SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 255 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 255

Select 3Map evidence to security frameworks (such as GDPR, HIPAA, etc.)

A healthcare analytics company stores protected health information (PHI) in Snowflake and is preparing for both a HIPAA audit and a GDPR readiness assessment. The security engineer must present evidence from Snowflake that demonstrates access to sensitive data is restricted and auditable. Which TWO pieces of evidence are the most appropriate to map directly to these framework expectations?

  1. A

    Query ACCOUNT_USAGE.ACCESS_HISTORY and relevant GRANTS metadata to show which roles accessed sensitive objects and how privileges were assigned

  2. B

    Provide a list of all virtual warehouses and their sizes to demonstrate that compute resources were segregated for regulated workloads

  3. C

    Export masking policy, row access policy, and tag assignments on PHI/PII-related columns and tables to show data protection controls are enforced at query time

  4. D

    Show that Time Travel is enabled on regulated tables because it is the primary Snowflake control for proving least-privilege access under HIPAA and GDPR

  5. E

    Provide network policy configuration and login history to show that user access to Snowflake was restricted and authentication events were auditable

Show answer and explanation

Correct answers: A, C, E

Explanation

The best evidence for mapping Snowflake controls to HIPAA and GDPR in this scenario is evidence that directly demonstrates restricted access to sensitive data and the ability to audit that access. In Snowflake, this commonly includes: (1) metadata and history views such as ACCOUNT_USAGE.ACCESS_HISTORY, LOGIN_HISTORY, and grant/role metadata; (2) policy-based controls such as masking policies and row access policies; and (3) supporting governance metadata such as tags used to identify PHI or PII. These artifacts are more defensible in an audit than general infrastructure details like warehouse sizing.

HIPAA emphasizes safeguards including access controls and audit controls, while GDPR expects organizations to implement appropriate technical and organizational measures to protect personal data and demonstrate accountability. Snowflake documentation on access control, masking policies, row access policies, tags, network policies, and Account Usage views supports using these features as evidence sources. In practice, security engineers often assemble control evidence by combining policy definitions, privilege assignments, and historical access/authentication data rather than relying on platform configuration details that do not directly prove enforcement.

  • A. Correct.

    Correct. ACCESS_HISTORY can help demonstrate which objects were accessed and by whom, while GRANTS-related metadata helps show how privileges were assigned through roles. Together, these are strong forms of evidence for framework requirements around access control, accountability, and auditability. For HIPAA, this aligns with audit controls and access management expectations. For GDPR, it supports demonstrating appropriate technical and organizational measures and controlled access to personal data.

  • B. Incorrect.

    Incorrect. Warehouse size and inventory may be useful for operational architecture discussions, but they are not strong direct evidence for framework controls related to restricting or auditing access to PHI or personal data. Segregated compute does not, by itself, prove access control effectiveness or auditability.

  • C. Correct.

    Correct. Masking policies, row access policies, and object tagging are strong pieces of evidence for demonstrating protection of sensitive data. Masking and row access policies show that Snowflake enforces data access restrictions at query time based on role or context. Tags help classify regulated data and support control mapping, reporting, and governance workflows for GDPR and HIPAA evidence collection.

  • D. Incorrect.

    Incorrect. Time Travel is a data recovery and historical data feature, not a primary control for least privilege, access restriction, or user audit evidence. A candidate might choose this because it sounds related to governance or retention, but it does not directly prove that access to PHI or PII was restricted or auditable in the way auditors typically expect.

  • E. Correct.

    Correct. Network policies and login history are appropriate evidence for showing restricted access paths and auditable authentication activity. Network policies help demonstrate that access to Snowflake is limited to approved network locations, while login history supports evidence of authentication attempts and user access events. This maps well to security framework expectations around access restriction, monitoring, and audit trails.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam