SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 295 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 295

Single answerDefine, enable, and automate audit policies to support compliance reporting

A financial services company must demonstrate to auditors that privileged access to sensitive data is being monitored continuously and that evidence can be produced monthly without manual querying. The security engineer wants a Snowflake-native solution that captures access events for regulated tables and automates evidence collection for compliance reports. Which approach best meets these requirements?

  1. A

    Create an audit policy for the sensitive tables, attach it to the relevant objects, and use a scheduled task to query the audit event data and store monthly results in a reporting table.

  2. B

    Enable query history retention on the account and ask auditors to use Snowsight history pages each month because this provides built-in evidence of access to sensitive tables.

  3. C

    Create a masking policy on the sensitive columns and schedule a task to export masking policy definitions monthly, because masking policies serve as the audit trail for privileged access.

  4. D

    Grant the SECURITYADMIN role access to ACCOUNT_USAGE views and create a monthly manual process to download login history, because login events alone satisfy table-level access auditing requirements.

Show answer and explanation

Correct answer: A

Explanation

The best answer is to use a Snowflake-native audit policy on the sensitive data objects and automate extraction or summarization of the resulting audit event data with a task. This directly supports the full lifecycle in the objective: define the audit policy, enable it on the relevant resources, and automate compliance reporting. In practice, security engineers commonly combine auditing controls with scheduled SQL tasks and reporting tables so evidence is generated consistently for auditors. By contrast, query history, login history, and masking policies each address related but different concerns: operational investigation, authentication monitoring, and data protection. They are not substitutes for formal auditing of regulated data access. Candidates should recognize the distinction between preventive controls such as masking policies and detective controls such as audit policies, as well as the importance of automation for recurring compliance reporting.

  • A. Correct.

    Correct. This approach aligns with the requirement to define, enable, and automate audit controls for compliance reporting. An audit policy is the Snowflake-native mechanism used to monitor access events for protected objects. Associating the policy with the relevant tables enables event capture where it matters, and using a scheduled task to persist or summarize the resulting audit event data creates repeatable, automated evidence for auditors. This is the most complete option because it covers policy definition, activation, and automated reporting.

  • B. Incorrect.

    Incorrect. Query history can help investigate activity, but relying on account history retention and manual review in Snowsight is not the same as implementing a formal audit policy. It also does not satisfy the requirement for automated monthly evidence collection. This option reflects a common misconception that general history views are a substitute for purpose-built auditing controls and automation.

  • C. Incorrect.

    Incorrect. Masking policies control data exposure at query time, but they are not audit policies and do not by themselves create a compliance-focused audit trail of privileged access events. Exporting masking policy definitions shows how data is protected, not who accessed the regulated tables or when they did so. This confuses preventive controls with detective auditing controls.

  • D. Incorrect.

    Incorrect. Login history is useful for authentication monitoring, but it does not provide the required table-level evidence of access to sensitive data. In addition, the process described is manual, which conflicts with the requirement to automate evidence production. This option reflects the misconception that account authentication logs alone are sufficient for data access compliance reporting.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam