 for production and has configured account failover to a secondary account in AWS us-west-2. The security team must ensure that if a regional outage occurs, applications can be redirected to the secondary account without exposing protected data or breaking key security controls. During a readiness review, the team discovers that a database containing highly sensitive customer data uses Tri-Secret Secure, several roles have grants on replicated databases, and users connect through account-level network policies. Which action should the security engineer recommend to support a secure failover with the fewest surprises during an actual event?

  1. A

    Enable replication and failover for the primary database only, because account objects such as users, roles, and network policies are automatically available after failover.

  2. B

    Configure account object replication and failover groups for the required account-level security objects, validate that customer-managed key requirements are supported in the target region/account, and test failover behavior before an outage occurs.

  3. C

    Rely on database replication alone and recreate users, roles, and network policies manually after failover, because security objects cannot be replicated between Snowflake accounts.

  4. D

    Disable Tri-Secret Secure before enabling replication, because databases protected with customer-managed keys cannot participate in cross-region replication or failover.

Show answer and explanation

Correct answer: B

Explanation

The best recommendation is to treat failover as both a data-availability and security-continuity problem. In Snowflake, database replication protects replicated databases, but secure failover often also requires replication of supported account objects through failover groups so that security posture is preserved in the secondary account. This can include items such as users, roles, grants, network policies, and other supported objects depending on the configuration. In addition, when advanced protection features such as Tri-Secret Secure are used, the security engineer must verify that the target account/region meets the relevant key-management and edition requirements. Finally, Snowflake best practice is to test replication and failover procedures before a real outage to confirm that authentication, authorization, network restrictions, and application connectivity behave as expected. These principles align with Snowflake documentation on replication and failover, failover groups, and Business Critical security features.

  • A. Incorrect.

    Incorrect. Database replication alone is not sufficient for a secure account failover scenario. While replicated databases can be made available in the secondary account, account-level objects such as users, roles, warehouses, resource monitors, network policies, and other supported securable/account objects are not simply available unless account replication is configured through a failover group. Assuming these objects appear automatically is a common misconception and can cause authentication or authorization failures during failover.

  • B. Correct.

    Correct. For secure failover, the engineer should use failover groups to replicate supported account objects needed in the secondary account and validate region/account prerequisites for encryption key management, especially when Business Critical features such as Tri-Secret Secure are involved. Testing is essential because failover readiness depends not only on database replication, but also on whether supported security objects, privileges, connectivity controls, and key-management dependencies function as expected in the target account and region.

  • C. Incorrect.

    Incorrect. Snowflake does support replication/failover of supported account objects by using failover groups. Recreating users, roles, and network policies manually increases operational risk, lengthens recovery time, and often leads to inconsistent permissions or missed controls during an incident. This option reflects an outdated or incomplete understanding of Snowflake secure replication capabilities.

  • D. Incorrect.

    Incorrect. Tri-Secret Secure does not need to be disabled just to use replication or failover. The real requirement is to ensure that the destination configuration supports the necessary encryption/key-management prerequisites and that the organization has validated compatibility for the planned topology. Disabling a key security control would weaken security rather than improve failover readiness.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam