SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 287 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 287

Single answerCredit consumption of advanced features, for example AI, Snowpark and Container Services

A security engineering team at a healthcare company is rolling out several new capabilities in Snowflake: analysts will use Cortex AI functions to summarize support cases, data scientists will run Snowpark Python workloads, and an internal security tool will be deployed with Snowpark Container Services. Management asks the security lead to recommend the MOST accurate way to control and attribute credit consumption for these advanced features without disrupting production. Which approach should the security lead recommend?

  1. A

    Require each workload to run under a dedicated warehouse, because Cortex AI functions, Snowpark Python processing, and Snowpark Container Services all consume credits exclusively through virtual warehouses.

  2. B

    Use resource monitors only, because they can directly stop all Cortex AI, Snowpark, and Container Services usage regardless of whether compute is warehouse-based or service-based.

  3. C

    Separate chargeback and monitoring by feature: track warehouse-backed consumption for Snowpark jobs with warehouse metering, and use organization/account usage views to monitor service-specific consumption for features such as Cortex AI and Snowpark Container Services.

  4. D

    Prevent excess spend by granting only the SECURITYADMIN role access to AI, Snowpark, and Container Services, since limiting role access is the primary mechanism for controlling compute credit consumption.

Show answer and explanation

Correct answer: C

Explanation

The key exam concept is that advanced Snowflake features do not all consume credits in the same way. A Security Engineer should understand both access control and cost attribution. Snowpark often runs with warehouse-backed compute, so warehouse metering, warehouse isolation, and resource monitors can help govern those costs. However, advanced services such as Cortex AI and Snowpark Container Services may incur service-specific compute charges that are tracked separately from traditional warehouse usage. Therefore, the best practice is to combine least-privilege access controls with feature-appropriate monitoring using Snowflake Account Usage or Organization Usage views and billing data rather than assuming all costs flow through warehouses. This aligns with Snowflake guidance on distinguishing warehouse consumption from service consumption and using usage views for chargeback, monitoring, and governance.

  • A. Incorrect.

    Incorrect. This reflects a common misconception that all advanced features are billed only through virtual warehouses. Snowpark workloads may use warehouses in many cases, but service-based features such as Cortex AI functions and Snowpark Container Services have their own billing and metering patterns and are not controlled exclusively through standard warehouse assignment.

  • B. Incorrect.

    Incorrect. Resource monitors are useful for warehouse credit governance, but they do not provide universal control over every type of Snowflake service consumption. Advanced services such as AI-related functions and Container Services can incur service-specific charges that are not fully governed by warehouse resource monitors alone.

  • C. Correct.

    Correct. This is the most accurate recommendation. In practice, Snowflake credit consumption must be attributed based on how the feature is billed. Snowpark processing may be warehouse-backed and therefore observable through warehouse metering and controllable with warehouse governance mechanisms. By contrast, Cortex AI and Snowpark Container Services can have service-specific usage and should be monitored through the appropriate account or organization usage views and billing data. This supports practical chargeback and governance without assuming one control model fits every feature.

  • D. Incorrect.

    Incorrect. RBAC helps restrict who can use costly features, which is important from a security and governance perspective, but it is not the primary metering or credit-control mechanism. Limiting access alone does not provide accurate attribution or monitoring of actual consumption, and assigning all access to SECURITYADMIN would violate least-privilege best practices.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam