SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 273 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 273

Single answerCompare and contrast the benefits and consequences of enabling or disabling Snowflake security services and features:

A financial services company stores highly sensitive customer data in Snowflake and uses both internal users and third-party BI tools. After a security review, the team proposes two changes to reduce friction for analysts and service accounts: (1) disable the NETWORK POLICY currently attached to a service user because the BI vendor's IP ranges change frequently, and (2) disable MFA enforcement for internal users because they already authenticate with username and password. The Security Engineer must evaluate the security impact and recommend the most appropriate response. Which option best compares the benefits and consequences of disabling these security features in Snowflake?

  1. A

    Disabling the NETWORK POLICY and MFA is low risk because Snowflake encrypts data by default, so access controls remain sufficiently protected.

  2. B

    Disabling the NETWORK POLICY may improve connectivity for the BI tool, but it broadens the allowed source locations for login attempts; disabling MFA for internal users reduces authentication assurance and increases account compromise risk.

  3. C

    Disabling the NETWORK POLICY affects only data plane traffic between virtual warehouses and storage, not user authentication, while disabling MFA mainly impacts Snowsight access but not SQL clients.

  4. D

    Disabling MFA for internal users is acceptable if users have strong passwords, but disabling the NETWORK POLICY is not because Snowflake requires a network policy on all service users.

Show answer and explanation

Correct answer: B

Explanation

The best answer is Option 2 because it correctly evaluates the tradeoff between usability and security for two Snowflake security features. NETWORK POLICY is used to restrict login access based on source IP addresses. Disabling it can reduce operational friction for clients with changing egress IPs, but it also removes an important layer of perimeter-style access control. MFA is a key authentication hardening measure for human users; disabling it weakens protection against credential theft and phishing-related compromise.

In Snowflake security best practices, controls such as MFA, network policies, SSO/federation, least privilege, and continuous monitoring are complementary. Encryption does not compensate for weakened authentication controls. Similarly, strong passwords alone do not provide the same protection as MFA. For service users, organizations often use network policies, key-pair authentication, and tightly scoped roles to reduce risk. For human users, MFA and federated authentication are generally preferred.

These points align with Snowflake documentation and best practices around network policies, MFA, and layered security: network policies help restrict where authentication attempts can originate, while MFA strengthens user authentication. The practical exam takeaway is to recognize the benefit of disabling a feature for operability and the security consequence that follows, then recommend compensating controls if an exception is necessary.

  • A. Incorrect.

    Incorrect. Snowflake's default encryption at rest and in transit does not replace preventive access controls such as network policies and MFA. Encryption protects data confidentiality, but disabling network restrictions and stronger authentication increases the attack surface for unauthorized access. A common misconception is to treat encryption as sufficient compensation for weakened authentication and network controls.

  • B. Correct.

    Correct. A NETWORK POLICY restricts authentication attempts based on allowed or blocked IP addresses, so disabling it can make integrations easier when vendor IP ranges are unstable, but it also allows logins from a broader set of source locations. MFA adds a second factor and materially improves login security for human users; disabling it lowers identity assurance and increases the likelihood that stolen passwords could be used successfully. This option accurately contrasts operational convenience with the resulting security consequences.

  • C. Incorrect.

    Incorrect. NETWORK POLICY is relevant to client connection and authentication source IP evaluation, not just internal Snowflake service traffic. Also, MFA is not limited to Snowsight alone in the way described; the statement oversimplifies how authentication controls apply and misrepresents the scope of both features.

  • D. Incorrect.

    Incorrect. Strong passwords are not a substitute for MFA, especially for users with access to sensitive regulated data. In addition, Snowflake does not require a network policy on all service users by default. Organizations may choose to apply network policies as a best practice, but this is not a universal platform requirement. This distractor reflects two common errors: overestimating passwords and assuming mandatory enforcement where Snowflake provides optional security controls.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam