SnowPro Advanced: Security Engineer Question 296
Single answerUse Snowflake Trust Center resources to support compliance and security:A security engineer is preparing evidence for an upcoming customer audit. The customer has asked for documentation showing Snowflake's third-party compliance attestations and current service security posture, but the engineer must avoid opening a support case or collecting information from multiple external sources. Which Snowflake resource should the engineer use first to most efficiently obtain this information?
- A
Snowflake Trust Center, because it centralizes security, privacy, compliance, and service-related trust resources for customer review
- B
Snowsight Query History, because it contains a record of administrative actions and can be exported as formal compliance evidence
- C
ACCOUNT_USAGE views, because they expose Snowflake's internal audit certifications and penetration test reports for each account
- D
The network policy configuration pages, because they include Snowflake's SOC reports and regulatory attestations alongside allowed IP rules
Show answer and explanation
Correct answer: A
Explanation
The best answer is Snowflake Trust Center. When customers, auditors, or procurement teams request information about Snowflake's security program, compliance posture, privacy commitments, or service trust materials, the Trust Center is the intended starting point. It helps security teams efficiently access relevant trust resources without relying on product telemetry views, query logs, or unrelated configuration pages. This aligns with Snowflake best practices for customer due diligence and audit support: use official trust and compliance resources for platform-level attestations, and use account-level views such as ACCOUNT_USAGE only for evidence about the customer's own environment. Candidates should distinguish between Snowflake corporate trust documentation and customer account operational data.
- A. Correct.
Correct. Snowflake Trust Center is the primary customer-facing resource for trust-related information, including security, privacy, compliance, and service-related documentation. In a real audit-preparation scenario, this is the most efficient first place to look when a customer requests Snowflake attestations and high-level security posture information. It is designed specifically to help customers evaluate Snowflake's controls and compliance standing without piecing together information from unrelated product areas.
- B. Incorrect.
Incorrect. Query History is useful for reviewing SQL activity and operational behavior inside a Snowflake account, but it is not the appropriate source for Snowflake corporate compliance attestations such as SOC reports or security trust materials. Someone might choose this option because audit evidence often involves logs, but this request is about Snowflake's own trust and compliance documentation, not the customer's account activity.
- C. Incorrect.
Incorrect. ACCOUNT_USAGE provides metadata and operational telemetry about usage, access, and governance within a customer's Snowflake environment. It does not expose Snowflake corporate audit certifications, independent attestations, or penetration test reports as account-level views. This distractor reflects a common misconception that all security evidence can be retrieved from system views.
- D. Incorrect.
Incorrect. Network policy pages are used to restrict network access to Snowflake and manage allowed or blocked IP rules. They do not serve as a repository for compliance reports or third-party attestations. A candidate might pick this because network controls are part of security posture, but they are unrelated to obtaining Snowflake trust documentation.