SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 28 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 28

Single answer1.2 Configure and monitor user authentication and session management.

A company uses Snowflake with federated SSO through an external identity provider for all human users. Security has identified two issues: some users can still authenticate with a Snowflake-managed password if they know it, and administrators want to reduce the risk of abandoned interactive sessions remaining active for too long in Snowsight and other SQL clients. The company wants a solution that enforces SSO for these users while minimizing disruption to service accounts that use key-pair authentication. Which configuration change best meets these requirements?

  1. A

    Set the authentication policy for the affected users to require SAML authentication and configure shorter session idle timeout settings for interactive sessions.

  2. B

    Disable all passwords at the account level and reduce the network policy session timeout so every client, including key-pair service accounts, must reauthenticate more frequently.

  3. C

    Create a password policy with stronger complexity rules and apply it to all users, then configure a session policy only for service accounts.

  4. D

    Enable MFA at the Snowflake account level and keep both password and SSO authentication methods available for users in case the identity provider is unavailable.

Show answer and explanation

Correct answer: A

Explanation

The best answer is to combine an authentication policy with a session policy. In Snowflake, authentication policies are designed to control which authentication methods users can use, making them the correct mechanism when an organization wants to enforce federated authentication and prevent fallback to Snowflake-native password sign-in for a set of users. Session policies are the correct mechanism for controlling session behavior such as idle timeouts, which helps reduce risk from abandoned sessions in Snowsight and SQL clients. This is a more precise and operationally safe solution than broad account-level changes.

Why the other options are wrong: network policies control network access by IP range, not session duration; password policies strengthen passwords but do not enforce SSO; and MFA alone does not remove the password-based fallback path. From a best-practice perspective, Snowflake recommends using the appropriate policy type for the control objective: authentication policies for login method restrictions, password policies for password governance, network policies for source network restrictions, and session policies for session management.

  • A. Correct.

    Correct. An authentication policy can be used to restrict which authentication methods are allowed for users, including requiring federated/SAML-based sign-in rather than allowing Snowflake password authentication. A session policy can then be used to reduce idle session duration for interactive access patterns, helping limit exposure from unattended sessions. This approach is targeted and avoids unnecessarily impacting service accounts that authenticate with key pairs.

  • B. Incorrect.

    Incorrect. Snowflake does not use a network policy to control session timeout behavior; network policies restrict allowed IP addresses. Also, disabling passwords at the account level is broader than necessary and could create operational issues. The scenario specifically calls for preserving service accounts that use key-pair authentication, not forcing all clients into the same reauthentication pattern.

  • C. Incorrect.

    Incorrect. A password policy only governs password composition, reuse, lockout, and related password controls; it does not prevent users from authenticating with a Snowflake-managed password when password authentication is still allowed. Applying a session policy only to service accounts misses the stated need to shorten interactive user sessions.

  • D. Incorrect.

    Incorrect. MFA can strengthen authentication, but it does not satisfy the requirement to prevent users from falling back to Snowflake-managed passwords if those passwords remain enabled. Keeping both methods available directly conflicts with the requirement to enforce SSO for the affected users. In addition, account-wide MFA is not the most precise solution for the scenario described.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam