SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 228 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 228

Single answerExecute replication and failover operations:

An enterprise uses Snowflake Business Critical Edition and has configured a secondary account in another region for disaster recovery. The security team must be able to promote the secondary account during a regional outage with minimal manual intervention, while ensuring that only approved administrators can perform the operation. The primary account contains replicated failover groups with users, roles, grants, warehouses, resource monitors, and databases. During a planned test, the team discovers that a senior analyst with ACCOUNTADMIN can view the replicated objects but should not be allowed to execute failover. Which role configuration best satisfies the requirement?

  1. A

    Grant OWNERSHIP on the replicated databases in the secondary account to a custom DR_ADMIN role, because database ownership is sufficient to run account-level failover.

  2. B

    Grant the FAILOVER privilege on the failover group to a custom DR_ADMIN role in the secondary account, and assign that role only to approved administrators.

  3. C

    Grant REPLICATION privilege on the primary failover group to the analyst's role, because REPLICATION also permits failover of the secondary account.

  4. D

    Grant IMPORTED PRIVILEGES on the replicated databases to a custom DR_ADMIN role, because imported privileges allow promotion of secondary objects during an outage.

Show answer and explanation

Correct answer: B

Explanation

In Snowflake, executing disaster recovery promotion is governed by privileges specific to replication and failover objects. For failover groups, a role in the secondary account must have the FAILOVER privilege to perform a failover. This allows organizations to separate visibility of replicated objects from authority to promote them, which is important for security governance and least privilege. ACCOUNTADMIN visibility or broad account-level power does not change the best-practice design: use a dedicated administrative role for DR actions and grant only the required privilege. Snowflake documentation on replication and failover groups distinguishes REPLICATION from FAILOVER privileges and describes how failover groups replicate account objects such as users, roles, grants, warehouses, resource monitors, and databases.

  • A. Incorrect.

    Incorrect. OWNERSHIP on replicated databases does not authorize execution of failover for a failover group. Failover is controlled through privileges on the replication/failover object itself, not merely by owning contained databases. This option reflects a common misunderstanding between object ownership and administrative control of replication topology.

  • B. Correct.

    Correct. To execute a failover, the role must have the FAILOVER privilege on the failover group in the target secondary account. Assigning this privilege to a dedicated DR_ADMIN role and limiting that role to approved administrators follows least-privilege principles and supports controlled disaster recovery operations.

  • C. Incorrect.

    Incorrect. REPLICATION and FAILOVER are distinct privileges. REPLICATION allows refresh/synchronization operations for replicated objects, but it does not by itself authorize promotion of a secondary during failover. This option is plausible because both privileges relate to replication features, but Snowflake separates them intentionally for operational control.

  • D. Incorrect.

    Incorrect. IMPORTED PRIVILEGES applies to using privileges from shared databases and is not the mechanism for promoting replicated databases or failover groups. It does not grant authority to perform failover operations. This distractor targets confusion between data sharing concepts and replication/failover administration.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam