SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 29 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 29

Single answerImplement authenticators, passkeys, and IdP-driven access

A company uses Microsoft Entra ID as its corporate identity provider and wants to centralize access to Snowflake through the IdP. Security requirements are: users must start from the corporate portal, MFA must be enforced by the IdP, and no Snowflake-native passwords should be used for these employees. The security team is also piloting phishing-resistant sign-in for browser-based Snowflake access using passkeys. Which configuration best meets these requirements?

  1. A

    Configure federated authentication with Entra ID using an external browser authenticator for users, disable Snowflake passwords for those users, and allow passkey/WebAuthn sign-in for supported browser flows.

  2. B

    Configure key-pair authentication for all human users, because key pairs provide MFA-equivalent security and still allow users to begin from the corporate portal.

  3. C

    Keep Snowflake passwords enabled as a fallback, configure SSO optionally, and require users to add a second Snowflake factor instead of enforcing MFA in Entra ID.

  4. D

    Use programmatic OAuth only for employee access, because OAuth eliminates the need for SAML federation and supports interactive sign-in from the corporate portal for all users.

Show answer and explanation

Correct answer: A

Explanation

The best answer is to use enterprise federation with the corporate IdP so that authentication and MFA policy are enforced centrally and users access Snowflake through IdP-driven SSO. In Snowflake, this is commonly paired with the external browser authenticator for interactive SSO flows. If the organization does not want employees using Snowflake-native passwords, those passwords should not remain as the normal sign-in method for those federated users. For browser-based phishing-resistant authentication, passkeys built on WebAuthn/FIDO2 are the right direction for supported sign-in experiences. Snowflake best practices distinguish between interactive user authentication methods such as SSO/federation and browser authenticators, versus programmatic methods such as key-pair authentication and OAuth for application use cases. Relevant Snowflake documentation includes topics on federated authentication/SSO, authentication policies and authenticators, and passkeys/WebAuthn support for user sign-in.

  • A. Correct.

    Correct. IdP-driven access for workforce users is typically implemented with federated authentication to Snowflake through the enterprise IdP. Using the external browser authenticator supports browser-based SSO flows that redirect users to the IdP, where MFA can be enforced centrally. If the requirement is to avoid Snowflake-native passwords, administrators can disable password-based sign-in for those federated users. For phishing-resistant sign-in, passkeys/WebAuthn are appropriate for supported browser experiences and align with modern strong authentication practices.

  • B. Incorrect.

    Incorrect. Key-pair authentication is intended for programmatic clients and service-style authentication patterns, not for general interactive workforce sign-in from a corporate identity portal. It also does not satisfy the requirement that users start from the IdP portal with MFA enforced there. A common misconception is treating key pairs as a replacement for interactive federation; they are not equivalent.

  • C. Incorrect.

    Incorrect. This conflicts directly with the stated requirement to avoid Snowflake-native passwords for employees. While some organizations keep local passwords for break-glass scenarios, that is not what this requirement asks for. It also shifts MFA responsibility away from the IdP, undermining centralized access policy enforcement.

  • D. Incorrect.

    Incorrect. OAuth is useful for delegated authorization and some application integration scenarios, but it is not a blanket replacement for workforce SAML/SSO federation for all interactive employee access. Using only programmatic OAuth would not be the standard way to satisfy portal-initiated enterprise user sign-in requirements across the workforce.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam