SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 265 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 265

Select 2

A Security Engineer needs to investigate whether a Snowflake account is being targeted by a password-spraying or brute-force attack against user accounts. The team wants a solution that can detect repeated failed logins from the same source over time, support manual investigation, and also feed a corporate SIEM for broader correlation with network logs. Which TWO actions best meet these requirements?

  1. A

    Query Snowflake login history to identify repeated failed authentication attempts by client IP, username, and time window, then forward the results to the SIEM using an external integration pattern.

  2. B

    Use Snowsight Trust Center security monitoring views and dashboards to review authentication-related signals, then correlate suspicious findings with account login history for deeper investigation.

  3. C

    Enable object tagging on users so failed login events are automatically blocked after a threshold and exported to the SIEM.

  4. D

    Rely only on QUERY_HISTORY because login failures are captured there even when authentication does not succeed.

  5. E

    Rotate the account master key immediately because brute-force activity against usernames is prevented only by key rotation.

Show answer and explanation

Correct answers: A, B

Explanation

The best answers are the actions that directly support both investigation and operational monitoring of authentication anomalies: reviewing login history and using Trust Center, while integrating findings with external monitoring tools such as a SIEM. In Snowflake, login history is the primary source for examining authentication attempts, including failures, timestamps, users, and client connection details relevant to brute-force and unauthorized access investigations. Trust Center in Snowsight can complement this by surfacing security posture and relevant monitoring insights. For enterprise detection and response, exporting or correlating Snowflake authentication data with external tools is a recommended practice because it enables cross-platform analysis, alerting, and incident triage. By contrast, QUERY_HISTORY is not appropriate for failed logins because no query runs if authentication never succeeds, and tagging or key rotation do not provide brute-force detection capabilities. This aligns with Snowflake best practices around monitoring access activity through account usage/login history, using Snowsight security tooling, and integrating with centralized security operations platforms.

  • A. Correct.

    Correct. Snowflake provides login history data that can be queried to investigate authentication activity, including failed logins, source IPs, users, and timestamps. This is a practical manual detection method for spotting patterns such as repeated failures from the same IP or against multiple usernames in a short interval, which are classic indicators of brute-force or password-spraying attempts. Exporting or forwarding the resulting findings to an enterprise SIEM is also a valid best practice so the security team can correlate Snowflake authentication anomalies with firewall, IdP, EDR, or VPN telemetry.

  • B. Correct.

    Correct. Trust Center in Snowsight is designed to help organizations monitor and assess security posture and investigate relevant security signals. Using Trust Center for visibility, then drilling into login history for detailed validation, is an appropriate combined approach. This reflects real-world operations: Trust Center can help highlight issues, while account-level history and SQL-based investigation provide evidence and granularity for incident response.

  • C. Incorrect.

    Incorrect. Object tagging does not provide automatic authentication blocking logic for failed logins, nor does it export failed login events to a SIEM. Tags are governance metadata used for classification and policy-based workflows, not for detecting or enforcing controls on login attempts. A candidate might choose this option if they confuse governance metadata features with runtime security monitoring and access enforcement.

  • D. Incorrect.

    Incorrect. QUERY_HISTORY tracks executed SQL statements, not failed authentication events that occur before a session is established. If login fails, there is no successful session in which a query could run, so QUERY_HISTORY is not the right source for brute-force detection. This distractor targets the common misconception that all security-relevant activity appears in query telemetry.

  • E. Incorrect.

    Incorrect. Rotating keys is unrelated to detecting or analyzing repeated failed username/password login attempts. Key rotation is important for cryptographic hygiene and protecting encrypted data, but it does not address password-spraying analysis. Someone might pick this if they broadly associate any security issue with key management, but it is not the appropriate control or monitoring action here.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam