SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 237 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 237

Select 2Verify that replicated network policies and security integrations are active and enforced on the new primary account

A Snowflake organization uses account replication and failover groups for disaster recovery. After a regional outage, a secondary account has been promoted to become the new primary account. The security engineer must verify that replicated network policies and security integrations are not only present, but actually active and enforced in the new primary account before allowing users and applications to reconnect.

Which TWO actions provide the most reliable verification?

  1. A

    Use SHOW NETWORK POLICIES and DESC SECURITY INTEGRATION to confirm the replicated objects exist, then verify the account-level network policy is assigned with SHOW PARAMETERS LIKE 'NETWORK_POLICY' IN ACCOUNT and perform a controlled login test from an allowed and a blocked source.

  2. B

    Query ACCOUNT_USAGE views to confirm the replicated network policy and security integrations were copied, and consider that sufficient proof that they are enforced in the new primary account.

  3. C

    Run SHOW PARAMETERS LIKE 'NETWORK_POLICY' IN ACCOUNT to verify the active account-level network policy assignment, and validate the security integration by performing an authentication flow test that depends on that integration, such as SSO sign-in for a SAML2 integration.

  4. D

    Assume that because the failover group successfully promoted the secondary account, all replicated security objects are automatically active and enforced with no additional verification required.

  5. E

    Execute ALTER ACCOUNT SET NETWORK_POLICY = <policy_name> on the new primary account regardless of current settings, because replication does not preserve account-level policy assignments or usable security integrations.

Show answer and explanation

Correct answers: A, C

Explanation

In a failover scenario, the key distinction is between replicated object existence and actual enforcement in the promoted account. For network policies, the engineer should verify the relevant policy exists and, more importantly, that it is actively assigned at the account level using SHOW PARAMETERS LIKE 'NETWORK_POLICY' IN ACCOUNT. Because network restrictions are enforced during connection attempts, a controlled login test from permitted and denied source locations is strong operational proof.

For security integrations, listing or describing the integration confirms configuration replication, but the best validation is an end-to-end functional test of the integration it supports, such as a SAML SSO sign-in. This reflects Snowflake administrative best practices: inspect configuration, confirm active assignment where applicable, and validate behavior using the real authentication path.

Relevant Snowflake documentation areas include account replication and failover groups, network policies, SHOW PARAMETERS / account parameters, and CREATE/DESC SECURITY INTEGRATION guidance. The exam often tests whether candidates understand that replicated metadata alone does not prove runtime enforcement.

  • A. Correct.

    Correct. This approach verifies both existence and enforcement. SHOW NETWORK POLICIES and DESC SECURITY INTEGRATION confirm the replicated objects are present and their configuration can be inspected. However, object presence alone is not enough for enforcement. Checking the account parameter with SHOW PARAMETERS LIKE 'NETWORK_POLICY' IN ACCOUNT confirms which network policy is actively assigned at the account level. A controlled connection test from an allowed and denied source is the strongest practical validation that the policy is enforced after failover.

  • B. Incorrect.

    Incorrect. Metadata visibility in ACCOUNT_USAGE or similar views can help confirm that objects were replicated, but it does not prove they are active or enforced. A network policy can exist without being assigned, and a security integration can exist but still require functional validation through an actual authentication or connectivity flow. This option reflects the common misconception that replication status equals runtime enforcement.

  • C. Correct.

    Correct. Verifying the NETWORK_POLICY account parameter confirms whether an account-level network policy is active in the promoted account. Testing the security integration through the real flow it governs, such as an SSO login for a SAML2 security integration, is the most reliable way to prove it is operational after promotion. This aligns with security best practice: validate both configuration state and end-to-end behavior.

  • D. Incorrect.

    Incorrect. Promotion of a secondary account does not eliminate the need for post-failover validation. Even when objects are replicated successfully, administrators should verify account parameter assignments and test security controls in the new primary environment. Assuming enforcement without validation is operationally risky and does not meet DR verification best practices.

  • E. Incorrect.

    Incorrect. Replication can include supported security objects, but blindly resetting the account parameter is not the best verification method and may introduce unnecessary changes during an outage. The task is to verify whether replicated controls are active and enforced, not to reconfigure them preemptively. A change should only be made if verification shows the assignment is missing or incorrect.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam